| programs.starship.transientPrompt.left | Fish code composing the body of the starship_transient_prompt_func function
|
| services.tarsnap.archives.<name>.cachedir | The cache allows tarsnap to identify previously stored data
blocks, reducing archival time and bandwidth usage
|
| programs.starship.transientPrompt.right | Fish code composing the body of the starship_transient_rprompt_func function
|
| services.oauth2-proxy.setXauthrequest | Set X-Auth-Request-User and X-Auth-Request-Email response headers (useful in Nginx auth_request mode)
|
| services.dawarich.sidekiqProcesses.<name>.threads | Number of threads this process should use for executing jobs
|
| services.mailpit.instances.<name>.database | Specify the local database filename to store persistent data
|
| services.mastodon.sidekiqProcesses.<name>.threads | Number of threads this process should use for executing jobs
|
| services.anubis.defaultOptions.settings.POLICY_FNAME | The policy file to use
|
| services.misskey.reverseProxy.webserver.nginx.acmeRoot | Directory for the ACME challenge, which is public
|
| services.thanos.query-frontend.tracing.config | Tracing configuration
|
| services.hardware.openrgb.motherboard | CPU family of motherboard
|
| services.anubis.instances.<name>.settings.POLICY_FNAME | The policy file to use
|
| boot.kernelPatches | A list of additional patches to apply to the kernel
|
| services.mpdscribble.passwordFile | File containing the password for the mpd daemon
|
| services.thanos.compact.compact.concurrency | Number of goroutines to use when compacting groups
|
| services.thanos.compact.consistency-delay | Minimum age of fresh (non-compacted) blocks before they are being
processed
|
| services.mastodon.elasticsearch.host | Elasticsearch host
|
| services.thanos.store.store.grpc.series-max-concurrency | Maximum number of concurrent Series calls
|
| services.prometheus.pushgateway.log.level | Only log messages with the given severity or above.
null will default to info.
|
| services.jitsi-meet.videobridge.passwordFile | File containing password to the Prosody account for videobridge
|
| services.thanos.store.store.limits.request-samples | The maximum samples allowed for a single Series request
|
| services.taskserver.pki.auto.expiration.ca | The expiration time of the CA certificate in days or null for no
expiration time.
|
| virtualisation.bootPartition | The path (inside the VM) to the device containing the EFI System Partition (ESP)
|
| services.immich.accelerationDevices | A list of device paths to hardware acceleration devices that immich should
have access to
|
| services.prometheus.pushgateway.log.format | Set the log target and format.
null will default to logger:stderr.
|
| services.thanos.downsample.tracing.config | Tracing configuration
|
| services.adguardhome.settings | AdGuard Home configuration
|
| services.taskserver.pki.auto.expiration.crl | The expiration time of the certificate revocation list (CRL) in days or null for no
expiration time.
|
| services.grafana.declarativePlugins | If non-null, then a list of packages containing Grafana plugins to install
|
| boot.loader.systemd-boot.configurationLimit | Maximum number of latest generations in the boot menu
|
| services.bluesky-pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.tarsnap.archives.<name>.checkpointBytes | Create a checkpoint every checkpointBytes
of uploaded data (optionally specified using an SI prefix).
1GB is the minimum value
|
| services.thanos.compact.retention.resolution-raw | How long to retain raw samples in bucket.
0d - disables this retention
Defaults to 0d in Thanos
when set to null.
|
| hardware.block.defaultSchedulerRotational | Default block I/O scheduler for rotational drives (e.g. hard disks)
|
| services.thanos.compact.retention.resolution-5m | How long to retain samples of resolution 1 (5 minutes) in bucket.
0d - disables this retention
Defaults to 0d in Thanos
when set to null.
|
| services.thanos.compact.retention.resolution-1h | How long to retain samples of resolution 2 (1 hour) in bucket.
