+1
-2
nixos/modules/config/i18n.nix
+1
-2
nixos/modules/config/i18n.nix
···
···+can be found at <link xlink:href="https://sourceware.org/git/?p=glibc.git;a=blob;f=localedata/SUPPORTED"/>.
+1
-2
nixos/modules/config/users-groups.nix
+1
-2
nixos/modules/config/users-groups.nix
···
···
+1
-1
nixos/modules/config/xdg/portal.nix
+1
-1
nixos/modules/config/xdg/portal.nix
+1
-1
nixos/modules/hardware/tuxedo-keyboard.nix
+1
-1
nixos/modules/hardware/tuxedo-keyboard.nix
···To configure the driver, pass the options to the <option>boot.kernelParams</option> configuration.There are several parameters you can change. It's best to check at the source code description which options are supported.-You can find all the supported parameters at: <link xlink:href="https://github.com/tuxedocomputers/tuxedo-keyboard#kernelparam" />In order to use the <literal>custom</literal> lighting with the maximumg brightness and a color of <literal>0xff0a0a</literal> one would put pass <option>boot.kernelParams</option> like this:
···To configure the driver, pass the options to the <option>boot.kernelParams</option> configuration.There are several parameters you can change. It's best to check at the source code description which options are supported.+You can find all the supported parameters at: <link xlink:href="https://github.com/tuxedocomputers/tuxedo-keyboard#kernelparam"/>In order to use the <literal>custom</literal> lighting with the maximumg brightness and a color of <literal>0xff0a0a</literal> one would put pass <option>boot.kernelParams</option> like this:
+1
-1
nixos/modules/programs/sway.nix
+1
-1
nixos/modules/programs/sway.nix
···
···
+2
-2
nixos/modules/security/acme/default.nix
+2
-2
nixos/modules/security/acme/default.nix
···-<listitem><para><link xlink:href="https://blog.apnic.net/2019/01/15/is-the-web-ready-for-ocsp-must-staple/" /></para></listitem>-<listitem><para><link xlink:href="https://blog.hboeck.de/archives/886-The-Problem-with-OCSP-Stapling-and-Must-Staple-and-why-Certificate-Revocation-is-still-broken.html" /></para></listitem>
···+<listitem><para><link xlink:href="https://blog.apnic.net/2019/01/15/is-the-web-ready-for-ocsp-must-staple/"/></para></listitem>+<listitem><para><link xlink:href="https://blog.hboeck.de/archives/886-The-Problem-with-OCSP-Stapling-and-Must-Staple-and-why-Certificate-Revocation-is-still-broken.html"/></para></listitem>
+9
-20
nixos/modules/security/pam.nix
+9
-20
nixos/modules/security/pam.nix
······<literal>username:first_keyHandle,first_public_key: second_keyHandle,second_public_key</literal>···<literal>username:first_keyHandle,first_public_key: second_keyHandle,second_public_key</literal>···············-xlink:href="https://developers.yubico.com/yubico-pam/Authentication_Using_Challenge-Response.html">here</link>.···If not null, set the path used by yubico pam module where the challenge expected response is stored.-xlink:href="https://developers.yubico.com/yubico-pam/Authentication_Using_Challenge-Response.html">here</link>.
···+More information can be found <link xlink:href="https://github.com/OpenSC/pam_p11">here</link>.···<literal>username:first_keyHandle,first_public_key: second_keyHandle,second_public_key</literal>+More information can be found <link xlink:href="https://developers.yubico.com/pam-u2f/">here</link>.···<literal>username:first_keyHandle,first_public_key: second_keyHandle,second_public_key</literal>+More information can be found <link xlink:href="https://developers.yubico.com/pam-u2f/">here</link>.···+More information can be found <link xlink:href="https://developers.yubico.com/pam-u2f/Manuals/pam_u2f.8.html">here</link>···+More information can be found <link xlink:href="https://developers.yubico.com/pam-u2f/Manuals/pam_u2f.8.html">here</link>···+More information can be found <link xlink:href="https://github.com/uber/pam-ussh">here</link>.···+More information can be found <link xlink:href="https://developers.yubico.com/yubico-pam/">here</link>.···+More information can be found <link xlink:href="https://developers.yubico.com/yubico-pam/Authentication_Using_Challenge-Response.html">here</link>.···If not null, set the path used by yubico pam module where the challenge expected response is stored.+More information can be found <link xlink:href="https://developers.yubico.com/yubico-pam/Authentication_Using_Challenge-Response.html">here</link>.
