| services.syncoid.interval | Run syncoid at this interval
|
| services.mosquitto.listeners | Listeners to configure on this broker.
|
| services.nginx.recommendedTlsSettings | Enable recommended TLS settings.
|
| services.mattermost.socket.export | Whether to enable Export socket control to system environment variables.
|
| services.mackerel-agent.settings.diagnostic | Whether to enable collecting memory usage for the agent itself.
|
| services.nsd.ratelimit.ipv6PrefixLength | IPv6 prefix length
|
| services.mediagoblin.settings.mediagoblin.sql_engine | Database to use.
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.authorization.type | Sets the authentication type
|
| services.onlyoffice.jwtSecretFile | Path to a file that contains the secret to sign web requests using JSON Web Tokens
|
| services.paisa.host | Host bind IP address.
|
| services.nebula.networks.<name>.key | Path or reference to the host key.
|
| services.thanos.store.grpc-address | Listen ip:port address for gRPC endpoints (StoreAPI)
|
| services.prometheus.exporters.ping.enable | Whether to enable the prometheus ping exporter.
|
| services.prosody.httpFileShare.size_limit | Maximum file size, in bytes.
|
| services.mediawiki.httpd.virtualHost.locations | Declarative location config
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.updown | Updown script to invoke on CHILD_SA up and down events.
|
| services.magnetico.web.credentialsFile | The path to the file holding the credentials to access the web
interface
|
| services.prometheus.scrapeConfigs.*.kubernetes_sd_configs.*.tls_config.key_file | Key file for client cert authentication to the server.
|
| services.miniupnpd.internalIPs | The IP address ranges to listen on.
|
| services.opencloud.webPackage | The web package to use.
|
| services.nginx.virtualHosts.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.prometheus.exporters.apcupsd.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.apcupsd.openFirewall is true.
|
| services.mautrix-telegram.enable | Whether to enable Mautrix-Telegram, a Matrix-Telegram hybrid puppeting/relaybot bridge.
|
| services.prometheus.exporters.chrony.listenAddress | Address to listen on.
|
| services.prometheus.exporters.systemd.extraFlags | Extra commandline options to pass to the systemd exporter.
|
| services.tahoe.nodes.<name>.tub.port | The port on which the tub will listen
|
| services.prometheus.pushgateway.extraFlags | Extra commandline options when launching the Pushgateway.
|
| services.nsd.ratelimit.ipv4PrefixLength | IPv4 prefix length
|
| services.prometheus.scrapeConfigs.*.kubernetes_sd_configs.*.authorization.credentials | Sets the credentials
|
| services.snipe-it.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.prometheus.scrapeConfigs.*.serverset_sd_configs.*.timeout | Timeout value
|
| services.redshift.brightness.night | Screen brightness to apply during the night,
between 0.1 and 1.0.
|
| services.taskserver.pki.auto.expiration.server | The expiration time of the server certificate in days or null for no
expiration time.
|
| services.omnom.settings.app.disable_signup | Whether to enable restricting user creation.
|
| services.mpdscribble.host | Host for the mpdscribble daemon to search for a mpd daemon on.
|
| services.maubot.settings.database | The full URI to the database
|
| services.strongswan-swanctl.swanctl.secrets.rsa.<name>.file | File name in the rsa folder for which this passphrase
should be used.
|
| services.meilisearch.listenPort | The port that Meilisearch will listen on.
|
| services.prometheus.exporters.deluge.delugeHost | Hostname where deluge server is running.
|
| services.pgbouncer.settings.peers | Optional
|
| services.networking.websockify.enable | Whether to enable websockify to forward websocket connections to TCP connections.
|
| services.tee-supplicant.reeFsParentPath | The directory where the secure filesystem will be stored in the rich
execution environment (REE FS).
|
| services.sftpgo.settings.sftpd.bindings.*.address | Network listen address
|
| services.prometheus.scrapeConfigs.*.hetzner_sd_configs.*.oauth2.token_url | The URL to fetch the token from.
|
| services.matomo.nginx.reuseport | Create an individual listening socket
|
| services.nginx.virtualHosts.<name>.http3_hq | Whether to enable the HTTP/0.9 protocol negotiation used in QUIC interoperability tests
|
| services.pdns-recursor.serveRFC1918 | Whether to directly resolve the RFC1918 reverse-mapping domains:
10.in-addr.arpa,
168.192.in-addr.arpa,
16-31.172.in-addr.arpa
This saves load on the AS112 servers.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.host | Address of the Docker daemon.
|
| services.postfix.aliasFiles | Aliases' tables to be compiled and placed into /var/lib/postfix/conf.
