| services.rke2.cisHardening | Enable CIS Hardening for RKE2
|
| services.vmalert.settings."datasource.url" | Datasource compatible with Prometheus HTTP API.
|
| services.fediwall.settings.hideSensitive | Hide sensitive (potentially NSFW) posts
|
| services.openssh.settings.X11Forwarding | Whether to allow X11 connections to be forwarded.
|
| services.grafana.settings.server.cert_file | Path to the certificate file (if protocol is set to https or h2).
|
| services.watchdogd.settings.filenr.logmark | Whether to log current stats every poll interval.
|
| services.hedgedoc.settings.protocolUseSSL | Use https:// for all links
|
| services.firewalld.settings.LogDenied | Add logging rules right before reject and drop rules in the INPUT, FORWARD and OUTPUT chains for the default rules and also final reject and drop rules in zones for the configured link-layer packet type.
|
| services.opensnitch.settings.Server.LogFile | File to write logs to (use /dev/stdout to write logs to standard
output).
|
| services.waagent.settings.OS.RootDeviceScsiTimeout | Configures the SCSI timeout in seconds on the OS disk and data drives
|
| services.saunafs.metalogger.settings | Contents of metalogger config file (see sfsmetalogger.cfg(5)).
|
| services.syncthing.settings.folders.<name>.type | Controls how the folder is handled by Syncthing
|
| services.sourcehut.settings.mail.smtp-password | Outgoing SMTP password.
|
| services.gemstash.settings.base_path | Path to store the gem files and the sqlite database
|
| services.tor.settings.DirAllowPrivateAddresses | See torrc manual.
|
| services.syncthing.settings.folders.<name>.label | The label of the folder.
|
| services.tor.settings.AuthDirSharedRandomness | See torrc manual.
|
| services.tor.settings.EnforceDistinctSubnets | See torrc manual.
|
| services.pretalx.settings.filesystem.logs | Path to the log directory, that pretalx logs message to.
|
| services.misskey.settings.redisForTimelines | ioredis options for timelines
|
| services.waagent.settings.ResourceDisk.SwapSizeMB | Specifies the size of the swap file in MiB (1024×1024 bytes)
|
| services.libinput.mouse.accelStepScroll | Sets the step between the points of the scroll acceleration function
|
| services.healthchecks.settings.DB | Database engine to use.
|
| services.oncall.settings.oncall_host | FQDN for the Oncall instance.
|
| services.opensearch.settings."network.host" | Which port this service should listen on.
|
| services.gitlab.pages.settings.artifacts-server | API URL to proxy artifact requests to.
|
| services.typesense.settings.server.api-address | Address to which Typesense API service binds.
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs | List of inputs for this camera.
|
| services.sourcehut.settings."pages.sr.ht".gemini-certs | An absolute file path (which should be outside the Nix-store)
to Gemini certificates.
|
| services.reposilite.settings.sslEnabled | Whether to listen for encrypted connections on settings.sslPort.
|
| services.wgautomesh.settings.peers.*.pubkey | Wireguard public key of this peer.
|
| services.postgrest.settings.server-host | Where to bind the PostgREST web server.
The admin server will also bind here, but potentially exposes sensitive information
|
| services.snapserver.settings.tcp-control.port | Port to listen on for snapclient connections.
|
| services.spacecookie.settings.log.enable | Whether to enable logging for spacecookie.
|
| services.keycloak.settings | Configuration options corresponding to parameters set in
conf/keycloak.conf
|
| services.sourcehut.settings."builds.sr.ht".api-origin | Origin URL for the API
|
| services.postfix.settings.master.<name>.private | Whether the service's sockets and storage directory is restricted to
be only available via the mail system
|
| services.sftpgo.settings.webdavd.bindings.*.port | The port for serving WebDAV requests
|
| services.postfix.settings.main.relayhost | List of hosts to use for relaying outbound mail.
Putting the hostname in angled brackets, e.g. [relay.example.com], turns off MX and SRV lookups for the hostname.
https://www.postfix.org/postconf.5.html#relayhost
|
| services.etebase-server.settings.database.engine | The database engine to use.
|
| services.lemmy.settings.captcha.difficulty | The difficultly of the captcha to solve.
|
| services.grafana-image-renderer.settings.server.addr | Listen address of the service.
|
| services.tor.settings.ServerDNSAllowNonRFC953Hostnames | See torrc manual.
|
| services.tor.settings.DoSConnectionEnabled | See torrc manual.
|
| services.tor.settings.DormantCanceledByStartup | See torrc manual.
|
| services.tor.settings.ExtORPortCookieAuthFileGroupReadable | See torrc manual.
|
| services.spacecookie.settings.log.hide-time | If enabled, spacecookie will not print timestamps
at the beginning of every log line.
|
| services.routinator.settings.expire | An integer value specifying the number of seconds an RTR client is requested to use a data set if it cannot get an update before throwing it away and continuing with no data at all.
