| services.jitsi-meet.videobridge.passwordFile | File containing password to the Prosody account for videobridge
|
| services.prometheus.scrapeConfigs.*.hetzner_sd_configs.*.tls_config.ca_file | CA certificate to validate API server certificate with.
|
| services.filesender.settings.log_facilities | Defines where FileSender logging is sent
|
| networking.networkmanager.ensureProfiles.profiles.<name>.connection.type | The connection type defines the connection kind, like vpn, wireguard, gsm, wifi and more.
|
| services.nextcloud.configureRedis | Whether to configure Nextcloud to use the recommended Redis settings for small instances.
The Nextcloud system check recommends to configure either Redis or Memcache for file lock caching.
The notify_push app requires Redis to be configured
|
| services.kavita.settings | Kavita configuration options, as configured in appsettings.json.
|
| services.cyrus-imap.imapdConfigFile | Path to the configuration file used for cyrus-imap.
|
| services.jirafeau.enable | Whether to enable Jirafeau file upload application.
|
| security.isolate.extraConfig | Extra configuration to append to the configuration file.
|
| services.kubernetes.apiserver.webhookConfig | Kubernetes apiserver Webhook config file
|
| programs.neovim.runtime.<name>.text | Text of the file.
|
| services.asusd.auraConfigs.<name>.text | Text of the file.
|
| services.lemmy.database.uri | The connection URI to use
|
| services.sftpgo.loadDataFile | Path to a json file containing users and folders to load (or update) on startup
|
| services.dae.openFirewall.port | Port to be opened
|
| services.kavita.tokenKeyFile | A file containing the TokenKey, a secret with at 512+ bits
|
| boot.initrd.systemd.storePaths.*.source | Path of the source file.
|
| services.lemmy.database.uriFile | File which contains the database uri.
|
| services.asusd.asusdConfig.source | Path of the source file.
|
| services.asusd.animeConfig.source | Path of the source file.
|
| services.rke2.agentTokenFile | File path containing the rke2 token agents can use to connect to the server
|
| boot.nixStoreMountOpts | Defines the mount options used on a bind mount for the /nix/store
|
| services.acme-dns.settings | Free-form settings written directly to the acme-dns.cfg file
|
| services.portunus.seedPath | Path to a portunus seed file in json format
|
| services.filesender.settings.site_url | Site URL
|
| services.prometheus.scrapeConfigs.*.uyuni_sd_configs.*.oauth2.client_secret_file | Read the client secret from a file
|
| services.datadog-agent.apiKeyFile | Path to a file containing the Datadog API key to associate the
agent with your account.
|
| services.syncthing.key | Path to the key.pem file, which will be copied into Syncthing's
configDir.
|
| services.varnish.listen.*.mode | Permission of the socket file (3-digit octal value).
|
| services.angrr.settings.profile-policies.<name>.keep-latest-n | Keep the latest N GC roots in this profile.
|
| services.kubernetes.proxy.kubeconfig.caFile | Kubernetes proxy certificate authority file used to connect to kube-apiserver.
|
| services.sympa.settingsFile | Set of files to be linked in /var/lib/sympa.
|
| services.soft-serve.settings | The contents of the configuration file for soft-serve
|
| services.uptime.usesRemoteMongo | Whether the configuration file specifies a remote mongo instance
|
| services.gerrit.settings | Gerrit configuration
|
| services.prometheus.exporters.borgmatic.configFile | The path to the borgmatic config file
|
| services.filebrowser.settings.database | The path to FileBrowser's Bolt database.
|
| programs.tsmClient.dsmSysText | This configuration key contains the effective text
of the client system-options file "dsm.sys"
|
| services.gitea.metricsTokenFile | Path to a file containing the metrics authentication token.
|
| services.prosody.checkConfig | Check the configuration file with prosodyctl check config
|
| services.pptpd.extraPppdOptions | Adds extra lines to the pppd options file.
|
| services.oxidized.routerDB | Path to the file/database which contains the targets for oxidized.
|
| services.weblate.extraConfig | Text to append to settings.py Weblate configuration file.
|
| services.privoxy.settings.actionsfile | List of paths to Privoxy action files
|
| services.outline.sslKeyFile | File path that contains the Base64-encoded private key for HTTPS
termination
|
| boot.initrd.luks.devices.<name>.keyFile | The name of the file (can be a raw device or a partition) that
should be used as the decryption key for the encrypted device
|
| services.beesd.filesystems.<name>.verbosity | Log verbosity (syslog keyword/level).
|
| services.distccd.logLevel | Set the minimum severity of error that will be included in the log
file
|
| services.prometheus.scrapeConfigs.*.kuma_sd_configs.*.authorization.credentials_file | Sets the credentials to the credentials read from the configured file
|
| services.davfs2.davGroup | The group of the running mount.davfs daemon
|
| services.kubernetes.proxy.kubeconfig.keyFile | Kubernetes proxy client key file used to connect to kube-apiserver.
