| services.skydns.nameservers | Skydns list of nameservers to forward DNS requests to when not authoritative for a domain.
|
| services.cloudflared.tunnels.<name>.originRequest.disableChunkedEncoding | Disables chunked transfer encoding
|
| services.prometheus.remoteWrite.*.tls_config.server_name | ServerName extension to indicate the name of the server.
http://tools.ietf.org/html/rfc4366#section-3.1
|
| virtualisation.oci-containers.containers.<name>.devices | List of devices to attach to this container.
|
| virtualisation.oci-containers.containers.<name>.podman.user | The user under which the container should run.
|
| services.strongswan-swanctl.swanctl.connections.<name>.pull | If the default of yes is used, Mode Config works in pull mode, where the
initiator actively requests a virtual IP
|
| virtualisation.oci-containers.containers.<name>.podman | Podman-specific settings in OCI containers
|
| virtualisation.oci-containers.containers.<name>.workdir | Override the default working directory for the container.
|
| services.ncps.cache.storage.s3.bucket | The name of the S3 bucket.
|
| services.athens.storage.s3.bucket | Bucket name for the S3 storage backend.
|
| services.usbrelayd.clientName | Name, your client connects as.
|
| services.syncthing.settings.folders.<name>.ignorePatterns | Syncthing can be configured to ignore certain files in a folder using ignore patterns
|
| networking.wireguard.interfaces.<name>.peers.*.presharedKey | Base64 preshared key generated by wg genpsk
|
| services.ghostunnel.servers.<name>.disableAuthentication | Disable client authentication, no client certificate will be required.
|
| services.matrix-synapse.workers.<name>.worker_listeners | List of ports that this worker should listen on, their purpose and their configuration.
|
| services.icingaweb2.modules.monitoring.transports.<name>.password | Password for the api transport
|
| users.extraUsers.<name>.initialHashedPassword | Specifies the initial hashed password for the user, i.e. the
hashed password assigned if the user does not already
exist
|
| services.authelia.instances.<name>.environmentVariables | Additional environment variables to provide to authelia
|
| services.icingaweb2.modules.monitoring.transports.<name>.instance | Assign a icinga instance to this transport
|
| virtualisation.oci-containers.containers.<name>.autoStart | When enabled, the container is automatically started on boot
|
| services.tor.torsocks.socks5Username | SOCKS5 username
|
| networking.wireguard.interfaces.<name>.interfaceNamespace | The pre-existing network namespace the WireGuard
interface is moved to
|
| services.postgresqlWalReceiver.receivers.<name>.slot | Require pg_receivewal to use an existing replication slot (see
Section 26.2.6 of the PostgreSQL manual)
|
| networking.nameservers | The list of nameservers
|
| services.mattermost.siteName | Name of this Mattermost site.
|
| services.miredo.interfaceName | Name of the network tunneling interface.
|
| services.prosody.httpFileShare.domain | Domain name for a http_file_share service.
|
| services.gnome.at-spi2-core.enable | Whether to enable at-spi2-core, a service for the Assistive Technologies
available on the GNOME platform
|
| services.factorio.saveName | The name of the savegame that will be used by the server
|
| services.bird-lg.frontend.servers | Server name prefixes.
|
| services.jigasi.defaultJvbRoomName | Name of the default JVB room that will be joined if no special header is included in SIP invite.
|
| services.freshrss.virtualHost | Name of the caddy/nginx virtualhost to use and setup.
|
| swapDevices.*.encrypted.label | Label of the unlocked encrypted device
|
| services.icingaweb2.modules.monitoring.transports.<name>.resource | SSH identity resource for the remote transport
|
| services.firezone.server.smtp.username | Username to authenticate against the SMTP relay
|
| services.tlsrpt.reportd.settings.dbname | Path to the sqlite database.
|
| services.microsocks.authUsername | Optional username to use for authentication.
|
| services.icecream.daemon.hostname | Hostname of the daemon in the icecream infrastructure
|
| services.strongswan-swanctl.swanctl.connections.<name>.encap | To enforce UDP encapsulation of ESP packets, the IKE daemon can fake the
NAT detection payloads
|
| virtualisation.oci-containers.containers.<name>.autoRemoveOnStop | Automatically remove the container when it is stopped or killed
|
| services.strongswan-swanctl.swanctl.connections.<name>.version | IKE major version to use for connection.
- 1 uses IKEv1 aka ISAKMP,
- 2 uses IKEv2.
- A connection using the default of 0 accepts both IKEv1 and IKEv2 as
responder, and initiates the connection actively with IKEv2
|
| virtualisation.oci-containers.containers.<name>.networks | Networks to attach the container to
|
| services.matrix-synapse.workers.<name>.worker_listeners.*.type | The type of the listener, usually http.
|
| services.cloudflared.tunnels.<name>.originRequest.keepAliveConnections | Maximum number of idle keepalive connections between Tunnel and your origin
|
| services.outline.storage.region | AWS S3 region name.
|
| services.shairport-sync.group | Group account name under which to run shairport-sync
|
| services.rspamd.overrides | Overridden configuration files, written into /etc/rspamd/override.d/{name}.
