| services.cfssl.responderKey | Private key for OCSP responder certificate
|
| services.postgrey.privacy | Store data using one-way hash functions (SHA1)
|
| services.mautrix-discord.environmentFile | File containing environment variables to substitute when copying the configuration
out of Nix store to the services.mautrix-discord.dataDir
|
| services.ncps.cache.lru.schedule | The cron spec for cleaning the store to keep it under
config.ncps.cache.maxSize
|
| services.rke2.agentToken | The rke2 token agents can use to connect to the server
|
| services.journald.storage | Controls where to store journal data
|
| virtualisation.docker.liveRestore | Alias of virtualisation.docker.daemon.settings.live-restore.
|
| services.headphones.dataDir | Path where to store data files.
|
| services.rss-bridge.config.FileCache.path | Directory where to store cache files (if cache.type = "file").
|
| services.rmfakecloud.environmentFile | Path to an environment file loaded for the rmfakecloud service
|
| services.teamspeak3.logPath | Directory to store log files in.
|
| services.nextcloud.config.objectstore.s3.key | The access key for the S3 bucket.
|
| services.pixelfed.secretFile | A secret file to be sourced for the .env settings
|
| services.mautrix-discord.dataDir | Directory to store the bridge's configuration and database files
|
| services.pgbackrest.commands.restore | Options for the 'restore' command
|
| services.limesurvey.nginx.virtualHost.locations.<name>.basicAuth | Basic Auth protection for a vhost
|
| boot.loader.grub.users | User accounts for GRUB
|
| services.traefik.dataDir | Location for any persistent data Traefik creates, such as the ACME certificate store.
If left as the default value, this directory will automatically be created
before the Traefik server starts, otherwise you are responsible for ensuring
the directory exists with appropriate ownership and permissions.
|
| nix.buildMachines.*.sshKey | The path to the SSH private key with which to authenticate on
the build machine
|
| networking.wireguard.interfaces.<name>.privateKey | Base64 private key generated by wg genkey
|
| services.mqtt2influxdb.influxdb.password | Password for InfluxDB login
|
| services.slurm.extraConfigPaths | Slurm expects config files for plugins in the same path
as slurm.conf
|
| services.librechat.dataDir | Absolute path for where the LibreChat server will use as its data directory to store logs, user uploads, and generated images.
|
| services.nextcloud.config.objectstore.s3.useSsl | Use SSL for objectstore access.
|
| services.nextcloud.config.objectstore.s3.port | Required for some non-Amazon implementations.
|
| services.thanos.compact.enable | Whether to enable the Thanos compactor which continuously compacts blocks in an object store bucket.
|
| services.gammu-smsd.backend.service | Service to use to store sms data.
|
| services.ghostunnel.servers.<name>.keystore | Path to keystore (combined PEM with cert/key, or PKCS12 keystore)
|
| services.outline.redisUrl | Connection to a redis server
|
| services.selfoss.database.type | Database to store feeds
|
| services.szurubooru.dataDir | The path to the data directory in which Szurubooru will store its data.
|
| services.teamspeak3.dataDir | Directory to store TS3 database and other state/data files.
|
| services.hebbot.botPasswordFile | A path to the password file for your bot
|
| services.syncplay.salt | Salt to allow room operator passwords generated by this server
instance to still work when the server is restarted
|
| services.resilio.storagePath | Where BitTorrent Sync will store it's database files (containing
things like username info and licenses)
|
| services.snmpd.configText | The contents of the snmpd.conf
|
| security.ipa.offlinePasswords | Whether to store offline passwords when the server is down.
|
| services.podgrab.dataDirectory | Directory to store downloads.
|
| services.gitolite.dataDir | The gitolite home directory used to store all repositories
|
| services.cfssl.metadata | Metadata file for root certificate presence
|
| services.nextcloud.config.objectstore.s3.bucket | The name of the S3 bucket.
|
| services.cross-seed.settingsFile | Path to a JSON file containing settings that will be merged with the
settings option
|
| services.crowdsec-firewall-bouncer.settings.api_key | API key to authenticate with a local crowdsec API
|
| services.minecraft-server.dataDir | Directory to store Minecraft database and other state/data files.
|
| services.shellhub-agent.privateKey | Location where to store the ShellHub Agent private
key.
|
| services.nextcloud.config.objectstore.s3.region | Required for some non-Amazon implementations.
|
| services.lidarr.settings | Attribute set of arbitrary config options
|
| services.cross-seed.settings | Configuration options for cross-seed
|
| services.sonarr.settings | Attribute set of arbitrary config options
|
| services.radarr.settings | Attribute set of arbitrary config options
|
| services.immich.mediaLocation | Directory used to store media files
|
| services.patroni.namespace | Path within the configuration store where Patroni will keep information about the cluster.
