| services.tox-node.udpAddress | UDP address to run DHT node.
|
| services.pinchflat.port | Port on which the Pinchflat web interface is available.
|
| services.tailscale.derper.openFirewall | Whether to open the firewall for the specified port
|
| services.pdns-recursor.luaConfig | The content Lua configuration file for PowerDNS Recursor
|
| services.lxd-image-server.nginx.enable | Whether to enable nginx.
|
| services.tor.settings.SocksPolicy | See torrc manual.
|
| services.postfix.rootAlias | Who should receive root e-mail
|
| services.logrotate.settings.<name>.files | Single or list of files for which rules are defined
|
| services.prometheus.exporters.bind.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.bind.openFirewall is true.
|
| services.tlsrpt.reportd.settings.organization_name | Name of the organization sending out the reports.
|
| services.mattermost.package | The mattermost package to use.
|
| services.lifecycled.instanceId | The instance ID to listen for events for.
|
| services.monica.nginx.locations.<name>.uwsgiPass | Adds uwsgi_pass directive and sets recommended proxy headers if
recommendedUwsgiSettings is enabled.
|
| services.ttyd.checkOrigin | Whether to allow a websocket connection from a different origin.
|
| services.mqtt2influxdb.points.*.tags | Tags applied
|
| services.printing.browsing | Specifies whether shared printers are advertised.
|
| services.strongswan-swanctl.swanctl.authorities.<name>.cacert | The certificates may use a relative path from the swanctl
x509ca directory or an absolute path
|
| services.opendkim.user | User for the daemon.
|
| services.plausible.server.secretKeybaseFile | Path to the secret used by the phoenix-framework
|
| services.unifi.initialJavaHeapSize | Set the initial heap size for the JVM in MB
|
| services.podgrab.group | Group under which Podgrab runs, and which owns the download directory.
|
| services.lifecycled.noSpot | Disable the spot termination listener.
|
| services.locate.pruneNames | Directory components which should exclude paths containing them from indexing
|
| services.prometheus.exporters.scaphandre.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.scaphandre.openFirewall is true.
|
| services.prosody-filer.settings | Configuration for Prosody Filer
|
| services.scrutiny.settings.web.influxdb.org | InfluxDB organisation under which to store data.
|
| services.matomo.periodicArchiveProcessing | Enable periodic archive processing, which generates aggregated reports from the visits
|
| services.limesurvey.database.name | Database name.
|
| services.renovate.schedule | How often to run renovate
|
| services.prometheus.scrapeConfigs.*.metric_relabel_configs.*.action | Action to perform based on regex matching
|
| services.logcheck.extraRulesDirs | Directories with extra rules.
|
| services.thanos.store.tracing.config-file | Path to YAML file that contains tracing configuration
|
| services.mainsail.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| services.tor.settings.ClientPreferIPv6ORPort | See torrc manual.
|
| services.networkd-dispatcher.extraArgs | Extra arguments to pass to the networkd-dispatcher command.
|
| services.marytts.port | Port to bind the MaryTTS server to.
|
| services.prometheus.scrapeConfigs.*.puppetdb_sd_configs.*.oauth2.client_id | OAuth client ID.
|
| services.prometheus.remoteWrite.*.queue_config.batch_send_deadline | Maximum time a sample will wait in buffer.
|
| services.prometheus.scrapeConfigs.*.scaleway_sd_configs.*.access_key | Access key to use. https://console.scaleway.com/project/credentials
|
| services.prometheus.exporters.rtl_433.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.rtl_433.openFirewall is true.
|
| services.miredo.enable | Whether to enable the Miredo IPv6 tunneling service.
|
| services.movim.podConfig.locale | The server main locale
|
| services.taskserver.enable | Whether to enable the Taskwarrior 2 server
|
| services.restic.server.listenAddress | Listen on a specific IP address and port or unix socket.
|
| services.mediawiki.httpd.virtualHost.locations.<name>.alias | Alias directory for requests
|
| services.tor.settings.UseMicrodescriptors | See torrc manual.
|
| services.neard.settings.General.ResetOnError | Power cycle the adapter when getting a driver error from the kernel.
|
| services.prometheus.exporters.libvirt.port | Port to listen on.
|
| services.lirc.extraArguments | Extra arguments to lircd.
|
| services.prometheus.exporters.node.enabledCollectors | Collectors to enable
|
| services.namecoind.rpc.certificate | Certificate file for securing RPC connections.
|
| services.traefik.enable | Whether to enable Traefik web server.
