| power.ups.mode | The MODE determines which part of the NUT is to be started, and
which configuration files must be modified
|
| hardware.cpu.amd.sev.mode | Mode to set for the SEV device.
|
| hardware.cpu.x86.msr.mode | Mode to set for devices of the msr kernel subsystem.
|
| hardware.cpu.amd.sevGuest.mode | Mode to set for the SEV guest device.
|
| networking.bonds.<name>.mode | DEPRECATED, use driverOptions
|
| services.pixiecore.mode | Which mode to use
|
| environment.etc.<name>.mode | If set to something else than symlink,
the file is copied instead of symlinked, with the given
file mode.
|
| boot.uvesafb.gfx-mode | Screen resolution in modedb format
|
| security.pam.yubico.mode | Mode of operation
|
| services.atticd.mode | Mode in which to run the server.
'monolithic' runs all components, and is suitable for single-node deployments.
'api-server' runs only the API server, and is suitable for clustering.
'garbage-collector' only runs the garbage collector periodically
|
| networking.macvlans.<name>.mode | The mode of the macvlan device.
|
| services.calibre-server.auth.mode | Choose the type of authentication used
|
| hardware.cpu.intel.sgx.provision.mode | Mode to set for the SGX provisioning device.
|
| services.varnish.listen.*.mode | Permission of the socket file (3-digit octal value).
|
| hardware.display.outputs.<name>.mode | A video kernel parameter (framebuffer mode) configuration for the specific output:
<xres>x<yres>[M][R][-<bpp>][@<refresh>][i][m][eDd]
See for more information:
|
| boot.loader.systemd-boot.consoleMode | The resolution of the console
|
| services.anuko-time-tracker.settings.email.mode | Mail sending mode
|
| services.shadowsocks.mode | Relay protocols.
|
| services.geth.<name>.gcmode | Blockchain garbage collection mode.
|
| services.suricata.settings.host-mode | If the Suricata box is a router for the sniffed networks, set it to 'router'
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.mode | IPsec Mode to establish CHILD_SA with.
tunnel negotiates the CHILD_SA in IPsec Tunnel Mode,
- whereas
transport uses IPsec Transport Mode.
transport_proxy signifying the special Mobile IPv6
Transport Proxy Mode.
beet is the Bound End to End Tunnel mixture mode,
working with fixed inner addresses without the need to include them in
each packet.
- Both
transport and beet modes are
subject to mode negotiation; tunnel mode is
negotiated if the preferred mode is not available.
pass and drop are used to install
shunt policies which explicitly bypass the defined traffic from IPsec
processing or drop it, respectively
|
| services.amazon-cloudwatch-agent.mode | Amazon CloudWatch Agent mode
|
| services.headscale.settings.policy.mode | The mode can be "file" or "database" that defines
where the ACL policies are stored and read from.
|
| hardware.uni-sync.devices.*.channels.*.mode | "PWM" to enable PWM sync. "Manual" to set speed.
|
| services.borgbackup.jobs.<name>.encryption.mode | Encryption mode to use
|
| services.fcgiwrap.instances.<name>.socket.mode | Mode to be set on the UNIX socket
|
| services.home-assistant.config.lovelace.mode | In what mode should the main Lovelace panel be, yaml or storage (UI managed).
|
| services.dependency-track.settings."alpine.database.mode" | Defines the database mode of operation
|
| services.crowdsec-firewall-bouncer.settings.mode | Firewall mode to use.
|
| services.geth.<name>.syncmode | Blockchain sync mode.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.quorum.syncmode | Blockchain sync mode.
|
| services.grafana-image-renderer.settings.rendering.mode | Rendering mode of grafana-image-renderer:
default: Creates on browser-instance
per rendering request.
reusable: One browser instance
will be started and reused for each rendering request.
clustered: allows to precisely
configure how many browser-instances are supposed to be used
|
| services.autorandr.profiles.<name>.config.<name>.mode | Output resolution.
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.matrix-synapse.settings.listeners.*.mode | File permissions on the UNIX domain socket.
|
| hardware.nvidia-container-toolkit.discovery-mode | The mode to use when discovering the available entities.
|
| services.llama-cpp.model | Model path.
|
| users.users.<name>.homeMode | The user's home directory mode in numeric format
|
| hardware.usb-modeswitch.enable | Enable this option to support certain USB WLAN and WWAN adapters
|
| services.llama-cpp.modelsDir | Models directory.
|
| services.xtreemfs.mrc.syncMode | The sync mode influences how operations are committed to the disk
log before the operation is acknowledged to the caller.
-ASYNC mode the writes to the disk log are buffered in memory by the operating system
|
| services.xtreemfs.dir.syncMode | The sync mode influences how operations are committed to the disk
log before the operation is acknowledged to the caller.
