| services.prometheus.exporters.restic.rcloneOptions | Options to pass to rclone to control its behavior
|
| services.unbound.enable | Whether to enable Unbound domain name server.
|
| services.mediawiki.httpd.virtualHost.listen.*.ip | IP to listen on. 0.0.0.0 for IPv4 only, * for all.
|
| services.monica.nginx.locations.<name>.index | Adds index directive.
|
| services.moosefs.master.openFirewall | Whether to automatically open required firewall ports for master service.
|
| services.stunnel.fipsMode | Enable FIPS 140-2 mode required for compliance.
|
| services.triggerhappy.bindings.*.cmd | What to run.
|
| services.tts.servers | TTS server instances.
|
| services.monica.nginx.forceSSL | Whether to add a separate nginx server block that redirects (defaults
to 301, configurable with redirectCode) all plain HTTP traffic to
HTTPS
|
| services.moodle.virtualHost.http2 | Whether to enable HTTP 2
|
| services.murmur.group | The name of an existing group to use to run the service
|
| services.prosody.httpPorts | Listening HTTP ports list for this service.
|
| services.redis.servers.<name>.syslog | Enable logging to the system logger.
|
| services.tor.settings.ControlSocket | See torrc manual.
|
| services.matomo.nginx.basicAuth | Basic Auth protection for a vhost
|
| services.oauth2-proxy.validateURL | Access token validation endpoint
|
| services.portunus.dex.port | Port where dex should listen on.
|
| services.tomcat.virtualHosts.*.webapps | List containing web application WAR files and/or directories containing
web applications and configuration files for the virtual host.
|
| services.prometheus.exporters.restic.user | User name under which the restic exporter shall be run.
|
| services.rkvm.client.settings.server | An RKVM server's internet socket address, either IPv4 or IPv6.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.oauth2 | Optional OAuth 2.0 configuration
|
| services.tailscaleAuth.package | The tailscale-nginx-auth package to use.
|
| services.prometheus.scrapeConfigs.*.dns_sd_configs.*.port | The port number used if the query type is not SRV.
|
| services.monetdb.dataDir | Data directory for the dbfarm.
|
| services.resilio.storagePath | Where BitTorrent Sync will store it's database files (containing
things like username info and licenses)
|
| services.multipath.devices | This option allows you to define arrays for use in multipath
groups.
|
| services.prometheus.exporters.deluge.user | User name under which the deluge exporter shall be run.
|
| services.prometheus.scrapeConfigs.*.eureka_sd_configs.*.authorization.credentials | Sets the credentials
|
| services.prometheus.exporters.rtl_433.channels.*.location | Location to match.
|
| services.prometheus.scrapeConfigs.*.static_configs.*.labels | Labels assigned to all metrics scraped from the targets.
|
| services.prometheus.exporters.sabnzbd.enable | Whether to enable the prometheus sabnzbd exporter.
|
| services.prometheus.scrapeConfigs.*.triton_sd_configs.*.account | The account to use for discovering new targets.
|
| services.scrutiny.package | The scrutiny package to use.
|
| services.microsocks.ip | IP on which microsocks should listen
|
| services.moodle.virtualHost.robotsEntries | Specification of pages to be ignored by web crawlers
|
| services.prometheus.exporters.nats.listenAddress | Address to listen on.
|
| services.sshd.enable | Alias of services.openssh.enable.
|
| services.stunnel.enable | Whether to enable the stunnel TLS tunneling service.
|
| services.prometheus.exporters.nextcloud.username | Username for connecting to Nextcloud
|
| services.rspamd.locals | Local configuration files, written into /etc/rspamd/local.d/{name}.
|
| services.tautulli.dataDir | The directory where Tautulli stores its data files.
|
| services.nextcloud-spreed-signaling.settings.stats.allowed_ips | List of IP addresses that are allowed to access the debug, stats and metrics endpoints
|
| services.prometheus.exporters.collectd.collectdBinary.authFile | File mapping user names to pre-shared keys (passwords).
|
| services.olivetin.path | Packages added to the service's PATH.
|
| services.opendkim.enable | Whether to enable OpenDKIM sender authentication system.
|
| services.prefect.enable | enable prefect server and worker services
|
| services.prometheus.exporters.v2ray.port | Port to listen on.
|
| services.netbird.server.enable | Whether to enable Netbird Server stack, comprising the dashboard, management API and signal service.
|
| services.postfix.settings.master.<name>.chroot | Whether the service is chrooted to have only access to the
services.postfix.queueDir and the closure of
store paths specified by the program option.
|
| services.prometheus.exporters.klipper.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.klipper.openFirewall
is true
|
| services.plausible.server.listenAddress | The IP address on which the server is listening.
