| services.mautrix-meta.package | The mautrix-meta package to use.
|
| services.microsocks.group | Group microsocks runs as.
|
| services.misskey.reverseProxy.webserver.nginx.listen | Listen addresses and ports for this virtual host
|
| services.prometheus.exporters.varnish.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.varnish.openFirewall is true.
|
| services.rumno.extraArgs | Extra command-line arguments to pass to the rumno daemon.
|
| services.thanos.store.stateDir | Data directory relative to /var/lib
in which to cache remote blocks.
|
| services.snapper.cleanupInterval | Cleanup interval
|
| services.tinyproxy.settings.Anonymous | If an Anonymous keyword is present, then anonymous proxying is enabled
|
| services.matter-server.package | The python-matter-server package to use.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceExportCircuitID | See torrc manual.
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.uwsgiPass | Adds uwsgi_pass directive and sets recommended proxy headers if
recommendedUwsgiSettings is enabled.
|
| services.livekit.settings.rtc.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.omnom.group | The Omnom service group.
|
| services.rmfakecloud.enable | Whether to enable rmfakecloud remarkable self-hosted cloud.
|
| services.sabnzbd.settings.misc.inet_exposure | Restrictions for access from non-local IP addresses
|
| services.openssh.settings.AllowGroups | If specified, login is allowed only for users part of the
listed groups
|
| services.outline.oidcAuthentication.usernameClaim | Specify which claims to derive user information from
|
| services.linkwarden.enableRegistration | Whether to enable registration for new users.
|
| services.postgresqlWalReceiver.receivers.<name>.statusInterval | Specifies the number of seconds between status packets sent back to the server
|
| services.prometheus.scrapeConfigs.*.eureka_sd_configs.*.oauth2 | Optional OAuth 2.0 configuration
|
| services.thanos.query.grpc-client-tls-secure | Use TLS when talking to the gRPC server
|
| services.thanos.store.store.grpc.series-max-concurrency | Maximum number of concurrent Series calls
|
| services.syncplay.interfaceIpv4 | The IP address to bind to for IPv4
|
| services.pgbouncer.settings.pgbouncer.listen_port | Which port to listen on
|
| services.slskd.settings.retention.transfers.upload.succeeded | Lifespan of succeeded upload tasks.
|
| services.tailscale.serve.services.<name>.endpoints | Map of incoming traffic patterns to local targets
|
| services.tor.settings.RejectPlaintextPorts | See torrc manual.
|
| services.tlp.pd.package | The tlp-pd package to use.
|
| services.misskey.settings.url | The final user-facing URL
|
| services.paperless.dataDir | Directory to store the Paperless data.
|
| services.tarsnap.package | The tarsnap package to use.
|
| services.tinc.networks | Defines the tinc networks which will be started
|
| services.reposilite.settings.port | The TCP port to bind to.
|
| services.multipath.devices.*.prio | The name of the path priority routine
|
| services.postfix.settings.master.<name>.command | A program name specifying a Postfix service/daemon process
|
| services.opensmtpd.setSendmail | Whether to set the system sendmail to OpenSMTPD's.
|
| services.osrm.enable | Enable the OSRM service.
|
| services.readarr.settings.update.automatically | Automatically download and install updates.
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.services | A list of services for which targets are retrieved.
|
| services.restic.backups.<name>.rcloneConfigFile | Path to the file containing rclone configuration
|
| services.prometheus.scrapeConfigs.*.kubernetes_sd_configs.*.selectors.*.label | Selector label
|
| services.trafficserver.strategies | Specify the next hop proxies used in an cache hierarchy and the
algorithms used to select the next proxy
|
| services.oxidized.enable | Whether to enable the oxidized configuration backup service.
|
| services.postfix.user | What to call the Postfix user (must be used only for postfix).
|
| services.prometheus.remoteWrite.*.sigv4.access_key | The Access Key ID.
|
| services.pixelfed.nginx.reuseport | Create an individual listening socket
|
| services.teeworlds.motd | The server's message of the day text.
|
| services.undervolt.useTimer | Whether to set a timer that applies the undervolt settings every 30s
|
| services.pixelfed.nginx.http3_hq | Whether to enable the HTTP/0.9 protocol negotiation used in QUIC interoperability tests
|
| services.mainsail.nginx.forceSSL | Whether to add a separate nginx server block that redirects (defaults
to 301, configurable with redirectCode) all plain HTTP traffic to
HTTPS
|
| services.prometheus.exporters.exportarr-bazarr.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.exportarr-bazarr.openFirewall is true.
|
| services.prometheus.exporters.pve.user | User name under which the pve exporter shall be run.
|
| services.transmission.package | The transmission package to use.