-ASYNC mode the writes to the disk log are buffered in memory by the operating system
|
| boot.loader.grub.gfxmodeEfi | The gfxmode to pass to GRUB when loading a graphical boot interface under EFI.
|
| boot.loader.grub.gfxmodeBios | The gfxmode to pass to GRUB when loading a graphical boot interface under BIOS.
|
| users.extraUsers.<name>.homeMode | The user's home directory mode in numeric format
|
| services.ollama.models | The directory that the ollama service will read models from and download new models to.
|
| systemd.services.<name>.confinement.mode | The value full-apivfs (the default) sets up
private /dev, /proc,
/sys, /tmp and /var/tmp file systems
in a separate user name space
|
| services.xserver.xkb.model | X keyboard model.
|
| services.hylafax.modems | Description of installed modems
|
| services.xserver.desktopManager.wallpaper.mode | The file ~/.background-image is used as a background image
|
| services.athens.index.postgres.params.sslmode | SSL mode for the Postgres database.
|
| services.mihomo.tunMode | Whether to enable necessary permission for Mihomo's systemd service for TUN mode to function properly
|
| services.xserver.cmt.models | Which models to enable cmt for
|
| programs.gamemode.enable | Whether to enable GameMode to optimise system performance on demand.
|
| services.hylafax.modems.<name>.name | Name of modem device,
will be searched for in /dev.
|
| services.prosody.muc.*.moderation | Allow rooms to be moderated
|
| services.chhoto-url.settings.public_mode | Whether to enable public mode.
|
| services.tts.servers.<name>.model | Name of the model to download and use for speech synthesis
|
| services.opengfw.pcapReplay | Path to PCAP replay file
|
| services.hylafax.modems.<name>.type | Name of modem configuration file,
will be searched for in config
in the spooling area directory.
|
| services.llama-cpp.modelsPreset | Models preset configuration as a Nix attribute set
|
| services.matrix-synapse.workers.<name>.worker_listeners.*.mode | File permissions on the UNIX domain socket.
|
| security.duosec.failmode | On service or configuration errors that prevent Duo
authentication, fail "safe" (allow access) or "secure" (deny
access)
|
| services.strongswan-swanctl.swanctl.connections.<name>.pull | If the default of yes is used, Mode Config works in pull mode, where the
initiator actively requests a virtual IP
|
| services.resolved.dnssec | If set to
"true":
all DNS lookups are DNSSEC-validated locally (excluding
LLMNR and Multicast DNS)
|
| services.hostapd.radios.<name>.networks.<name>.authentication.mode | Selects the authentication mode for this AP.
- "none": Don't configure any authentication
|
| services.coder.database.sslmode | Password for accessing the database.
|
| services.teeworlds.game.tournamentMode | Whether to enable tournament mode
|
| programs.gamemode.enableRenice | Whether to enable CAP_SYS_NICE on gamemoded to support lowering process niceness.
|
| hardware.display.edid.modelines | Attribute set of XFree86 Modelines automatically converted
and exposed as edid/<name>.bin files in initrd
|
| power.ups.upsd.enable | Whether to enable upsd.
|
| services.grafana.settings.server.socket_mode | Mode where the socket should be set when protocol=socket
|
| hardware.sane.brscan4.netDevices.<name>.model | The model of the network device.
|
| hardware.sane.brscan5.netDevices.<name>.model | The model of the network device.
|
| programs.gamemode.settings | System-wide configuration for GameMode (/etc/gamemode.ini)
|
| programs.soundmodem.package | The soundmodem package to use.
|
| services.restic.server.appendOnly | Enable append only mode
|
| programs.soundmodem.enable | Whether to add Soundmodem to the global environment and configure a
wrapper for 'soundmodemconfig' for users in the 'soundmodem' group.
|
| services.litellm.settings.model_list | List of supported models on the server, with model-specific configs.
|
| services.node-red.safe | Whether to launch Node-RED in --safe mode.
|
| networking.modemmanager.package | The modemmanager package to use.
|
| boot.vesa | (Deprecated) This option, if set, activates the VESA 800x600 video
mode on boot and disables kernel modesetting
|
| boot.loader.grub.efiInstallAsRemovable | Whether to invoke grub-install with
--removable
|
| services.hylafax.modems.<name>.config | Attribute set of values for the given modem
|
| power.ups.upsmon.enable | Whether to enable upsmon.
|
| systemd.enableEmergencyMode | Whether to enable emergency mode, which is an
sulogin shell started on the console if
mounting a filesystem fails
|
| hardware.nvidia.modesetting.enable | Whether to enable kernel modesetting when using the NVIDIA proprietary driver
|
| networking.modemmanager.enable | Whether to use ModemManager to manage modem devices
|
| services.tabby.model | Specify the model that tabby will use to generate completions
|
| services.uwsgi.instance | uWSGI configuration
|
| services.pgbouncer.settings.pgbouncer.pool_mode | Specifies when a server connection can be reused by other clients.
session
Server is released back to pool after client disconnects
|
| hardware.printers.ensurePrinters.*.model | Location of the ppd driver file for the printer.
lpinfo -m shows a list of supported models.
|
| services.vault.dev | In this mode, Vault runs in-memory and starts unsealed
|
| services.gitlab.smtp.tls | Whether to use TLS wrapper-mode.
|
| services.rspamd.debug | Whether to run the rspamd daemon in debug mode.
|
| services.chhoto-url.settings.public_mode_expiry_delay | The maximum expiry delay in seconds to force in public mode.
|
| networking.modemmanager.fccUnlockScripts | List of FCC unlock scripts to enable on the system, behaving as described in
https://modemmanager.org/docs/modemmanager/fcc-unlock/#integration-with-third-party-fcc-unlock-tools.
|
| networking.modemmanager.fccUnlockScripts.*.id | vid:pid of either the PCI or USB vendor and product ID
|
| networking.modemmanager.fccUnlockScripts.*.path | Path to the unlock script
|