Skip to content

Global values#

Values under global are shared by every subchart: image registry and pull secrets, storage class, scheduling, cloud provider and which optional services are enabled.

Generated from the Hopsworks Helm chart 5.1.0 (Hopsworks 5.1.0).

General#

Defaults as YAML
global:
  _hopsworks:
    airflow:
      enabled: true
      keysSecretName: hopsworks-airflow-keys
    airflowApiKeySecretName: airflow-api-key
    autoscalers: {}
    buildkitd:
      enabled: false
    centralNamespace: hopsworks
    cloudProvider: ''
    consulDomainName: consul
    executor_uid: 1235
    full_platform: true
    grafana:
      extraDashboardProviders: []
    imagePullPolicy: IfNotPresent
    imagePullSecrets: []
    imageRegistry: docker.hops.works
    initContainerResources:
      runtime:
        limits:
          cpu: 1
          memory: 1Gi
        requests:
          cpu: 250m
          memory: 512Mi
      tool:
        limits:
          cpu: 500m
          memory: 512Mi
        requests:
          cpu: 100m
          memory: 128Mi
      waiter:
        limits:
          cpu: 500m
          memory: 256Mi
        requests:
          cpu: 50m
          memory: 64Mi
    jobs:
      ttlSecondsAfterFinished: 86400
    kafka:
      enabled: true
    kueue:
      enabled: false
    managedObjectStorage:
      enabled: false
      s3: null
    mode: auto
    mysql:
      hopsworksUser: hopsworksroot
      usersSecretname: mysql-users-secrets
    networkPolicy:
      rondbAccessLabels:
        access: mgmd-and-ndbmtd
    nodeSelector: {}
    onlinefs:
      email: onlinefs@hopsworks.ai
      password: onlinefspw
    opensearch:
      enabled: true
    openshift:
      enabled: false
    ray:
      enabled: false
    restoreFromBackup:
      backupId: null
      forceDataClear: false
      inPlace: false
    security:
      tls:
        enabled: true
    securityContextEnabled: true
    serviceAccount:
      annotations: {}
      create: true
      name: hopsworks-service-account
    serviceAccountAnnotations: {}
    skipDatabaseMigration: false
    spark:
      history:
        enabled: true
    storageClassName: null
    superset:
      enabled: true
      mysql:
        enabled: true
      redis:
        enabled: true
    tolerations: []
    toolbox:
      image: hwutils
      tag: '1.9'
    topologySpreadConstraint:
      maxSkew: 1
      nodeAffinityPolicy: Honor
      nodeTaintsPolicy: Honor
      topologyKey: topology.kubernetes.io/zone
      whenUnsatisfiable: ScheduleAnyway
    vpaEnabled: false
    wipeDataOnUninstall: true
  _kserve:
    servingruntime:
      vllmomni:
        tag: v0.20.0
      vllmopenai:
        tag: v0.20.0
  imageDigests: {}
  unmanagedLoadBalancers: {}
global._hopsworks.airflow.enabled #
Type bool, default true. Enable or disable the installation of the airflow sub chart
global._hopsworks.airflow.keysSecretName #
Type string, default "hopsworks-airflow-keys". Name of the Secret holding the shared-bearer secret that hopsworks-instance uses to call the Airflow /auth/internal/* routes. Must match airflow.airflowApi.keysSecretName so the same Secret is mounted on both sides. The default airflow-webserver-airflow-crypto-material is the cert-only secret and does NOT contain internal-shared-secret, so the hopsworks-instance pod fails to mount on a fresh v3 install.
global._hopsworks.airflowApiKeySecretName #
Type string, default "airflow-api-key".
global._hopsworks.autoscalers #
Type object, default {}. Map of autoscaler name to VPA configuration. Each key becomes a VerticalPodAutoscaler resource named -vpa.
global._hopsworks.buildkitd.enabled #
Type bool, default false.
global._hopsworks.centralNamespace #
Type string, default "hopsworks". Namespace to fetch OLK signing key from. Set to null to generate a new key.
global._hopsworks.cloudProvider #
Type string, default "". cloud provider (AWS, AZURE, GCP, OVH). It is used by HopsFS, Consul, and Hopsworks. Hopsfs uses it to configure the object storage parameters. Consul uses it to configure coredns accordingly. Hopsworks uses it to determine how to store the users docker images within the same hopsworks-base repo as tags or in different repo per project, If cloud provider is set all the users docker images are stored as tags - it is an AWS limitation where only tags within the repo can share layers.
global._hopsworks.consulDomainName #
Type string, default "consul". The domain name for consul where it will answer DNS queries, e.g. service-name.service.consul. If changed, make sure to update consul.consul.global.domain to the same value.
global._hopsworks.executor_uid #
Type int, default 1235. User ID for the user running Hopsworks and Airflow containers
global._hopsworks.full_platform #
Type bool, default true. Flag to indicate if the full platform is installed or just the online feature store infrastructure
global._hopsworks.grafana.extraDashboardProviders #
Type list, default []. Extra Grafana dashboard providers, appended to the provider file the grafana chart renders. The dashboards themselves ship in the Grafana image, so this is the way to provision one without rebuilding the image: mount it (for example through grafana.grafana.dashboardsConfigMaps, which lands at /var/lib/grafana/dashboards/) and point a provider at the mount path. Entries are Grafana provider objects, so each needs at least name, folder, type: file and options.path; provider names must be unique across all providers. Paths under /usr/share/grafana/dashboards are the image's own and are verified by the verify-dashboards init container, so point elsewhere. Setting this changes the provider ConfigMap's content hash, which rolls the Grafana pod.
global._hopsworks.imagePullPolicy #
Type string, default "IfNotPresent".
global._hopsworks.imagePullSecrets #
Type list, default []. image pull secrets to be used by all the subcharts. Notice that for subcharts the have external dependices, you need to update the image pull secrets accordingly in those subcharts
global._hopsworks.imageRegistry #
Type string, default "docker.hops.works".
global._hopsworks.initContainerResources #

