| services.quassel.enable | Whether to enable the Quassel IRC client daemon.
|
| services.mail.sendmailSetuidWrapper.source | The absolute path to the program to be wrapped.
|
| services.prometheus.exporters.frr.port | Port to listen on.
|
| services.pretix.settings.pretix.currency | Default currency for events in its ISO 4217 three-letter code.
|
| services.prometheus.scrapeConfigs.*.docker_sd_configs.*.tls_config.key_file | Key file for client cert authentication to the server.
|
| services.meshtasticd.port | Port to listen on
|
| services.rspamd.localLuaRules | Path of file to link to /etc/rspamd/rspamd.local.lua for local
rules written in Lua
|
| services.slskd.nginx.listen.*.ssl | Enable SSL.
|
| services.tt-rss.phpPackage | php package to use for php fpm and update daemon.
|
| services.tuned.settings.profile_dirs | Directories to search for profiles, separated by , or ;.
|
| services.tayga.ipv6.address | The source IPv6 address of the TAYGA server.
|
| services.thanos.query.arguments | Arguments to the thanos query command
|
| services.tabby.usageCollection | Enable sending anonymous usage data
|
| services.opengfw.settings.ruleset.geosite | Path to geosite.dat.
|
| services.turn-rs.package | The turn-rs package to use.
|
| services.pleroma.secretConfigFile | Path to the file containing your secret pleroma configuration.
DO NOT POINT THIS OPTION TO THE NIX
STORE, the store being world-readable, it'll
compromise all your secrets.
|
| services.rspamd.extraConfig | Extra configuration to add at the end of the rspamd configuration
file.
|
| services.trafficserver.plugins | Controls run-time loadable plugins available to Traffic Server, as
well as their configuration
|
| services.monica.nginx.listen.*.ssl | Enable SSL.
|
| services.strongswan-swanctl.swanctl.secrets.private.<name>.file | File name in the private folder for which this passphrase should be used.
|
| services.prometheus.exporters.mqtt.mqttUsername | Username which should be used to authenticate against the MQTT broker.
|
| services.pretalx.nginx.domain | The domain name under which to set up the virtual host.
|
| services.snapper.configs.<name>.SUBVOLUME | Path of the subvolume or mount point
|
| services.monica.nginx.sslCertificate | Path to server SSL certificate.
|
| services.squid.enable | Whether to run squid web proxy.
|
| services.nginx.virtualHosts.<name>.locations.<name>.extraConfig | These lines go to the end of the location verbatim.
|
| services.strongswan.ca | A set of CAs (certification authorities) and their options for
the ‘ca xxx’ sections of the ipsec.conf
file.
|
| services.stirling-pdf.package | The stirling-pdf package to use.
|
| services.tp-auto-kbbl.arguments | List of arguments appended to ./tp-auto-kbbl --device [device] [arguments]
|
| services.radicle.httpd.enable | Whether to enable Radicle HTTP gateway to radicle-node.
|
| services.nginx.virtualHosts.<name>.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.prometheus.exporters.mail.environmentFile | File containing env-vars to be substituted into the exporter's config.
|
| services.multipath.devices.*.detect_prio | If set to "yes", multipath will try to detect if the device supports
SCSI-3 ALUA
|
| services.mastodon.database.user | Database user.
|
| services.nitter.preferences.muteVideos | Mute videos by default.
|
| services.porn-vault.package | The porn-vault package to use.
|
| services.tor.settings.ExitPolicyRejectPrivate | See torrc manual.
|
| services.listmonk.database.settings."app.notify_emails" | Administrator emails for system notifications
|
| services.prometheus.exporters.unbound.unbound.host | Path to the unbound control socket
|
| services.mailman.ldap.groupSearch.ou | Organizational unit to look up a group.
|
| services.static-web-server.root | The location of files for SWS to serve
|
| services.prometheus.exporters.snmp.logLevel | Only log messages with the given severity or above.
|
| services.misskey.meilisearch.createLocally | Create and use a local Meilisearch instance
|
| services.tor.settings.EntryStatistics | See torrc manual.
|
| services.peering-manager.listenAddress | Address the server will listen on.
|
| services.minio.consoleAddress | IP address and port of the web UI (console).
|
| services.maddy.tls.extraConfig | Arguments for the specified certificate loader
|
| services.trickster.profiler-port | Port that the /debug/pprof endpoint will listen on.
|
| services.nagios.cgiConfigFile | Derivation for the configuration file of Nagios CGI scripts
that can be used in web servers for running the Nagios web interface.