|
| services.prosody.uploadHttp.domain | Domain name for the http-upload service
|
| services.autossh.sessions.*.user | Name of the user the AutoSSH session should run as
|
| services.httpd.extraModules | Additional Apache modules to be used
|
| services.keyd.keyboards | Configuration for one or more device IDs
|
| services.kresd.enable | Whether to enable knot-resolver (version 5) domain name server
|
| services.avahi.nssmdns4 | Whether to enable the mDNS NSS (Name Service Switch) plug-in for IPv4
|
| services.strongswan-swanctl.swanctl.connections.<name>.local | Section for a local authentication round
|
| services.matrix-synapse.workers.<name>.worker_listeners.*.port | The port to listen for HTTP(S) requests on.
|
| services.matrix-synapse.workers.<name>.worker_listeners.*.mode | File permissions on the UNIX domain socket.
|
| services.kanidm.provision.systems.oauth2.<name>.supplementaryScopeMaps | Maps kanidm groups to additionally returned oauth scopes
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.proxyWebsockets | Whether to support proxying websocket connections with HTTP/1.1.
|
| virtualisation.oci-containers.containers.<name>.extraOptions | Extra options for podman run.
|
| systemd.network.networks.<name>.enhancedTransmissionSelectionConfig | Each attribute in this set specifies an option in the
[EnhancedTransmissionSelection] section of the unit
|
| services.btrbk.instances.<name>.settings.stream_compress | Compress the btrfs send stream before transferring it from/to remote locations using a
compression command.
|
| services.bcg.automaticRenameGenericNodes | Automatically rename generic nodes.
|
| services.prometheus.exporters.imap-mailstat.accounts.<name>.serverport | imap port number (at the moment only tls connection is supported)
|
| services.nextcloud-spreed-signaling.backends | A list of backends from which clients are allowed to connect from
|
| services.cloudlog.virtualHost | Name of the nginx virtualhost to use and setup
|
| services.discourse.admin.fullName | The admin user's full name.
|
| services.guacamole-server.host | The host name or IP address the server should listen to.
|
| services.airsonic.virtualHost | Name of the nginx virtualhost to use and setup
|
| services.consul.interface.bind | The name of the interface to pull the bind_addr from.
|
| services.wiki-js.stateDirectoryName | Name of the directory in /var/lib.
|
| services.deye-dummycloud.mqttUsername | MQTT username
|
| services.prometheus.scrapeConfigs.*.tls_config.server_name | ServerName extension to indicate the name of the server.
http://tools.ietf.org/html/rfc4366#section-3.1
|
| services.hqplayerd.auth.username | Username used for HQPlayer's WebUI
|
| services.matrix-synapse.log | Default configuration for the loggers used by matrix-synapse and its workers
|
| services.kerberos_server.settings.realms.<name>.acl.*.principal | Which principal the rule applies to
|
| services.peertube-runner.instancesToRegister.<name>.registrationTokenFile | Path to a file containing a registration token for the PeerTube instance
|
| services.matrix-continuwuity.settings.global.server_name | The server_name is the name of this server
|
| services.easytier.instances.<name>.settings.network_secret | EasyTier network credential used for verification and
encryption
|
| services.castopod.database.hostname | Database hostname.
|
| services.prometheus.exporters.sql.configuration.jobs.<name>.queries | SQL queries to run.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceNumIntroductionPoints | See torrc manual.
|
| services.matrix-synapse.workers.<name>.worker_listeners.*.tls | Whether to enable TLS on the listener socket.
This option will be ignored for UNIX domain sockets.
|
| services.thanos.rule.alert.label-drop | Labels by name to drop before sending to alertmanager
|
| services.synergy.client.screenName | Use the given name instead of the hostname to identify
ourselves to the server.
|
| services.unpoller.influxdb.db | Database name
|
| services.youtrack.virtualHost | Name of the nginx virtual host to use and setup
|
| services.strongswan-swanctl.swanctl.connections.<name>.mediation | Whether this connection is a mediation connection, that is, whether this
connection is used to mediate other connections using the IKEv2 Mediation
Extension
|
| services.strongswan-swanctl.swanctl.connections.<name>.remote | Section for a remote authentication round
|
| services.postgresqlWalReceiver.receivers.<name>.synchronous | Flush the WAL data to disk immediately after it has been received
|
| users.users.<name>.hashedPasswordFile | The full path to a file that contains the hash of the user's
password
|
| networking.dhcpcd.setHostname | Whether to set the machine hostname based on the information
received from the DHCP server.
The hostname will be changed only if the current one is
the empty string, localhost or nixos
|
| virtualisation.oci-containers.containers.<name>.login.registry | Registry where to login to.
|
| services.stargazer.routes.*.route | Route section name
|
| services.synergy.server.screenName | Use the given name instead of the hostname to identify
this screen in the configuration.
|
| services.lasuite-docs.settings.DB_NAME | Name of the database
|
| services.lasuite-meet.settings.DB_NAME | Name of the database
|
| services.hadoop.hdfs.namenode.openFirewall | Open firewall ports for HDFS NameNode.
|
| virtualisation.oci-containers.containers.<name>.preRunExtraOptions | Extra options for podman that go before the run argument.
|
| services.kubernetes.proxy.hostname | Kubernetes proxy hostname override.
|
| services.maubot.settings.server.hostname | The IP to listen on
|