Trino values#
Values under trino configure Trino, the SQL query engine, and its test coordinator for user catalogs.
Generated from the Hopsworks Helm chart 5.2.0-alpha-1791549041 (Hopsworks 5.2.0).
Deployed according to the first of these values that is set: global._hopsworks.trino.enabled, global._hopsworks.full_platform.
Upstream charts
- Values under
trino.trinogo totrino1.41.0 fromhttps://trinodb.github.io/charts. - Values under
trino.trinotestgo totrino1.41.0 fromhttps://trinodb.github.io/charts.
Only the values Hopsworks sets under trino.trino and trino.trinotest are listed on this page. Any other value of the charts can be set under the same keys; each link opens the chart's documentation for the version Hopsworks pins.
General#
Defaults as YAML
trino#- Type
object, default{}. override trino values trino.catalogsConfigmapName#- Type
string, default"hopsworks-trino-catalogs". trino.hopsworkslib#- Type
object, default{}. override hopsworkslib values trino.trinotest#- Type
object, default check [values.yaml](./values.yaml) for more information, passed to thetrino1.41.0 chart, whose other values are documented there. override trinotest values. Rendered only when global._hopsworks.trino.testCoordinator.enabled is true (see Chart.yaml). An optional single-node coordinator running catalog.management=dynamic with a WRITABLE catalog dir, used by the backend to connection-test user catalogs (CREATE CATALOG / SHOW SCHEMAS / DROP CATALOG) before they are synced to the production coordinator. Mirrors the production coordinator's image, certs, TLS, and PASSWORD auth so the backend's admin credentials and discovery work identically. trino.trinotest.initContainers.coordinator[2].name#- Type
string, default"mountable-secrets". readOnly is not optional. Without it the query engine gains a write channel into HopsFS as the trino service user; the volume's readOnly makes the kernel refuse writes too. --srcDir bounds what the mount exposes to the backend-owned tree; the mount authenticates as trino, which is in the hdfs superuser group, so srcDir is the only thing containing it. No preStop unmount: the node plugin owns the mount and unmounts it in NodeUnpublishVolume, and hopsfs-sidecar.sh exits on SIGTERM, so the container terminates cleanly on its own.
auth#
Defaults as YAML
trino.auth.adminUserPwd#- Type
string, default"". Plaintext password foradminUsername, read by the backend and bcrypted into password.db by the seeder Job. Empty generates one on first install and reuses it from the existing Secret; empty in a non-auto mode fails the render, since the existing Secret cannot be read back. trino.auth.adminUsername#- Type
string, default"trino". Trino admin username. Should not be changed. Used in hadoop.proxyuser.trino trino.auth.createSecrets#- Type
bool, defaulttrue. If createSecrets is false, you must manually create the following Kubernetes Secrets: 1. trino-admin-credentials (keysusername,password): the backend's principal. 2. trino-monitoring-credentials (same keys): the principal Prometheus scrapes with. The seeder Job bcrypts both into password.db in HopsFS. Label bothbackup.hops.works/include: "true"so Velero captures them. In any non-autoglobal._hopsworks.mode(ArgoCD) the existing Secret cannot be read back, so the render fails unless both passwords below are set or this is false. - Type
bool, defaulttrue. IfcreateSharedSecretis set tofalse, you must generate aninternal-communication.shared-secretvalue and store it in a Kubernetes Secret namedtrino-internal-secretunder the keyshared-secret. trino-internal-secret is intentionally NOT captured by the Velero backup (it has no coupling to user state and is regenerated on a fresh install). With createSharedSecret=false it is operator-managed, so disaster recovery must restore it from an independent source, followed by a coordinated restart of all Trino pods so coordinator and workers share the same value. trino.auth.monitoringUser#- Type
string, default"prometheus". Username used by Prometheus for scraping Trino metrics. If you override this value, you MUST also: 1. Update Trino access control to grant this user the required permissions (e.g. adjustaccessControl.rules.rules.jsonaccordingly). 2. Update the Prometheus scrape configuration so that the same username is used: set.Values.prometheus.prometheus.serverFiles.prometheus.yml.scrape_configs[*].basic_auth.usernamefor the scrape job withjob_name: "trino"to match this value. trino.auth.monitoringUserPwd#- Type
string, default"". Plaintext password formonitoringUser, read by Prometheus and bcrypted into password.db. Generated likeadminUserPwd. trino.auth.adminUserPwdHashDeprecated #- Type
string, defaultnil. DEPRECATED, read by nothing: the seeder derives the hash fromadminUserPwd. Kept so an existing override still validates. trino.auth.monitoringUserPwdHashDeprecated #- Type
string, defaultnil. DEPRECATED, read by nothing, likeadminUserPwdHash.
