| services.tor.settings.TransProxyType | See torrc manual.
|
| services.prometheus.exporters.deluge.delugePassword | Password to connect to deluge server
|
| services.prometheus.scrapeConfigs.*.kuma_sd_configs.*.authorization.type | Sets the authentication type
|
| services.livekit.redis.host | Address to bind local redis instance to.
|
| services.nipap.nipapd.enable | Whether to enable nipapd server.
|
| services.prometheus.exporters.sql.configuration.jobs | An attrset of metrics scraping jobs to run.
|
| services.prometheus.exporters.imap-mailstat.accounts.<name>.password | |
| services.photoprism.importPath | Relative or absolute to the originalsPath from where the files should be imported.
|
| services.prometheus.remoteWrite.*.queue_config.capacity | Number of samples to buffer per shard before we block reading of more
samples from the WAL
|
| services.plausible.server.secretKeybaseFile | Path to the secret used by the phoenix-framework
|
| services.mqtt2influxdb.package | The mqtt2influxdb package to use.
|
| services.resilio.enable | If enabled, start the Resilio Sync daemon
|
| services.stalwart.credentials | Credentials envs used to configure Stalwart secrets
|
| services.magnetico.crawler.extraOptions | Extra command line arguments to pass to magneticod.
|
| services.prefect.workerPools | define a set of worker pools with submodule config. example:
workerPools.my-pool = {
installPolicy = "never";
};
|
| services.radicle.httpd.nginx.locations.<name>.proxyPass | Adds proxy_pass directive and sets recommended proxy headers if
recommendedProxySettings is enabled.
|
| services.system76-scheduler.settings.processScheduler.refreshInterval | Process list poll interval, in seconds
|
| services.netdata.user | User account under which netdata runs.
|
| services.thanos.receive.receive.grpc-compression | Compression algorithm to use for gRPC requests to other receivers.
|
| services.tayga.tunDevice | Name of the nat64 tun device.
|
| services.thanos.rule.arguments | Arguments to the thanos rule command
|
| services.prometheus.alertmanagerGotify.port | The local port the bridge is listening on.
|
| services.opensearch.settings."plugins.security.disabled" | Whether to enable the security plugin,
plugins.security.ssl.transport.keystore_filepath or
plugins.security.ssl.transport.server.pemcert_filepath and
plugins.security.ssl.transport.client.pemcert_filepath
must be set for this plugin to be enabled.
|
| services.radicle.ci.broker.settings.triggers | CI triggers.
|
| services.nextcloud-whiteboard-server.enable | Whether to enable Nextcloud backend server for the Whiteboard app.
|
| services.taler.runtimeDir | Runtime directory shared between the taler services
|
| services.syncthing.settings.folders.<name>.label | The label of the folder.
|
| services.tarsnap.archives.<name>.includes | Include only files and directories matching these
patterns (the empty list includes everything)
|
| services.public-inbox.inboxes.<name>.watchheader | If specified, public-inbox-watch(1) will only process
mail containing a matching header.
|
| services.strongswan-swanctl.swanctl.connections.<name>.remote.<name>.cert.<name>.slot | Optional slot number of the token that stores the certificate.
|
| services.matomo.nginx.listen.*.addr | Listen address.
|
| services.reposilite.settings.cachedLogSize | Amount of messages stored in the cache logger.
|
| services.nagios.virtualHost.acmeRoot | Directory for the acme challenge which is PUBLIC, don't put certs or keys in here
|
| services.pghero.listenAddress | hostname:port to listen for HTTP traffic
|
| services.monica.appURL | The root URL that you want to host monica on
|
| services.postgresqlBackup.backupAll | Backup all databases using pg_dumpall
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.filters.*.name | See this list
for the available filters.
|
| services.system76-scheduler.assignments.<name>.prio | CPU scheduler priority.
|
| services.slskd.nginx.addSSL | Whether to enable HTTPS in addition to plain HTTP
|
| services.ttyd.checkOrigin | Whether to allow a websocket connection from a different origin.
|
| services.prometheus.exporters.graphite.graphitePort | Port to use for the graphite server.
|
| services.thanos.query.web.prefix-header | Name of HTTP request header used for dynamic prefixing of UI links and
redirects
|
| services.pretalx.gunicorn.extraArgs | Extra arguments to pass to gunicorn
|
| services.renovate.package | The renovate package to use.
|
| services.mattermost.user | User which runs the Mattermost service.
|
| services.mastodon.trustedProxy | You need to set it to the IP from which your reverse proxy sends requests to Mastodon's web process,
otherwise Mastodon will record the reverse proxy's own IP as the IP of all requests, which would be
bad because IP addresses are used for important rate limits and security functions.