+3
-6
nixos/modules/security/pam_mount.nix
+3
-6
nixos/modules/security/pam_mount.nix
·········
···+For more information, visit <link xlink:href="http://pam-mount.sourceforge.net/pam_mount.conf.5.html"/>.···+For more information, visit <link xlink:href="http://pam-mount.sourceforge.net/pam_mount.conf.5.html"/>.···+For more information, visit <link xlink:href="http://pam-mount.sourceforge.net/pam_mount.conf.5.html"/>.
+1
-2
nixos/modules/security/pam_usb.nix
+1
-2
nixos/modules/security/pam_usb.nix
+1
-2
nixos/modules/services/backup/zrepl.nix
+1
-2
nixos/modules/services/backup/zrepl.nix
+1
-2
nixos/modules/services/continuous-integration/github-runner.nix
+1
-2
nixos/modules/services/continuous-integration/github-runner.nix
···Note: GitHub recommends using self-hosted runners with private repositories only. Learn more here:-<link xlink:href="https://docs.github.com/en/actions/hosting-your-own-runners/about-self-hosted-runners"
···Note: GitHub recommends using self-hosted runners with private repositories only. Learn more here:+<link xlink:href="https://docs.github.com/en/actions/hosting-your-own-runners/about-self-hosted-runners">About self-hosted runners</link>.
+1
-2
nixos/modules/services/databases/postgresql.nix
+1
-2
nixos/modules/services/databases/postgresql.nix
···
···+<link xlink:href="https://www.postgresql.org/docs/current/auth-pg-hba-conf.html">PostgreSQL documentation for pg_hba.conf</link>
+2
-2
nixos/modules/services/databases/victoriametrics.nix
+2
-2
nixos/modules/services/databases/victoriametrics.nix
···
···
+1
-1
nixos/modules/services/development/zammad.nix
+1
-1
nixos/modules/services/development/zammad.nix
+3
-1
nixos/modules/services/games/asf.nix
+3
-1
nixos/modules/services/games/asf.nix
+2
-3
nixos/modules/services/hardware/udev.nix
+2
-3
nixos/modules/services/hardware/udev.nix
···-xlink:href='http://www.freedesktop.org/wiki/Software/systemd/PredictableNetworkInterfaceNames'>predictable
···+Whether to assign <link xlink:href="http://www.freedesktop.org/wiki/Software/systemd/PredictableNetworkInterfaceNames">predictable names to network interfaces</link>.
+1
-2
nixos/modules/services/logging/filebeat.nix
+1
-2
nixos/modules/services/logging/filebeat.nix
···See <link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html"/>.
···See <link xlink:href="https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html"/>.
+1
-1
nixos/modules/services/mail/mailman.nix
+1
-1
nixos/modules/services/mail/mailman.nix
+3
-3
nixos/modules/services/mail/sympa.nix
+3
-3
nixos/modules/services/mail/sympa.nix
·········
·········
+1
-2
nixos/modules/services/matrix/appservice-discord.nix
+1
-2
nixos/modules/services/matrix/appservice-discord.nix
···-<link xlink:href="https://github.com/Half-Shot/matrix-appservice-discord/blob/master/config/config.sample.yaml">should be set to match the public host name of the Matrix homeserver for webhooks and avatars to work.