0d - disables this retention
Defaults to 0d in Thanos
when set to null.
|
| services.kanidm.provision.systems.oauth2.<name>.basicSecretFile | The basic secret to use for this service
|
| services.thanos.query.query.default-evaluation-interval | Set default evaluation interval for sub queries
|
| services.thanos.rule.alertmanagers.send-timeout | Timeout for sending alerts to alertmanager
|
| services.thanos.downsample.objstore.config | Object store configuration
|
| services.firezone.server.settingsSecret.TOKENS_SALT | A file containing a unique base64 encoded secret for the
TOKENS_SALT
|
| services.taskserver.pki.auto.expiration.client | The expiration time of client certificates in days or null for no
expiration time.
|
| services.nextcloud-spreed-signaling.settings.https.key | Path to the private key used for the HTTPS listener
|
| services.taskserver.pki.auto.expiration.server | The expiration time of the server certificate in days or null for no
expiration time.
|
| services.firezone.server.settingsSecret.TOKENS_KEY_BASE | A file containing a unique base64 encoded secret for the
TOKENS_KEY_BASE
|
| services.firezone.server.settingsSecret.SECRET_KEY_BASE | A file containing a unique base64 encoded secret for the
SECRET_KEY_BASE
|
| services.nextcloud-spreed-signaling.settings.grpc.listen | IP and port to listen on for GRPC requests
|
| services.tinc.networks.<name>.hostSettings.<name>.subnets.*.prefixLength | The prefix length of the subnet
|
| services.printing.cups-pdf.instances.<name>.settings | Settings for a cups-pdf instance, see the descriptions in the template config file in the cups-pdf package
|
| services.ollama.acceleration | What interface to use for hardware acceleration
|
| services.thanos.query-frontend.query-frontend.downstream-url | URL of downstream Prometheus Query compatible API
|
| services.nextcloud-spreed-signaling.settings.http.listen | IP and port to listen on for HTTP requests, in the format of ip:port
|
| services.tabby.acceleration | Specifies the device to use for hardware acceleration.
cpu: no acceleration just use the CPU
rocm: supported by modern AMD GPUs
cuda: supported by modern NVIDIA GPUs
metal: supported on darwin aarch64 machines
Tabby will try and determine what type of acceleration that is
already enabled in your configuration when acceleration = null.
- nixpkgs.config.cudaSupport
- nixpkgs.config.rocmSupport
- if stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isAarch64
IFF multiple acceleration methods are found to be enabled or if you
haven't set either cudaSupport or rocmSupport you will have to
specify the device type manually here otherwise it will default to
the first from the list above or to cpu.
|
| services.prometheus.pushgateway.web.listen-address | Address to listen on for the web interface, API and telemetry.
null will default to :9091.
|
| services.cassandra.incrementalRepairInterval | Set the interval how often incremental repairs are run, i.e.
nodetool repair is executed
|
| services.firezone.server.settingsSecret.RELEASE_COOKIE | A file containing a unique secret identifier for the Erlang
cluster
|
| services.chhoto-url.settings.hash_algorithm | The hash algorithm to use for passwords and API keys
|
| services.prometheus.pushgateway.web.telemetry-path | Path under which to expose metrics.
null will default to /metrics.
|
| services.firezone.server.settingsSecret.LIVE_VIEW_SIGNING_SALT | A file containing a unique base64 encoded secret for the
LIVE_VIEW_SIGNING_SALT
|
| services.firezone.server.settingsSecret.COOKIE_SIGNING_SALT | A file containing a unique base64 encoded secret for the
COOKIE_SIGNING_SALT
|
| services.prometheus.scrapeConfigs.*.metrics_path | The HTTP resource path on which to fetch metrics from targets
|
| services.xserver.displayManager.lightdm.greeters.gtk.clock-format | Clock format string (as expected by strftime, e.g. "%H:%M")
to use with the lightdm gtk greeter panel
|
| services.archisteamfarm.bots.<name>.passwordFile | Path to a file containing the password
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.cacert | Path to CA bundle file (PEM/X509)
|
| services.jellyfin.transcoding.maxConcurrentStreams | Maximum number of concurrent transcoding streams
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes | List of path prefixes to ignore
|
| services.nextcloud-spreed-signaling.settings.https.listen | IP and port to listen on for HTTPS requests, in the format of ip:port
|
| services.prometheus.scrapeConfigs.*.label_limit | Per-scrape limit on number of labels that will be accepted for a sample
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes-in-home | Path prefixes to ignore under home directory
|
| services.oauth2-proxy.nginx.virtualHosts.<name>.allowed_emails | List of emails to allow access to this vhost, or null to allow all.