Type object. Resource requests and limits for the chart's init containers, in three tiers by what the container does: waiter for shell wait loops, tool for file copies and small binaries, runtime for anything starting a JVM or a Python interpreter or pulling images. Every init container declares both requests and limits. A namespace LimitRange that supplies a default limit injects it into any container declaring none, and a pod's effective request is max(sum of app containers, highest single init container) where the init term is a floor for the pod's whole lifetime. An init container without resources can therefore pin a node's allocatable to the LimitRange default even after it has exited. Retune these if the target namespace has a LimitRange whose min/max would reject the defaults, since an out-of-range explicit value is rejected rather than defaulted.

Default
runtime:
  limits:
    cpu: 1
    memory: 1Gi
  requests:
    cpu: 250m
    memory: 512Mi
tool:
  limits:
    cpu: 500m
    memory: 512Mi
  requests:
    cpu: 100m
    memory: 128Mi
waiter:
  limits:
    cpu: 500m
    memory: 256Mi
  requests:
    cpu: 50m
    memory: 64Mi
global._hopsworks.jobs #
Type object, default {"ttlSecondsAfterFinished":86400}. Global configuration for Kubernetes Jobs created by the chart
global._hopsworks.jobs.ttlSecondsAfterFinished #
Type int, default 86400. Time in seconds after a finished Job is eligible for automatic cleanup. Applies to all Jobs unless overridden by a subchart-specific ttlSecondsAfterFinished value.
global._hopsworks.kafka.enabled #
Type bool, default true. Enable or disable the installation of the kafka sub chart.
global._hopsworks.kueue.enabled #
Type bool, default false.
global._hopsworks.managedObjectStorage #
Type object, default {"enabled":false,"s3":null}. Configuration for managed object storage to be used by HopsFS, Opensearch, RonDB, and Hopsworks. Opensearch and RonDB uses this configuration to setup a remote sink for their backup, if a different remote sink is configured on the subchart then it will take precedence. Hopsworks uses the bucket configuration as context cache when building users' docker images, only S3 is supported at the moment.
global._hopsworks.managedObjectStorage.s3 #
Type string, default nil. S3 configuration
global._hopsworks.mode #
Type string, default "auto". Helm installation model. "auto" lets the chart decide based on the Release.IsInstall value. "install" forces installation mode, while "upgrade" forces upgrade mode.
global._hopsworks.mysql.hopsworksUser #
Type string, default "hopsworksroot".
global._hopsworks.mysql.usersSecretname #
Type string, default "mysql-users-secrets".
global._hopsworks.networkPolicy.rondbAccessLabels.access #
Type string, default "mgmd-and-ndbmtd".
global._hopsworks.nodeSelector #
Type object, default {}. Specifies the global nodeSelector settings applied across all subcharts unless explicitly overridden within a specific subchart. This ensures Kubernetes schedules Pods only onto nodes that match all the specified labels. Notice that some subcharts do not use this global variable, and you must manually override those by defining them in the values.yaml file, using anchors if necessary.
global._hopsworks.onlinefs.email #
Type string, default "onlinefs@hopsworks.ai".
global._hopsworks.onlinefs.password #
Type string, default "onlinefspw".
global._hopsworks.opensearch #
Type object, default {"enabled":true}. Enable or disable the opensearch
global._hopsworks.opensearch.enabled #
Type bool, default true. Enable or disable the opensearch
