| power.ups.upsd | Options for the upsd.conf configuration file.
|
| services.greetd.useTextGreeter | Whether the greeter uses text-based user interfaces (For example, tuigreet)
|
| services._3proxy.services.*.acl | Use this option to limit user access to resources.
|
| services.blockbook-frontend.<name>.rpc.port | Port for JSON-RPC connections.
|
| services.biboumi.credentialsFile | Path to a configuration file to be merged with the settings
|
| services.lanraragi.redis.port | Port for LANraragi's Redis server.
|
| hardware.sane.brscan4.netDevices.<name>.nodename | The node name of the device
|
| services.angrr.settings.temporary-root-policies | Policies for temporary GC roots(e.g. result and direnv).
|
| services.anuko-time-tracker.settings.email.smtpDebug | Debug mail sending.
|
| services.headscale.settings.prefixes.allocation | Strategy used for allocation of IPs to nodes, available options:
- sequential (default): assigns the next free IP from the previous given IP.
- random: assigns the next free IP from a pseudo-random IP generator (crypto/rand).
|
| services.dependency-track.oidc.clientId | Defines the client ID for OpenID Connect.
|
| services.hydra.buildMachinesFiles | List of files containing build machines.
|
| services.dawarich.redis.host | The redis host Dawarich will connect to.
|
| programs.wshowkeys.enable | Whether to enable wshowkeys (displays keypresses on screen on supported Wayland
compositors)
|
| services.discourse.enableACME | Whether an ACME certificate should be used to secure
connections to the server.
|
| security.pam.oath.usersFile | Set the path to file where the user's credentials are
stored
|
| services.bacula-fd.director | This option defines director resources in Bacula File Daemon.
|
| services.bacula-fd.director.<name>.tls.certificate | The full path to the PEM encoded TLS certificate
|
| services.hledger-web.enable | Whether to enable hledger-web service.
|
| services.hypridle.package | The hypridle package to use.
|
| services.filebrowser.settings.port | The port to listen on.
|
| services.librespeed.frontend.servers.*.ulURL | URL path to upload test on this server
|
| services.awstats.configs.<name>.type | The type of log being collected.
|
| services.bacula-fd.director.<name>.tls.key | The path of a PEM encoded TLS private key
|
| security.tpm2.fapi.tcti | The TCTI which will be used
|
| services.keycloak.sslCertificate | The path to a PEM formatted certificate to use for TLS/SSL
connections.
|
| boot.plymouth.package | The plymouth package to use.
|
| services.buildkite-agents.<name>.name | The name of the agent as seen in the buildkite dashboard.
|
| hardware.trackpoint.jenks | Minimum curvature in degrees required to generate a double click without a release.
|
| services.borgbackup.jobs.<name>.environment | Environment variables passed to the backup script
|
| boot.tmp.zramSettings.compression-algorithm | The compression algorithm to use for the zram device
|
| programs.light.enable | Whether to install Light backlight control command
and udev rules granting access to members of the "video" group.
|
| image.repart.verityStore.partitionIds.store | Specify the attribute name of the store partition.
|
| services.flexget.systemScheduler | When true, execute the runs via the flexget-runner.timer
|
| services.bookstack.nginx.locations | Declarative location config
|
| services.inadyn.settings.provider.<name>.password | Password for this DDNS provider
|
| hardware.nvidia.nvidiaSettings | Whether to enable nvidia-settings, NVIDIA's GUI configuration tool
.
|
| services.audiobookshelf.user | User account under which Audiobookshelf runs.
|
| services.gmediarender.friendlyName | A "friendly name" for identifying the endpoint.
|
| services.dolibarr.database.user | Database username.
|
| services.bonsaid.settings.*.event_name | Name of the event which should trigger this transition when received by bonsaid
|
| services.dae.openFirewall | Open the firewall port.
|
| services.firewalld.zones.<name>.ports | Ports to allow in the zone.
|
| services.druid.middleManager.restartIfChanged | Automatically restart the service on config change
|
| services.gnunet.package | The gnunet package to use.
|
| services.fwupd.daemonSettings | Configurations for the fwupd daemon.
|
| services.diod.allsquash | Remap all users to "nobody"
|
| services.jicofo.userDomain | Domain part of the JID for XMPP user connection.
|
| services.goatcounter.package | The goatcounter package to use.
|
| services.displayManager.lemurs.settings | Configuration for lemurs, provided as a Nix attribute set and automatically
serialized to TOML
|
| services.homebridge.group | Group to run homebridge as.
