| boot.initrd.clevis.devices.<name>.secretFile | Clevis JWE file used to decrypt the device at boot, in concert with the chosen pin (one of TPM2, Tang server, or SSS).
|
| services.xserver.displayManager.lightdm.greeters.slick.iconTheme.name | Name of the icon theme to use for the lightdm-slick-greeter.
|
| services.firefox-syncserver.database.name | Database to use for storage
|
| services.geth.<name>.websocket.enable | Whether to enable Go Ethereum WebSocket API.
|
| services.udp-over-tcp.tcp2udp.<name>.recvTimeout | An application timeout on receiving data from the TCP socket.
|
| services.nebula.networks.<name>.relays | List of IPs of relays that this node should allow traffic from.
|
| services.udp-over-tcp.udp2tcp.<name>.recvTimeout | An application timeout on receiving data from the TCP socket.
|
| systemd.services.<name>.conflicts | If the specified units are started, then this unit is stopped
and vice versa.
|
| services.udp-over-tcp.tcp2udp.<name>.threads | Sets the number of worker threads to use
|
| services.redis.servers.<name>.group | Group account under which this instance of redis-server runs.
If left as the default value this group will automatically be
created on system activation, otherwise you are responsible for
ensuring the group exists before the redis service starts.
|
| services.grafana.provision.alerting.rules.settings.groups.*.name | Name of the rule group
|
| services.rss2email.feeds.<name>.to | Email address to which to send feed items
|
| services.multipath.devices.*.all_tg_pt | Set the 'all targets ports' flag when registering keys with mpathpersist
|
| services.parsedmarc.settings.elasticsearch.cert_path | The path to a TLS certificate bundle used to verify
the server's certificate.
|
| services.fedimintd.<name>.nginx.config.locations.<name>.proxyWebsockets | Whether to support proxying websocket connections with HTTP/1.1.
|
| services.borgbackup.jobs.<name>.appendFailedSuffix | Append a .failed suffix
to the archive name, which is only removed if
borg create has a zero exit status.
|
| services.geoclue2.appConfig.<name>.isSystem | Whether the application is a system component or not.
|
| services.errbot.instances.<name>.dataDir | Data directory for errbot instance.
|
| systemd.watchdog.device | The path to a hardware watchdog device which will be managed by systemd
|
| services.gitea.metricsTokenFile | Path to a file containing the metrics authentication token.
|
| services.angrr.configFile | Path to the angrr configuration file in TOML format
|
| services.dovecot2.sslServerKey | Path to the server's private key.
|
| services.datadog-agent.apiKeyFile | Path to a file containing the Datadog API key to associate the
agent with your account.
|
| services.beszel.agent.extraPath | Extra packages to add to beszel path (such as nvidia-smi or rocm-smi).
|
| environment.localBinInPath | Add ~/.local/bin/ to $PATH
|
| boot.initrd.systemd.storePaths.*.target | Path of the symlink.
|
| services.oxidized.routerDB | Path to the file/database which contains the targets for oxidized.
|
| services.syncthing.key | Path to the key.pem file, which will be copied into Syncthing's
configDir.
|
| services.syncthing.dataDir | The path where synchronised directories will exist.
|
| services.sftpgo.loadDataFile | Path to a json file containing users and folders to load (or update) on startup
|
| services.portunus.seedPath | Path to a portunus seed file in json format
|
| services.wiki-js.settings.db.host | Hostname or socket-path to connect to.
|
| services.stash.settings.cache | Path to cache
|
| boot.specialFileSystems.<name>.stratis.poolUuid | UUID of the stratis pool that the fs is located in
This is only relevant if you are using stratis.
|
| services.nsd.zones.<name>.allowAXFRFallback | If NSD as secondary server should be allowed to AXFR if the primary
server does not allow IXFR.
|
| networking.wg-quick.interfaces.<name>.listenPort | 16-bit port for listening
|
| security.acme.certs.<name>.dnsResolver | Set the resolver to use for performing recursive DNS queries
|
| systemd.network.links.<name>.matchConfig | Each attribute in this set specifies an option in the
[Match] section of the unit
|
| services.dokuwiki.sites.<name>.phpPackage | The php package to use.
|
| services.redis.servers.<name>.requirePassFile | File with password for the database.
|
| services.sanoid.templates.<name>.daily | Number of daily snapshots.
|
| services.vault-agent.instances.<name>.user | User under which this instance runs.
|
| security.pam.services.<name>.gnupg.storeOnly | Don't send the password immediately after login, but store for PAM
session.
|
| services.snapper.configs.<name>.FSTYPE | Filesystem type
|
| services.znapzend.zetup.<name>.destinations.<name>.postsend | Command to run after sending the snapshot to the destination
|
| services.firezone.server.provision.accounts.<name>.groups.<name>.forceMembers | Ensure that only the given members are part of this group at every server start.
|
| services.sourcehut.settings."builds.sr.ht::worker".name | Listening address and listening port
of the build runner (with HTTP port if not 80).