···+<link xlink:href="https://github.com/Half-Shot/matrix-appservice-discord/blob/master/config/config.sample.yaml">config.sample.yaml</link>.should be set to match the public host name of the Matrix homeserver for webhooks and avatars to work.
+1
-2
nixos/modules/services/matrix/mautrix-facebook.nix
+1
-2
nixos/modules/services/matrix/mautrix-facebook.nix
···-<link xlink:href="https://github.com/mautrix/facebook/blob/master/mautrix_facebook/example-config.yaml">
···+<link xlink:href="https://github.com/mautrix/facebook/blob/master/mautrix_facebook/example-config.yaml">example-config.yaml</link>.
+1
-2
nixos/modules/services/matrix/mautrix-telegram.nix
+1
-2
nixos/modules/services/matrix/mautrix-telegram.nix
···
···+<link xlink:href="https://github.com/tulir/mautrix-telegram/blob/master/example-config.yaml">example-config.yaml</link>.
+1
-1
nixos/modules/services/misc/etcd.nix
+1
-1
nixos/modules/services/misc/etcd.nix
+2
-2
nixos/modules/services/misc/etebase-server.nix
+2
-2
nixos/modules/services/misc/etebase-server.nix
···-<link xlink:href="https://github.com/etesync/server/blob/master/etebase-server.ini.example" />
···
+2
-3
nixos/modules/services/misc/geoipupdate.nix
+2
-3
nixos/modules/services/misc/geoipupdate.nix
······
······
+2
-2
nixos/modules/services/misc/persistent-evdev.nix
+2
-2
nixos/modules/services/misc/persistent-evdev.nix
···Physical devices should already exist in <filename class="devicefile">/dev/input/by-id/</filename>.-See the <link xlink:href="https://github.com/aiberia/persistent-evdev#example-usage-with-libvirt"><literal>cgroup_device_acl</literal> list (see <xref linkend="opt-virtualisation.libvirtd.qemu.verbatimConfig"/>).
···Physical devices should already exist in <filename class="devicefile">/dev/input/by-id/</filename>.+See the <link xlink:href="https://github.com/aiberia/persistent-evdev#example-usage-with-libvirt">project page</link><literal>cgroup_device_acl</literal> list (see <xref linkend="opt-virtualisation.libvirtd.qemu.verbatimConfig"/>).
+2
-2
nixos/modules/services/monitoring/cadvisor.nix
+2
-2
nixos/modules/services/monitoring/cadvisor.nix
···-Tip: use <link xlink:href='https://nixos.org/nixops/manual/#idm140737318306400'>nixops key management</link>···-See <link xlink:href='https://github.com/google/cadvisor/blob/master/docs/runtime_options.md'/> for available options.
···+Tip: use <link xlink:href="https://nixos.org/nixops/manual/#idm140737318306400">nixops key management</link>···+See <link xlink:href="https://github.com/google/cadvisor/blob/master/docs/runtime_options.md"/> for available options.
