| address | string matching [A-Za-z0-9][A-Za-z0-9.:-]* | Address for the authenticated kubelet HTTPS endpoint. |
| authentication1 child | | |
| cgroupDriver | one of ["cgroupfs","systemd"] | Cgroup manager shared with the container runtime. |
| clusterDns | list of string matching [0-9a-fA-F:.]+ | DNS service addresses written into pod resolv.conf files. |
| clusterDomain | string matching [A-Za-z0-9]([A-Za-z0-9.-]*[A-Za-z0-9])? | DNS domain appended to Kubernetes service names. |
| config | attribute set of attribute set of any value | Desired values for the package's declared config artifacts. |
| credentials | attribute set of submodule | Opaque references for the package's declared credentials. |
| enable | boolean | Enable the package-owned standalone kubelet service. |
| failSwapOn | boolean | Refuse to start when swap is enabled on the host. |
| kubeconfig | submodule | Kubernetes API client identity delivered as a systemd credential. |
| maxPods | signed integer | Maximum number of pods admitted on this node. |
| nodeName | string matching [a-z0-9]([-a-z0-9.]*[a-z0-9])? | Node name reported to the Kubernetes API. |
| registerNode | boolean | Register and maintain this node through the Kubernetes API. Disabling registration selects standalone authentication and authorization defaults for static-pod operation. |
| runtimeEndpoint | string matching unix:///[^[:space:]]+ | CRI runtime endpoint used to create pods and images. |
| staticPodPath | string matching /[^[:space:]]+ | Host directory watched for static pod manifests. |