| services.rsnapshot.enable | Whether to enable rsnapshot backups.
|
| services.netbird.server.signal.port | Internal port of the signal server.
|
| services.prometheus.scrapeConfigs.*.kuma_sd_configs.*.follow_redirects | Configure whether HTTP requests follow HTTP 3xx redirects
|
| services.prosody.s2sSecureDomains | Even if you leave s2s_secure_auth disabled, you can still require valid
certificates for some domains by specifying a list here.
|
| services.salt.master.configuration | Salt master configuration as Nix attribute set.
|
| services.spiped.config.<name>.keyfile | Name of a file containing the spiped key
|
| services.udisks2.package | The udisks package to use.
|
| services.movim.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.pixelfed.nginx.locations.<name>.index | Adds index directive.
|
| services.postfix.settings.main.mynetworks_style | The method used for generating the default value for mynetworks, if that option is unset.
https://www.postfix.org/postconf.5.html#mynetworks_style
|
| services.prometheus.exporters.deluge.delugeUser | User to connect to deluge server.
|
| services.pyload.user | User under which pyLoad runs, and which owns the download directory.
|
| services.strongswan-swanctl.swanctl.connections.<name>.local_addrs | Local address(es) to use for IKE communication
|
| services.moosefs.cgiserver.openFirewall | Whether to automatically open the web interface port.
|
| services.rsnapshot.enableManualRsnapshot | Whether to enable manual usage of the rsnapshot command with this module.
|
| services.tinc.networks.<name>.hostSettings.<name>.rsaPublicKey | Legacy RSA public key of the host in PEM format, including start and
end markers
|
| services.multipath.devices.*.uid_attribute | The udev attribute providing a unique path identifier (WWID)
|
| services.nginx.virtualHosts.<name>.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.mame.emuAddr | IP address of the guest system
|
| services.matrix-continuwuity.enable | Whether to enable continuwuity.
|
| services.maubot.settings.plugin_directories.load | The directories from which plugins should be loaded
|
| services.nagios.virtualHost.logFormat | Log format for Apache's log files
|
| services.pufferpanel.extraGroups | Additional groups for the systemd service.
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.basic_auth.username | HTTP username
|
| services.schleuder.settings | Settings for schleuder.yml
|
| services.suwayomi-server.settings.server.localSourcePath | Path to the local source folder.
|
| services.netbird.server.dashboard.managementServer | The address of the management server, used for the API endpoints.
|
| services.prosody.xmppComplianceSuite | The XEP-0423 defines a set of recommended XEPs to implement
for a server
|
| services.schleuder.extraSettingsFile | YAML file to merge into the schleuder config at runtime
|
| services.snmpd.port | The port to listen on for SNMP and AgentX messages.
|
| services.taskserver.config | Configuration options to pass to Taskserver
|
| services.udp-over-tcp.tcp2udp.<name>.threads | Sets the number of worker threads to use
|
| services.udp-over-tcp.udp2tcp.<name>.recvTimeout | An application timeout on receiving data from the TCP socket.
|
| services.unit.logDir | Unit log directory.
|
| services.limesurvey.webserver | Webserver to configure for reverse-proxying limesurvey.
|
| services.linkwarden.database.name | The name of the Linkwarden database.
|
| services.nixseparatedebuginfod2.substituters | nix substituter to fetch debuginfo from
|
| services.slskd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.opensmtpd.enable | Whether to enable the OpenSMTPD server.
|
| services.netbird.clients.<name>.hardened | Hardened service:
- runs as a dedicated user with minimal set of permissions (see caveats),
- restricts daemon configuration socket access to dedicated user group
(you can grant access to it with
users.users."<user>".extraGroups = [ netbird-‹name› ]),
Even though the local system resources access is restricted:
CAP_NET_RAW, CAP_NET_ADMIN and CAP_BPF still give unlimited network manipulation possibilites,
- older kernels don't have
CAP_BPF and use CAP_SYS_ADMIN instead,
Known security features that are not (yet) integrated into the module:
- 2024-02-14:
rosenpass is an experimental feature configurable solely
through --enable-rosenpass flag on the netbird up command,
see the docs
|
| services.prometheus.exporters.nextcloud.timeout | Timeout for getting server info document.
|
| services.rtorrent.group | Group under which rtorrent runs.
|
| services.prometheus.exporters.postgres.listenAddress | Address to listen on.
|
| services.picom.vSync | Enable vertical synchronization
|
| services.opendkim.domains | Local domains set (see opendkim(8) for more information on datasets)
|
| services.prometheus.exporters.bitcoin.openFirewall | Open port in firewall for incoming connections.
|
| services.openssh.sftpFlags | Commandline flags to add to sftp-server.
|
| services.pid-fan-controller.settings.fans.*.cutoff | Whether to stop the fan when minPwm is reached.