|
| services.easytier.instances.<name>.settings.instance_name | Identify different instances on same host
|
| services.fireqos.config | The FireQOS configuration.
|
| hardware.coral.pcie.enable | Whether to enable Coral PCIe support.
|
| services.gitlab.sidekiq.memoryKiller.enable | Whether the Sidekiq MemoryKiller should be turned
on
|
| services._3proxy.resolution.nserver | List of nameservers to use
|
| boot.loader.refind.efiInstallAsRemovable | Whether or not to install the rEFInd EFI files as removable
|
| services.kapacitor.alerta.url | The URL to the Alerta REST API
|
| services.headphones.enable | Whether to enable the headphones server.
|
| services.cfdyndns.enable | Whether to enable Cloudflare Dynamic DNS Client.
|
| services.factorio.token | Authentication token
|
| services.ghostunnel.servers.<name>.extraArguments | Extra arguments to pass to ghostunnel server
|
| services.go-httpbin.settings.HOST | The host to listen on.
|
| programs.localsend.package | The localsend package to use.
|
| services.anuko-time-tracker.nginx | With this option, you can customize the Nginx virtualHost settings.
|
| services.doh-server.settings | Configuration of doh-server in toml
|
| services.gvpe.configFile | GVPE config file, if already present
|
| programs.television.enable | Whether to enable Blazingly fast general purpose fuzzy finder TUI.
|
| hardware.cpu.intel.sgx.enableDcapCompat | Whether to enable backward compatibility for SGX software build for the
out-of-tree Intel SGX DCAP driver
|
| services.esphome.openFirewall | Whether to open the firewall for the specified port.
|
| services.evremap.settings.device_name | The name of the device that should be remapped
|
| services.i2pd.proto.http.address | Bind address for http endpoint.
|
| services.glitchtip.database.createLocally | Whether to enable and configure a local PostgreSQL database server.
|
| services.gitlab.smtp.enable | Enable gitlab mail delivery over SMTP.
|
| services.jellyfin.hardwareAcceleration.device | Path to the hardware acceleration device that Jellyfin should use
|
| services.distccd.stats.port | The TCP port which the distccd statistics HTTP server will listen
on.
|
| services.firezone.server.provision.accounts.<name>.actors.<name>.email | The email address used to authenticate as this account
|
| services.jenkins.jobBuilder.accessToken | User token in Jenkins used to reload config
|
| boot.initrd.systemd.packages | Packages providing systemd units and hooks.
|
| programs.digitalbitbox.package | The digitalbitbox package to use
|
| services.gotenberg.chromium.package | The chromium package to use.
|
| hardware.trackpoint.ztime | This attribute determines how sharp a press has to be in order to be recognized.
|
| hardware.nvidia-container-toolkit.csv-files | The path to the list of CSV files to use when generating the CDI specification in CSV mode.
|
| boot.initrd.network.udhcpc.extraArgs | Additional command-line arguments passed verbatim to
udhcpc if boot.initrd.network.enable and
boot.initrd.network.udhcpc.enable are enabled.
|
| programs.pmount.package | The pmount package to use.
|
| services.anki-sync-server.users.*.passwordFile | File containing the password accepted by anki-sync-server for
the associated username
|
| security.pam.services.<name>.howdy.enable | Whether to enable the Howdy PAM module
|
| services.distccd.nice | Niceness of the compilation tasks.
|
| services.fedimintd.<name>.api_ws.openFirewall | Opens TCP port in firewall for fedimintd's Websocket API
|
| services.dovecot2.imapsieve.mailbox.*.causes | Only execute the administrator Sieve scripts for the mailbox configured with services.dovecot2.imapsieve.mailbox..name when one of the listed IMAPSIEVE causes apply
|
| services.forgejo.customDir | Base directory for custom templates and other options
|
| services.ghostunnel.servers.<name>.key | Path to certificate private key (PEM with private key)
|
| services.c2fmzq-server.settings | Configuration for c2FmZQ-server passed as CLI arguments
|
| programs.proxychains.chain.length | Chain length for random chain.
|
| services.drupal.sites.<name>.virtualHost.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.doh-server.settings.ecs_use_precise_ip | If ECS is added to the request, let the full IP address or cap it to 24 or 128 mask
|
| services.fediwall.settings.servers | Servers to load posts from
|
| services.hadoop.hbase.rest.extraFlags | Extra flags for the rest service.
|
| services.hqplayerd.auth.password | Password used for HQPlayer's WebUI
|
| services.invidious-router.enable | Whether to enable the invidious-router service.
|