+1
-1
nixos/modules/services/monitoring/grafana-image-renderer.nix
+1
-1
nixos/modules/services/monitoring/grafana-image-renderer.nix
+1
-1
nixos/modules/services/monitoring/graphite.nix
+1
-1
nixos/modules/services/monitoring/graphite.nix
+6
-6
nixos/modules/services/monitoring/munin.nix
+6
-6
nixos/modules/services/monitoring/munin.nix
···-See <link xlink:href='http://guide.munin-monitoring.org/en/latest/architecture/index.html' />.···-<link xlink:href='http://guide.munin-monitoring.org/en/latest/reference/munin-node.conf.html' />······-See <link xlink:href='http://guide.munin-monitoring.org/en/latest/reference/munin.conf.html' />.···
······+<link xlink:href="http://guide.munin-monitoring.org/en/latest/reference/munin-node.conf.html"/>······+See <link xlink:href="http://guide.munin-monitoring.org/en/latest/reference/munin.conf.html"/>.···
+1
-1
nixos/modules/services/monitoring/nagios.nix
+1
-1
nixos/modules/services/monitoring/nagios.nix
+7
-12
nixos/modules/services/monitoring/parsedmarc.nix
+7
-12
nixos/modules/services/monitoring/parsedmarc.nix
···············
···+Whether to enable and configure the <link linkend="opt-services.geoipupdate.enable">geoipupdate</link>+To finish the setup, you need to manually set the <xref linkend="opt-services.geoipupdate.settings.AccountID"/> and············
+6
-9
nixos/modules/services/monitoring/prometheus/default.nix
+6
-9
nixos/modules/services/monitoring/prometheus/default.nix
···-xlink:href="https://prometheus.io/docs/prometheus/latest/configuration/configuration/#gce_sd_config">the·········-<link xlink:href="https://docs.mesosphere.com/1.11/security/ent/iam-api/#passing-an-authentication-token" />It is mutually exclusive with <literal>auth_token_file</literal> and other authentication mechanisms.-<link xlink:href="https://docs.mesosphere.com/1.11/security/ent/iam-api/#passing-an-authentication-token" />It is mutually exclusive with <literal>auth_token</literal> and other authentication mechanisms.
···+See <link xlink:href="https://prometheus.io/docs/prometheus/latest/configuration/configuration/#gce_sd_config">the relevant Prometheus configuration docs</link>···+query parameter section: <link xlink:href="https://cloud.google.com/compute/docs/reference/latest/instances/list"/>.······+<link xlink:href="https://docs.mesosphere.com/1.11/security/ent/iam-api/#passing-an-authentication-token"/>It is mutually exclusive with <literal>auth_token_file</literal> and other authentication mechanisms.+<link xlink:href="https://docs.mesosphere.com/1.11/security/ent/iam-api/#passing-an-authentication-token"/>It is mutually exclusive with <literal>auth_token</literal> and other authentication mechanisms.
+4
-4
nixos/modules/services/monitoring/prometheus/exporters/dovecot.nix
+4
-4
nixos/modules/services/monitoring/prometheus/exporters/dovecot.nix
···-<xref linkend="opt-services.prometheus.exporters.dovecot.socketPath" /> = "/var/run/dovecot2/old-stats";
···+<xref linkend="opt-services.prometheus.exporters.dovecot.socketPath"/> = "/var/run/dovecot2/old-stats";
+1
-1
nixos/modules/services/monitoring/prometheus/exporters/process.nix
+1
-1
nixos/modules/services/monitoring/prometheus/exporters/process.nix
+1
-1
nixos/modules/services/monitoring/prometheus/exporters/script.nix
+1
-1
nixos/modules/services/monitoring/prometheus/exporters/script.nix
+6
-6
nixos/modules/services/networking/bird-lg.nix
+6
-6
nixos/modules/services/networking/bird-lg.nix
···-Extra parameters documented <link xlink:href=\"https://github.com/xddxdd/bird-lg-go#frontend\">here</link>.···-Extra parameters documented <link xlink:href=\"https://github.com/xddxdd/bird-lg-go#proxy\">here</link>.
···+Extra parameters documented <link xlink:href="https://github.com/xddxdd/bird-lg-go#frontend">here</link>.···+Extra parameters documented <link xlink:href="https://github.com/xddxdd/bird-lg-go#proxy">here</link>.
