| services.timesyncd.servers | The set of NTP servers from which to synchronise
|
| services.kapacitor.loadDirectory | Directory where to load services from, such as tasks, templates and handlers (or null to disable service loading on startup)
|
| services.hardware.pommed.configFile | The path to the pommed.conf file
|
| services.mysql.initialDatabases.*.schema | The initial schema of the database; if null (the default),
an empty database is created.
|
| services.home-assistant.config | Your configuration.yaml as a Nix attribute set
|
| services.postfix.masterConfig.<name>.maxproc | The maximum number of processes to spawn for this service
|
| services.resolved.fallbackDns | A list of IPv4 and IPv6 addresses to use as the fallback DNS servers
|
| services.keepalived.snmp.socket | Socket to use for connecting to SNMP master agent
|
| services.fedimintd.<name>.nginx.config.acmeRoot | Directory for the ACME challenge, which is public
|
| services.pomerium.useACMEHost | If set, use a NixOS-generated ACME certificate with the specified name
|
| services.rsyncd.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| virtualisation.bios | An alternate BIOS (such as qboot) with which to start the VM
|
| services.vwifi.client.serverAddress | The address of the server
|
| boot.loader.limine.maxGenerations | Maximum number of latest generations in the boot menu
|
| boot.loader.refind.maxGenerations | Maximum number of latest generations in the boot menu
|
| services.thanos.rule.tracing.config | Tracing configuration
|
| services.vsmartcard-vpcd.hostname | Hostname of a waiting vpicc server vpcd will be connecting to
|
| services.postfix.masterConfig.<name>.private | Whether the service's sockets and storage directory is restricted to
be only available via the mail system
|
| services.thanos.receive.remote-write.address | Address to listen on for remote write requests
|
| services.keycloak.database.caCert | The SSL / TLS CA certificate that verifies the identity of the
database server
|
| services.mattermost.plugins | Plugins to add to the configuration
|
| services.limesurvey.virtualHost.acmeRoot | Directory for the acme challenge which is PUBLIC, don't put certs or keys in here
|
| services.icecream.daemon.maxProcesses | Maximum number of compile jobs started in parallel for this daemon
|
| services.hickory-dns.settings.zones.*.file | Path to the .zone file
|
| boot.initrd.systemd.emergencyAccess | Set to true for unauthenticated emergency access, and false or
null for no emergency access
|
| services.thanos.receive.tsdb.retention | How long to retain raw samples on local storage.
0d - disables this retention
Defaults to 15d in Thanos
when set to null.
|
| services.thanos.store.tracing.config | Tracing configuration
|
| services.thanos.query.tracing.config | Tracing configuration
|
| services.thanos.query-frontend.grpc-address | Listen ip:port address for gRPC endpoints (StoreAPI)
|
| services.mediawiki.httpd.virtualHost.acmeRoot | Directory for the acme challenge which is PUBLIC, don't put certs or keys in here
|
| services.xserver.windowManager.qtile.configFile | Path to the qtile configuration file
|
| services.dragonflydb.memcachePort | To enable memcached compatible API on this port.
null means disabled.
|
| programs.tsmClient.servers | Server definitions ("stanzas")
for the client system-options file
|
| security.tpm2.fapi.ekFingerprint | The fingerprint of the endorsement key
|
| services.thanos.query.query.max-concurrent | Maximum number of queries processed concurrently by query node
|
| services.xserver.windowManager.bspwm.configFile | Path to the bspwm configuration file
|
| services.ghostunnel.servers.<name>.cacert | Path to CA bundle file (PEM/X509)
|
| boot.kernel.sysfs | sysfs attributes to be set as soon as they become available
|
| services.icecream.daemon.schedulerHost | Explicit scheduler hostname, useful in firewalled environments
|
| services.borgbackup.jobs.<name>.prune.prefix | Only consider archive names starting with this prefix for pruning
|
| services.tor.relay.onionServices.<name>.secretKey | Secret key of the onion service
|
| services.thanos.rule.objstore.config | Object store configuration
|
| services.icingaweb2.groupBackends | groups.ini contents
|
| services.librespeed.frontend.enable | Enables the LibreSpeed frontend and adds a nginx virtual host if
not explicitly disabled and services.librespeed.domain is not null.
