| admin.bindAddress | string matching [^[:space:]]+ | Socket address used by the administration API. |
| admin.enable | boolean | Enable Garage's authenticated administration and metrics API. |
| admin.metrics.requireToken | boolean | Require a bearer token when scraping metrics. |
| admin.metrics.token | submodule or null | Opaque reference for the metrics bearer token. |
| admin.token | submodule or null | Opaque reference for the administration bearer token. |
| config | attribute set of attribute set of any value | Desired values for the package's declared config artifacts. |
| credentials | attribute set of submodule | Opaque references for the package's declared credentials. |
| dbEngine | one of ["lmdb","sqlite"] | Embedded metadata database engine. |
| enable | boolean | Whether to enable the Garage object-storage service. |
| replicationFactor | signed integer | Number of copies Garage maintains for each object. |
| rpc.bindAddress | string matching [^[:space:]]+ | Socket address used for Garage cluster RPC. |
| rpc.bootstrapPeers | list of string | Garage node-ID and RPC-address peers used for cluster discovery. |
| rpc.publicAddress | string matching [^[:space:]]+ or null | Externally reachable cluster RPC address advertised to peers. |
| rpc.secret | submodule or null | Opaque reference for the shared 32-byte hexadecimal RPC secret. |
| s3.bindAddress | string matching [^[:space:]]+ | Socket address used by the S3 API. |
| s3.region | string | S3 region returned to clients and used for request signing. |
| s3.rootDomain | string or null | Optional DNS suffix for virtual-host-style S3 requests. |
| web.bindAddress | string matching [^[:space:]]+ | Socket address used by the bucket website endpoint. |
| web.enable | boolean | Enable Garage's public bucket website endpoint. |
| web.rootDomain | string | DNS suffix used to select website buckets. |