+1
-1
nixos/modules/services/networking/bird.nix
+1
-1
nixos/modules/services/networking/bird.nix
+4
-1
nixos/modules/services/networking/coredns.nix
+4
-1
nixos/modules/services/networking/coredns.nix
+1
-1
nixos/modules/services/networking/seafile.nix
+1
-1
nixos/modules/services/networking/seafile.nix
+6
-6
nixos/modules/services/networking/ssh/sshd.nix
+6
-6
nixos/modules/services/networking/ssh/sshd.nix
·········
·········
+2
-4
nixos/modules/services/networking/wireguard.nix
+2
-4
nixos/modules/services/networking/wireguard.nix
······
······
+1
-1
nixos/modules/services/networking/wpa_supplicant.nix
+1
-1
nixos/modules/services/networking/wpa_supplicant.nix
···
···
+3
-3
nixos/modules/services/security/privacyidea.nix
+3
-3
nixos/modules/services/security/privacyidea.nix
·········
·········
+2
-2
nixos/modules/services/security/step-ca.nix
+2
-2
nixos/modules/services/security/step-ca.nix
···
···
+5
-5
nixos/modules/services/security/tor.nix
+5
-5
nixos/modules/services/security/tor.nix
···············
···············
+1
-1
nixos/modules/services/security/vaultwarden/default.nix
+1
-1
nixos/modules/services/security/vaultwarden/default.nix
···<link xlink:href="https://github.com/dani-garcia/vaultwarden/blob/${vaultwarden.version}/.env.template">the environment template file</link>.
···<link xlink:href="https://github.com/dani-garcia/vaultwarden/blob/${vaultwarden.version}/.env.template">the environment template file</link>.
+1
-2
nixos/modules/services/web-apps/hedgedoc.nix
+1
-2
nixos/modules/services/web-apps/hedgedoc.nix
+6
-13
nixos/modules/services/web-apps/keycloak.nix
+6
-13
nixos/modules/services/web-apps/keycloak.nix
···············
···+To use this with a local database, set <xref linkend="opt-services.keycloak.database.createLocally"/> to···+To use this with a local database, set <xref linkend="opt-services.keycloak.database.createLocally"/> to·········+Most available options are documented at <link xlink:href="https://www.keycloak.org/server/all-config"/>.
+1
-1
nixos/modules/services/web-apps/mediawiki.nix
+1
-1
nixos/modules/services/web-apps/mediawiki.nix
+6
-6
nixos/modules/services/web-apps/nextcloud.nix
+6
-6
nixos/modules/services/web-apps/nextcloud.nix
···-Data storage path of nextcloud. Will be <xref linkend="opt-services.nextcloud.home" /> by default.This folder will be populated with a config.php and data folder which contains the state of the instance (excl the database).";···Extra apps to install. Should be an attrSet of appid to packages generated by fetchNextcloudApp.-Using this will disable the appstore to prevent Nextcloud from updating these apps (see <xref linkend="opt-services.nextcloud.appstoreEnable" />).···-Automatically enable the apps in <xref linkend="opt-services.nextcloud.extraApps" /> every time nextcloud starts.If set to false, apps need to be enabled in the Nextcloud user interface or with nextcloud-occ app:enable.···-Enabled by default unless there are packages in <xref linkend="opt-services.nextcloud.extraApps" />.-Set to true to force enable the store even if <xref linkend="opt-services.nextcloud.extraApps" /> is used.Set to false to disable the installation of apps from the global appstore. App management is always enabled regardless of this setting.···This is used by the theming app and for generating previews of certain images (e.g. SVG and HEIF).You may want to disable it for increased security. In that case, previews will still be available
···+Data storage path of nextcloud. Will be <xref linkend="opt-services.nextcloud.home"/> by default.This folder will be populated with a config.php and data folder which contains the state of the instance (excl the database).";···Extra apps to install. Should be an attrSet of appid to packages generated by fetchNextcloudApp.+Using this will disable the appstore to prevent Nextcloud from updating these apps (see <xref linkend="opt-services.nextcloud.appstoreEnable"/>).···+Automatically enable the apps in <xref linkend="opt-services.nextcloud.extraApps"/> every time nextcloud starts.If set to false, apps need to be enabled in the Nextcloud user interface or with nextcloud-occ app:enable.···+Enabled by default unless there are packages in <xref linkend="opt-services.nextcloud.extraApps"/>.+Set to true to force enable the store even if <xref linkend="opt-services.nextcloud.extraApps"/> is used.Set to false to disable the installation of apps from the global appstore. App management is always enabled regardless of this setting.···This is used by the theming app and for generating previews of certain images (e.g. SVG and HEIF).You may want to disable it for increased security. In that case, previews will still be available
+1
-2
nixos/modules/services/web-apps/node-red.nix
+1
-2
nixos/modules/services/web-apps/node-red.nix
···-xlink:href="https://github.com/node-red/node-red/blob/master/packages/node_modules/node-red/settings.js"/>
···+See <link xlink:href="https://github.com/node-red/node-red/blob/master/packages/node_modules/node-red/settings.js"/>
+2
-3
nixos/modules/services/web-apps/wiki-js.nix
+2
-3
nixos/modules/services/web-apps/wiki-js.nix
···
···+corresponds to <link xlink:href="https://docs.requarks.io/install/config">the upstream configuration options</link>.