|
| services.spacecookie.settings.log.hide-ips | If enabled, spacecookie will hide personal
information of users like IP addresses from
log output.
|
| services.postgrest.settings.server-unix-socket | Unix domain socket where to bind the PostgREST web server.
|
| services.libinput.mouse.accelStepMotion | Sets the step between the points of the (pointer) motion acceleration function
|
| services.stash.settings.stash_boxes | Stash-box facilitates automated tagging of scenes and performers based on fingerprints and filenames
|
| services.maubot.settings.server.public_url | Public base URL where the server is visible.
|
| services.postsrsd.settings.separator | SRS tag separator used in generated sender addresses
|
| services.hostapd.radios.<name>.settings | Extra configuration options to put at the end of global initialization, before defining BSSs
|
| services.evremap.settings.dual_role.*.hold | The key sequence that should be output when the input key is held
|
| services.anuko-time-tracker.settings.emailRequired | Defines whether an email is required for new registrations.
|
| services.matrix-synapse.settings.turn_uris | The public URIs of the TURN server to give to clients
|
| services.sslh.settings.protocols | List of protocols sslh will probe for and redirect
|
| services.headscale.settings.dns.magic_dns | Whether to use MagicDNS.
|
| services.sympa.settingsFile.<name>.source | Path of the source file.
|
| services.keyd.keyboards.<name>.settings | Configuration, except ids section, that is written to /etc/keyd/.conf
|
| services.evremap.settings.dual_role.*.input | The key that should be remapped
|
| services.reposilite.settings.idleTimeout | Default idle timeout used by Jetty.
|
| services.wastebin.settings.WASTEBIN_MAX_BODY_SIZE | Number of bytes to accept for POST requests
|
| services.stash.settings.stash_boxes.*.name | The name of the Stash Box
|
| services.sslh.settings.transparent | Whether the services behind sslh (Apache, sshd and so on) will see the
external IP and ports as if the external world connected directly to
them.
|
| services.inadyn.settings.custom.<name>.password | Password for this DDNS provider
|
| services.grafana.settings.users.home_page | Path to a custom home page
|
| services.writefreely.settings.server.port | The port WriteFreely should listen on.
|
| services.grafana.settings.server.cdn_url | Specify a full HTTP URL address to the root of your Grafana CDN assets
|
| services.journald.remote.settings.Remote.SplitMode | With "host", a separate output file is used, based on the
hostname of the other endpoint of a connection
|
| services.snapserver.settings.stream.source | One or multiple URIs to PCM input streams.
|
| documentation.man.mandoc.settings | Configuration for man.conf(5)
|
| services.tor.settings.DoSCircuitCreationEnabled | See torrc manual.
|
| services.rosenpass.settings.verbosity | Verbosity of output produced by the service.
|
| services.sourcehut.settings."builds.sr.ht::worker".name | Listening address and listening port
of the build runner (with HTTP port if not 80).
|
| services.suricata.settings.app-layer.error-policy | The error-policy setting applies to all app-layer parsers
|
| services.sourcehut.settings."lists.sr.ht::worker".reject-url | Reject URL.
|
| services.litellm.settings.litellm_settings | LiteLLM Module settings
|
| services.litellm.settings.general_settings | LiteLLM Server settings
|
| services.libinput.touchpad.accelSpeed | Cursor acceleration (how fast speed increases from minSpeed to maxSpeed)
|
| services.pid-fan-controller.settings.fans.*.cutoff | Whether to stop the fan when minPwm is reached.
|
| services.lasuite-meet.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.lasuite-docs.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.szurubooru.server.settings.smtp.passFile | File containing the password associated to the given user for the SMTP server.
|
| services.sourcehut.settings."lists.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.taler.merchant.settings.merchant.SERVE | Whether the HTTP server should listen on a UNIX domain socket ("unix") or on a TCP socket ("tcp").
|
| services.suricata.settings.af-xdp.*.interface | af-xdp capture interface, see upstream docs.
|
| services.opensnitch.settings.Firewall | Which firewall backend to use.
|
| services.wastebin.settings.WASTEBIN_BASE_URL | Base URL for the QR code display
|
| services.grafana.settings.server.http_addr | Listening address.
This setting intentionally varies from upstream's default to be a bit more secure by default.
|
| services.spacecookie.settings.root | The directory spacecookie should serve via gopher
|
| services.botamusique.settings.server.port | Port of the mumble server to connect to.
|
| services.botamusique.settings.server.host | Hostname of the mumble server to connect to.
|
| services.livekit.ingress.settings.whip_port | TCP port for WHIP connections
|
| services.livekit.ingress.settings.rtmp_port | TCP port for RTMP connections
|
| services.consul-template.instances.<name>.settings | Free-form settings written directly to the config.json file
|
| services.syncthing.settings | Extra configuration options for Syncthing
|
| services.suricata.settings.pcap.*.interface | pcap capture interface, see upstream docs.
|