| services.audiobookshelf.enable | Whether to enable Audiobookshelf, self-hosted audiobook and podcast server.
|
| services.paretosecurity.enable | Whether to enable ParetoSecurity agent and its root helper.
|
| programs.ssh.enableAskPassword | Whether to configure SSH_ASKPASS in the environment.
|
| hardware.facter.detected.fingerprint.enable | Whether to enable Fingerprint devices.
|
| programs.foot.enableFishIntegration | Whether to enable foot fish integration.
|
| programs.foot.enableBashIntegration | Whether to enable foot bash integration.
|
| services.memcached.enableUnixSocket | Whether to enable Unix Domain Socket at /run/memcached/memcached.sock instead of listening on an IP address and port
|
| documentation.info.enable | Whether to install info pages and the info command
|
| services.elasticsearch-curator.enable | Whether to enable elasticsearch curator.
|
| services.teeworlds.game.enableReadyMode | Whether to enable "ready mode"; where players can pause/unpause the game
and start the game in warmup, using their ready state.
|
| programs.wireshark.usbmon.enable | Whether to allow users in the 'wireshark' group to capture USB traffic
|
| services.evdevremapkeys.enable | Whether to enable evdevremapkeys, a daemon to remap events on linux input devices.
|
| virtualisation.xen.enable | Whether to enable the Xen Project Hypervisor, a virtualisation technology defined as a type-1 hypervisor, which allows multiple virtual machines, known as domains, to run concurrently on the physical machine
|
| services.disnix.enableMultiUser | Whether to support multi-user mode by enabling the Disnix D-Bus service
|
| services.invoiceplane.sites.<name>.cron.enable | Enable cron service which periodically runs Invoiceplane tasks
|
| services.davis.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.movim.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.slskd.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| containers.<name>.enableTun | Allows the container to create and setup tunnel interfaces
by granting the NET_ADMIN capability and
enabling access to /dev/net/tun.
|
| services.cloudlog.update-lotw-users.enable | Whether to periodically update the list of LoTW users
|
| services.invidious.nginx.enable | Whether to configure nginx as a reverse proxy for Invidious
|
| services.asusd.enableUserService | Activate the asusd-user service.
|
| programs.wireshark.dumpcap.enable | Whether to allow users in the 'wireshark' group to capture network traffic
|
| services.prometheus.exporters.nvidia-gpu.enable | Whether to enable the prometheus nvidia-gpu exporter.
|
| documentation.doc.enable | Whether to install documentation distributed in packages' /share/doc
|
| services.warpgate.settings.recordings.enable | Whether to enable session recording.
|
| services.prometheus.pushgateway.enable | Whether to enable Prometheus Pushgateway.
|
| services.victoriatraces.enable | Whether to enable VictoriaTraces is an open source distributed traces storage and query engine from VictoriaMetrics.
|
| services.geoclue2.enableNmea | Whether to fetch location from NMEA sources on local network.
|
| services.teeworlds.game.enableTeamDamage | Whether to enable team damage; whether to allow team mates to inflict damage on one another.
|
| services.immich.database.enableVectors | Whether to enable pgvecto.rs in the database
|
| services.bacula-sd.director.<name>.tls.enable | Specifies if TLS should be enabled
|
| services.bacula-fd.director.<name>.tls.enable | Specifies if TLS should be enabled
|
| services.angrr.enableNixGcIntegration | Whether to enable nix-gc.service integration.
|
| programs.command-not-found.enable | Whether interactive shells should show which Nix package (if
any) provides a missing command
|
| services.prometheus.exporters.rtl_433.enable | Whether to enable the prometheus rtl_433 exporter.
|
| programs.nix-index.enableZshIntegration | Whether to enable Zsh integration.
|
| services.movim.precompressStaticFiles.brotli.enable | Whether to enable Brotli precompression.
|
| services.immich.database.enableVectorChord | Whether to enable the new VectorChord extension for full-text search in Postgres.
|
| services.snipe-it.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.shibboleth-sp.fastcgi.enable | Whether to include the shibauthorizer and shibresponder FastCGI processes
|
| services.prometheus.exporters.apcupsd.enable | Whether to enable the prometheus apcupsd exporter.
|
| services.prometheus.exporters.klipper.enable | Whether to enable the prometheus klipper exporter.
|
| services.prometheus.exporters.dovecot.enable | Whether to enable the prometheus dovecot exporter.
|
| services.prometheus.exporters.postfix.enable | Whether to enable the prometheus postfix exporter.
|
| services.prometheus.exporters.mongodb.enable | Whether to enable the prometheus mongodb exporter.
|
| services.prometheus.exporters.systemd.enable | Whether to enable the prometheus systemd exporter.
|
| services.prometheus.exporters.ecoflow.enable | Whether to enable the prometheus ecoflow exporter.
