| services.gollum.stateDir | Specifies the path of the repository directory
|
| services.nginx.sslDhparam | Path to DH parameters file.
|
| services.skydns.etcd.caCert | Skydns path of TLS certificate authority public key.
|
| services.ncps.cache.tempPath | The path to the temporary directory that is used by the cache to download NAR files
|
| services.mptcpd.enable | Whether to enable the Multipath TCP path management daemon.
|
| services.node-red.configFile | Path to the JavaScript configuration file
|
| services.rke2.configPath | File path containing the rke2 YAML config
|
| boot.initrd.compressor | The compressor to use on the initrd image
|
| services.multipath.devices.*.alias_prefix | The user_friendly_names prefix to use for this device type, instead of the default mpath
|
| services.librenms.logDir | Path of the LibreNMS logging directory.
|
| services.jenkins.home | The path to use as JENKINS_HOME
|
| services.galene.certFile | Path to the server's certificate
|
| services.klipper.inputTTY | Path of the virtual printer symlink to create.
|
| services.qui.secretFile | Path to a file that contains the session secret
|
| services.self-deploy.nixFile | Path to nix file in repository
|
| services.slskd.domain | If non-null, enables an nginx reverse proxy virtual host at this FQDN,
at the path configurated with services.slskd.web.url_base.
|
| services.minio.dataDir | The list of data directories or nodes for storing the objects
|
| services.slurm.mpi.PmixCliTmpDirBase | Base path for PMIx temporary files.
|
| services.zwave-js.serialPort | Serial port device path for Z-Wave controller.
|
| services.keycloak.database.passwordFile | The path to a file containing the database password
|
| services.multipath.devices.*.detect_prio | If set to "yes", multipath will try to detect if the device supports
SCSI-3 ALUA
|
| services.graylog.nodeIdFile | Path of the file containing the graylog node-id
|
| services.cfssl.configFile | Path to configuration file
|
| programs.zsh.ohMyZsh.custom | Path to a custom oh-my-zsh package to override config of oh-my-zsh.
(Can't be used along with customPkgs).
|
| programs.rush.shell | The resolved shell path that users can inherit to set rush as their login shell
|
| services.klipper.logFile | Path of the file Klipper should log to
|
| services.uptermd.hostKey | Path to SSH host key
|
| users.ldap.bind.passwordFile | The path to a file containing the credentials to use when binding
to the LDAP server (if not binding anonymously).
|
| services.angrr.settings.profile-policies.<name>.profile-paths | Paths to the Nix profile
|
| services.librenms.dataDir | Path of the LibreNMS state directory.
|
| hardware.pcmcia.config | Path to the configuration file which maps the memory, IRQs
and ports used by the PCMCIA hardware.
|
| services.gatus.configFile | Path to the Gatus configuration file
|
| services.code-server.socket | Path to a socket (bind-addr will be ignored).
|
| services.self-deploy.sshKeyFile | Path to SSH private key used to fetch private repositories over
SSH.
|
| services.opengfw.rulesFile | Path to file containing OpenGFW rules.
|
| services.grafana.settings.paths.provisioning | Folder that contains provisioning config files that grafana will apply on startup and while running
|
| services.varnish.listen.*.address | If given an IP address, it can be a host name ("localhost"), an IPv4 dotted-quad
("127.0.0.1") or an IPv6 address enclosed in square brackets ("[::1]").
(VCL4.1 and higher) If given an absolute Path ("/path/to/listen.sock") or "@"
followed by the name of an abstract socket ("@myvarnishd") accept connections
on a Unix domain socket
|
| services.bitwarden-directory-connector-cli.secrets.bitwarden.client_path_secret | Path to file that contains Client Secret.
|
| services.headscale.settings.oidc.client_secret_path | Path to OpenID Connect client secret file
|
| services.quorum.nodekeyFile | Path to the nodekey.
|
| console.font | The font used for the virtual consoles
|
| services.klipper.apiSocket | Path of the API socket to create.
|
| services.bird-lg.proxy.birdSocket | Bird control socket path.
|
| services.dovecot2.sslCACert | Path to the server's CA certificate key.
|
| services.klipper.configDir | Path to Klipper config file.
|
| services.llama-swap.tls.keyFile | Path to the TLS private key file
|
| services.munge.password | The path to a daemon's secret key.
|
| services.nginx.proxyCachePath | Configure a proxy cache path entry
|
| services.llama-swap.tls.certFile | Path to the TLS certificate file
|
| services.netbox.secretKeyFile | Path to a file containing the secret key.
