| authentication.rules | list of submodule | Ordered pg_hba.conf authentication rules. |
| bootstrap.password | submodule or null | Opaque reference to the initial superuser password. |
| bootstrap.superuser | string matching [A-Za-z_][A-Za-z0-9_$-]* | Database superuser created when an empty cluster is initialized. |
| clusterName | string matching [^
]+ | Cluster name included in process titles and logs. |
| config | attribute set of attribute set of any value | Desired values for the package's declared config artifacts. |
| credentials | attribute set of submodule | Opaque references for the package's declared credentials. |
| enable | boolean | Enable the PostgreSQL database server. |
| listen.addresses | list of string matching [^,'[:space:]]+ | TCP addresses on which PostgreSQL accepts connections. |
| listen.port | TCP/UDP port number (1-65535) | TCP port on which PostgreSQL accepts connections. |
| replication.applicationName | string matching [A-Za-z_][A-Za-z0-9_$-]* | Standby application name reported to the primary. |
| replication.hotStandby | boolean | Allow read-only queries while the server is in recovery. |
| replication.maxReplicationSlots | signed integer | Maximum replication slots retained by this server. |
| replication.maxWalSenders | signed integer | Maximum concurrent WAL sender processes. |
| replication.passfile | submodule or null | Opaque reference to a libpq passfile used by a standby. |
| replication.primary | submodule or null | Primary endpoint used by a standby. |
| replication.slot | string matching [A-Za-z_][A-Za-z0-9_$-]* or null | Optional physical replication slot consumed by the standby. |
| replication.user | string matching [A-Za-z_][A-Za-z0-9_$-]* | Database role used by a standby connection. |
| replication.walLevel | one of ["minimal","replica","logical"] | Write-ahead log detail retained for recovery and replication. |
| resources.maintenanceWorkMem | string matching [1-9][0-9]*(B|kB|MB|GB|TB) | Memory available to maintenance operations. |
| resources.maxConnections | signed integer | Maximum concurrent client connections. |
| resources.sharedBuffers | string matching [1-9][0-9]*(B|kB|MB|GB|TB) | Memory dedicated to PostgreSQL shared buffers. |
| resources.workMem | string matching [1-9][0-9]*(B|kB|MB|GB|TB) | Memory available to each query operation before spilling. |
| settings | attribute set of boolean or signed integer or string matching [^
]* | Additional non-secret PostgreSQL settings not owned by a dedicated option. |
| tls.ca | submodule or null | Optional opaque reference to the client-certificate CA bundle. |
| tls.certificate | submodule or null | Opaque reference to the PEM server certificate. |
| tls.enable | boolean | Enable TLS for TCP connections. |
| tls.minimumProtocol | one of ["TLSv1.2","TLSv1.3"] | Minimum accepted TLS protocol version. |
| tls.privateKey | submodule or null | Opaque reference to the PEM server private key. |
| topology | one of ["standalone","primary","standby"] | The database server's replication role. |