|
| services.prometheus.exporters.varnish.enable | Whether to enable the prometheus varnish exporter.
|
| services.prometheus.exporters.libvirt.enable | Whether to enable the prometheus libvirt exporter.
|
| services.prometheus.exporters.unbound.enable | Whether to enable the prometheus unbound exporter.
|
| services.prometheus.exporters.process.enable | Whether to enable the prometheus process exporter.
|
| services.prometheus.exporters.bitcoin.enable | Whether to enable the prometheus bitcoin exporter.
|
| services.prometheus.exporters.dnsmasq.enable | Whether to enable the prometheus dnsmasq exporter.
|
| services.prometheus.exporters.sabnzbd.enable | Whether to enable the prometheus sabnzbd exporter.
|
| boot.loader.limine.enableEditor | Whether to allow editing the boot entries before booting them
|
| services.privatebin.enableNginx | Whether to enable nginx or not
|
| services.suricata.settings.logging.outputs.file.enable | Whether to enable logging to file.
|
| services.lighthouse.validator.metrics.enable | Whether to enable Validator node prometheus metrics.
|
| virtualisation.libvirtd.dbus.enable | Whether to enable exposing libvirtd APIs over D-Bus.
|
| hardware.alsa.enablePersistence | Whether to enable ALSA sound card state saving on shutdown
|
| services.calibre-web.options.enableKepubify | Whether to enable kepub conversion support.
|
| services.nginx.enableReload | Reload nginx when configuration file changes (instead of restart)
|
| programs.nix-index.enableFishIntegration | Whether to enable Fish integration.
|
| programs.zoxide.enableZshIntegration | Whether to enable Zsh integration.
|
| programs.direnv.enableZshIntegration | Whether to enable Zsh integration
.
|
| services.firezone.relay.enableTelemetry | Whether to enable telemetry.
|
| programs.nix-index.enableBashIntegration | Whether to enable Bash integration.
|
| services.scrutiny.influxdb.enable | Enables InfluxDB on the host system using the services.influxdb2 NixOS module
with default options
|
| services.journalwatch.enable | If enabled, periodically check the journal with journalwatch and report the results by mail.
|
| security.tpm2.tctiEnvironment.enable | Set common TCTI environment variables to the specified value
|
| services.gitlab.smtp.enableStartTLSAuto | Whether to try to use StartTLS.
|
| virtualisation.multipass.enable | Whether to enable Multipass, a simple manager for virtualised Ubuntu instances.
|
| services.librenms.enableLocalBilling | Enable billing Cron-Jobs on the local instance
|
| networking.nftables.enable | Whether to enable nftables and use nftables based firewall if enabled.
nftables is a Linux-based packet filtering framework intended to
replace frameworks like iptables
|
| services.bitwarden-directory-connector-cli.enable | Whether to enable Bitwarden Directory Connector.
|
| services.ethercalc.enable | ethercalc, an online collaborative spreadsheet server
|
| services.discourse.mail.incoming.enable | Whether to set up Postfix to receive incoming mail.
|
| services.xserver.desktopManager.xfce.enableXfwm | Enable the XFWM (default) window manager.
|
| boot.zfs.enabled | True if ZFS filesystem support is enabled
|
| services.radicle.ci.broker.enableHardening | Whether to enable systemd hardening.
|
| services.cloudlog.upload-clublog.enable | Whether to periodically upload logs to Clublog
|
| programs.direnv.enableBashIntegration | Whether to enable Bash integration
.
|
| programs.zoxide.enableFishIntegration | Whether to enable Fish integration.
|
| programs.zoxide.enableBashIntegration | Whether to enable Bash integration.
|
| programs.direnv.enableFishIntegration | Whether to enable Fish integration
.
|
| services.chrony.enableRTCTrimming | Enable tracking of the RTC offset to the system clock and automatic trimming
|
| services.automysqlbackup.enable | Whether to enable AutoMySQLBackup.
|
| virtualisation.kvmgt.enable | Whether to enable KVMGT (iGVT-g) VGPU support
|
| programs.light.brightnessKeys.enable | Whether to enable brightness control with keyboard keys
|
| services.gitlab-runner.clear-docker-cache.enable | Whether to periodically prune gitlab runner's Docker resources
|
| services.prometheus.exporters.py-air-control.enable | Whether to enable the prometheus py-air-control exporter.
|
| services.keepalived.snmp.enableChecker | Enable SNMP handling of checker element of KEEPALIVED MIB.
|
| services.gancio.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.fluidd.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.akkoma.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.monica.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.matomo.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| security.pam.services.<name>.ttyAudit.enablePattern | For each user matching one of comma-separated
glob patterns, enable TTY auditing
|
| services.angrr.settings.temporary-root-policies.<name>.enable | Whether to enable this angrr policy.
|