| clusterCidr | string matching .+ or null | CIDR from which pod addresses are allocated. |
| clusterDns | string matching .+ or null | Cluster DNS service address. |
| disableKubeProxy | boolean | Disable kube-proxy for a replacement data plane. |
| disableNetworkPolicy | boolean | Disable the built-in network-policy controller. |
| flannelBackend | one of ["vxlan","host-gw","wireguard-native","none"] | Flannel backend, or `none` when an external CNI owns pod networking. |
| flannelInterface | string matching .+ or null | Host interface used for Flannel traffic. |
| serviceCidr | string matching .+ or null | CIDR from which service addresses are allocated. |