| services.endlessh-go.openFirewall | Whether to open a firewall port for the SSH listener.
|
| services.homebridge.uiSettings | Configuration options for homebridge config UI plugin
|
| security.duosec.fallbackLocalIP | Duo Unix reports the IP address of the authorizing user, for
the purposes of authorization and whitelisting
|
| services.athens.storage.s3.token | Token for the S3 storage backend
|
| services.galene.httpAddress | HTTP listen address for galene.
|
| hardware.fw-fanctrl.config.defaultStrategy | Default strategy to use
|
| services.foundationdb.pidfile | Path to pidfile for fdbmonitor.
|
| services.graylog.user | User account under which graylog runs
|
| services.anubis.defaultOptions.enable | Whether to enable this instance of Anubis.
|
| security.isolate.boxRoot | All sandboxes are created under this directory
|
| services.desktopManager.cosmic.xwayland.enable | Whether to enable Xwayland support for the COSMIC compositor.
|
| services.libretranslate.enable | Whether to enable LibreTranslate service.
|
| networking.nftables.tables.<name>.family | Table family.
|
| services.akkoma.nginx.locations.<name>.fastcgiParams | FastCGI parameters to override
|
| services.journalbeat.enable | Whether to enable journalbeat.
|
| services.firefly-iii-data-importer.dataDir | The place where firefly-iii data importer stores its state.
|
| boot.iscsi-initiator.discoverPortal | iSCSI portal to boot from.
|
| services.calibre-server.user | The user under which calibre-server runs.
|
| security.krb5.package | The krb5 package to use.
|
| services.duplicity.enable | Whether to enable backups with duplicity.
|
| services.homebridge.uiSettings.restart | Command to restart the homebridge UI service
|
| services.firefly-iii.settings.APP_KEY_FILE | The path to your appkey
|
| services.gitolite.user | Gitolite user account
|
| services.firezone.gui-client.name | The name of this client as shown in firezone
|
| services.gitea.database.name | Database name.
|
| services.boinc.enable | Whether to enable the BOINC distributed computing client
|
| services.hydra.port | TCP port the web server should listen to.
|
| services.graylog.elasticsearchHosts | List of valid URIs of the http ports of your elastic nodes
|
| hardware.flirc.enable | Whether to enable software to configure a Flirc USB device.
|
| hardware.sane.brscan5.netDevices.<name>.name | The friendly name you give to the network device
|
| services.akkoma.frontends.<name>.package | Akkoma frontend package.
|
| services.fedimintd.<name>.nginx.config.basicAuthFile | Basic Auth password file for a vhost
|
| services.blendfarm.serverConfig.BypassScriptUpdate | Prevents blendfarm from replacing the .py self-generated scripts.
|
| powerManagement.cpufreq.max | The maximum frequency the CPU will use
|
| programs.openvpn3.package | The openvpn3 package to use.
|
| services.grafana.provision.datasources.settings.datasources.*.secureJsonData | Datasource specific secure configuration
|
| services.dovecot2.sslCACert | Path to the server's CA certificate key.
|
| boot.loader.grub.mirroredBoots.*.devices | The path to the devices which will have the GRUB MBR written
|
| services.icecream.daemon.schedulerHost | Explicit scheduler hostname, useful in firewalled environments
|
| services.diod.authRequired | Allow clients to connect without authentication, i.e. without a valid MUNGE credential.
|
| services.grafana.provision.alerting.muteTimings.path | Path to YAML mute timings configuration
|
| power.ups.upsmon.monitor.<name>.type | The relationship with upsd
|
| services.cfdyndns.email | The email address to use to authenticate to CloudFlare.
|
| services.journaldriver.logName | Configures the name of the target log in Stackdriver Logging
|
| services.earlyoom.freeSwapKillThreshold | Minimum free swap space (in percent) before sending SIGKILL
|
| services.firewalld.zones.<name>.short | Short description for the zone.
|
| services.hadoop.hbase.regionServer.environment | Environment variables passed to regionServer.
|
| services.fediwall.hostName | The hostname to serve fediwall on.
|
| services.diod.enable | Whether to enable the diod 9P file server.
|
| services.fedimintd.<name>.consensus.finalityDelay | Consensus peg-in finality delay.
|
| services.hardware.lcd.client.extraConfig | Additional configuration added verbatim to the client config.
|
| services.fedimintd.<name>.enable | Whether to enable fedimintd.