global._hopsworks.openshift.enabled #
Type bool, default false. Enable when installing on Openshift platform
global._hopsworks.ray.enabled #
Type bool, default false.
global._hopsworks.restoreFromBackup #
Type object, default {"backupId":null,"forceDataClear":false,"inPlace":false}. restore cluster from a backup id
global._hopsworks.restoreFromBackup.backupId #
Type string, default nil. the backup id to restore
global._hopsworks.restoreFromBackup.forceDataClear #
Type bool, default false. flag to indicate if the data should be forcibly cleared before restore
global._hopsworks.restoreFromBackup.inPlace #
Type bool, default false. flag to indicate if the restore should be done in-place or to a new cluster
global._hopsworks.security.tls.enabled #
Type bool, default true.
global._hopsworks.securityContextEnabled #
Type bool, default true. Flag to disable templating SecurityContext for Openshift
global._hopsworks.serviceAccount.annotations #
Type object, default {}. custom annotations for the Hopsworks service account
global._hopsworks.serviceAccount.create #
Type bool, default true.
global._hopsworks.serviceAccount.name #
Type string, default "hopsworks-service-account".
global._hopsworks.serviceAccountAnnotations #
Type object, default {}. Use it to annotate the serviceAccounts we create for Hopsworks
global._hopsworks.skipDatabaseMigration #
Type bool, default false. Special flag which MUST be used only for 3.x -> 4.0 migrations (HWORKS-1600)
global._hopsworks.spark.history.enabled #
Type bool, default true. Enable or disable installing of the spark history server
global._hopsworks.storageClassName #
Type string, default nil. global storage class name
global._hopsworks.superset.enabled #
Type bool, default true. Enable or disable the installation of the superset sub chart.
global._hopsworks.superset.mysql.enabled #
Type bool, default true. Enable or disable MySQL for Superset. Must match superset.mysql.enabled for consistent behavior across charts.
global._hopsworks.superset.redis.enabled #
Type bool, default true. Enable or disable Redis for Superset. Must match superset.superset.redis.enabled for consistent behavior across charts.
global._hopsworks.tolerations #
Type list, default []. Specifies the global tolerations settings applied to all subcharts unless explicitly overridden in a specific subchart. These tolerations allow Kubernetes to schedule Pods on nodes with matching taints, ensuring proper placement based on cluster policies. Notice that some subcharts do not use this global variable, and you must manually override those by defining them in the values.yaml file, using anchors if necessary.
global._hopsworks.toolbox.image #
Type string, default "hwutils".
global._hopsworks.toolbox.tag #
Type string, default "1.9".
global._hopsworks.topologySpreadConstraint #

Type object. default topology spread constraint. If not defined the global topology spread constraint would be used

Default
maxSkew: 1
nodeAffinityPolicy: Honor
nodeTaintsPolicy: Honor
topologyKey: topology.kubernetes.io/zone
whenUnsatisfiable: ScheduleAnyway
global._hopsworks.vpaEnabled #
Type bool, default false.
global._hopsworks.wipeDataOnUninstall #
Type bool, default true. on uninstall, delete data PVCs left behind by StatefulSets unless the PVC carries the label hopsworks.ai/keep=true. Consumed by subchart post-delete cleanup hooks via the hopsworkslib.wipeDataOnUninstall helper.
global._kserve #

Type object. Global KServe values shared between the kserve and hopsworks subcharts

