Global values#
Values under global are shared by every subchart: image registry and pull secrets, storage class, scheduling, cloud provider and which optional services are enabled.
Generated from the Hopsworks Helm chart 5.1.0 (Hopsworks 5.1.0).
General#
Defaults as YAML
global:
_hopsworks:
airflow:
enabled: true
keysSecretName: hopsworks-airflow-keys
airflowApiKeySecretName: airflow-api-key
autoscalers: {}
buildkitd:
enabled: false
centralNamespace: hopsworks
cloudProvider: ''
consulDomainName: consul
executor_uid: 1235
full_platform: true
grafana:
extraDashboardProviders: []
imagePullPolicy: IfNotPresent
imagePullSecrets: []
imageRegistry: docker.hops.works
initContainerResources:
runtime:
limits:
cpu: 1
memory: 1Gi
requests:
cpu: 250m
memory: 512Mi
tool:
limits:
cpu: 500m
memory: 512Mi
requests:
cpu: 100m
memory: 128Mi
waiter:
limits:
cpu: 500m
memory: 256Mi
requests:
cpu: 50m
memory: 64Mi
jobs:
ttlSecondsAfterFinished: 86400
kafka:
enabled: true
kueue:
enabled: false
managedObjectStorage:
enabled: false
s3: null
mode: auto
mysql:
hopsworksUser: hopsworksroot
usersSecretname: mysql-users-secrets
networkPolicy:
rondbAccessLabels:
access: mgmd-and-ndbmtd
nodeSelector: {}
onlinefs:
email: onlinefs@hopsworks.ai
password: onlinefspw
opensearch:
enabled: true
openshift:
enabled: false
ray:
enabled: false
restoreFromBackup:
backupId: null
forceDataClear: false
inPlace: false
security:
tls:
enabled: true
securityContextEnabled: true
serviceAccount:
annotations: {}
create: true
name: hopsworks-service-account
serviceAccountAnnotations: {}
skipDatabaseMigration: false
spark:
history:
enabled: true
storageClassName: null
superset:
enabled: true
mysql:
enabled: true
redis:
enabled: true
tolerations: []
toolbox:
image: hwutils
tag: '1.9'
topologySpreadConstraint:
maxSkew: 1
nodeAffinityPolicy: Honor
nodeTaintsPolicy: Honor
topologyKey: topology.kubernetes.io/zone
whenUnsatisfiable: ScheduleAnyway
vpaEnabled: false
wipeDataOnUninstall: true
_kserve:
servingruntime:
vllmomni:
tag: v0.20.0
vllmopenai:
tag: v0.20.0
imageDigests: {}
unmanagedLoadBalancers: {}
global._hopsworks.airflow.enabled#- Type
bool, defaulttrue. Enable or disable the installation of the airflow sub chart global._hopsworks.airflow.keysSecretName#- Type
string, default"hopsworks-airflow-keys". Name of the Secret holding the shared-bearer secret that hopsworks-instance uses to call the Airflow/auth/internal/*routes. Must match airflow.airflowApi.keysSecretName so the same Secret is mounted on both sides. The defaultairflow-webserver-airflow-crypto-materialis the cert-only secret and does NOT containinternal-shared-secret, so the hopsworks-instance pod fails to mount on a fresh v3 install. global._hopsworks.airflowApiKeySecretName#- Type
string, default"airflow-api-key". global._hopsworks.autoscalers#- Type
object, default{}. Map of autoscaler name to VPA configuration. Each key becomes a VerticalPodAutoscaler resource named-vpa. global._hopsworks.buildkitd.enabled#- Type
bool, defaultfalse. global._hopsworks.centralNamespace#- Type
string, default"hopsworks". Namespace to fetch OLK signing key from. Set to null to generate a new key. global._hopsworks.cloudProvider#- Type
string, default"". cloud provider (AWS, AZURE, GCP, OVH). It is used by HopsFS, Consul, and Hopsworks. Hopsfs uses it to configure the object storage parameters. Consul uses it to configure coredns accordingly. Hopsworks uses it to determine how to store the users docker images within the same hopsworks-base repo as tags or in different repo per project, If cloud provider is set all the users docker images are stored as tags - it is an AWS limitation where only tags within the repo can share layers. global._hopsworks.consulDomainName#- Type
string, default"consul". The domain name for consul where it will answer DNS queries, e.g.service-name.service.consul. If changed, make sure to update consul.consul.global.domain to the same value. global._hopsworks.executor_uid#- Type