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.secret_key | The AWS API key secret
|
| services.stunnel.enable | Whether to enable the stunnel TLS tunneling service.
|
| services.thanos.sidecar.grpc-server-tls-cert | TLS Certificate for gRPC server, leave blank to disable TLS
|
| services.sympa.database.port | Database port
|
| services.oauth2-proxy.cookie.name | The name of the cookie that the oauth_proxy creates.
|
| services.prosody.dataDir | The prosody home directory used to store all data
|
| services.slurm.mpi.extraMpiConfig | Extra configuration for that will be added to mpi.conf.
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.authorization.credentials_file | Sets the credentials to the credentials read from the configured file
|
| services.metricbeat.settings.tags | Tags to place on the shipped metrics
|
| services.postfix.settings.main.relay_domains | List of domains delivered via the relay transport.
https://www.postfix.org/postconf.5.html#relay_domains
|
| services.pocket-id.settings.APP_URL | The URL where you will access the app.
|
| services.prometheus.scrapeConfigs.*.marathon_sd_configs.*.servers | List of URLs to be used to contact Marathon servers
|
| services.mopidy.extensionPackages | Mopidy extensions that should be loaded by the service.
|
| services.prometheus.exporters.varnish.noExit | Do not exit server on Varnish scrape errors.
|
| services.prometheus.exporters.kea.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.kea.openFirewall is true.
|
| services.serviio.enable | Whether to enable the Serviio Media Server.
|
| services.oauth2-proxy.github.org | Restrict logins to members of this organisation.
|
| services.privoxy.settings.enable-edit-actions | Whether the web-based actions file editor may be used.
|
| services.tor.settings.CookieAuthFile | See torrc manual.
|
| services.mattermost.pluginsBundle | Derivation building to a directory of plugin tarballs
|
| services.taskserver.group | Group for Taskserver.
|
| services.nix-serve.package | The nix-serve package to use.
|
| services.privatebin.dataDir | The place where privatebin stores its state.
|
| services.navidrome.environmentFile | Environment file, used to set any secret ND_* environment variables.
|
| services.quicktun.<name>.publicKey | Remote public key in hexadecimal form.
Not needed when services.quicktun..protocol is set to raw.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".username | User used to connect to the database
|
| services.thelounge.package | The thelounge package to use.
|
| services.mainsail.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.prometheus.exporters.klipper.moonrakerApiKey | API Key to authenticate with the Moonraker APIs
|
| services.litellm.settings | Configuration for LiteLLM
|
| services.peertube.listenHttp | The port that the local PeerTube web server will listen on.
|
| services.tor.settings.RejectPlaintextPorts | See torrc manual.
|
| services.logrotate.settings | logrotate freeform settings: each attribute here will define its own section,
ordered by services.logrotate.settings.<name>.priority,
which can either define files to rotate with their settings
or settings common to all further files settings
|
| services.prometheus.exporters.borgmatic.port | Port to listen on.
|
| services.recyclarr.command | The recyclarr command to run (e.g., sync).
|
| services.neo4j.ssl.policies | Defines the SSL policies for use with Neo4j connectors
|
| services.physlock.muteKernelMessages | Disable kernel messages on console while physlock is running.
|
| services.spotifyd.config | (Deprecated) Configuration for Spotifyd
|
| services.prometheus.exporters.fastly.environmentFile | An environment file containg at least the FASTLY_API_TOKEN= environment
variable.
|
| services.livekit.redis.host | Address to bind local redis instance to.
|
| services.postgresqlBackup.databases | List of database names to dump.
|
| services.meme-bingo-web.baseUrl | URL to be used for the HTML <base> element on all HTML routes.
|
| services.thanos.rule.alertmanagers.send-timeout | Timeout for sending alerts to alertmanager
|
| services.pdns-recursor.enable | Whether to enable PowerDNS Recursor, a recursive DNS server.
|
| services.monica.nginx.default | Makes this vhost the default.
|
| services.phpfpm.pools.<name>.phpOptions | "Options appended to the PHP configuration file php.ini used for this PHP-FPM pool."
|
| services.mqtt2influxdb.mqtt.password | MQTT password
|
| services.ocis.stateDir | ownCloud data directory.
|
| services.lighthouse.beacon.address | Listen address of Beacon node.
|
| services.syncoid.commands.<name>.recursive | Whether to enable the transfer of child datasets.
|
| services.prometheus.exporters.node-cert.includeGlobs | List files matching a pattern to include
|