Default
servingruntime:
  vllmomni:
    tag: v0.20.0
  vllmopenai:
    tag: v0.20.0
global._kserve.servingruntime #
Type object, default {"vllmomni":{"tag":"v0.20.0"},"vllmopenai":{"tag":"v0.20.0"}}. Mirrors the kserve subchart's kserve.servingruntime layout. Tags here drive both the kserve ClusterServingRuntime images and the kube_serving_vllm*_versions hopsworks variable seeds.
global._kserve.servingruntime.vllmomni #
Type object, default {"tag":"v0.20.0"}. vLLM-Omni runtime image tag. Drives both the kserve ClusterServingRuntime image and the kube_serving_vllm_omni_versions hopsworks variable seed.
global._kserve.servingruntime.vllmopenai #
Type object, default {"tag":"v0.20.0"}. vLLM-OpenAI runtime image tag. Drives both the kserve ClusterServingRuntime image and the kube_serving_vllm_versions hopsworks variable seed.
global.imageDigests #
Type object, default {}. map image name to sha digest to be used instead of tags for reproducible deployment
global.unmanagedLoadBalancers #
Type object, default {}. Load balancer configuration when using unmanaged LB, in AWS is the TargetGroup ARNs for each service

backups#

Defaults as YAML
global:
  _hopsworks:
    backups:
      enabled: true
      metadataStore:
        configMap:
          opensearch: opensearch-backups-metadata
          ronDB: rondb-backups-metadata
      schedule: '@weekly'
      ttl: null
global._hopsworks.backups #

Type object. enable global backups configuration

Default
enabled: true
metadataStore:
  configMap:
    opensearch: opensearch-backups-metadata
    ronDB: rondb-backups-metadata
schedule: '@weekly'
ttl: null
global._hopsworks.backups.enabled #
Type bool, default true. enable global backup
global._hopsworks.backups.metadataStore #

Type object. backups metadata store

Default
configMap:
  opensearch: opensearch-backups-metadata
  ronDB: rondb-backups-metadata
global._hopsworks.backups.metadataStore.configMap.opensearch #
Type string, default "opensearch-backups-metadata". name of the configmap to store metadata information about opensearch backups
global._hopsworks.backups.metadataStore.configMap.ronDB #
Type string, default "rondb-backups-metadata". name of the configmap to store metadata information about rondb backups
global._hopsworks.backups.schedule #
Type string, default "@weekly". cron schedule
global._hopsworks.backups.ttl #
Type string, default nil. time to live to control when to clean up backups. It is a number followed by either d (days) or h (hours) suffix.

externalLoadBalancers#

Defaults as YAML
global:
  _hopsworks:
    externalLoadBalancers:
      annotations: {}
      class: null
      enabled: true
      managed: true
global._hopsworks.externalLoadBalancers #
Type object, default {"annotations":{},"class":null,"enabled":true,"managed":true}. Global load balancer configuration for external access to Hopsworks services: ArrowFlight, Kafka, and MySQL We fallback to this loadBalancerClass if the local loadBalancerClass is not defined
global._hopsworks.externalLoadBalancers.annotations #
Type object, default {}. Generic annotations attached to LoadBalancer objects
global._hopsworks.externalLoadBalancers.class #
Type string, default nil. Name of the LoadBalancer class
global._hopsworks.externalLoadBalancers.enabled #
Type bool, default true. Enable LoadBalancer Services
global._hopsworks.externalLoadBalancers.managed #
Type bool, default true. Cloud provider provisions Load Balancers

externalServices#

Defaults as YAML
global:
  _hopsworks:
    externalServices:
      hopsfs:
        external: false
        namenodeAddresses: []
      opensearch:
        addresses: []
        external: false
      prometheus:
        addresses: []
        external: false
      rondb:
        external: false
        mgmdHostname: ''
global._hopsworks.externalServices #

Type object. Configuration for when services are external to this Kubernetes installation

