| enable | boolean | Enable the selected k3s role. |
| integrations.cni | attribute set of submodule | Named, package-contributable CNI integration requirements. |
| integrations.csi | attribute set of submodule | Named, package-contributable CSI integration requirements. |
| integrations.resources | attribute set of submodule | Named, package-contributable Kubernetes YAML bundles reconciled by server roles. |
| kubeconfigMode | one of ["0600","0640","0644"] | Mode of the administrator kubeconfig emitted by server roles. |
| networking.clusterCidr | string matching .+ or null | CIDR from which pod addresses are allocated. |
| networking.clusterDns | string matching .+ or null | Cluster DNS service address. |
| networking.disableKubeProxy | boolean | Disable kube-proxy for a replacement data plane. |
| networking.disableNetworkPolicy | boolean | Disable the built-in network-policy controller. |
| networking.flannelBackend | one of ["vxlan","host-gw","wireguard-native","none"] | Flannel backend, or `none` when an external CNI owns pod networking. |
| networking.flannelInterface | string matching .+ or null | Host interface used for Flannel traffic. |
| networking.serviceCidr | string matching .+ or null | CIDR from which service addresses are allocated. |
| node.externalIp | string matching .+ or null | External IP address advertised for the node. |
| node.ip | string matching .+ or null | IP address advertised for the node. |
| node.labels | attribute set of string | Labels registered on the node. |
| node.name | string matching .+ or null | Kubernetes node name. |
| node.taints | list of string matching .+ | Taints registered on the node in Kubernetes taint syntax. |
| role | one of ["worker","control-plane","combined"] | The k3s role implemented by the selected package. |
| server.clusterInit | boolean | Initialize a new embedded-etcd cluster. |
| server.disableComponents | list of one of ["coredns","servicelb","traefik","local-storage","metrics-server","runtimes"] | Packaged server components not deployed by k3s. |
| server.tlsSans | list of string matching .+ | Additional subject alternative names for the API server certificate. |
| serverUrl | string matching .+ or null | HTTPS URL of an existing k3s server to join. |
| token | submodule or null | Opaque reference to the cluster token loaded as a systemd credential. |