| client.advertiseUrls | non-empty list of string matching https?://[^[:space:],]+ | Client endpoints advertised to clients and peers. |
| client.enableGrpcGateway | boolean | Enable the embedded gRPC-to-JSON gateway. |
| client.listenUrls | non-empty list of string matching https?://[^[:space:],]+ | Client endpoints on which etcd listens. |
| client.tls | submodule | TLS policy and opaque credential references for client traffic. |
| cluster.members | attribute set of submodule | Initial member topology keyed by stable member name. |
| cluster.state | one of ["new","existing"] | Whether this member creates or joins the declared cluster. |
| cluster.token | string matching [A-Za-z0-9_.-]+ | Non-secret identifier preventing accidental cross-cluster joins. |
| config | attribute set of attribute set of any value | Desired values for the package's declared config artifacts. |
| credentials | attribute set of submodule | Opaque references for the package's declared credentials. |
| enable | boolean | Enable the package-owned etcd service. |
| metrics | one of ["basic","extensive"] | Prometheus metric detail exported by etcd. |
| name | string matching [A-Za-z0-9][A-Za-z0-9_.-]* | Stable name of this etcd member. |
| peer.advertiseUrls | non-empty list of string matching https?://[^[:space:],]+ | Peer endpoints advertised to the other members. |
| peer.listenUrls | non-empty list of string matching https?://[^[:space:],]+ | Peer endpoints on which this member listens. |
| peer.tls | submodule | Mutual-TLS policy and opaque credential references for replication traffic. |
| storage.autoCompaction.mode | one of ["periodic","revision"] | Automatic history compaction mode. |
| storage.autoCompaction.retention | string matching .+ | History retention interpreted according to the compaction mode. |
| storage.quotaBackendBytes | signed integer | Maximum backend database size in bytes before writes are alarmed. |
| storage.snapshotCount | signed integer | Committed transactions between Raft snapshots. |