Default
hopsfs:
  external: false
  namenodeAddresses: []
opensearch:
  addresses: []
  external: false
prometheus:
  addresses: []
  external: false
rondb:
  external: false
  mgmdHostname: ''
global._hopsworks.externalServices.hopsfs #
Type object, default {"external":false,"namenodeAddresses":[]}. HopsFS configuration when it is installed externally
global._hopsworks.externalServices.hopsfs.external #
Type bool, default false. Flag to indicate HopsFS is installed externally
global._hopsworks.externalServices.hopsfs.namenodeAddresses #
Type list, default []. IP addresses where HopsFS Namenodes are installed
global._hopsworks.externalServices.opensearch #
Type object, default {"addresses":[],"external":false}. Opensearch configuration when it is installed externally
global._hopsworks.externalServices.opensearch.addresses #
Type list, default []. IP addresses where OpenSearch is installed
global._hopsworks.externalServices.opensearch.external #
Type bool, default false. Flag to indicate Opensearch is installed externally
global._hopsworks.externalServices.prometheus #
Type object, default {"addresses":[],"external":false}. prometheus configuration when it is installed externally
global._hopsworks.externalServices.prometheus.addresses #
Type list, default []. IP addresses where prometheus is installed
global._hopsworks.externalServices.prometheus.external #
Type bool, default false. Flag to indicate prometheus is installed externally
global._hopsworks.externalServices.rondb #
Type object, default {"external":false,"mgmdHostname":""}. RonDB configuration when it is installed externally
global._hopsworks.externalServices.rondb.external #
Type bool, default false. Flag to indicate RonDB is installed externally
global._hopsworks.externalServices.rondb.mgmdHostname #
Type string, default "". Hostname of the machine where RonDB management service is running

kyverno#

Defaults as YAML
global:
  _hopsworks:
    kyverno:
      enabled: false
      policies:
        addCertificatesVolume:
          enabled: false
          initContainers:
            annotation:
              key: kyverno-inject-certs-init
              value: enabled
            enabled: false
          mountPath: /etc/ssl/certs
          preconditions:
            annotation:
              key: kyverno-inject-certs
              value: enabled
            enabled: true
global._hopsworks.kyverno.enabled #
Type bool, default false. Enable or disable kyverno policies installation
global._hopsworks.kyverno.policies.addCertificatesVolume #

Type object. Configuration to add custom certificates to pods as a mounted volume

Default
enabled: false
initContainers:
  annotation:
    key: kyverno-inject-certs-init
    value: enabled
  enabled: false
mountPath: /etc/ssl/certs
preconditions:
  annotation:
    key: kyverno-inject-certs
    value: enabled
  enabled: true
global._hopsworks.kyverno.policies.addCertificatesVolume.enabled #
Type bool, default false. Enable add certificates volume
global._hopsworks.kyverno.policies.addCertificatesVolume.initContainers #

Type object. Opt-in for injecting the certificates volume into init containers. The main addCertificatesVolume policy only mutates spec.containers; init containers are intentionally left untouched because they are often injected by third-party operators (Istio, KServe, sidecar injectors) that ship minimal images where overwriting /etc/ssl/certs would break them. When enabled, a second mutate rule is rendered that iterates spec.initContainers and is gated by an OR of the dedicated init-container annotation below and any extraAnnotations / labels configured under the hw-kyverno subchart at policies.addCertificatesVolume.initContainers. The annotation is distinct from preconditions.annotation so authors can opt main containers and init containers in independently.

Default
annotation:
  key: kyverno-inject-certs-init
  value: enabled
enabled: false
global._hopsworks.kyverno.policies.addCertificatesVolume.initContainers.annotation #
Type object, default {"key":"kyverno-inject-certs-init","value":"enabled"}. The key and value of the annotation used to opt a pod's init containers into certificate volume injection. Distinct from preconditions.annotation so authors can opt main containers and init containers in independently. A pod opts in by matching any one of: this annotation, an entry in the hw-kyverno subchart's policies.addCertificatesVolume.initContainers.extraAnnotations, or an entry in policies.addCertificatesVolume.initContainers.labels.
global._hopsworks.kyverno.policies.addCertificatesVolume.initContainers.enabled #
Type bool, default false. Render the init-container mutate rule. When false (default), the policy never touches init containers regardless of any annotation, label, or extra annotation set on a pod.
global._hopsworks.kyverno.policies.addCertificatesVolume.mountPath #
Type string, default "/etc/ssl/certs". Path to mount the certificates volume
global._hopsworks.kyverno.policies.addCertificatesVolume.preconditions.annotation #
Type object, default {"key":"kyverno-inject-certs","value":"enabled"}. The key and value of the annotation used to inject kyverno certificates. If a pod has this annotation, it will be mutated. There are other options under hw-kyverno subchart to use labels and extra annotations as needed.
global._hopsworks.kyverno.policies.addCertificatesVolume.preconditions.enabled #
Type bool, default true. Enable adding preconditions to the police. If disabled, the policy will apply to all the pods in the installation namespace and the hopsworks projects' namespaces created when crating a project.