|
| networking.wlanInterfaces.<name>.mac | MAC address to use for the device
|
| services.wordpress.sites.<name>.virtualHost.acmeRoot | Directory for the acme challenge which is PUBLIC, don't put certs or keys in here
|
| services.librespeed.settings | LibreSpeed configuration written as Nix expression
|
| services.btrbk.instances.<name>.onCalendar | How often this btrbk instance is started
|
| services.thanos.sidecar.prometheus.url | URL at which to reach Prometheus's API
|
| services.anubis.defaultOptions.botPolicy | Anubis policy configuration in Nix syntax
|
| services.dovecot2.mailboxes.<name>.specialUse | Null if no special use flag is set
|
| security.pam.yubico.challengeResponsePath | If not null, set the path used by yubico pam module where the challenge expected response is stored
|
| services.thanos.store.objstore.config | Object store configuration
|
| services.postsrsd.settings.srs-domain | Dedicated mail domain used for ephemeral SRS envelope addresses
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".socket_dir | Path to the postgres socket directory
|
| services.anubis.instances.<name>.botPolicy | Anubis policy configuration in Nix syntax
|
| services.kanidm.serverSettings.domain | The domain that Kanidm manages
|
| services.cassandra.fullRepairInterval | Set the interval how often full repairs are run, i.e.
nodetool repair --full is executed
|
| networking.interfaces.<name>.useDHCP | Whether this interface should be configured with DHCP
|
| services.thanos.query.store.unhealthy-timeout | Timeout before an unhealthy store is cleaned from the store UI page
|
| programs.ssh.forwardX11 | Whether to request X11 forwarding on outgoing connections by default
|
| services.prometheus.scrapeConfigs.*.scheme | The URL scheme with which to fetch metrics from targets
|
| services.thanos.compact.tracing.config | Tracing configuration
|
| services.limesurvey.httpd.virtualHost.acmeRoot | Directory for the acme challenge which is PUBLIC, don't put certs or keys in here
|
| services.limesurvey.nginx.virtualHost.acmeRoot | Directory for the ACME challenge, which is public
|
| services.mediawiki.extensions | Attribute set of paths whose content is copied to the extensions
subdirectory of the MediaWiki installation and enabled in configuration
|
| services.postfix.settings.master.<name>.maxproc | The maximum number of processes to spawn for this service
|
| services.thanos.sidecar.tracing.config | Tracing configuration
|
| services.thanos.receive.tracing.config | Tracing configuration
|
| system.nixos.label | NixOS version name to be used in the names of generated
outputs and boot labels
|
| virtualisation.diskImage | Path to the disk image containing the root filesystem
|
| services.thanos.query.store.response-timeout | If a Store doesn't send any data in this specified duration then a
Store will be ignored and partial data will be returned if it's
enabled. 0 disables timeout
|
| services.kanidm.server.settings.domain | The domain that Kanidm manages
|
| services.thanos.store.block-sync-concurrency | Number of goroutines to use when syncing blocks from object storage
|
| services.postfix.settings.master.<name>.private | Whether the service's sockets and storage directory is restricted to
be only available via the mail system
|
| services.xserver.windowManager.bspwm.sxhkd.configFile | Path to the sxhkd configuration file
|
| services.icingaweb2.resources | resources.ini contents
|
| services.cloudflare-dyndns.frequency | Run cloudflare-dyndns with the given frequency (see
systemd.time(7) for the format)
|
| services.biboumi.settings.password | The password used to authenticate the XMPP component to your XMPP server
|
| services.fcgiwrap.instances.<name>.process.user | User as which this instance of fcgiwrap will be run
|
| networking.dhcpcd.allowInterfaces | Enable the DHCP client for any interface whose name matches
any of the shell glob patterns in this list
|
| services.gitlab.sidekiq.concurrency | How many processor threads to use for processing sidekiq background job queues
|
| networking.interfaces.<name>.virtualOwner | In case of a virtual device, the user who owns it.
null will not set owner, allowing access to any user.
|
| services.paperless.exporter.onCalendar | When to run the exporter
|
| services.transmission.webHome | If not null, sets the value of the TRANSMISSION_WEB_HOME
environment variable used by the service
|
| services.waagent.settings.OS.RootDeviceScsiTimeout | Configures the SCSI timeout in seconds on the OS disk and data drives
|
| services.icingaweb2.generalConfig | config.ini contents
|
| services.matrix-synapse.settings.database.args.user | Username to connect with psycopg2, set to null
when using sqlite3.
|
| services.discourse.backendSettings | Additional settings to put in the
discourse.conf file
|
| services.dawarich.secretKeyBaseFile | Path to file containing the secret key base
|
| services.pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.thanos.sidecar.objstore.config | Object store configuration
|
| services.thanos.compact.objstore.config | Object store configuration
|
| services.thanos.receive.objstore.config | Object store configuration
|
| services.timesyncd.fallbackServers | The set of fallback NTP servers from which to synchronise
|
| services.discourse.mail.incoming.apiKeyFile | A file containing the Discourse API key used to add
posts and messages from mail
|
| i18n.inputMethod.type | Select the enabled input method
|
| systemd.services.<name>.confinement.binSh | The program to make available as /bin/sh inside
the chroot
|
| services.jellyfin.transcoding.threadCount | Number of threads to use when transcoding
|
| services.borgbackup.jobs.<name>.archiveBaseName | How to name the created archives
|