|
| services.slurm.controlAddr | Name that ControlMachine should be referred to in establishing a
communications path.
|
| services.oink.secretApiKeyFile | Path to a file containing the secret API key to use when modifying DNS records.
|
| services.soju.configFile | Path to config file
|
| services.v2ray.configFile | The absolute path to the configuration file
|
| services.bitwarden-directory-connector-cli.secrets.bitwarden.client_path_id | Path to file that contains Client ID.
|
| services.neo4j.ssl.policies.<name>.revokedDir | Path to directory of CRLs (Certificate Revocation Lists) in
PEM format
|
| services.duckdns.tokenFile | The path to a file containing the token
used to authenticate with DuckDNS.
|
| services.terraria.dataDir | Path to variable state data directory for terraria.
|
| services.sogo.ealarmsCredFile | Optional path to a credentials file for email alarms
|
| services.pangolin.dataDir | Path to variable state data directory for Pangolin.
|
| services.stash.jwtSecretKeyFile | Path to file containing a secret used to sign JWT tokens.
|
| services.borgbackup.repos.<name>.allowSubRepos | Allow clients to create repositories in subdirectories of the
specified path
|
| services.artalk.configFile | Artalk config file path
|
| services.gitea.minioAccessKeyId | Path to a file containing the Minio access key id.
|
| boot.initrd.systemd.users.<name>.shell | The path to the user's shell in initrd.
|
| services.dnsmasq.configFile | Path to the configuration file of dnsmasq.
|
| services.erigon.secretJwtPath | Path to the secret jwt used for the http api authentication.
|
| services.getty.loginProgram | Path to the login binary executed by agetty.
|
| services.klipper.configFile | Path to default Klipper config.
|
| programs.less.configFile | Path to lesskey configuration file.
configFile takes precedence over commands,
clearDefaultCommands, lineEditingKeys, and
envVariables.
|
| services.portunus.stateDir | Path where Portunus stores its state.
|
| services.terraria.banListPath | The path to the ban list.
|
| services.mailman.restApiPassFile | Path to the file containing the value for MAILMAN_REST_API_PASS.
|
| environment.homeBinInPath | Include ~/bin/ in $PATH.
|
| services.calibre-web.dataDir | Where Calibre-Web stores its data
|
| services.corerad.configFile | Path to CoreRAD TOML configuration file.
|
| services.public-inbox.nntp.key | Path to TLS key to use for connections to public-inbox-nntpd(1).
|
| services.nextcloud.home | Storage path of nextcloud.
|
| services.rshim.index | Specify the index to create device path /dev/rshim<index>
|
| services.public-inbox.imap.key | Path to TLS key to use for connections to public-inbox-imapd(1).
|
| services.solanum.motd | Solanum MOTD text
|
| services.lasuite-meet.bind | The path, host/port or file descriptior to bind the gunicorn socket to
|
| services.lasuite-docs.bind | The path, host/port or file descriptior to bind the gunicorn socket to
|
| services.webdav.configFile | Path to config file
|
| services.webhook.urlPrefix | The URL path prefix to use for served hooks (protocol://yourserver:port/${prefix}/hook-id).
|
| containers.<name>.flake | The Flake URI of the NixOS configuration to use for the container
|
| services.tor.relay.onionServices | See torrc manual.
Because tor.service runs in its own RootDirectory=,
when using a onion service to reverse-proxy to a Unix socket,
you need to make that Unix socket available
within the mount namespace of tor.service
|
| services.pingvin-share.dataDir | The path to the data directory in which Pingvin Share will store its data.
|
| boot.initrd.luks.devices.<name>.device | Path of the underlying encrypted block device.
|
| services.gns3-server.ssl.certFile | Path to the SSL certificate file
|
| services.knot.enableXDP | Extends the systemd unit with permissions to allow for the use of
the eXpress Data Path (XDP).
Make sure to read up on functional limitations
when running in XDP mode.
|
| programs.dms-shell.plugins.<name>.src | Source of the plugin package or path
|
| services.jenkinsSlave.home | The path to use as JENKINS_HOME
|
| services.atalkd.configFile | Optional path to a custom atalkd.conf file
|
| services.conman.configFile | The absolute path to the configuration file
|
| services.nipap.nipap-www.unixSocket | Path to UNIX socket to bind to.
|
| services.snmpd.configFile | Path to the snmpd.conf file
|
| services.k3s.agentTokenFile | File path containing the k3s token agents can use to connect to the server
|
| services.cyrus-imap.cyrusConfigFile | Path to the configuration file used for Cyrus.
|
| services.bluesky-pds.goat.enable | Add goat to PATH
|