managedDockerRegistery#

Defaults as YAML
global:
  _hopsworks:
    managedDockerRegistery:
      credHelper:
        enabled: false
        secretName: ''
      domain: ''
      enabled: false
      namespace: ''
      port: null
global._hopsworks.managedDockerRegistery #

Type object. configure managed docker registry for Hopsworks to store the user's docker image

Default
credHelper:
  enabled: false
  secretName: ''
domain: ''
enabled: false
namespace: ''
port: null
global._hopsworks.managedDockerRegistery.credHelper #
Type object, default {"enabled":false,"secretName":""}. credentials helper to use for the managed docker registry. We only support cred helpers for AWS and GCP
global._hopsworks.managedDockerRegistery.credHelper.secretName #
Type string, default "". the name of the secret to be created with the credentials helper configuration
global._hopsworks.managedDockerRegistery.domain #
Type string, default "". the managed docker registry domain name
global._hopsworks.managedDockerRegistery.namespace #
Type string, default "". the namespace to be used
global._hopsworks.managedDockerRegistery.port #
Type string, default nil. port number for the managed docker registry

minio#

Defaults as YAML
global:
  _hopsworks:
    minio:
      enabled: true
      hopsfs:
        bucket: hopsfs
        enabled: true
      password: minioadmin
      region: eu-west-1
      user: minioadmin
global._hopsworks.minio.enabled #
Type bool, default true.
global._hopsworks.minio.hopsfs.bucket #
Type string, default "hopsfs".
global._hopsworks.minio.hopsfs.enabled #
Type bool, default true.
global._hopsworks.minio.password #
Type string, default "minioadmin".
global._hopsworks.minio.region #
Type string, default "eu-west-1".
global._hopsworks.minio.user #
Type string, default "minioadmin".

trino#

Defaults as YAML
global:
  _hopsworks:
    trino:
      egressProbe:
        echoUrl: ''
      enabled: true
      mountableSecrets:
        enabled: true
        image:
          repository: hopsworks/hopsfs-mount
          tag: 3.4.3.3-EE-RC0-1
        mechanism: hopsfsMount
        mountPath: /opt/hopsworks/mounts
        storeRoot: /apps/mountable-secrets
      testCoordinator:
        enabled: true
      userCatalogShards: 2
global._hopsworks.trino.egressProbe #
Type object, default {"echoUrl":""}. Egress-address probe on the Trino pods. An init container prints the address the pod reaches the internet from, and the backend reads it back off the pod log so the catalog dialog can name the addresses to add to an external database's access control list. Nothing is stored: the log lives as long as the pod, and a terminated pod stops being listed.
global._hopsworks.trino.egressProbe.echoUrl #
Type string, default "". URL of a service that echoes the caller's public IP address in its response body. Empty by default, so the probe is opt-in: it is the only outbound call this chart makes on its own, and a query engine reaching a third party on every pod start is not a default an on-premise cluster can be given without asking. While empty the init container prints disabled and exits without calling anything, the backend reports no addresses, and the catalog dialog tells the user to ask their administrator instead of naming them. Set it to turn the feature on: https://ifconfig.me and https://api.ipify.org both answer in the required shape, and an internal equivalent is preferable where one exists. The probe never fails a pod and never delays startup by more than its 5 second timeout.
global._hopsworks.trino.enabled #
Type bool, default true. Enable or disable the installation of the trino sub chart.
global._hopsworks.trino.mountableSecrets #

Type object. Per-project credential files (Oracle wallets, keystores) delivered to the Trino pods, so a connector property can name a real directory. Named after the capability rather than the transport: mechanism selects how the files arrive, and a future CSI-based transport changes that value rather than this key.

