| boot.specialFileSystems.<name>.options | Options used to mount the file system
|
| services.mediawiki.httpd.virtualHost.sslServerChain | Path to server SSL chain file.
|
| services.tinc.networks.<name>.chroot | Change process root directory to the directory where the config file is located (/etc/tinc/netname/), for added security
|
| services.gotenberg.downloadFrom.maxRetries | The maximum amount of times to retry downloading a file specified with downloadFrom.
|
| services.moosefs.chunkserver.enable | Whether to enable MooseFS chunkserver daemon that stores file data.
|
| services.wordpress.sites.<name>.database.socket | Path to the unix socket file to use for authentication.
|
| services.lidarr.environmentFiles | Environment file to pass secret configuration values
|
| services.sonarr.environmentFiles | Environment file to pass secret configuration values
|
| services.radarr.environmentFiles | Environment file to pass secret configuration values
|
| services.kubernetes.apiserver.etcd.certFile | Etcd cert file.
|
| services.rathole.credentialsFile | Path to a TOML file to be merged with the settings
|
| services.readeck.environmentFile | File containing environment variables to be passed to Readeck
|
| services.suricata.settings.default-log-dir | The default logging directory
|
| services.ghostunnel.servers.<name>.cacert | Path to CA bundle file (PEM/X509)
|
| services.lighttpd.mod_userdir | If true, requests in the form /~user/page.html are rewritten to take
the file public_html/page.html from the home directory of the user.
|
| services.ntfy-sh.environmentFile | Path to a file containing extra ntfy environment variables in the systemd EnvironmentFile
format
|
| services.prometheus.exporters.imap-mailstat.configurationFile | File containing the configuration
|
| services.lavalink.environmentFile | Add custom environment variables from a file
|
| image.repart.partitions.<name>.contents.<name>.source | Path of the source file.
|
| services.munin-node.disabledPlugins | Munin plugins to disable, even if
munin-node-configure --suggest tries to enable
them
|
| services.mautrix-signal.settings | config.yaml configuration as a Nix attribute set
|
| services.bookstack.settings | Options for Bookstack configuration
|
| services.davis.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.movim.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.slskd.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.foundationdb.maxLogSize | Delete the oldest log file when the total size of all log
files exceeds the specified size
|
| services.inadyn.settings.provider.<name>.include | File to include additional settings for this provider from.
|
| services.limesurvey.virtualHost.sslServerChain | Path to server SSL chain file.
|
| services.invidious.database.passwordFile | Path to file containing the database password.
|
| services.namecoind.rpc.certificate | Certificate file for securing RPC connections.
|
| services.prometheus.exporters.mikrotik.configuration | Mikrotik exporter configuration as nix attribute set
|
| networking.networkmanager.ensureProfiles.secrets.entries.*.trim | whether leading and trailing whitespace should be stripped from the files content before being passed to NetworkManager
|
| services.beszel.agent.environmentFile | File path containing environment variables for configuring the beszel-agent service in the format of an EnvironmentFile
|
| services.wordpress.sites.<name>.extraConfig | Any additional text to be appended to the wp-config.php
configuration file
|
| services.jitsi-meet.prosody.lockdown | Whether to disable Prosody features not needed by Jitsi Meet
|
| services.freeswitch.enableReload | Issue the reloadxml command to FreeSWITCH when configuration directory changes (instead of restart)
|
| services.prometheus.enableReload | Reload prometheus when configuration file changes (instead of restart)
|
| services.triggerhappy.extraConfig | Literal contents to append to the end of triggerhappy configuration file.
|
| services.snipe-it.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.saunafs.metalogger.settings | Contents of metalogger config file (see sfsmetalogger.cfg(5)).
|
| services.bookstack.database.passwordFile | A file containing the password corresponding to
database.user.
|
| services.mediawiki.database.passwordFile | A file containing the password corresponding to
database.user.
|
| services.lasuite-meet.environmentFile | Path to environment file
|
| services.lasuite-docs.environmentFile | Path to environment file
|
| services.n8n.environment.N8N_USER_FOLDER | Provide the path where n8n will create the .n8n folder
|
| networking.networkmanager.ensureProfiles.secrets.entries | A list of secrets to provide to NetworkManager by reading their values from configured files
|
| virtualisation.msize | The msize (maximum packet size) option passed to 9p file systems, in
bytes
|
| services.mautrix-telegram.settings | config.yaml configuration as a Nix attribute set
|
| services.dnsdist.dnscrypt.providerKey | The filepath to the provider secret key
|
| services.meilisearch.masterKeyFile | Path to file which contains the master key
|
| services.screego.environmentFile | Environment file (see systemd.exec(5) "EnvironmentFile="
section for the syntax) passed to the service
|
| services.dependency-track.ldap.bindPasswordFile | The path to a file containing the LDAP bind password.
