| config | attribute set of attribute set of any value | Desired values for the package's declared config artifacts. |
| credentials | attribute set of submodule | Opaque references for the package's declared credentials. |
| defaultRuntime | one of ["runc"] | Default OCI runtime registered with the CRI plugin. |
| disabledPlugins | list of string matching [A-Za-z0-9][A-Za-z0-9._-]* | Containerd plugins disabled at startup. |
| enable | boolean | Whether to run containerd as a standalone host runtime. |
| grpcAddress | string matching /run/containerd(/[A-Za-z0-9._/-]+)? | Unix socket used by local containerd clients. |
| metricsAddress | string matching [^[:space:]]+:[0-9]+ or null | Optional Prometheus metrics listen address. |
| registryConfigPath | string matching /etc/containerd(/[A-Za-z0-9._/-]+)? | Root containing host-specific registry configuration. |
| requiredPlugins | list of string matching [A-Za-z0-9][A-Za-z0-9._-]* | Plugins whose initialization failure aborts startup. |
| root | string matching /var/lib/containerd(/[A-Za-z0-9._/-]+)? | Persistent containerd content and metadata root. |
| sandboxImage | string matching [^[:space:]]+ | CRI pod sandbox image reference. |
| snapshotter | one of ["overlayfs","native"] | Default CRI image snapshotter. |
| state | string matching /run/containerd(/[A-Za-z0-9._/-]+)? | Volatile containerd state directory. |
| systemdCgroup | boolean | Whether runc delegates cgroup management to systemd. |