|
| services.prometheus.exporters.unpoller.controllers.*.hash_pii | Hash, with md5, client names and MAC addresses
|
| services.pulseaudio.tcp.openFirewall | Whether to enable Open firewall for the specified port.
|
| services.rspamd.workers.<name>.bindSockets | List of sockets to listen, in format acceptable by rspamd
|
| services.prometheus.scrapeConfigs.*.kubernetes_sd_configs.*.authorization.credentials_file | Sets the credentials to the credentials read from the configured file
|
| services.system76-scheduler.settings.cfsProfiles.responsive.bandwidth-size | sched_cfs_bandwidth_slice_us.
|
| services.samba.smbd.enable | Whether to enable Samba's smbd daemon.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.basic_auth.password | HTTP password
|
| services.tt-rss.database.user | The database user
|
| services.mautrix-meta.instances.<name>.serviceDependencies | List of Systemd services to require and wait for when starting the application service.
|
| services.syncoid.commands.<name>.sendOptions | Advanced options to pass to zfs send
|
| services.nscd.enable | Whether to enable the Name Service Cache Daemon
|
| services.peertube.database.user | Database user.
|
| services.mediawiki.nginx.hostName | The hostname to use for the nginx virtual host
|
| services.postgrey.greylistAction | Response status for greylisted messages (see access(5))
|
| services.prometheus.exporters.idrac.listenAddress | Address to listen on.
|
| services.pipewire.extraLv2Packages | List of packages that provide LV2 plugins in lib/lv2 that should
be made available to PipeWire for [filter chains][wiki-filter-chain]
|
| services.printing.webInterface | Specifies whether the web interface is enabled.
|
| services.matomo.nginx | With this option, you can customize an nginx virtualHost which already has sensible defaults for Matomo
|
| services.prometheus.exporters.postfix.extraFlags | Extra commandline options to pass to the postfix exporter.
|
| services.ncdns.port | The port the ncdns resolver will bind to.
|
| services.neo4j.bolt.sslPolicy | Neo4j SSL policy for BOLT traffic
|
| services.prometheus.exporters.nvidia-gpu.openFirewall | Open port in firewall for incoming connections.
|
| services.prometheus.exporters.snmp.environmentFile | EnvironmentFile as defined in systemd.exec(5)
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.basic_auth | Optional HTTP basic authentication information.
|
| services.pyload.port | Port to listen on for the web UI.
|
| services.netbird.tunnels.<name>.name | Primary name for use (as a suffix) in:
- systemd service name,
- hardened user name and group,
- systemd
*Directory= names,
- desktop application identification,
|
| services.prometheus.exporters.exportarr-bazarr.url | The full URL to Sonarr, Radarr, or Lidarr.
|
| services.open-webui.port | Which port the Open-WebUI server listens to.
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.tag_separator | The string by which Linode Instance tags are joined into the tag label
|
| services.tor.settings.AuthDirPinKeys | See torrc manual.
|
| services.prometheus.exporters.mqtt.mqttIgnoredTopics | Lists of topics to ignore
|
| services.prometheus.exporters.borgmatic.enable | Whether to enable the prometheus borgmatic exporter.
|
| services.radicle.httpd.nginx.forceSSL | Whether to add a separate nginx server block that redirects (defaults
to 301, configurable with redirectCode) all plain HTTP traffic to
HTTPS
|
| services.prometheus.exporters.varnish.openFirewall | Open port in firewall for incoming connections.
|
| services.thanos.query-frontend.enable | Whether to enable the Thanos query frontend implements a service deployed in front of queriers to
improve query parallelization and caching..
|
| services.mailhog.storage | Store mails on disk or in memory.
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.basic_auth.password | HTTP password
|
| services.prometheus.alertmanagerWebhookLogger.extraFlags | Extra command line options to pass to alertmanager-webhook-logger.
|
| services.rsyncd.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.tayga.enable | Whether to enable Tayga.
|
| services.tayga.ipv6.pool.address | IPv6 address.
|
| services.radicle.httpd.nginx.locations.<name>.fastcgiParams | FastCGI parameters to override
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.per_cpu_sas | Enable per-CPU CHILD_SAs
|
| services.moodle.package | The moodle package to use.
|
| services.opengfw.package | The opengfw package to use.
|
| services.prometheus.exporters.varnish.listenAddress | Address to listen on.
|
| services.tsidp.package | The tsidp package to use.
|
| services.locate.extraFlags | Extra flags to pass to updatedb.
|
| services.netbird.tunnels.<name>.logLevel | Log level of the NetBird daemon.
|