| services.vsmartcard-vpcd.hostname | Hostname of a waiting vpicc server vpcd will be connecting to
|
| services.vmalert.settings."notifier.url" | Prometheus Alertmanager URL
|
| boot.loader.grub.timeoutStyle |
menu shows the menu.
countdown uses a text-mode countdown.
hidden hides GRUB entirely
|
| programs.tmux.customPaneNavigationAndResize | Override the hjkl and HJKL bindings for pane navigation and resizing in VI mode.
|
| boot.initrd.systemd.emergencyAccess | Set to true for unauthenticated emergency access, and false or
null for no emergency access
|
| services.sillytavern.whitelist | Enables whitelist mode.
|
| services.xserver.displayManager.xpra.desktop | Start a desktop environment instead of seamless mode
|
| services.headscale.settings.policy.path | If the mode is set to "file", the path to a
HuJSON file containing ACL policies.
|
| services.autorandr.hooks.postswitch | Postswitch hook executed after mode switch.
|
| services.mtprotoproxy.secureOnly | Don't allow users to connect in non-secure mode (without random padding).
|
| services.hylafax.userAccessFile | The hosts.hfaxd
file entry in the spooling area
will be symlinked to the location given here
|
| services.userborn.static | Whether to generate the password files at build time and store them directly
in the system closure, without requiring any services at boot time
|
| security.wrappers.<name>.permissions | The permissions of the wrapper program
|
| services.nextcloud.settings.mail_sendmailmode | For smtp, the sendmail binary is started with the parameter -bs: Use the SMTP protocol on standard input and output
|
| services.teleport.insecure.enable | Whether to enable starting teleport in insecure mode
|
| services.reposilite.settings.debugEnabled | Whether to enable debug mode.
|
| services.bitcoind.<name>.prune | Reduce storage requirements by enabling pruning (deleting) of old
blocks
|
| services.healthchecks.settings.DEBUG | Enable debug mode.
|
| nix.settings.sandbox | If set, Nix will perform builds in a sandboxed environment that it
will set up automatically for each build
|
| services.athens.networkMode | Configures how Athens will return the results
of the /list endpoint as it can be assembled from both its own
storage and the upstream VCS
|
| virtualisation.graphics | Whether to run QEMU with a graphics window, or in nographic mode
|
| services.routinator.settings.rtr-listen | An array of string values each providing an address and port on which the RTR server should listen in TCP mode
|
| services.varnish.listen.*.address | If given an IP address, it can be a host name ("localhost"), an IPv4 dotted-quad
("127.0.0.1") or an IPv6 address enclosed in square brackets ("[::1]").
(VCL4.1 and higher) If given an absolute Path ("/path/to/listen.sock") or "@"
followed by the name of an abstract socket ("@myvarnishd") accept connections
on a Unix domain socket
|
| services.oauth2-proxy.setXauthrequest | Set X-Auth-Request-User and X-Auth-Request-Email response headers (useful in Nginx auth_request mode)
|
| services.routinator.settings.refresh | An integer value specifying the number of seconds Routinator should wait between consecutive validation runs in server mode
|
| services.ocsinventory-agent.settings.debug | Whether to enable debug mode.
|
| services.autorandr.profiles.<name>.hooks.preswitch | Preswitch hook executed before mode switch.
|
| services.teeworlds.server.enableHighBandwidth | Whether to enable high bandwidth mode on LAN servers
|
| services.teeworlds.game.restrictSpectators | Whether to restrict access to information such as health, ammo and armour in spectator mode.
|
| services.btrbk.instances.<name>.snapshotOnly | Whether to run in snapshot only mode
|
| services.teeworlds.server.inactivePenalty | Specify what to do when a client goes inactive (see services.teeworlds.server.inactiveTime).
