| services.nghttpx.single-process | Run this program in a single process mode for debugging
purpose
|
| boot.loader.limine.secureBoot.enable | Whether to use sign the limine binary with sbctl.
This requires you to already have generated the keys and enrolled them with sbctl
|
| services.nextcloud.settings.mail_smtpmode | Which mode to use for sending mail
|
| services.samba-wsdd.listen | Listen on path or localhost port in discovery mode.
|
| programs.clash-verge.tunMode | Whether to enable Setcap for TUN Mode
|
| services.vwifi.client.spy | Whether to enable spy mode, useful for wireless monitors.
|
| services.suricata.settings.exception-policy | Define a common behavior for all exception policies
|
| services.hydra.debugServer | Whether to run the server in debug mode.
|
| services.minio.dataDir | The list of data directories or nodes for storing the objects
|
| services.stunnel.fipsMode | Enable FIPS 140-2 mode required for compliance.
|
| security.pam.makeHomeDir.umask | The user file mode creation mask to use on home directories
newly created by pam_mkhomedir.
|
| hardware.nvidia.nvidiaPersistenced | Whether to enable nvidia-persistenced a update for NVIDIA GPU headless mode, i.e
|
| services.code-server.socketMode | File mode of the socket.
|
| services.webdav-server-rs.debug | Enable debug mode.
|
| programs.throne.tunMode.enable | Whether to enable TUN mode of Throne.
|
| services.grafana.settings.database.ssl_mode | For Postgres, use either disable, require or verify-full
|
| services.prometheus.exporters.modemmanager.port | Port to listen on.
|
| services.prometheus.exporters.modemmanager.user | User name under which the modemmanager exporter shall be run.
|
| services.tlsrpt.collectd.settings.socketmode | Permissions on the UNIX socket.
|
| services.knot.enableXDP | Extends the systemd unit with permissions to allow for the use of
the eXpress Data Path (XDP).
Make sure to read up on functional limitations
when running in XDP mode.
|
| services.prometheus.exporters.modemmanager.group | Group under which the modemmanager exporter shall be run.
|
| services.suricata.settings.unix-command | Unix command socket that can be used to pass commands to Suricata
|
| services.openafsClient.startDisconnected | Start up in disconnected mode
|
| programs.clash-verge.serviceMode | Whether to enable Service Mode.
|
| services.prometheus.exporters.modemmanager.enable | Whether to enable the prometheus modemmanager exporter.
|
| services.kubernetes.addons.dns.reconcileMode | Controls the addon manager reconciliation mode for the DNS addon
|
| services.lact.enable | Whether to enable LACT, a tool for monitoring, configuring and overclocking GPUs.
If you are on an AMD GPU, it is recommended to enable overdrive mode by using
hardware.amdgpu.overdrive.enable = true; in your configuration
|
| services.quicktun.<name>.tunMode | Whether to operate in tun (IP) or tap (Ethernet) mode.
|
| programs.nekoray.tunMode.enable | Whether to enable TUN mode of nekoray.
|
| services.prometheus.exporters.modemmanager.extraFlags | Extra commandline options to pass to the modemmanager exporter.
|
| environment.etc.<name>.gid | GID of created file
|
| environment.etc.<name>.uid | UID of created file
|
| services.grafana.settings.database.cache_mode | For sqlite3 only.
Shared cache setting used for connecting to the database.
|
| services.documize.offline | Set true for offline mode.
|
| services.tt-rss.singleUserMode | Operate in single user mode, disables all functionality related to
multiple users and authentication
|
| services.searx.runInUwsgi | Whether to run searx in uWSGI as a "vassal", instead of using its
built-in HTTP server
|
| services.disnix.enableMultiUser | Whether to support multi-user mode by enabling the Disnix D-Bus service
|
| services.pixiecore.cmdLine | Kernel commandline arguments
|
| services.prometheus.exporters.dovecot.socketPath | Path under which the stats socket is placed
|
| services.samba-wsdd.discovery | Enable discovery operation mode.
|
| services.stargazer.debugMode | Run Stargazer in debug mode.
|
| services.strongswan-swanctl.swanctl.connections.<name>.aggressive | Enables Aggressive Mode instead of Main Mode with Identity
Protection
|
| services.prometheus.exporters.modemmanager.listenAddress | Address to listen on.
|
| boot.loader.grub.splashImage | Background image used for GRUB
|
| services.k3s.role | Whether k3s should run as a server or agent
|
| services.weechat.headless | Allows specifying if weechat should run in TUI or headless mode.
|
| services.prometheus.exporters.modemmanager.openFirewall | Open port in firewall for incoming connections.
|
| services.prometheus.exporters.modemmanager.refreshRate | How frequently ModemManager will refresh the extended signal quality
information for each modem
|
| services.dbus.apparmor | AppArmor mode for dbus.
enabled enables mediation when it's
supported in the kernel, disabled
always disables AppArmor even with kernel support, and
required fails when AppArmor was not found
in the kernel.
|
| services.omnom.settings.app.debug | Whether to enable debug mode.
|
| services.zapret.httpMode | By default this service only changes the first packet sent, which is enough in most cases
|
| services.apache-kafka.formatLogDirs | Whether to format log dirs in KRaft mode if all log dirs are
unformatted, ie. they contain no meta.properties.