int, default1235. User ID for the user running Hopsworks and Airflow containers global._hopsworks.full_platform#- Type
bool, defaulttrue. Flag to indicate if the full platform is installed or just the online feature store infrastructure global._hopsworks.grafana.extraDashboardProviders#- Type
list, default[]. Extra Grafana dashboard providers, appended to the provider file the grafana chart renders. The dashboards themselves ship in the Grafana image, so this is the way to provision one without rebuilding the image: mount it (for example throughgrafana.grafana.dashboardsConfigMaps, which lands at /var/lib/grafana/dashboards/) and point a provider at the mount path. Entries are Grafana provider objects, so each needs at least name,folder,type: fileandoptions.path; provider names must be unique across all providers. Paths under /usr/share/grafana/dashboards are the image's own and are verified by the verify-dashboards init container, so point elsewhere. Setting this changes the provider ConfigMap's content hash, which rolls the Grafana pod. global._hopsworks.imagePullPolicy#- Type
string, default"IfNotPresent". global._hopsworks.imagePullSecrets#- Type
list, default[]. image pull secrets to be used by all the subcharts. Notice that for subcharts the have external dependices, you need to update the image pull secrets accordingly in those subcharts global._hopsworks.imageRegistry#- Type
string, default"docker.hops.works". global._hopsworks.initContainerResources#-
Type
object. Resource requests and limits for the chart's init containers, in three tiers by what the container does:waiterfor shell wait loops,toolfor file copies and small binaries,runtimefor anything starting a JVM or a Python interpreter or pulling images. Every init container declares both requests and limits. A namespaceLimitRangethat supplies adefaultlimit injects it into any container declaring none, and a pod's effective request ismax(sum of app containers, highest single init container)where the init term is a floor for the pod's whole lifetime. An init container without resources can therefore pin a node's allocatable to theLimitRangedefault even after it has exited. Retune these if the target namespace has aLimitRangewhosemin/maxwould reject the defaults, since an out-of-range explicit value is rejected rather than defaulted. global._hopsworks.jobs#- Type
object, default{"ttlSecondsAfterFinished":86400}. Global configuration for Kubernetes Jobs created by the chart global._hopsworks.jobs.ttlSecondsAfterFinished#- Type
int, default86400. Time in seconds after a finished Job is eligible for automatic cleanup. Applies to all Jobs unless overridden by a subchart-specific ttlSecondsAfterFinished value. global._hopsworks.kafka.enabled#- Type
bool, defaulttrue. Enable or disable the installation of the kafka sub chart. global._hopsworks.kueue.enabled#- Type
bool, defaultfalse. global._hopsworks.managedObjectStorage#- Type
object, default{"enabled":false,"s3":null}. Configuration for managed object storage to be used by HopsFS, Opensearch, RonDB, and Hopsworks. Opensearch and RonDB uses this configuration to setup a remote sink for their backup, if a different remote sink is configured on the subchart then it will take precedence. Hopsworks uses the bucket configuration as context cache when building users' docker images, only S3 is supported at the moment. global._hopsworks.managedObjectStorage.s3#- Type
string, defaultnil. S3 configuration global._hopsworks.mode#- Type
string, default"auto". Helm installation model. "auto" lets the chart decide based on the Release.IsInstall value. "install" forces installation mode, while "upgrade" forces upgrade mode. global._hopsworks.mysql.hopsworksUser#- Type
string, default"hopsworksroot". global._hopsworks.mysql.usersSecretname#- Type