-
spectator: send the client into spectator mode
-
spectator/kick: send the client into a free spectator slot, otherwise kick the client
-
kick: kick the client
|
| services.hostapd.radios | This option allows you to define APs for one or multiple physical radios
|
| boot.loader.limine.resolution | The framebuffer resolution to set when booting Linux entries
|
| services.home-assistant.customLovelaceModules | List of custom lovelace card packages to load as lovelace resources
|
| containers.<name>.ephemeral | Runs container in ephemeral mode with the empty root filesystem at boot
|
| services.autorandr.profiles.<name>.hooks.postswitch | Postswitch hook executed after mode switch.
|
| services.xserver.displayManager.lightdm.greeter.enable | If set to false, run lightdm in greeterless mode
|
| programs.captive-browser.browser | The shell (/bin/sh) command executed once the proxy starts
|
| services.ocsinventory-agent.settings.local | If specified, the OCS Inventory Agent will run in offline mode
and the resulting inventory file will be stored in the specified path.
|
| services.yggdrasil.denyDhcpcdInterfaces | Disable the DHCP client for any interface whose name matches
any of the shell glob patterns in this list
|
| services.uwsgi.capabilities | Grant capabilities to the uWSGI instance
|
| services.transmission.settings.umask | Sets transmission's file mode creation mask
|
| services.vmalert.instances.<name>.settings."notifier.url" | Prometheus Alertmanager URL
|
| networking.networkmanager.dns | Set the DNS (resolv.conf) processing mode
|
| services.mail.sendmailSetuidWrapper.permissions | The permissions of the wrapper program
|
| services.home-assistant.defaultIntegrations | List of integrations set are always set up, unless in recovery mode.
|
| networking.firewall.checkReversePath | Performs a reverse path filter test on a packet
|
| services.nullmailer.config.pausetime | The minimum time to pause between successive queue runs when there
are messages in the queue, in seconds
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.esp_proposals | ESP proposals to offer for the CHILD_SA
|
| services.resolved.dnsovertls | If set to
"true":
all DNS lookups will be encrypted
|
| services.victoriametrics.enable | Whether to enable VictoriaMetrics in single-node mode
|
| virtualisation.docker.rootless.enable | This option enables docker in a rootless mode, a daemon that manages
linux containers
|
| services.prometheus.alertmanagerGotify.debug | Enables extended logs for debugging purposes
|
| services.prometheus.exporters.wireguard.verbose | Whether to enable verbose logging mode for prometheus-wireguard-exporter.
|
| services.neo4j.ssl.policies.<name>.allowKeyGeneration | Allows the generation of a private key and associated self-signed
certificate
|
| services.nextcloud-spreed-signaling.settings.grpc.targets | For target type static: List of GRPC targets to connect to for clustering mode.
|
| services.netbird.server.management.singleAccountModeDomain | Enables single account mode
|
| services.netbird.server.management.disableSingleAccountMode | If set to true, disables single account mode
|
| services.jellyfin.transcoding.enableIntelLowPowerEncoding | Enable low-power encoding mode for Intel Quick Sync Video
|
| documentation.man.mandoc.settings.output.width | The ASCII and UTF-8 output width, default is 78
|
| virtualisation.virtualbox.guest.seamless | Whether to enable seamless mode
|
| services.system76-scheduler.settings.cfsProfiles.default.preempt | Preemption mode.
|
| services.kubernetes.apiserver.authorizationMode | Kubernetes apiserver authorization mode (AlwaysAllow/AlwaysDeny/ABAC/Webhook/RBAC/Node)
|
| services.strongswan-swanctl.swanctl.connections.<name>.vips | List of virtual IPs to request in IKEv2 configuration payloads or IKEv1
Mode Config
|
| services.system76-scheduler.settings.cfsProfiles.responsive.preempt | Preemption mode.