|
| services.oauth2-proxy.nginx.virtualHosts.<name>.allowed_groups | List of groups to allow access to this vhost, or null to allow all.
|
| virtualisation.fileSystems.<name>.overlay.upperdir | The path to the upperdir
|
| services.postgresql.ensureUsers.*.ensureClauses.inherit | Grants the user created inherit permissions
|
| services.icingaweb2.authentications | authentication.ini contents
|
| services.kanidm.serverSettings.ldapbindaddress | Address and port the LDAP server is bound to
|
| services.prometheus.scrapeConfigs.*.sample_limit | Per-scrape limit on number of scraped samples that will be accepted
|
| services.prometheus.globalConfig.scrape_timeout | How long until a scrape request times out
|
| networking.wireguard.interfaces.<name>.socketNamespace | The pre-existing network namespace in which the
WireGuard interface is created, and which retains the socket even if the
interface is moved via interfaceNamespace
|
| services.kanidm.server.settings.ldapbindaddress | Address and port the LDAP server is bound to
|
| services.xserver.windowManager.xmonad.enableConfiguredRecompile | Enable recompilation even if config is set to a
non-null value
|
| services.firezone.server.settingsSecret.COOKIE_ENCRYPTION_SALT | A file containing a unique base64 encoded secret for the
COOKIE_ENCRYPTION_SALT
|
| services.postgresql.ensureUsers.*.ensureClauses.createdb | Grants the user, created by the ensureUser attr, createdb permissions
|
| services.prometheus.scrapeConfigs.*.target_limit | Per-scrape config limit on number of unique targets that will be
accepted
|
| security.virtualisation.flushL1DataCache | Whether the hypervisor should flush the L1 data cache before
entering guests
|
| services.nextcloud-spreed-signaling.settings.https.certificate | Path to the certificate used for the HTTPS listener
|
| services.prometheus.scrapeConfigs.*.dns_sd_configs.*.type | The type of DNS query to perform
|
| virtualisation.oci-containers.containers.<name>.podman | Podman-specific settings in OCI containers
|
| services.prometheus.globalConfig.scrape_interval | How frequently to scrape targets by default
|
| services.postgresql.ensureUsers.*.ensureClauses.login | Grants the user, created by the ensureUser attr, login permissions
|
| services.nextcloud-spreed-signaling.settings.stats.allowed_ips | List of IP addresses that are allowed to access the debug, stats and metrics endpoints
|
| networking.wireguard.interfaces.<name>.interfaceNamespace | The pre-existing network namespace the WireGuard
interface is moved to
|
| services.prometheus.pushgateway.persistence.interval | The minimum interval at which to write out the persistence file.
null will default to 5m.
|
| services.postgresql.ensureUsers.*.ensureClauses.bypassrls | Grants the user, created by the ensureUser attr, replication permissions
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.port | The port to scrape metrics from
|
| services.prometheus.scrapeConfigs.*.gce_sd_configs.*.port | The port to scrape metrics from
|
| services.nextcloud.settings.mail_smtpmode | Which mode to use for sending mail
|
| services.postgresql.ensureUsers.*.ensureClauses.superuser | Grants the user, created by the ensureUser attr, superuser permissions
|
| services.xserver.displayManager.lightdm.greeters.gtk.indicators | List of allowed indicator modules to use for the lightdm gtk
greeter panel
|
| services.prometheus.scrapeConfigs.*.relabel_configs.*.regex | Regular expression against which the extracted value is matched
|
| services.prometheus.scrapeConfigs.*.relabel_configs.*.action | Action to perform based on regex matching
|