string, default"mysql-users-secrets". global._hopsworks.networkPolicy.rondbAccessLabels.access#- Type
string, default"mgmd-and-ndbmtd". global._hopsworks.nodeSelector#- Type
object, default{}. Specifies the global nodeSelector settings applied across all subcharts unless explicitly overridden within a specific subchart. This ensures Kubernetes schedules Pods only onto nodes that match all the specified labels. Notice that some subcharts do not use this global variable, and you must manually override those by defining them in the values.yaml file, using anchors if necessary. global._hopsworks.onlinefs.email#- Type
string, default"onlinefs@hopsworks.ai". global._hopsworks.onlinefs.password#- Type
string, default"onlinefspw". global._hopsworks.opensearch#- Type
object, default{"enabled":true}. Enable or disable the opensearch global._hopsworks.opensearch.enabled#- Type
bool, defaulttrue. Enable or disable the opensearch global._hopsworks.openshift.enabled#- Type
bool, defaultfalse. Enable when installing on Openshift platform global._hopsworks.ray.enabled#- Type
bool, defaultfalse. global._hopsworks.restoreFromBackup#- Type
object, default{"backupId":null,"forceDataClear":false,"inPlace":false}. restore cluster from a backup id global._hopsworks.restoreFromBackup.backupId#- Type
string, defaultnil. the backup id to restore global._hopsworks.restoreFromBackup.forceDataClear#- Type
bool, defaultfalse. flag to indicate if the data should be forcibly cleared before restore global._hopsworks.restoreFromBackup.inPlace#- Type
bool, defaultfalse. flag to indicate if the restore should be done in-place or to a new cluster global._hopsworks.security.tls.enabled#- Type
bool, defaulttrue. global._hopsworks.securityContextEnabled#- Type
bool, defaulttrue. Flag to disable templating SecurityContext for Openshift global._hopsworks.serviceAccount.annotations#- Type
object, default{}. custom annotations for the Hopsworks service account global._hopsworks.serviceAccount.create#- Type
bool, defaulttrue. global._hopsworks.serviceAccount.name#- Type
string, default"hopsworks-service-account". global._hopsworks.serviceAccountAnnotations#- Type
object, default{}. Use it to annotate the serviceAccounts we create for Hopsworks global._hopsworks.skipDatabaseMigration#- Type
bool, defaultfalse. Special flag which MUST be used only for 3.x -> 4.0 migrations (HWORKS-1600) global._hopsworks.spark.history.enabled#- Type
bool, defaulttrue. Enable or disable installing of the spark history server global._hopsworks.storageClassName#- Type
string, defaultnil. global storage class name global._hopsworks.superset.enabled#- Type
bool, defaulttrue. Enable or disable the installation of the superset sub chart. global._hopsworks.superset.mysql.enabled#- Type
bool, defaulttrue. Enable or disable MySQL for Superset. Must match superset.mysql.enabled for consistent behavior across charts. global._hopsworks.superset.redis.enabled#- Type
bool, defaulttrue. Enable or disable Redis for Superset. Must match superset.superset.redis.enabled for consistent behavior across charts. global._hopsworks.tolerations#- Type
list, default[]. Specifies the global tolerations settings applied to all subcharts unless explicitly overridden in a specific subchart. These tolerations allow Kubernetes to schedule Pods on nodes with matching taints, ensuring proper placement based on cluster policies. Notice that some subcharts do not use this global variable, and you must manually override those by defining them in the values.yaml file, using anchors if necessary. global._hopsworks.toolbox.image#- Type
string, default"hwutils". global._hopsworks.toolbox.tag#- Type
string, default"1.9". global._hopsworks.topologySpreadConstraint#-
Type
object. default topology spread constraint. If not defined the global topology spread constraint would be used global._hopsworks.vpaEnabled#- Type
bool, defaultfalse. global._hopsworks.wipeDataOnUninstall#- Type