|
| services.prometheus.exporters.pve.collectors.cluster | Collect PVE cluster info
|
| services.livekit.ingress.settings.rtmp_port | TCP port for RTMP connections
|
| services.shadowsocks.pluginOpts | Options to pass to the plugin if one was specified
|
| services.prosody.modules.smacks | Allow a client to resume a disconnected session, and prevent message loss
|
| services.pipewire.wireplumber.extraLv2Packages | List of packages that provide LV2 plugins in lib/lv2 that should
be made available to WirePlumber for [filter chains][wiki-filter-chain]
|
| services.mainsail.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.prometheus.exporters.dnsmasq.dnsmasqListenAddress | Address on which dnsmasq listens.
|
| services.openldap.settings.attrs | Attributes of the parent entry.
|
| services.prometheus.exporters.pihole.extraFlags | Extra commandline options to pass to the pihole exporter.
|
| services.tinc.networks.<name>.extraConfig | Extra lines to add to the tinc service configuration file
|
| services.prometheus.exporters.unpoller.controllers.*.save_events | Collect and save data from UniFi events to influxdb and Loki.
|
| services.prometheus.exporters.kafka.group | Group under which the kafka exporter shall be run.
|
| services.ncps.cache.database.pool.maxOpenConns | Maximum number of open connections to the database (0 = use
database-specific defaults).
|
| services.unpoller.prometheus.disable | Whether to disable the prometheus output plugin.
|
| services.sillytavern.listen | Whether to listen on all network interfaces.
|
| services.slskd.nginx.default | Makes this vhost the default.
|
| services.thanos.receive.stateDir | Data directory relative to /var/lib of TSDB.
|
| services.slurm.dbdserver.storageUser | Database user name.
|
| services.prometheus.exporters.process.user | User name under which the process exporter shall be run.
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.oauth2.endpoint_params | Optional parameters to append to the token URL.
|
| services.monit.enable | Whether to enable Monit.
|
| services.listmonk.database.settings.smtp.*.tls_type | Type of TLS authentication with the SMTP server
|
| services.oauth2-proxy.signatureKey | GAP-Signature request signature key.
|
| services.openssh.knownHosts.<name>.hostNames | A list of host names and/or IP numbers used for accessing
the host's ssh service
|
| services.prometheus.exporters.keylight.user | User name under which the keylight exporter shall be run.
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.services | A list of services for which targets are retrieved.
|
| services.openssh.listenAddresses.*.addr | Host, IPv4 or IPv6 address to listen to.
|
| services.radicle.httpd.nginx.reuseport | Create an individual listening socket
|
| services.samba-wsdd.hostname | Override (NetBIOS) hostname to be used (default hostname).
|
| services.tsidp.environmentFile | Path to an environment file loaded for the tsidp service
|
| services.syncthing.dataDir | The path where synchronised directories will exist.
|
| services.mautrix-meta.instances.<name>.environmentFile | File containing environment variables to substitute when copying the configuration
out of Nix store to the services.mautrix-meta.dataDir
|
| services.prometheus.scrapeConfigs.*.docker_sd_configs.*.proxy_url | Optional proxy URL.
|
| services.prometheus.scrapeConfigs.*.hetzner_sd_configs.*.oauth2.client_id | OAuth client ID.
|
| services.orangefs.server.extraDefaults | Extra config for <Defaults> section.
|
| services.prometheus.exporters.unbound.group | Group under which the unbound exporter shall be run.
|
| services.prometheus.remoteWrite.*.bearer_token_file | Sets the Authorization header on every remote write request with the bearer token
read from the configured file
|
| services.thanos.receive.objstore.config-file | Path to YAML file that contains object store configuration
|
| services.suricata.settings.vars.address-groups.MODBUS_SERVER | MODBUS_SERVER variable.
|
| services.pantalaimon-headless.instances.<name>.listenAddress | The address where the daemon will listen to client connections
for this homeserver.
|
| services.prometheus.exporters.ipmi.webConfigFile | Path to configuration file that can enable TLS or authentication.
|
| services.stargazer.responseTimeout | Number of seconds to wait for the client to send a complete
request and for stargazer to finish sending the response
|
| services.podgrab.enable | Whether to enable Podgrab, a self-hosted podcast manager.
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs | List of EC2 service discovery configurations.
|
| services.prometheus.exporters.rspamd.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.rspamd.openFirewall is true.
|
| services.olivetin.settings | Configuration of OliveTin
|
| services.movim.nginx.locations.<name>.return | Adds a return directive, for e.g. redirections.
|
| services.nitter.preferences.autoplayGifs | Autoplay GIFs.
|
| services.pipewire.extraConfig.pipewire | Additional configuration for the PipeWire server
|
| services.mpd.credentials.*.permissions | List of permissions that are granted with this password
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.authorization.type | Sets the authentication type
|