authSeeder#
Defaults as YAML
trino.authSeeder#-
Type
object. The Job that seeds password.db and group.db into HopsFS, and the pre-upgrade hook that migrates them from the legacy Secrets. Not optional: Trino cannot start without them. trino.authSeeder.image#- Type
object, default{"name":"hopsfs","registry":"","tag":"3.4.3.3-EE-RC1"}. The HopsFS client image. The seeder writes withhdfs dfs; the trino-files mount is read-only. trino.authSeeder.image.name#- Type
string, default"hopsfs". Image name. trino.authSeeder.image.registry#- Type
string, default"". Full registry+path prefix, ending with/. Empty usesglobal._hopsworks.imageRegistryplus/hopsworks/, matching charts/hopsfs. trino.authSeeder.image.tag#- Type
string, default"3.4.3.3-EE-RC1". Image tag. Keep in step withhopsfs.image.tagin charts/hopsfs/values.yaml. trino.authSeeder.ttlSecondsAfterFinished#- Type
int, default3600. Seconds to keep the finished Jobs; their logs record what was seeded. trino.authSeeder.waitSeconds#- Type
int, default600. Seconds the seeder waits for HopsFS before failing.
dependencies#
Defaults as YAML
trino.dependencies.hive.consulServiceName#- Type
string, default"hive". trino.dependencies.hive.consulServiceTag#- Type
string, default"metastore". trino.dependencies.hive.port#- Type
int, default9083. trino.dependencies.mysql.consulServiceName#- Type
string, default"mysql". trino.dependencies.mysql.port#- Type
int, default3306.
externalLoadBalancer#
Defaults as YAML
trino.externalLoadBalancer.annotations#- Type
object, default{}. annotations for load balancer trino.externalLoadBalancer.class#- Type
string, defaultnil. load balancer class name trino.externalLoadBalancer.enabled#- Type
string, defaultnil. Enable External Load Balancers for the Trino coordinator/service. If not set the .global._hopsworks.externalLoadBalancers.enabled will be used instead trino.externalLoadBalancer.managed#- Type
string, defaultnil. Cloud provider provisions Load Balancers. If not set the .global._hopsworks.externalLoadBalancers.managed will be used instead trino.externalLoadBalancer.nodePort#- Type
string, defaultnil. Explicit nodePort for the external service when the load balancer is unmanaged (managed: false), so a load balancer outside Kubernetes can target a fixed port. Null lets Kubernetes allocate one from the cluster's node-port range; a set value must lie in that range (30000-32767 by default), which the API server enforces at install. trino.externalLoadBalancer.nodeSelector#- Type
object, default{}. selector for nodes the load balancer can use to route traffic
trino#
Defaults as YAML
trino.trino#- Type
object, default check [values.yaml](./values.yaml) for more information, passed to thetrino1.41.0 chart, whose other values are documented there. override trino values trino.trino.coordinator.additionalJVMConfig#- Type
list, default["--add-opens=java.base/java.nio=ALL-UNNAMED"]. add-opens for java.nio, and the failure is a CONFIGURATION error raised while the catalog is being loaded. On this coordinator that is fatal rather than local, because Trino runs catalog.management=static and exits when a catalog file fails to load -- so one project's Snowflake catalog would stop the whole cluster from starting. Set here rather than left to the operator because the connector is in TRINO_CONNECTORS, i.e. the backend offers it to every project. Other Arrow-based connectors need the same opens, so this is not Snowflake-specific. trino.trino.image.registry#- Type
string, default"docker.hops.works". Image registry, defaults to empty, which results in DockerHub usage trino.trino.image.repository#- Type
string, default"hopsworks/trino". Repository location of the Trino image, typicallyorganization/imagename trino.trino.image.tag#- Type
string, default"483-v1". Image tag for the Trino image. This value is explicitly pinned here and overrides any defaulting toappVersionfrom Chart.yaml. trino.trino.initContainers.coordinator[2].name#- Type
string, default"mountable-secrets". readOnly is not optional. Without it the query engine gains a write channel into HopsFS as the trino service user; the volume's readOnly makes the kernel refuse writes too. --srcDir bounds what the mount exposes to the backend-owned tree; the mount authenticates as trino, which is in the hdfs superuser group, so srcDir is the only thing containing it. No preStop unmount: the node plugin owns the mount and unmounts it in NodeUnpublishVolume, and hopsfs-sidecar.sh exits on SIGTERM, so the container terminates cleanly on its own. trino.trino.initContainers.worker[1].name#- Type
string, default"mountable-secrets". readOnly is not optional. Without it the query engine gains a write channel into HopsFS as the trino service user; the volume's readOnly makes the kernel refuse writes too. --srcDir bounds what the mount exposes to the backend-owned tree; the mount authenticates as trino, which is in the hdfs superuser group, so srcDir is the only thing containing it. No preStop unmount: the node plugin owns the mount and unmounts it in NodeUnpublishVolume, and hopsfs-sidecar.sh exits on SIGTERM, so the container terminates cleanly on its own.