bool, defaulttrue. on uninstall, delete data PVCs left behind by StatefulSets unless the PVC carries the label hopsworks.ai/keep=true. Consumed by subchart post-delete cleanup hooks via the hopsworkslib.wipeDataOnUninstall helper. global._kserve#-
Type
object. Global KServe values shared between the kserve and hopsworks subcharts global._kserve.servingruntime#- Type
object, default{"vllmomni":{"tag":"v0.20.0"},"vllmopenai":{"tag":"v0.20.0"}}. Mirrors the kserve subchart'skserve.servingruntimelayout. Tags here drive both the kserve ClusterServingRuntime images and the kube_serving_vllm*_versions hopsworks variable seeds. global._kserve.servingruntime.vllmomni#- Type
object, default{"tag":"v0.20.0"}. vLLM-Omni runtime image tag. Drives both the kserve ClusterServingRuntime image and the kube_serving_vllm_omni_versions hopsworks variable seed. global._kserve.servingruntime.vllmopenai#- Type
object, default{"tag":"v0.20.0"}. vLLM-OpenAI runtime image tag. Drives both the kserve ClusterServingRuntime image and the kube_serving_vllm_versions hopsworks variable seed. global.imageDigests#- Type
object, default{}. map image name to sha digest to be used instead of tags for reproducible deployment global.unmanagedLoadBalancers#- Type
object, default{}. Load balancer configuration when using unmanaged LB, in AWS is the TargetGroup ARNs for each service
backups#
Defaults as YAML
global._hopsworks.backups#-
Type
object. enable global backups configuration global._hopsworks.backups.enabled#- Type
bool, defaulttrue. enable global backup global._hopsworks.backups.metadataStore#-
Type
object. backups metadata store global._hopsworks.backups.metadataStore.configMap.opensearch#- Type
string, default"opensearch-backups-metadata". name of the configmap to store metadata information about opensearch backups global._hopsworks.backups.metadataStore.configMap.ronDB#- Type
string, default"rondb-backups-metadata". name of the configmap to store metadata information about rondb backups global._hopsworks.backups.schedule#- Type
string, default"@weekly". cron schedule global._hopsworks.backups.ttl#- Type
string, defaultnil. time to live to control when to clean up backups. It is a number followed by either d (days) or h (hours) suffix.
externalLoadBalancers#
Defaults as YAML
global._hopsworks.externalLoadBalancers#- Type
object, default{"annotations":{},"class":null,"enabled":true,"managed":true}. Global load balancer configuration for external access to Hopsworks services: ArrowFlight, Kafka, and MySQL We fallback to this loadBalancerClass if the local loadBalancerClass is not defined global._hopsworks.externalLoadBalancers.annotations#- Type
object, default{}. Generic annotations attached to LoadBalancer objects global._hopsworks.externalLoadBalancers.class#- Type
string, defaultnil. Name of the LoadBalancer class global._hopsworks.externalLoadBalancers.enabled#- Type
bool, defaulttrue. Enable LoadBalancer Services global._hopsworks.externalLoadBalancers.managed#- Type
bool, defaulttrue. Cloud provider provisions Load Balancers
externalServices#
Defaults as YAML
global._hopsworks.externalServices#-
Type
object. Configuration for when services are external to this Kubernetes installation global._hopsworks.externalServices.hopsfs#- Type
object, default{"external":false,"namenodeAddresses":[]}. HopsFS configuration when it is installed externally global._hopsworks.externalServices.hopsfs.external#- Type
bool, defaultfalse. Flag to indicate HopsFS is installed externally global._hopsworks.externalServices.hopsfs.namenodeAddresses#- Type
list, default[]. IP addresses where HopsFS Namenodes are installed global._hopsworks.externalServices.opensearch#- Type
object, default{"addresses":[],"external":false}. Opensearch configuration when it is installed externally global._hopsworks.externalServices.opensearch.addresses#- Type
list, default[]. IP addresses where OpenSearch is installed global._hopsworks.externalServices.opensearch.external#- Type