|
| services.rabbitmq.configItems | Configuration options in RabbitMQ's new config file format,
which is a simple key-value format that can not express nested
data structures
|
| services.pufferpanel.environmentFile | File to load environment variables from
|
| services.linkwarden.secretFiles | Attribute set containing paths to files to add to the environment of linkwarden
|
| services.mattermost.user | User which runs the Mattermost service.
|
| services.misskey.reverseProxy.webserver.caddy.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.neo4j.bolt.sslPolicy | Neo4j SSL policy for BOLT traffic
|
| services.openbao.settings.listener.<name>.address | The TCP address or UNIX socket path to listen on.
|
| services.sanoid.datasets.<name>.yearly | Number of yearly snapshots.
|
| services.tlsrpt.reportd.settings.log_level | Level of log messages to emit.
|
| services.lidarr.settings | Attribute set of arbitrary config options
|
| services.matrix-conduit.settings.global.database_backend | The database backend for the service
|
| services.postgres-websockets.environment | postgres-websockets configuration as defined in:
https://github.com/diogob/postgres-websockets/blob/master/src/PostgresWebsockets/Config.hs#L71-L87
PGWS_DB_URI is represented as an attribute set, see [`environment
|
| services.strongswan-swanctl.swanctl.secrets.pkcs12.<name>.file | File name in the pkcs12 folder for which this
passphrase should be used.
|
| services.openafsClient.packages.module | OpenAFS kernel module package
|
| services.prometheus.exporters.exportarr-readarr.package | The exportarr package to use.
|
| services.slurm.mpi.PmixCliTmpDirBase | Base path for PMIx temporary files.
|
| services.sympa.enable | Whether to enable Sympa mailing list manager.
|
| services.mlmmj.enable | Enable mlmmj
|
| services.moosefs.cgiserver.settings.GUISERV_LISTEN_HOST | IP address to bind GUI server to (* means any).
|
| services.prometheus.exporters.storagebox.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.storagebox.openFirewall
is true
|
| services.prometheus.remoteWrite.*.bearer_token | Sets the Authorization header on every remote write request with
the configured bearer token
|
| services.sanoid.datasets.<name>.force_post_snapshot_script | Whether to run the post script if the pre script fails
|
| services.strongswan-swanctl.package | The strongswan package to use.
|
| services.pleroma.package | The pleroma package to use.
|
| services.plex.extraPlugins | A list of paths to extra plugin bundles to install in Plex's plugin
directory
|
| services.prometheus.alertmanager-ntfy.package | The alertmanager-ntfy package to use.
|
| services.pleroma.enable | Whether to enable pleroma.
|
| services.prometheus.exporters.mqtt.openFirewall | Open port in firewall for incoming connections.
|
| services.prometheus.exporters.opnsense.disabledExporter | Collectors to enable or disable
|
| services.stargazer.allowCgiUser | When enabled, the stargazer process will be given CAP_SETGID
and CAP_SETUID so that it can run cgi processes as a different
user
|
| services.lldap.enable | Whether to enable lldap, a lightweight authentication server that provides an opinionated, simplified LDAP interface for authentication.
|
| services.nextcloud.settings.overwriteprotocol | Force Nextcloud to always use HTTP or HTTPS i.e. for link generation
|
| services.nsd.zones | Define your zones here
|
| services.tomcat.baseDir | Location where Tomcat stores configuration files, web applications
and logfiles
|
| services.prometheus.exporters.fritz.enable | Whether to enable the prometheus fritz exporter.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.filters.*.name | Name of the filter
|
| services.system76-scheduler.settings.cfsProfiles.default.latency | sched_latency_ns.
|
| services.thanos.sidecar.tsdb.path | Data directory of TSDB.
|
| services.netbird.tunnels | Alias of services.netbird.clients.
|
| services.nextjs-ollama-llm-ui.hostname | The hostname under which the Ollama UI interface should be accessible
|
| services.prometheus.exporters.nats.port | Port to listen on.
|
| services.prometheus.exporters.script.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.script.openFirewall is true.
|
| services.prometheus.exporters.rspamd.extraLabels | Set of labels added to each metric.
|
| services.toxvpn.auto_add_peers | peers to automatically connect to on startup
|
| services.netbird.clients.<name>.bin.suffix | A system group name for this client instance.
|
| services.prometheus.scrapeConfigs.*.dns_sd_configs.*.refresh_interval | The time after which the provided names are refreshed
|
| services.open-web-calendar.domain | The domain under which open-web-calendar is made available
|
| services.pipewire.package | The pipewire package to use.
|
| services.prometheus.exporters.v2ray.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.v2ray.openFirewall is true.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.oauth2.client_secret | OAuth client secret.
|
| services.qbittorrent.serverConfig | Free-form settings mapped to the qBittorrent.conf file in the profile
|
| services.thanos.store.grpc-address | Listen ip:port address for gRPC endpoints (StoreAPI)
|