|
| services.moodle.extraConfig | Any additional text to be appended to the config.php
configuration file
|
| networking.getaddrinfo.enable | Enables custom address sorting configuration for getaddrinfo(3) according to RFC 3484
|
| services.printing.snmpConf | The contents of /etc/cups/snmp.conf
|
| services.xray.settingsFile | The absolute path to the configuration file
|
| services.monica.appKeyFile | A file containing the Laravel APP_KEY - a 32 character long,
base64 encoded key used for encryption where needed
|
| services.prometheus.exporters.unpoller.loki.pass | Path of a file containing the password for Loki
|
| services.pinchflat.secretsFile | Secrets like SECRET_KEY_BASE and BASIC_AUTH_PASSWORD
should be passed to the service without adding them to the world-readable Nix store
|
| security.auditd.settings | auditd configuration file contents
|
| services.mchprs.settings | Configuration for MCHPRS via Config.toml
|
| services.zenohd.settings | Config options for zenoh.json5 configuration file
|
| services.postfix.extraConfig | Extra lines to be added verbatim to the main.cf configuration file.
|
| services.bacula-fd.director | This option defines director resources in Bacula File Daemon.
|
| services.connman.extraConfig | Configuration lines appended to the generated connman configuration file.
|
| services.varnish.listen.*.group | Group name who owns the socket file.
|
| services.nghttpx.extraConfig | Extra configuration options to be appended to the generated
configuration file.
|
| services.guix.storeDir | The store directory where the Guix service will serve to/from
|
| boot.loader.grub.splashImage | Background image used for GRUB
|
| services.aria2.settings.conf-path | Configuration file path.
|
| services.lemmy.smtpPasswordFile | File which contains the value of email.smtp_password.
|
| programs.tsmClient.enable | Whether to enable IBM Storage Protect (Tivoli Storage Manager, TSM)
client command line applications with a
client system-options file "dsm.sys"
.
|
| services.oauth2-proxy.keyFile | oauth2-proxy allows passing sensitive configuration via environment variables
|
| boot.initrd.systemd.storePaths.*.enable | Whether to enable copying of this file and symlinking it.
|
| services.lk-jwt-service.keyFile | Path to a file containing the credential mapping (<keyname>: <secret>) to access LiveKit
|
| services.outline.sslCertFile | File path that contains the Base64-encoded certificate for HTTPS
termination
|
| services.fedimintd.<name>.nginx.config.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| boot.tmp.zramSettings.options | By default, file systems and swap areas are trimmed on-the-go
by setting "discard"
|
| services.pgmanage.sqlRoot | This tells pgmanage where to put the SQL file history
|
| services.nagios.cgiConfigFile | Derivation for the configuration file of Nagios CGI scripts
that can be used in web servers for running the Nagios web interface.
|
| services.beesd.filesystems.<name>.spec | Description of how to identify the filesystem to be duplicated by this
instance of bees
|
| programs.tsmClient.package | The tsm-client package to use
|
| services.kubernetes.proxy.kubeconfig.certFile | Kubernetes proxy client certificate file used to connect to kube-apiserver.
|
| services.autorandr.profiles.<name>.hooks.preswitch | Preswitch hook executed before mode switch.
|
| services.clight.settings | Additional configuration to extend clight.conf
|
| services.diod.allsquash | Remap all users to "nobody"
|
| services.gokapi.settings | Configuration settings for the generated config json file
|
| services.netatalk.extmap | File name extension mappings
|
| services.syncthing.cert | Path to the cert.pem file, which will be copied into Syncthing's
configDir.
|
| services.icecast.extraConfig | Extra configuration added to icecast.xml inside the <icecast> element.
|
| services.transfer-sh.enable | Whether to enable Easy and fast file sharing from the command-line.
|
| services.zerobin.extraConfig | Extra configuration to be appended to the 0bin config file
(see https://0bin.readthedocs.org/en/latest/en/options.html)
|
| services.xserver.extraConfig | Additional contents (sections) included in the X server configuration file
|
| services.forgejo.dump.age | Age of backup used to decide what files to delete when cleaning
|
| services.stash.sessionStoreKeyFile | Path to file containing a secret for session store.
|
| services.sympa.database.name | Database name
|
| services.printing.clientConf | The contents of the client configuration.
(client.conf)
|
| services.rspamd.locals.<name>.source | Path of the source file.
|
| services.uhub.<name>.plugins.*.plugin | Path to plugin file.
|
| services.nginx.sso.configuration | nginx-sso configuration
(documentation)
as a Nix attribute set
|
| services.prometheus.exporters.fritz.settings.devices.*.password_file | Path to a file which contains the password to authenticate with the target device
|