bool, defaultfalse. Flag to indicate Opensearch is installed externally global._hopsworks.externalServices.prometheus#- Type
object, default{"addresses":[],"external":false}. prometheus configuration when it is installed externally global._hopsworks.externalServices.prometheus.addresses#- Type
list, default[]. IP addresses where prometheus is installed global._hopsworks.externalServices.prometheus.external#- Type
bool, defaultfalse. Flag to indicate prometheus is installed externally global._hopsworks.externalServices.rondb#- Type
object, default{"external":false,"mgmdHostname":""}. RonDB configuration when it is installed externally global._hopsworks.externalServices.rondb.external#- Type
bool, defaultfalse. Flag to indicate RonDB is installed externally global._hopsworks.externalServices.rondb.mgmdHostname#- Type
string, default"". Hostname of the machine where RonDB management service is running
kyverno#
Defaults as YAML
global._hopsworks.kyverno.enabled#- Type
bool, defaultfalse. Enable or disable kyverno policies installation global._hopsworks.kyverno.policies.addCertificatesVolume#-
Type
object. Configuration to add custom certificates to pods as a mounted volume global._hopsworks.kyverno.policies.addCertificatesVolume.enabled#- Type
bool, defaultfalse. Enable add certificates volume global._hopsworks.kyverno.policies.addCertificatesVolume.initContainers#-
Type
object. Opt-in for injecting the certificates volume into init containers. The main addCertificatesVolume policy only mutates spec.containers; init containers are intentionally left untouched because they are often injected by third-party operators (Istio, KServe, sidecar injectors) that ship minimal images where overwriting /etc/ssl/certs would break them. When enabled, a second mutate rule is rendered that iterates spec.initContainers and is gated by an OR of the dedicated init-container annotation below and any extraAnnotations / labels configured under the hw-kyverno subchart at policies.addCertificatesVolume.initContainers. The annotation is distinct from preconditions.annotation so authors can opt main containers and init containers in independently. global._hopsworks.kyverno.policies.addCertificatesVolume.initContainers.annotation#- Type
object, default{"key":"kyverno-inject-certs-init","value":"enabled"}. The key and value of the annotation used to opt a pod's init containers into certificate volume injection. Distinct from preconditions.annotation so authors can opt main containers and init containers in independently. A pod opts in by matching any one of: this annotation, an entry in the hw-kyverno subchart's policies.addCertificatesVolume.initContainers.extraAnnotations, or an entry in policies.addCertificatesVolume.initContainers.labels. global._hopsworks.kyverno.policies.addCertificatesVolume.initContainers.enabled#- Type
bool, defaultfalse. Render the init-container mutate rule. When false (default), the policy never touches init containers regardless of any annotation, label, or extra annotation set on a pod. global._hopsworks.kyverno.policies.addCertificatesVolume.mountPath#- Type
string, default"/etc/ssl/certs". Path to mount the certificates volume global._hopsworks.kyverno.policies.addCertificatesVolume.preconditions.annotation#- Type
object, default{"key":"kyverno-inject-certs","value":"enabled"}. The key and value of the annotation used to inject kyverno certificates. If a pod has this annotation, it will be mutated. There are other options under hw-kyverno subchart to use labels and extra annotations as needed. global._hopsworks.kyverno.policies.addCertificatesVolume.preconditions.enabled#- Type
bool, defaulttrue. Enable adding preconditions to the police. If disabled, the policy will apply to all the pods in the installation namespace and the hopsworks projects' namespaces created when crating a project.
