avahi — service discovery / MDNSfstrim — TRIM daemon for SSDsfwupd — fwupdgdm — GNOME DIsplay Managergnome-keyring — gnome-keyringgnupg-agent — gnupg agent (for pinentry)greetd — greetd+regreethome-assistant — enables Home Assistant, with @psyclyx's configkanata — kanata (keyboard remapper)locate — locate service
users : [str]— users to put in the mlocate group
nginx — nginx web server with Let's Encrypt
acme
email : str— email for Let's Encrypt registration
virtualHosts
virtualHosts : {…}— virtual hosts to configure (keys are domain names)
<name>
locations
locations : {…}— location blocks
<name>
proxyPass : ?str— proxy requests to this URL
root : ?absolute path— document root for this location
root : ?absolute path— document root for static files
nsd — NSD authoritative DNS server
zones
zones : {…}— zone definitions
<name>
data : strings concatenated with "\n"— zone file data
interfaces : [str] = [
"127.0.0.1"
"::1"
]— interfaces to listen on
port : u16 = 5353— port for authoritative DNS (5353 for local stub, 53 for public)
openrgb — openRGBopenssh — enable OpenSSH
agentAuth — respect SSH Agent authentication in PAM
printing — enable printingresolved — systemd-resolved dns resolversddm — simple Desktop Display Managertailscale — enable tailscale service and related settings
exitNode : bool— configure tailscale client as an exit node
thermald — thermal throttling daemon for intel cpusunbound — unbound DNS resolver