| services.prometheus.exporters.exportarr-lidarr.port | Port to listen on.
|
| services.prometheus.globalConfig.query_log_file | Path to the file prometheus should write its query log to.
|
| services.movim.precompressStaticFiles.gzip.compressionLevel | Gzip compression level
|
| services.prometheus.exporters.sql.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.sql.openFirewall is true.
|
| services.novacomd.enable | Whether to enable Novacom service for connecting to WebOS devices.
|
| services.prometheus.exporters.junos-czerwonk.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.junos-czerwonk.openFirewall
is true
|
| services.syncplay.permanentRoomsFile | File with list of rooms that will be listed even if the room is empty,
newline delimited
|
| services.osquery.flags.pidfile | Path used for pid file.
|
| services.nginx.virtualHosts.<name>.listenAddresses | Listen addresses for this virtual host
|
| services.mailman.siteOwner | Certain messages that must be delivered to a human, but which can't
be delivered to a list owner (e.g. a bounce from a list owner), will
be sent to this address
|
| services.stunnel.fipsMode | Enable FIPS 140-2 mode required for compliance.
|
| services.mchprs.settings.address | Address for the server
|
| services.offlineimap.onCalendar | How often is offlineimap started
|
| services.prometheus.scrapeConfigs.*.docker_sd_configs.*.port | The port to scrape metrics from, when role is nodes, and for discovered
tasks and services that don't have published ports
|
| services.ncdns.identity.address | The IP address the hostname specified in
services.ncdns.identity.hostname should resolve to
|
| services.monit.enable | Whether to enable Monit.
|
| services.tor.settings.DisableOOSCheck | See torrc manual.
|
| services.outline.cdnUrl | If using a Cloudfront/Cloudflare distribution or similar it can be set
using this option
|
| services.prometheus.scrapeConfigs.*.metric_relabel_configs.*.source_labels | The source labels select values from existing labels
|
| services.minecraft-server.dataDir | Directory to store Minecraft database and other state/data files.
|
| services.pantalaimon-headless.instances.<name>.ssl | Whether or not SSL verification should be enabled for outgoing
connections to the homeserver.
|
| services.paretosecurity.enable | Whether to enable ParetoSecurity agent and its root helper.
|
| services.matomo.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.mihomo.configFile | Configuration file to use.
|
| services.sonarr.openFirewall | Open ports in the firewall for the Sonarr web interface
|
| services.prometheus.exporters.exportarr-bazarr.package | The exportarr package to use.
|
| services.readarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.systemd-lock-handler.enable | Whether to enable systemd-lock-handler.
|
| services.radvd.debugLevel | The debugging level is an integer in the range from 1 to 5,
from quiet to very verbose
|
| services.opengfw.rules.*.action | Action of the rule. Supported actions
|
| services.prosody.modules.tls | Add support for secure TLS on c2s/s2s connections
|
| services.synergy.client.serverAddress | The server address is of the form: [hostname][:port]
|
| services.ostinato.enable | Whether to enable Ostinato agent-controller (Drone).
|
| services.pid-fan-controller.settings.fans.*.minPwm | Minimum PWM value.
|
| services.mobilizon.settings.":mobilizon".":instance".hostname | Your instance's hostname
|
| services.suwayomi-server.settings.server.port | The port that Suwayomi will listen to.
|
| services.prometheus.remoteWrite.*.tls_config.server_name | ServerName extension to indicate the name of the server.
http://tools.ietf.org/html/rfc4366#section-3.1
|
| services.tomcat.sharedLibs | List containing JAR files or directories with JAR files which are libraries shared by the web applications
|
| services.pairdrop.package | The pairdrop package to use.
|
| services.nextcloud.notify_push.logLevel | Log level
|
| services.mjolnir.homeserverUrl | Where the homeserver is located (client-server URL)
|
| services.pihole-ftl.lists.*.url | URL of the domain list
|
| services.prometheus.exporters.bitcoin.rpcPort | RPC port number.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.oauth2.endpoint_params | Optional parameters to append to the token URL.
|
| services.send.redis.host | Redis server address.
|
| services.spice-autorandr.enable | Whether to enable spice-autorandr service that will automatically resize display to match SPICE client window size.
|
| services.udp-over-tcp.tcp2udp.<name>.bind | Which local IP to bind the UDP socket to.
|
| services.tang.ipAddressAllow | Whitelist a list of address prefixes
|
| services.oauth2-proxy.enable | Whether to enable oauth2-proxy.
|
| services.monica.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.mediawiki.package | The mediawiki package to use.