managedDockerRegistery#
Defaults as YAML
global._hopsworks.managedDockerRegistery#-
Type
object. configure managed docker registry for Hopsworks to store the user's docker image global._hopsworks.managedDockerRegistery.credHelper#- Type
object, default{"enabled":false,"secretName":""}. credentials helper to use for the managed docker registry. We only support cred helpers for AWS and GCP global._hopsworks.managedDockerRegistery.credHelper.secretName#- Type
string, default"". the name of the secret to be created with the credentials helper configuration global._hopsworks.managedDockerRegistery.domain#- Type
string, default"". the managed docker registry domain name global._hopsworks.managedDockerRegistery.namespace#- Type
string, default"". the namespace to be used global._hopsworks.managedDockerRegistery.port#- Type
string, defaultnil. port number for the managed docker registry
minio#
Defaults as YAML
global._hopsworks.minio.enabled#- Type
bool, defaulttrue. global._hopsworks.minio.hopsfs.bucket#- Type
string, default"hopsfs". global._hopsworks.minio.hopsfs.enabled#- Type
bool, defaulttrue. global._hopsworks.minio.password#- Type
string, default"minioadmin". global._hopsworks.minio.region#- Type
string, default"eu-west-1". global._hopsworks.minio.user#- Type
string, default"minioadmin".
trino#
Defaults as YAML
global:
_hopsworks:
trino:
egressProbe:
echoUrl: ''
enabled: true
mountableSecrets:
enabled: true
image:
repository: hopsworks/hopsfs-mount
tag: 3.4.3.3-EE-RC0-1
mechanism: hopsfsMount
mountPath: /opt/hopsworks/mounts
storeRoot: /apps/mountable-secrets
testCoordinator:
enabled: true
userCatalogShards: 2
global._hopsworks.trino.egressProbe#- Type
object, default{"echoUrl":""}. Egress-address probe on the Trino pods. An init container prints the address the pod reaches the internet from, and the backend reads it back off the pod log so the catalog dialog can name the addresses to add to an external database's access control list. Nothing is stored: the log lives as long as the pod, and a terminated pod stops being listed. global._hopsworks.trino.egressProbe.echoUrl#- Type
string, default"". URL of a service that echoes the caller's public IP address in its response body. Empty by default, so the probe is opt-in: it is the only outbound call this chart makes on its own, and a query engine reaching a third party on every pod start is not a default an on-premise cluster can be given without asking. While empty the init container printsdisabledand exits without calling anything, the backend reports no addresses, and the catalog dialog tells the user to ask their administrator instead of naming them. Set it to turn the feature on:https://ifconfig.meandhttps://api.ipify.orgboth answer in the required shape, and an internal equivalent is preferable where one exists. The probe never fails a pod and never delays startup by more than its 5 second timeout. global._hopsworks.trino.enabled#- Type
bool, defaulttrue. Enable or disable the installation of the trino sub chart. global._hopsworks.trino.mountableSecrets#-
Type
object. Per-project credential files (Oracle wallets, keystores) delivered to the Trino pods, so a connector property can name a real directory. Named after the capability rather than the transport:mechanismselects how the files arrive, and a future CSI-based transport changes that value rather than this key. global._hopsworks.trino.mountableSecrets.enabled#- Type
bool, defaulttrue. Whether the Trino pods are given the backend-owned /apps/mountable-secrets tree at all. This is trino's own declaration of intent, deliberately not a mirror of hopsworks.hopsfsMount.enabled: charts/hopsworks validates the two against each other and fails the render if Trino asks for the mount on a cluster where the HopsFS FUSE mount is turned off. When false the backend variable mountable_secrets_enabled is unset, the feature is reported unavailable, and the sidecar entries must be removed from charts/trino/values.yaml (charts/trino fails the render otherwise: the sidecar cannot be omitted by a conditional, since values.yaml is not templated by Helm). global._hopsworks.trino.mountableSecrets.image.repository#- Type