|
| services.pixiecore.initrd | Initrd path
|
| services.pixiecore.kernel | Kernel path
|
| services.angrr.settings.profile-policies.<name>.profile-paths | Paths to the Nix profile
|
| services.prometheus.exporters.modemmanager.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.modemmanager.openFirewall is true.
|
| security.loginDefs.settings.UMASK | The file mode creation mask is initialized to this value.
|
| services.apache-kafka.clusterId | KRaft mode ClusterId used for formatting log directories
|
| services.prometheus.exporters.surfboard.modemAddress | The hostname or IP of the cable modem.
|
| services.kanidm.provision.groups.<name>.overwriteMembers | Whether the member list should be overwritten each time (true) or appended
(false)
|
| services.pixiecore.apiServer | URI to connect to the API
|
| services.hostapd.radios.<name>.noScan | Disables scan for overlapping BSSs in HT40+/- mode
|
| services.prometheus.exporters.modemmanager.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.modemmanager.openFirewall
is true
|
| services.mediagoblin.settings.mediagoblin.email_debug_mode | Disable email debug mode to start sending outgoing mails
|
| services.zitadel.tlsMode | The TLS mode to use
|
| services.wyoming.faster-whisper.servers.<name>.model | Name of the voice model to use
|
| environment.etc.<name>.user | User name of file owner
|
| containers.<name>.bindMounts.<name>.isReadOnly | Determine whether the mounted path will be accessed in read-only mode.
|
| environment.etc.<name>.group | Group name of file owner
|
| hardware.amdgpu.overdrive.enable | Whether to enable amdgpu overdrive mode for overclocking.
|
| services.libinput.mouse.sendEventsMode | Sets the send events mode to disabled, enabled,
or disabled-on-external-mouse
|
| boot.loader.initScript.enable | Some systems require a /sbin/init script which is started
|
| services.displayManager.sddm.enableHidpi | Whether to enable automatic HiDPI mode.
|
| services.aria2.serviceUMask | The file mode creation mask for Aria2 service
|
| services.ghostunnel.servers | Server mode ghostunnels (TLS listener -> plain TCP/UNIX target)
|
| services.apache-kafka.settings."broker.id" | Broker ID. -1 or null to auto-allocate in zookeeper mode.
|
| programs.proxychains.quietMode | Whether to enable Quiet mode (no output from the library).
|
| services.misskey.settings.chmodSocket | The file access mode of the UNIX socket.
|
| services.prometheus.enableAgentMode | Whether to enable agent mode.
|
| services.hqplayerd.licenseFile | Path to the HQPlayer license key file
|
| services.neo4j.ssl.policies.<name>.trustAll | Makes this policy trust all remote parties
|
| services.ebusd.device | Use DEV as eBUS device [/dev/ttyUSB0]
|
| services.tt-rss.simpleUpdateMode | Enables fallback update mode where tt-rss tries to update feeds in
background while tt-rss is open in your browser
|
| services.searx.settingsFile | The path of the Searx server settings.yml file
|
| services.journald.gateway.cert | The path to a file or AF_UNIX stream socket to read the server
certificate from
|
| services.coturn.static-auth-secret | 'Static' authentication secret value (a string) for TURN REST API only
|
| networking.bonds.<name>.lacp_rate | DEPRECATED, use driverOptions
|
| services.searx.configureUwsgi | Whether to run searx in uWSGI as a "vassal", instead of using its
built-in HTTP server
|
| services.spamassassin.debug | Whether to run the SpamAssassin daemon in debug mode
|
| services.hbase-standalone.enable | Whether to enable HBase master in standalone mode with embedded regionserver and zookeper
|
| services.dragonflydb.cacheMode | Once this mode is on, Dragonfly will evict items least likely to be stumbled
upon in the future but only when it is near maxmemory limit.
|
| services.blockbook-frontend.<name>.debug | Debug mode, return more verbose errors, reload templates on each request.
|
| hardware.tuxedo-drivers.enable | Whether to enable The tuxedo-drivers driver enables access to the following on TUXEDO notebooks:
- Driver for Fn-keys
- SysFS control of brightness/color/mode for most TUXEDO keyboards
- Hardware I/O driver for TUXEDO Control Center
For more inforation it is best to check at the source code description: https://gitlab.com/tuxedocomputers/development/packages/tuxedo-drivers
.
|
| services.cockroachdb.insecure | Run in insecure mode.
|
| services.autorandr.hooks.preswitch | Preswitch hook executed before mode switch.
|
| services.teeworlds.game.enableReadyMode | Whether to enable "ready mode"; where players can pause/unpause the game
and start the game in warmup, using their ready state.
|
| services.gpsd.readonly | Whether to enable the broken-device-safety, otherwise
known as read-only mode
|
| services.libinput.touchpad.sendEventsMode | Sets the send events mode to disabled, enabled,
or disabled-on-external-mouse
|
| hardware.nvidia-container-toolkit.csv-files | The path to the list of CSV files to use when generating the CDI specification in CSV mode.
|
| networking.wlanInterfaces.<name>.fourAddr | Whether to enable 4-address mode with type managed.
|