|
| services.prometheus.exporters.unpoller.log.quiet | Whether to enable startup and error logs only.
|
| services.prometheus.exporters.klipper.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.klipper.openFirewall
is true
|
| services.redmine.components.subversion | Whether to enable Subversion integration..
|
| services.prometheus.scrapeConfigs.*.puppetdb_sd_configs.*.authorization.credentials | Sets the credentials
|
| services.redsocks.redsocks.*.port | Port on which redsocks should listen.
|
| services.prometheus.exporters.sql.configuration.jobs.<name>.startupSql | A list of SQL statements to execute once after making a connection.
|
| services.mjpg-streamer.enable | Whether to enable mjpg-streamer webcam streamer.
|
| services.neo4j.package | The neo4j package to use.
|
| services.oxidized.routerDB | Path to the file/database which contains the targets for oxidized.
|
| services.reposilite.workingDirectory | Working directory for Reposilite.
|
| services.sickbeard.configFile | Path to config file.
|
| services.prometheus.scrapeConfigs.*.scaleway_sd_configs.*.tls_config | TLS configuration.
|
| services.ocsinventory-agent.settings.tag | Tag for the generated inventory.
|
| services.tor.settings.PerConnBWBurst | See torrc manual.
|
| services.prometheus.exporters.nginxlog.openFirewall | Open port in firewall for incoming connections.
|
| services.redlib.enable | Whether to enable Private front-end for Reddit.
|
| services.ndppd.proxies.<name>.rules.<name>.network | This is the target address is to match against
|
| services.openafsClient.afsdb | Resolve cells via AFSDB DNS records.
|
| services.opensnitch.settings.ProcMonitorMethod | Which process monitoring method to use.
|
| services.outline.oidcAuthentication.userinfoUrl | OIDC userinfo URL endpoint.
|
| services.longview.apiKey | Longview API key
|
| services.spiped.config.<name>.weakHandshake | Use fast/weak handshaking: This reduces the CPU time spent
in the initial connection setup, at the expense of losing
perfect forward secrecy.
|
| services.movim.podConfig.xmppdomain | The default XMPP server domain
|
| services.opencloud.address | Web server bind address.
|
| services.nextcloud.database.createLocally | Whether to create the database and database user locally.
|
| services.nullmailer.config.doublebounceto | If the original sender was empty (the original message was a
delivery status or disposition notification), the double bounce
is sent to the address in this attribute.
|
| services.smokeping.targetConfig | Target configuration
|
| services.netbird.tunnels.<name>.dir.state | A state directory used by NetBird client to store config.json, state.json & resolv.conf.
|
| services.logrotate.configFile | Override the configuration file used by logrotate
|
| services.postfix.settings.main.mynetworks_style | The method used for generating the default value for mynetworks, if that option is unset.
https://www.postfix.org/postconf.5.html#mynetworks_style
|
| services.ncdns.dnssec.keys.private | Path to the file containing the KSK private key.
|
| services.mailman.serve.virtualRoot | Path to mount the mailman-web django application on.
|
| services.nebula.networks.<name>.listen.port | Port number to listen on.
|
| services.nextcloud-spreed-signaling.backends.<name>.urls | List of URLs of the Nextcloud instance
|
| services.ntfy-sh.package | The ntfy-sh package to use.
|
| services.patroni.postgresqlPackage | PostgreSQL package to use
|
| services.pgadmin.settings | Settings for pgadmin4.
Documentation
|
| services.prometheus.exporters.ebpf.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.ebpf.openFirewall is true.
|
| services.limesurvey.httpd.virtualHost.logFormat | Log format for Apache's log files
|
| services.peering-manager.environmentFile | Environment file as defined in systemd.exec(5)
|
| services.prometheus.exporters.idrac.listenAddress | Address to listen on.
|
| services.opensmtpd.serverConfiguration | The contents of the smtpd.conf configuration file
|
| services.sabnzbd.settings.misc.email_server | SMTP server for email alerts (server:host)
|
| services.nitter.config.proxy | URL to a HTTP/HTTPS proxy.
|
| services.public-inbox.spamAssassinRules | SpamAssassin configuration specific to public-inbox.
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.mark_out | Netfilter mark and mask for output traffic
|
| services.pdns-recursor.exportHosts | Whether to export names and IP addresses defined in /etc/hosts.
|
| services.limesurvey.httpd.virtualHost.locations.<name>.proxyPass | Sets up a simple reverse proxy as described by https://httpd.apache.org/docs/2.4/howto/reverse_proxy.html#simple.
|