string, default"hopsworks/hopsfs-mount". Repository for the sidecar image. The dedicated hopsfs-mount image built in docker-images, which carries the HopsFS FUSE client, fusermount3, bash and umount and nothing else, at 90.8 MB. It replaces airflow, which was a stopgap chosen only because it was the sole published image shipping both hopsfs-mount and fuse3, at 4.06 GB paid next to every Trino pod. hwutils remains unusable here: it carries hopsfs-mount but no fusermount3, and the Go FUSE library shells out to fusermount3 even when running as root, so the mount fails withfusermount: exec: "fusermount3": executable file not found in $PATH. global._hopsworks.trino.mountableSecrets.image.tag#- Type
string, default"3.4.3.3-EE-RC0-1". Tag for the sidecar image,<artifact version>-<image fix>. The first half is the hops-fuse-mount artifact version, not the platform version: the image carries the HopsFS FUSE client and nothing else, so it turns over with HopsFS. Keep that half in step with charts/hopsfs image.tag, since the FUSE client should match the HopsFS line it talks to. The second half moves when the image is rebuilt without the artifact changing, a base bump or a security rebuild, so such a rebuild cannot silently replace the bytes behind a tag already deployed. Both halves are pinned here on purpose. global._hopsworks.trino.mountableSecrets.mechanism#- Type
string, default"hopsfsMount". How the tree reaches the pods.hopsfsMountis the shipped transport: a privileged root sidecar on every Trino pod FUSE-mounts HopsFS directly, which is why it requires hopsworks.hopsfsMount.enabled.csiis reserved for the hopsfs-csi node plugin (hopsworks-helm#1931), where the mount is performed by a per-node DaemonSet and the pod-side sidecar is unprivileged; it is not implemented yet and setting it fails the render. The two differ in the sidecar the guard expects to find in charts/trino/values.yaml, and in whether a mount failure can keep a pod from starting. global._hopsworks.trino.mountableSecrets.mountPath#- Type
string, default"/opt/hopsworks/mounts". Where the tree is mounted inside the Trino pods. Seeded to the backend as thetrino_mountable_secrets_rootvariable and used for the sidecar's mount point, its preStop unmount and the Trino containers' mount, so one value drives both sides. They agreed only by both defaulting to the same literal before, which meant an operator moving the mount left the backend resolving${HOPSWORKS_MOUNT:...}under a path nothing was mounted at. global._hopsworks.trino.mountableSecrets.storeRoot#- Type
string, default"/apps/mountable-secrets". Where the store lives in HopsFS, the source side of the mount. One value, three consumers: charts/hopsfs presets the directory, the mount sidecar passes it as--srcDir, and it is seeded to the backend as themountable_secrets_pathvariable so the backend writes bundles where the mount reads them. It was a literal in all three places before, agreeing only by coincidence, which is the trapmountPathhad on the container side. Not a knob to reach for: moving it does not move the bundles already written under the old path, and the tree is backend-owned (payara:hdfs, 0750) rather than operator-managed. global._hopsworks.trino.testCoordinator#- Type
object, default{"enabled":true}. Optional dedicated Trino test coordinator used to connection-test user catalogs before they are synced to the production coordinator. global._hopsworks.trino.testCoordinator.enabled#- Type
bool, defaulttrue. Deploy an optional dedicated Trino coordinator (catalog.management=dynamic, writable catalog dir) used to connection-test user catalogs before syncing them to the production coordinator. When true, the backend variable trino_test_coordinator_enabled is set so the "test connection" feature becomes available. Enabled by default; set to false to skip the extra coordinator (the "test connection" action is then reported unavailable). global._hopsworks.trino.userCatalogShards#- Type
int, default2. How many backend-owned Secrets hold user-created catalogs. The single source of truth for the shard count: the backend bin-packs catalogs across this many shards, and charts/trino mounts one projected source per shard. Raising it means adding the matching source there too, and charts/trino refuses to render if the two disagree. Also the knob for the total capacity, since each shard is capped near the 1 MiB Secret limit.