+2
-2
nixos/modules/services/web-apps/wordpress.nix
+2
-2
nixos/modules/services/web-apps/wordpress.nix
······
······
+2
-4
nixos/modules/services/web-servers/apache-httpd/vhost-options.nix
+2
-4
nixos/modules/services/web-servers/apache-httpd/vhost-options.nix
······
···+Specification of pages to be ignored by web crawlers. See <link xlink:href="http://www.robotstxt.org/"/> for details.···+Declarative location config. See <link xlink:href="https://httpd.apache.org/docs/2.4/mod/core.html#location"/> for details.
+4
-4
nixos/modules/services/web-servers/nginx/default.nix
+4
-4
nixos/modules/services/web-servers/nginx/default.nix
···
···
+1
-2
nixos/modules/services/web-servers/uwsgi.nix
+1
-2
nixos/modules/services/web-servers/uwsgi.nix
···
···+See the uWSGI <link xlink:href="https://uwsgi-docs.readthedocs.io/en/latest/Capabilities.html">docs</link>
+2
-3
nixos/modules/system/boot/initrd-network.nix
+2
-3
nixos/modules/system/boot/initrd-network.nix
···
···+as described in <link xlink:href="https://www.kernel.org/doc/Documentation/filesystems/nfs/nfsroot.txt">the kernel documentation</link>.
+2
-5
nixos/modules/system/boot/networkd.nix
+2
-5
nixos/modules/system/boot/networkd.nix
······-See <link xlink:href="https://www.freedesktop.org/software/systemd/man/systemd-networkd-wait-online.service.html">-<citerefentry><refentrytitle>systemd-networkd-wait-online.service</refentrytitle><manvolnum>8</manvolnum>
···+<link xlink:href="https://www.kernel.org/doc/Documentation/networking/vrf.txt">kernel docs</link>.···+See <link xlink:href="https://www.freedesktop.org/software/systemd/man/systemd-networkd-wait-online.service.html"><citerefentry><refentrytitle>systemd-networkd-wait-online.service</refentrytitle><manvolnum>8</manvolnum></citerefentry></link> for all available options.
+1
-2
nixos/modules/system/boot/systemd/logind.nix
+1
-2
nixos/modules/system/boot/systemd/logind.nix
···See <link xlink:href="https://www.freedesktop.org/software/systemd/man/logind.conf.html#KillUserProcesses=">logind.conf(5)</link>
···+<link xlink:href="https://www.freedesktop.org/software/systemd/man/systemd.scope.html#">systemd.scope(5)</link>), and processes are not killed.See <link xlink:href="https://www.freedesktop.org/software/systemd/man/logind.conf.html#KillUserProcesses=">logind.conf(5)</link>
+1
-1
nixos/modules/tasks/network-interfaces.nix
+1
-1
nixos/modules/tasks/network-interfaces.nix