|
| services.h2o.hosts.<name>.acme.useHost | An existing Let’s Encrypt certificate to use for this virtual
host
|
| services.prometheus.exporters.fritz.settings.devices.*.name | Name to use for the device.
|
| boot.initrd.luks.devices.<name>.postOpenCommands | Commands that should be run right after we have mounted our LUKS device.
|
| services.znapzend.zetup.<name>.sendDelay | Specify delay (in seconds) before sending snaps to the destination
|
| systemd.user.targets.<name>.requiredBy | Units that require (i.e. depend on and need to go down with) this unit
|
| systemd.user.sockets.<name>.requiredBy | Units that require (i.e. depend on and need to go down with) this unit
|
| services.agate.hostnames | Domain name of this Gemini server, enables checking hostname and port
in requests. (multiple occurrences means basic vhosts)
|
| services.xserver.displayManager.lightdm.greeters.gtk.cursorTheme.name | Name of the cursor theme to use for the lightdm-gtk-greeter.
|
| programs.uwsm.waylandCompositors.<name>.prettyName | The full name of the desktop entry file.
|
| services.jupyter.kernels.<name>.extraPaths | Extra paths to link in kernel directory
|
| services.ytdl-sub.instances.<name>.enable | Whether to enable ytdl-sub instance.
|
| systemd.services.<name>.requiredBy | Units that require (i.e. depend on and need to go down with) this unit
|
| services.wstunnel.clients.<name>.tlsSNI | Use this as the SNI while connecting via TLS
|
| systemd.slices.<name>.restartTriggers | An arbitrary list of items such as derivations
|
| systemd.timers.<name>.restartTriggers | An arbitrary list of items such as derivations
|
| services.frp.instances.<name>.role | The frp consists of client and server
|
| services.drupal.sites.<name>.virtualHost.hostName | Canonical hostname for the server.
|
| image.repart.partitions.<name>.storePaths | The store paths to include in the partition.
|
| services.fedimintd.<name>.nginx.enable | Whether to configure nginx for fedimintd
|
| services.firewalld.zones.<name>.target | Action for packets that doesn't match any rules.
|
| services.vdirsyncer.jobs.<name>.group | group to run vdirsyncer as
|
| services.akkoma.initDb.username | Name of the database user to initialise the database with
|
| services.alloy.configPath | Alloy configuration file/directory path
|
| services.kubernetes.pki.etcClusterAdminKubeconfig | Symlink a kubeconfig with cluster-admin privileges to environment path
(/etc/<path>).
|
| services.pds.pdsadmin.enable | Add pdsadmin script to PATH
|
| services.gotenberg.rootPath | Root path for the Gotenberg API.
|
| services.asusd.asusdConfig.source | Path of the source file.
|
| services.dspam.domainSocket | Path to local domain socket which is used for communication with the daemon
|
| services.envfs.enable | Fuse filesystem that returns symlinks to executables based on the PATH
of the requesting process
|
| services.honk.passwordFile | Password for admin account
|
| boot.initrd.systemd.storePaths.*.source | Path of the source file.
|
| services.iperf3.rsaPrivateKey | Path to the RSA private key (not password-protected) used to decrypt authentication credentials from the client.
|
| services.forgejo.dump.backupDir | Path to the directory where the dump archives will be stored.
|
| services.asusd.animeConfig.source | Path of the source file.
|
| services.outline.sslKeyFile | File path that contains the Base64-encoded private key for HTTPS
termination
|
| services.sabnzbd.configFile | Path to config file (deprecated, use settings instead and set this value to null)
|
| services.oauth2-proxy.proxyPrefix | The url root path that this proxy should be nested under.
|
| services.nitter.server.staticDir | Path to the static files directory.
|
| services.paisa.settings.dataDir | Path to paisa data directory.
|
| services.oxidized.configFile | Path to the oxidized configuration file.
|
| services.xray.settingsFile | The absolute path to the configuration file
|
| services.easytier.instances.<name>.extraSettings | Extra settings to add to easytier-‹name›.toml.
|
| security.acme.certs.<name>.reloadServices | The list of systemd services to call systemctl try-reload-or-restart
on.
|
| services.kanata.keyboards.<name>.port | Port to run the TCP server on. null will not run the server.
|
| services.sympa.settingsFile.<name>.enable | Whether this file should be generated
|
| systemd.shutdownRamfs.contents.<name>.text | Text of the file.
|
| security.pam.services.<name>.ttyAudit.enable | Enable or disable TTY auditing for specified users
|
| services.httpd.virtualHosts.<name>.servedDirs | This option provides a simple way to serve static directories.
|
| services.hostapd.radios.<name>.wifi6.enable | Enables support for IEEE 802.11ax (WiFi 6, HE)
|
| services.tahoe.nodes.<name>.client.shares.total | The number of shares required to store a file.
|
| services.redis.servers.<name>.settings | Redis configuration
|
| services.nginx.virtualHosts.<name>.basicAuth | Basic Auth protection for a vhost
|
| systemd.network.netdevs.<name>.xfrmConfig | Each attribute in this set specifies an option in the
[Xfrm] section of the unit
|