|
| services.httpd.virtualHosts.<name>.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| services.buildbot-worker.home | Buildbot home directory.
|
| programs.npm.enable | Whether to enable npm global config.
|
| services.kismet.settings | Options for Kismet
|
| services.cloudflare-ddns.cacheExpiration | Duration for which API responses (like Zone ID, Record IDs) are cached
|
| boot.initrd.luks.devices.<name>.gpgCard.publicKey | Path to the Public Key.
|
| services.gancio.nginx.locations.<name>.basicAuthFile | Basic Auth password file for a vhost
|
| services.icecast.enable | Whether to enable Icecast server.
|
| services.agorakit.database.port | Database host port.
|
| services.fastnetmon-advanced.settings | Extra configuration options to declaratively load into FastNetMon Advanced
|
| boot.initrd.systemd.users.<name>.group | Group the user belongs to in initrd.
|
| boot.uvesafb.v86d.package | Which v86d package to use with uvesafb
|
| programs.singularity.package | The singularity package to use.
|
| services.jellyfin.transcoding.hardwareDecodingCodecs.mpeg2 | Enable hardware decoding for mpeg2 codec.
|
| boot.loader.external.installHook | The full path to a program of your choosing which performs the bootloader installation process
|
| services.atuin.enable | Whether to enable Atuin server for shell history sync.
|
| services.borgbackup.repos.<name>.path | Where to store the backups
|
| services.cgit | Configure cgit instances.
|
| security.doas.extraRules.*.args | Arguments that must be provided to the command
|
| services.bitwarden-directory-connector-cli.ldap.pagedSearch | Whether the LDAP server paginates search results.
|
| services.dolibarr.nginx.listen.*.addr | Listen address.
|
| services.dendrite.settings.sync_api.search.index_path | The path the search index will be created in.
|
| services.foldingathome.team | The team ID associated with the reported computation results
|
| services.headscale.settings.policy.path | If the mode is set to "file", the path to a
HuJSON file containing ACL policies.
|
| programs.zsh.ohMyZsh.cacheDir | Cache directory to be used by oh-my-zsh
|
| services.ferretdb.settings.FERRETDB_SQLITE_URL | SQLite URI (directory) for 'sqlite' handler
|
| security.acme.certs.<name>.credentialFiles | Environment variables suffixed by "_FILE" to set for the cert's service
for your selected dnsProvider
|
| services.calibre-server.group | The group under which calibre-server runs.
|
| services.fluidd.nginx.onlySSL | Whether to enable HTTPS and reject plain HTTP connections
|
| services.firezone.server.provision.accounts.<name>.features.internet_resource | Whether to enable the internet_resource feature for this account.
|
| services.jupyterhub.kernels.<name>.argv | Command and arguments to start the kernel.
|
| services.anuko-time-tracker.nginx.locations.<name>.basicAuth | Basic Auth protection for a vhost
|
| services.gitlab.registry.port | GitLab container registry port.
|
| services.anubis.defaultOptions.settings.BIND_NETWORK | The network family that Anubis should bind to
|
| services.adguardhome.enable | Whether to enable AdGuard Home network-wide ad blocker.
|
| services.immich.secretsFile | Path of a file with extra environment variables to be loaded from disk
|
| services.gancio.nginx | Extra configuration for the nginx virtual host of gancio.
|
| services.fedimintd.<name>.nginx.config.locations.<name>.fastcgiParams | FastCGI parameters to override
|
| boot.zfs.allowHibernation | Allow hibernation support, this may be a unsafe option depending on your
setup
|
| services.gitolite.enable | Enable gitolite management under the
gitolite user
|
| programs.uwsm.waylandCompositors.<name>.binPath | The wayland-compositor binary path that will be called by UWSM
|
| services.apache-kafka.configFiles.serverProperties | Kafka server.properties configuration file path
|
| services.drupal.sites.<name>.virtualHost.sslServerCert | Path to server SSL certificate.
|
| security.tpm2.applyUdevRules | Whether to make the /dev/tpm[0-9] devices accessible by the tssUser, or
the /dev/tpmrm[0-9] by tssGroup respectively
|
| services.grafana.settings.users.allow_sign_up | Set to false to prohibit users from being able to sign up / create user accounts
|
| services.cfssl.caBundle | Path to root certificate store.
|
| services.anubis.defaultOptions.settings | Freeform configuration via environment variables for Anubis
|
| services.distccd.package | The distcc package to use.
|