Default
enabled: true
image:
  repository: hopsworks/hopsfs-mount
  tag: 3.4.3.3-EE-RC0-1
mechanism: hopsfsMount
mountPath: /opt/hopsworks/mounts
storeRoot: /apps/mountable-secrets
global._hopsworks.trino.mountableSecrets.enabled #
Type bool, default true. Whether the Trino pods are given the backend-owned /apps/mountable-secrets tree at all. This is trino's own declaration of intent, deliberately not a mirror of hopsworks.hopsfsMount.enabled: charts/hopsworks validates the two against each other and fails the render if Trino asks for the mount on a cluster where the HopsFS FUSE mount is turned off. When false the backend variable mountable_secrets_enabled is unset, the feature is reported unavailable, and the sidecar entries must be removed from charts/trino/values.yaml (charts/trino fails the render otherwise: the sidecar cannot be omitted by a conditional, since values.yaml is not templated by Helm).
global._hopsworks.trino.mountableSecrets.image.repository #
Type string, default "hopsworks/hopsfs-mount". Repository for the sidecar image. The dedicated hopsfs-mount image built in docker-images, which carries the HopsFS FUSE client, fusermount3, bash and umount and nothing else, at 90.8 MB. It replaces airflow, which was a stopgap chosen only because it was the sole published image shipping both hopsfs-mount and fuse3, at 4.06 GB paid next to every Trino pod. hwutils remains unusable here: it carries hopsfs-mount but no fusermount3, and the Go FUSE library shells out to fusermount3 even when running as root, so the mount fails with fusermount: exec: "fusermount3": executable file not found in $PATH.
global._hopsworks.trino.mountableSecrets.image.tag #
Type string, default "3.4.3.3-EE-RC0-1". Tag for the sidecar image, <artifact version>-<image fix>. The first half is the hops-fuse-mount artifact version, not the platform version: the image carries the HopsFS FUSE client and nothing else, so it turns over with HopsFS. Keep that half in step with charts/hopsfs image.tag, since the FUSE client should match the HopsFS line it talks to. The second half moves when the image is rebuilt without the artifact changing, a base bump or a security rebuild, so such a rebuild cannot silently replace the bytes behind a tag already deployed. Both halves are pinned here on purpose.
global._hopsworks.trino.mountableSecrets.mechanism #
Type string, default "hopsfsMount". How the tree reaches the pods. hopsfsMount is the shipped transport: a privileged root sidecar on every Trino pod FUSE-mounts HopsFS directly, which is why it requires hopsworks.hopsfsMount.enabled. csi is reserved for the hopsfs-csi node plugin (hopsworks-helm#1931), where the mount is performed by a per-node DaemonSet and the pod-side sidecar is unprivileged; it is not implemented yet and setting it fails the render. The two differ in the sidecar the guard expects to find in charts/trino/values.yaml, and in whether a mount failure can keep a pod from starting.
global._hopsworks.trino.mountableSecrets.mountPath #
Type string, default "/opt/hopsworks/mounts". Where the tree is mounted inside the Trino pods. Seeded to the backend as the trino_mountable_secrets_root variable and used for the sidecar's mount point, its preStop unmount and the Trino containers' mount, so one value drives both sides. They agreed only by both defaulting to the same literal before, which meant an operator moving the mount left the backend resolving ${HOPSWORKS_MOUNT:...} under a path nothing was mounted at.
global._hopsworks.trino.mountableSecrets.storeRoot #
Type string, default "/apps/mountable-secrets". Where the store lives in HopsFS, the source side of the mount. One value, three consumers: charts/hopsfs presets the directory, the mount sidecar passes it as --srcDir, and it is seeded to the backend as the mountable_secrets_path variable so the backend writes bundles where the mount reads them. It was a literal in all three places before, agreeing only by coincidence, which is the trap mountPath had on the container side. Not a knob to reach for: moving it does not move the bundles already written under the old path, and the tree is backend-owned (payara:hdfs, 0750) rather than operator-managed.
global._hopsworks.trino.testCoordinator #
Type object, default {"enabled":true}. Optional dedicated Trino test coordinator used to connection-test user catalogs before they are synced to the production coordinator.
global._hopsworks.trino.testCoordinator.enabled #
Type bool, default true. Deploy an optional dedicated Trino coordinator (catalog.management=dynamic, writable catalog dir) used to connection-test user catalogs before syncing them to the production coordinator. When true, the backend variable trino_test_coordinator_enabled is set so the "test connection" feature becomes available. Enabled by default; set to false to skip the extra coordinator (the "test connection" action is then reported unavailable).
global._hopsworks.trino.userCatalogShards #
Type int, default 2. How many backend-owned Secrets hold user-created catalogs. The single source of truth for the shard count: the backend bin-packs catalogs across this many shards, and charts/trino mounts one projected source per shard. Raising it means adding the matching source there too, and charts/trino refuses to render if the two disagree. Also the knob for the total capacity, since each shard is capped near the 1 MiB Secret limit.