| bindAddress | string matching [A-Za-z0-9_.:-]+ | Address on which MariaDB accepts client connections. |
| bootstrap.adminSql | submodule or null | Optional credential containing idempotent SQL for administrator provisioning. |
| bootstrap.replicationSql | submodule or null | Optional credential containing idempotent SQL for replication provisioning. |
| characterSet | one of ["utf8mb4","utf8mb3","latin1"] | Default server character set. |
| collation | string matching [A-Za-z0-9_]+ | Default server collation. |
| config | attribute set of attribute set of any value | Desired values for the package's declared config artifacts. |
| credentials | attribute set of submodule | Opaque references for the package's declared credentials. |
| enable | boolean | Whether to enable the MariaDB database service. |
| maxConnections | signed integer | Maximum simultaneous MariaDB client connections. |
| port | signed integer | TCP port on which MariaDB accepts client connections. |
| skipNameResolve | boolean | Disable DNS lookups while matching client grant entries. |
| sqlMode | string matching [A-Z0-9_,]* | Comma-separated server SQL modes. |
| tls.ca | submodule or null | Optional opaque reference for the client CA bundle. |
| tls.certificate | submodule or null | Opaque reference for the PEM server certificate. |
| tls.enable | boolean | Enable TLS using credential-backed certificate material. |
| tls.privateKey | submodule or null | Opaque reference for the PEM server private key. |