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.basicAuth | Basic Auth protection for a vhost
|
| services.prometheus.exporters.blackbox.enableConfigCheck | Whether to run a correctness check for the configuration file
|
| services.vault.storageConfig | HCL configuration to insert in the storageBackend section
|
| services.typesense.apiKeyFile | Sets the admin api key for typesense
|
| services.zitadel.extraStepsPaths | A list of paths to extra steps files
|
| services.xtreemfs.dir.extraConfig | Configuration of XtreemFS DIR service
|
| services.xtreemfs.osd.extraConfig | Configuration of XtreemFS OSD service
|
| services.xtreemfs.mrc.extraConfig | Configuration of XtreemFS MRC service
|
| services.couchdb.extraConfigFiles | Extra configuration files
|
| services.tahoe.nodes.<name>.client.shares.total | The number of shares required to store a file.
|
| services.scollector.bosunHost | Host and port of the bosun server that will store the collected
data.
|
| services.nextcloud.config.objectstore.s3.secretFile | The full path to a file that contains the access secret.
|
| services.gokapi.settingsFile | Path to config file to parse and append to settings
|
| services.mautrix-meta.instances.<name>.environmentFile | File containing environment variables to substitute when copying the configuration
out of Nix store to the services.mautrix-meta.dataDir
|
| services.icecream.daemon.cacheLimit | Maximum size in Megabytes of cache used to store compile environments of compile clients.
|
| services.stalwart.settings | Configuration options for the Stalwart server
|
| services.tahoe.nodes.<name>.client.shares.happy | The number of distinct storage nodes required to store
a file.
|
| services.fider.database.url | URI to use for the main PostgreSQL database
|
| services.godns.loadCredential | This can be used to pass secrets to the systemd service without adding
them to the nix store.
|
| services.warpgate.settings.ssh.keys | Path to store SSH host & client keys.
|
| services.gammu-smsd.backend.sql.database | Database name to store sms data
|
| services.buildbot-worker.workerPassFile | File used to store the Buildbot Worker password
|
| services.fedimintd.<name>.dataDir | Path to the data dir fedimintd will use to store its data
|
| networking.wg-quick.interfaces.<name>.peers.*.presharedKey | Base64 preshared key generated by wg genpsk
|
| services.immich.secretsFile | Path of a file with extra environment variables to be loaded from disk
|
| services.readarr.settings | Attribute set of arbitrary config options
|
| services.prometheus.exporters.pve.environmentFile | Path to the service's environment file
|
| services.netbird.clients.<name>.dir.state | A state directory used by NetBird client to store config.json, state.json & resolv.conf.
|
| services.netbird.tunnels.<name>.dir.state | A state directory used by NetBird client to store config.json, state.json & resolv.conf.
|
| services.hadoop.hdfs.datanode.dataDirs.*.path | Determines where on the local filesystem a data node should store its blocks.
|
| services.nextcloud.config.objectstore.s3.hostname | Required for some non-Amazon implementations.
|
| services.nextcloud.config.objectstore.s3.usePathStyle | Required for some non-Amazon S3 implementations
|
| boot.loader.grub.users.<name>.hashedPassword | Specifies the password hash for the account,
generated with grub-mkpasswd-pbkdf2
|
| security.dhparams.params.<name>.path | The resulting path of the generated Diffie-Hellman parameters
file for other services to reference
|
| services.prometheus.stateDir | Directory below /var/lib to store Prometheus metrics data
|
| services.sourcehut.builds.images | Images for builds.sr.ht
|
| services.ncps.upstream.publicKeys | A list of public keys of upstream caches in the format
host[-[0-9]*]:public-key
|
| services.powerdns.secretFile | Environment variables from this file will be interpolated into the
final config file using envsubst with this syntax: $ENVIRONMENT
or ${VARIABLE}
|
| services.usbguard.restoreControllerDeviceState | The USBGuard daemon modifies some attributes of controller
devices like the default authorization state of new child device
instances
|
| services.borgbackup.repos.<name>.path | Where to store the backups
|
| services.nextcloud.config.objectstore.s3.enable | Whether to enable S3 object storage as primary storage
|
| services.olivetin.extraConfigFiles | Config files to merge into the settings defined in services.olivetin.settings
|
| services.stalwart-mail.settings | Configuration options for the Stalwart email server
|
| services.minidlna.settings.db_dir | Specify the directory to store database and album art cache.
|
| services.kubernetes.secretsPath | Default location for kubernetes secrets
|
| services.firezone.relay.tokenFile | A file containing the firezone relay token
|
| fileSystems.<name>.neededForBoot | If set, this file system will be mounted in the initial ramdisk
|
| services.weblate.djangoSecretKeyFile | Location of the Django secret key
|