|
| services.pipewire.wireplumber.extraConfig | Additional configuration for the WirePlumber daemon when run in
single-instance mode (the default in nixpkgs and currently the only
supported way to run WirePlumber configured via extraConfig)
|
| services.grafana.provision.datasources.settings.datasources.*.access | Access mode. proxy or direct (Server or Browser in the UI)
|
| services.headscale.settings.database.sqlite.write_ahead_log | Enable WAL mode for SQLite
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.copy_df | Whether to copy the DF bit to the outer IPv4 header in tunnel mode
|
| services.hostapd.radios.<name>.networks.<name>.authentication.wpaPasswordFile | Sets the password for WPA-PSK
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.copy_ecn | Whether to copy the ECN (Explicit Congestion Notification) header field
to/from the outer IP header in tunnel mode
|
| virtualisation.sharedDirectories.<name>.securityModel | The security model to use for this share:
passthrough: files are stored using the same credentials as they are created on the guest (this requires QEMU to run as root)
mapped-xattr: some of the file attributes like uid, gid, mode bits and link target are stored as file attributes
mapped-file: the attributes are stored in the hidden .virtfs_metadata directory
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords | Sets allowed passwords for WPA3-SAE
|
| environment.memoryAllocator.provider | The system-wide memory allocator
|
| services.hostapd.radios.<name>.networks.<name>.authentication.wpaPassword | Sets the password for WPA-PSK that will be converted to the pre-shared key
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswordsFile | Sets the password for WPA3-SAE
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.hw_offload | Enable hardware offload for this CHILD_SA, if supported by the IPsec
implementation
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.copy_dscp | Whether to copy the DSCP (Differentiated Services Field Codepoint)
header field to/from the outer IP header in tunnel mode
|
| services.hostapd.radios.<name>.networks.<name>.authentication.wpaPskFile | Sets the password(s) for WPA-PSK
|
| services.strongswan-swanctl.swanctl.connections.<name>.proposals | A proposal is a set of algorithms
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.ah_proposals | AH proposals to offer for the CHILD_SA
|
| services.strongswan-swanctl.swanctl.connections.<name>.local.<name>.auth | Authentication to perform locally.
- The default
pubkey uses public key authentication
using a private key associated to a usable certificate.
psk uses pre-shared key authentication.
- The IKEv1 specific
xauth is used for XAuth or Hybrid
authentication,
- while the IKEv2 specific
eap keyword defines EAP
authentication.
- For
xauth, a specific backend name may be appended,
separated by a dash
|
| services.prometheus.scrapeConfigs.*.docker_sd_configs.*.host_networking_host | The host to use if the container is in host networking mode
|
| services.grafana.settings.security.content_security_policy_report_only | Set to true to add the Content-Security-Policy-Report-Only header to your requests
|
| services.ollama.loadModels | Download these models using ollama pull as soon as ollama.service has started
|
| programs.qgroundcontrol.blacklistModemManagerFromTTYUSB | Disallow ModemManager from interfering with serial connections that QGroundControl might use
|
| services.draupnir.enable | Whether to enable Draupnir, a moderations bot for Matrix.
|
| services.mjolnir.enable | Whether to enable Mjolnir, a moderation tool for Matrix.
|
| services.microsocks.enable | Whether to enable Tiny, portable SOCKS5 server with very moderate resource usage.
|
| services.prosody.muc.*.roomDefaultModerated | If set, the MUC rooms will be moderated by default.
|
| services.hylafax.areaCode | Area code for server and all modems.
|
| services.wyoming.openwakeword.customModelsDirectories | Paths to directories with custom wake word models (*.tflite model files).
|
| services.rtorrent.configText | The content of rtorrent.rc
|
| hardware.display.edid.packages | List of packages containing EDID binary files at $out/lib/firmware/edid
|
| services.hylafax.countryCode | Country code for server and all modems.
|
| services.draupnir.settings.managementRoom | The room ID or alias where moderators can use the bot's functionality
|
| services.hylafax.longDistancePrefix | Long distance prefix for server and all modems.
|
| hardware.nvidia.prime.sync.enable | Whether to enable NVIDIA Optimus support using the NVIDIA proprietary driver via PRIME
|
| hardware.nvidia.prime.reverseSync.enable | Whether to enable NVIDIA Optimus support using the NVIDIA proprietary driver via reverse
PRIME
|
| services.eg25-manager.enable | Whether to enable Quectel EG25 modem manager service.
|