|
| services.patroni.otherNodesIps | IP addresses of the other nodes.
|
| services.misskey.settings.redisForTimelines.port | The Redis port.
|
| services.matomo.nginx.basicAuthFile | Basic Auth password file for a vhost
|
| services.stunnel.logLevel | Verbosity of stunnel output.
|
| services.strongswan-swanctl.swanctl.connections.<name>.local.<name>.cert.<name>.file | Absolute path to the certificate to load
|
| services.system76-scheduler.assignments | Process profile assignments.
|
| services.plex.extraScanners | A list of paths to extra scanners to install in Plex's scanners
directory
|
| services.lighthouse.package | The lighthouse package to use.
|
| services.mchprs.dataDir | Directory to store MCHPRS database and other state/data files.
|
| services.prometheus.exporters.nextcloud.timeout | Timeout for getting server info document.
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.role_arn | AWS Role ARN, an alternative to using AWS API keys.
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.access_key | The AWS API key id
|
| services.prometheus.remoteWrite.*.write_relabel_configs.*.source_labels | The source labels select values from existing labels
|
| services.prometheus.exporters.flow.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.flow.openFirewall
is true
|
| services.mtr-exporter.jobs.*.address | Target address for MTR client.
|
| services.pgbouncer.settings.peers | Optional
|
| services.linkwarden.group | The group Linkwarden should run as.
|
| services.supergfxd.settings | The content of /etc/supergfxd.conf
|
| services.prometheus.exporters.bird.extraFlags | Extra commandline options to pass to the bird exporter.
|
| services.pixelfed.nginx.acmeRoot | Directory for the ACME challenge, which is public
|
| services.pixelfed.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| services.pgbouncer.enable | Whether to enable PostgreSQL connection pooler.
|
| services.qbittorrent.package | The qbittorrent-nox package to use.
|
| services.ttyd.keyFile | SSL key file path
|
| services.ncps.enable | Whether to enable ncps: Nix binary cache proxy service implemented in Go.
|
| services.nfs.idmapd.settings | libnfsidmap configuration
|
| services.prometheus.scrapeConfigs.*.uyuni_sd_configs.*.tls_config.ca_file | CA certificate to validate API server certificate with.
|
| services.nginx.virtualHosts.<name>.locations.<name>.index | Adds index directive.
|
| services.openafsServer.roles.backup.cellServDB.<name>.*.dnsname | DNS full-qualified domain name of a database server
|
| services.lxd-image-server.enable | Whether to enable lxd-image-server.
|
| services.prometheus.exporters.influxdb.sampleExpiry | How long a sample is valid for
|
| services.prosody.disco_items.*.url | URL of the endpoint you want to make discoverable
|
| services.prometheus.exporters.exportarr-lidarr.port | Port to listen on.
|
| services.netclient.package | The netclient package to use.
|
| services.mpdscribble.host | Host for the mpdscribble daemon to search for a mpd daemon on.
|
| services.postfix.settings.main | The main.cf configuration file as key value set
|
| services.renovate.validateSettings | Whether to run renovate's config validator on the built configuration.
|
| services.slskd.settings.retention.transfers.download.cancelled | Lifespan of cancelled download tasks.
|
| services.peertube.dataDirs | Allow access to custom data locations.
|
| services.scrutiny.enable | Whether to enable Scrutiny, a web application for drive monitoring.
|
| services.prometheus.scrapeConfigs.*.target_limit | Per-scrape config limit on number of unique targets that will be
accepted
|
| services.prometheus.pushgateway.package | The prometheus-pushgateway package to use.
|
| services.prometheus.exporters.chrony.enabledCollectors | Collectors to enable
|
| services.teeworlds.register | Whether the server registers as a public server in the global server list
|
| services.rustus.url | url path for uploads
|
| services.tuned.settings.reapply_sysctl | Whether to enable the reapplying of global sysctls after TuneD sysctls are applied.
|
| services.pgmanage.port | This tells pgmanage what port to listen on for browser requests.
|
| services.oauth2-proxy.provider | OAuth provider.
|
| services.lldap.package | The lldap package to use.
|
| services.neo4j.directories.imports | The root directory for file URLs used with the Cypher
LOAD CSV clause
|
| services.networkaudiod.enable | Whether to enable Networkaudiod (NAA).
|
| services.thanos.query-frontend.log.format | Log format to use.
|
| services.mastodon.database.name | Database name.
|
| services.peertube.database.passwordFile | Password for PostgreSQL database.
|