|
| services.spacecookie.settings | Settings for spacecookie
|
| boot.supportedFilesystems | Names of supported filesystem types, or an attribute set of file system types
and their state
|
| boot.initrd.compressor | The compressor to use on the initrd image
|
| services.prometheus.exporters.junos-czerwonk.configurationFile | Specify the JunOS exporter configuration file to use.
|
| services.firefox-syncserver.secrets | A file containing the various secrets
|
| services.hylafax.faxcron.enable.frequency | purging old files from the spooling area with
faxcron with the given frequency
(see systemd.time(7))
|
| programs.tsmClient.servers.<name>.genPasswd | Whether to enable automatic client password generation
|
| services.postgresql.settings | PostgreSQL configuration
|
| services.buildkite-agents.<name>.privateSshKeyPath | OpenSSH private key
A run-time path to the key file, which is supposed to be provisioned
outside of Nix store.
|
| services.wordpress.sites.<name>.virtualHost.enableUserDir | Whether to enable serving ~/public_html as
/~«username».
|
| services.gitlab.secrets.activeRecordSaltFile | A file containing the salt for active record encryption in the DB
|
| services.crowdsec.settings.simulation | Attributes inside the simulation.yaml file.
|
| services.athens.storage.azureblob.accountKey | Account key for the Azure Blob storage backend
|
| services.karakeep.environmentFile | An optional path to an environment file that will be used in the web and workers
services
|
| services.librenms.environmentFile | File containing env-vars to be substituted into the final config
|
| services.librenms.database.passwordFile | A file containing the password for the user of the MySQL/MariaDB server
|
| services.openvpn.servers.<name>.authUserPass | This option can be used to store the username / password credentials
with the "auth-user-pass" authentication method
|
| services.opensnitch.settings.Server.LogFile | File to write logs to (use /dev/stdout to write logs to standard
output).
|
| services.sourcehut.settings."pages.sr.ht".gemini-certs | An absolute file path (which should be outside the Nix-store)
to Gemini certificates.
|
| services.easytier.instances.<name>.settings | Settings to generate easytier-‹name›.toml
|
| services.matrix-alertmanager.tokenFile | File that contains a valid Matrix token for the Matrix user.
|
| services.gotenberg.environmentFile | Environment file to load extra environment variables from.
|
| services.commafeed.environmentFile | Environment file as defined in systemd.exec(5).
|
| programs.uwsm.waylandCompositors | Configuration for UWSM-managed Wayland Compositors
|
| services.gancio.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.fluidd.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.akkoma.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.matomo.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.monica.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| networking.networkmanager.ensureProfiles.secrets.entries.*.matchIface | interface name of the NetworkManager connection
|
| services.bookstack.settings.DB_PASSWORD_FILE | The file containing your mysql/mariadb database password.
|
| services.readarr.environmentFiles | Environment file to pass secret configuration values
|
| services.jigasi.environmentFile | File containing environment variables to be passed to the jigasi service,
in which secret tokens can be specified securely by defining values for
JIGASI_SIPUSER,
JIGASI_SIPPWD,
JIGASI_SIPSERVER and
JIGASI_SIPPORT.
|
| services.mautrix-telegram.registerToSynapse | Whether to add the bridge's app service registration file to
services.matrix-synapse.settings.app_service_config_files.
|
| services.mautrix-whatsapp.registerToSynapse | Whether to add the bridge's app service registration file to
services.matrix-synapse.settings.app_service_config_files.
|
| services.prometheus.alertmanager.configuration | Alertmanager configuration as nix attribute set
|
| services.icingaweb2.groupBackends | groups.ini contents
|
| services.gerrit.replicationSettings | Replication configuration
|
| services.limesurvey.httpd.virtualHost.enableUserDir | Whether to enable serving ~/public_html as
/~«username».
|
| security.agnos.settings.accounts.*.certificates.*.fullchain_output_file | Output path for the full chain including the acquired certificate
|
| services.clamsmtp.instances.*.keepAlives | Number of seconds to wait between each NOOP sent to the sending
server. 0 to disable
|
| services.mediawiki.extensions | Attribute set of paths whose content is copied to the extensions
subdirectory of the MediaWiki installation and enabled in configuration
|
| security.wrappers.<name>.permissions | The permissions of the wrapper program
|
| services.waagent.settings.ResourceDisk.SwapSizeMB | Specifies the size of the swap file in MiB (1024×1024 bytes)
|
| services.wordpress.sites.<name>.virtualHost.sslServerChain | Path to server SSL chain file.
|
| services.gokapi.environment.GOKAPI_CONFIG_DIR | Sets the directory for the config file.
|
| services.keyd.keyboards.<name>.settings | Configuration, except ids section, that is written to /etc/keyd/.conf
|
| services.docling-serve.environmentFile | Environment file to be passed to the systemd service
|