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs | List of Consul service discovery configurations.
|
| services.unifi.initialJavaHeapSize | Set the initial heap size for the JVM in MB
|
| services.mediawiki.httpd.virtualHost.locations.<name>.index | Adds DirectoryIndex directive
|
| services.outline.storage.secretKeyFile | File path that contains the S3 secret key.
|
| services.rabbitmq.managementPlugin.port | On which port to run the management plugin
|
| services.strongswan-swanctl.swanctl.secrets.private.<name>.secret | Value of decryption passphrase for private key.
|
| services.prometheus.exporters.dovecot.telemetryPath | Path under which to expose metrics.
|
| services.restic.backups.<name>.createWrapper | Whether to generate and add a script to the system path, that has the same environment variables set
as the systemd service
|
| services.shairport-sync.settings | Configuration options for Shairport-Sync
|
| services.mycelium.package | The mycelium package to use.
|
| services.mautrix-discord.registrationServiceUnit | The registration service that generates the registration file
|
| services.openvscode-server.group | The group to run openvscode-server under
|
| services.tt-rss.database.type | Database to store feeds
|
| services.slurm.extraConfigPaths | Slurm expects config files for plugins in the same path
as slurm.conf
|
| services.prometheus.exporters.sql.configuration.jobs.<name>.connections | A list of connection strings of the SQL servers to scrape metrics from
|
| services.tinc.networks.<name>.rsaPrivateKeyFile | Path of the private RSA keyfile.
|
| services.rutorrent.plugins | List of plugins to enable
|
| services.tor.client.socksListenAddress | Bind to this address to listen for connections from
Socks-speaking applications.
|
| services.magnetico.crawler.maxLeeches | Maximum number of simultaneous leeches.
|
| services.prometheus.exporters.node-cert.port | Port to listen on.
|
| services.prometheus.exporters.mikrotik.port | Port to listen on.
|
| services.prosody.modules.tls | Add support for secure TLS on c2s/s2s connections
|
| services.paperless.user | User under which Paperless runs.
|
| services.trilium-server.instanceName | Instance name used to distinguish between different instances
|
| services.linkwarden.database.port | Port of the postgresql server.
|
| services.tor.settings.Nickname | See torrc manual.
|
| services.minidlna.settings.media_dir | Directories to be scanned for media files
|
| services.osrm.extraFlags | Extra command line arguments passed to osrm-routed
|
| services.metabase.openFirewall | Open ports in the firewall for Metabase.
|
| services.moodle.database.socket | Path to the unix socket file to use for authentication.
|
| services.murmur.hostName | Host to bind to
|
| services.maddy.tls.certificates.*.keyPath | Path to the private key used for TLS.
|
| services.prometheus.exporters.exportarr-readarr.user | User name under which the exportarr-readarr exporter shall be run.
|
| services.pppd.package | The ppp package to use.
|
| services.prometheus.exporters.mail.configuration.monitoringInterval | Time interval between two probe attempts.
|
| services.metricbeat.enable | Whether to enable metricbeat.
|
| services.prometheus.exporters.rasdaemon.user | User name under which the rasdaemon exporter shall be run.
|
| services.moodle.virtualHost.robotsEntries | Specification of pages to be ignored by web crawlers
|
| services.prometheus.exporters.surfboard.user | User name under which the surfboard exporter shall be run.
|
| services.nginx.commonHttpConfig | With nginx you must provide common http context definitions before
they are used, e.g. log_format, resolver, etc. inside of server
or location contexts
|
| services.opengfw.dir | Working directory of the OpenGFW service and home of opengfw.user.
|
| services.pufferpanel.package | The pufferpanel package to use.
|
| services.netbird.tunnels.<name>.dir.runtime | A runtime directory used by NetBird client.
|
| services.prometheus.exporters.py-air-control.user | User name under which the py-air-control exporter shall be run.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.basic_auth | Optional HTTP basic authentication information.
|
| services.prometheus.exporters.klipper.user | User name under which the klipper exporter shall be run.
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.ah_proposals | AH proposals to offer for the CHILD_SA
|