|
| services.opensearch.settings."cluster.name" | The name of the cluster.
|
| services.prometheus.exporters.borgmatic.enable | Whether to enable the prometheus borgmatic exporter.
|
| services.paisa.settings | Paisa configuration
|
| services.strongswan-swanctl.package | The strongswan package to use.
|
| services.lubelogger.openFirewall | Open ports in the firewall for the LubeLogger web interface.
|
| services.tarsnap.archives.<name>.maxbw | Abort archival if upstream bandwidth usage in bytes
exceeds this threshold.
|
| services.slurm.server.enable | Whether to enable the slurm control daemon
|
| services.prometheus.scrapeConfigs.*.docker_sd_configs.*.oauth2.client_secret | OAuth client secret.
|
| services.ntp.extraFlags | Extra flags passed to the ntpd command.
|
| services.onlyoffice.postgresUser | The username OnlyOffice should use to connect to Postgresql
|
| services.psd.enable | Whether to enable the Profile Sync daemon.
|
| services.redis.servers.<name>.slaveOf | IP and port to which this redis instance acts as a slave.
|
| services.sonarr.user | User account under which Sonarr runs.";
If left as the default value this user will automatically be created
on system activation, otherwise you are responsible for
ensuring the user exists before the Sonarr service starts.
|
| services.prefect.databaseHost | database host for postgres only
|
| services.slurm.dbdserver.extraConfig | Extra configuration for slurmdbd.conf See also:
slurmdbd.conf(8).
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.basic_auth.password | HTTP password
|
| services.osquery.flags.database_path | Path used for the database file.
If left as the default value, this directory will be automatically created before the
service starts, otherwise you are responsible for ensuring the directory exists with
the appropriate ownership and permissions.
|
| services.livebook.extraPackages | Extra packages to make available to the Livebook service.
|
| services.mail.sendmailSetuidWrapper.program | The name of the wrapper program
|
| services.prometheus.scrapeConfigs.*.kubernetes_sd_configs | List of Kubernetes service discovery configurations.
|
| services.nohang.package | The nohang package to use.
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs | List of Consul service discovery configurations.
|
| services.tomcat.user | User account under which Apache Tomcat runs.
|
| services.prometheus.exporters.nginx.group | Group under which the nginx exporter shall be run.
|
| services.outline.slackAuthentication.secretFile | File path containing the authentication secret.
|
| services.linux-enable-ir-emitter.enable | Whether to enable IR emitter hardware
|
| services.scrutiny.settings.log.level | Log level for Scrutiny.
|
| services.spiped.config.<name>.disableKeepalives | Disable transport layer keep-alives.
|
| services.nextcloud.config.objectstore.s3.secretFile | The full path to a file that contains the access secret.
|
| services.mqtt2influxdb.influxdb.ssl | Use SSL to connect to the InfluxDB server.
|
| services.tailscale.extraDaemonFlags | Extra flags to pass to tailscaled.
|
| services.tabby.usageCollection | Enable sending anonymous usage data
|
| services.pdfding.database.passwordFile | File containing POSTGRES_PASSWORD
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.basic_auth.password | HTTP password
|
| services.sftpgo.settings.smtp.host | Location of SMTP email server
|
| services.prometheus.exporters.mailman3.extraFlags | Extra commandline options to pass to the mailman3 exporter.
|
| services.maubot.extraConfigFile | A file for storing secrets
|
| services.tlsrpt.reportd.extraFlags | List of extra flags to pass to the tlsrpt-reportd executable
|
| services.nats.user | User account under which NATS runs.
|
| services.strongswan-swanctl.swanctl.secrets.xauth | EAP secret section for a specific secret
|
| services.ncps.cache.upstream.urls | A list of URLs of upstream binary caches.
|
| services.radicle.httpd.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.openssh.moduliFile | Path to moduli file to install in
/etc/ssh/moduli
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.copy_dscp | Whether to copy the DSCP (Differentiated Services Field Codepoint)
header field to/from the outer IP header in tunnel mode
|
| services.mediawiki.httpd.virtualHost.sslServerCert | Path to server SSL certificate.
|
| services.miniupnpd.natpmp | Whether to enable NAT-PMP support.
|
| services.pdfding.openFirewall | Open ports in the firewall for the PdfDing web interface.
|
| services.openafsServer.cellServDB.<name>.*.dnsname | DNS full-qualified domain name of a database server
|
| services.prometheus.exporters.sabnzbd.extraFlags | Extra commandline options to pass to the sabnzbd exporter.
|