Trino values#
Values under trino configure Trino, the SQL query engine, and its test coordinator for user catalogs.
Generated from the Hopsworks Helm chart 5.1.0 (Hopsworks 5.1.0).
Deployed according to the first of these values that is set: global._hopsworks.trino.enabled, global._hopsworks.full_platform.
Upstream charts
- Values under
trino.trinogo totrino1.41.0 fromhttps://trinodb.github.io/charts. - Values under
trino.trinotestgo totrino1.41.0 fromhttps://trinodb.github.io/charts.
Only the values Hopsworks sets under trino.trino and trino.trinotest are listed on this page. Any other value of the charts can be set under the same keys; each link opens the chart's documentation for the version Hopsworks pins.
General#
Defaults as YAML
trino:
catalogsConfigmapName: hopsworks-trino-catalogs
hopsworkslib: {}
trinotest:
accessControl:
configFile: rules.json
refreshPeriod: 10s
rules:
rules.json: |-
{
"catalogs": [
{
"group": "admin",
"catalog": ".*",
"allow": "owner"
},
{
"catalog": "system",
"allow": "none"
}
],
"schemas": [
{
"group": "admin",
"schema": ".*",
"owner": true
}
],
"tables": [
{
"group": "admin",
"privileges": [
"SELECT",
"INSERT",
"DELETE",
"UPDATE",
"OWNERSHIP"
]
}
],
"queries": [
{
"group": "admin",
"allow": ["execute", "kill", "view"]
}
]
}
type: configmap
additionalCatalogs: {}
additionalConfigProperties:
- internal-communication.shared-secret=${ENV:TRINO_SHARED_SECRET}
- http-server.process-forwarded=true
- catalog.management=dynamic
auth:
groupsAuthSecret: trino-groups-file
passwordAuthSecret: trino-password-file
refreshPeriod: 5s
catalogs: []
coordinator:
additionalJVMConfig:
- --add-opens=java.base/java.nio=ALL-UNNAMED
additionalVolumeMounts:
- mountPath: /certs
name: certs
readOnly: true
- mountPath: /etc/trino/catalog
name: catalog-volume
- mountPath: /opt/hopsworks/mounts
mountPropagation: HostToContainer
name: mountable-secrets
readOnly: true
additionalVolumes:
- emptyDir: {}
name: certs
- emptyDir: {}
name: catalog-volume
- emptyDir: {}
name: mountable-secrets
config:
nodeScheduler:
includeCoordinator: true
configMounts:
- configMap: hopsfs-config
name: hdfs-site
path: /etc/hadoop/hdfs-site.xml
subPath: hdfs-site.xml
- configMap: hopsfs-config
name: core-site
path: /etc/hadoop/core-site.xml
subPath: core-site.xml
secretMounts:
- name: super-crypto-kstore
path: /srv/hops/super_crypto/trino
secretName: hopsworks-trino-test-crypto-material
coordinatorNameOverride: hopsworks-trino-test-coordinator
env:
- name: SSL_CERT_KEY_PASSWORD
valueFrom:
secretKeyRef:
key: trino__passwd
name: hopsworks-trino-test-crypto-material
- name: TRINO_SHARED_SECRET
valueFrom:
secretKeyRef:
key: shared-secret
name: trino-internal-secret
image:
pullPolicy: IfNotPresent
registry: docker.hops.works
repository: hopsworks/trino
tag: 480-v10
initContainers:
coordinator:
- command:
- /bin/sh
- -c
- |
# Never hang and never fail. This is an init container, so it runs before Trino, and a
# probe that exists to improve an error message must not be able to delay or block the
# query engine. Both outcomes are swallowed and the line is always printed.
URL='{{ .Values.global._hopsworks.trino.egressProbe.echoUrl }}'
if [ -z "$URL" ]; then
echo "trino-egress-address=disabled"
exit 0
fi
echo "trino-egress-address=$(curl -s --max-time 5 "$URL" || echo unknown)"
image: '{{ .Values.image.registry }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}'
imagePullPolicy: IfNotPresent
name: egress-probe
resources:
limits:
cpu: 500m
memory: 256Mi
requests:
cpu: 10m
memory: 32Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
- command:
- sh
- -c
- cat /srv/hops/super_crypto/trino/trino_priv.pem /srv/hops/super_crypto/trino/trino_certificate_bundle.pem > /certs/keystore.pem
image: '{{ .Values.image.registry }}/hopsworks/hwutils:{{ .Values.global._hopsworks.toolbox.tag }}'
imagePullPolicy: IfNotPresent
name: init-coordinator-cert
resources:
limits:
cpu: 500m
memory: 256Mi
requests:
cpu: 50m
memory: 64Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
volumeMounts:
- mountPath: /certs
name: certs
- mountPath: /srv/hops/super_crypto/trino
name: super-crypto-kstore
- command:
- /bin/bash
- -c
- |
set -euo pipefail
export HADOOP_CONF_DIR=/etc/hadoop
CERTS=/srv/hops/super_crypto/trino
mkdir -p {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} /tmp/.hopsfs-mount-staging
# Foreground: this is a sidecar, it must not exit. No startupProbe gates Trino on the
# mount, deliberately: a mount that never comes up must not keep the query engine down.
# A catalog whose bundle is missing fails its own connection instead.
exec hopsfs-mount \
--logLevel warning \
--stageDir /tmp/.hopsfs-mount-staging \
--readOnly \
--srcDir {{ .Values.global._hopsworks.trino.mountableSecrets.storeRoot }} \
--hopsFSUserName trino \
-allowOther=true \
-tls \
-rootCABundle "$CERTS/hops_root_ca.pem" \
-clientCertificate "$CERTS/trino_certificate_bundle.pem" \
-clientKey "$CERTS/trino_priv.pem" \
namenode.service.{{ .Values.global._hopsworks.consulDomainName | default "consul" }}:8020 \
{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}
image: '{{ $img := printf "%s/%s:%s" .Values.image.registry .Values.global._hopsworks.trino.mountableSecrets.image.repository .Values.global._hopsworks.trino.mountableSecrets.image.tag }}{{ $img }}{{ include "hopsworkslib.imageDigest" (dict "global" .Values.global "entry" $img) }}'
imagePullPolicy: IfNotPresent
lifecycle:
preStop:
exec:
command:
- /bin/bash
- -c
- umount -l {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} || true
name: mountable-secrets
resources:
limits:
cpu: 500m
memory: 512Mi
requests:
cpu: 100m
memory: 128Mi
restartPolicy: Always
securityContext:
privileged: true
runAsGroup: 0
runAsNonRoot: false
runAsUser: 0
volumeMounts:
- mountPath: '{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}'
mountPropagation: Bidirectional
name: mountable-secrets
- mountPath: /srv/hops/super_crypto/trino
name: super-crypto-kstore
- mountPath: /etc/hadoop/core-site.xml
name: core-site
subPath: core-site.xml
- mountPath: /etc/hadoop/hdfs-site.xml
name: hdfs-site
subPath: hdfs-site.xml
nameOverride: hopsworks-trino-test
securityContext:
runAsGroup: 1000
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
server:
config:
authenticationType: PASSWORD
https:
enabled: true
keystore:
path: /certs/keystore.pem
port: 8443
workers: 0
service:
type: ClusterIP
serviceAccount:
annotations: {}
create: true
name: hopsworks-trino-test
workerNameOverride: hopsworks-trino-test-worker
trino#- Type
object, default{}. override trino values trino.catalogsConfigmapName#- Type
string, default"hopsworks-trino-catalogs". trino.hopsworkslib#- Type
object, default{}. override hopsworkslib values trino.trinotest#-
Type
object, passed to thetrino1.41.0 chart, whose other values are documented there. override trinotest values. Rendered only when global._hopsworks.trino.testCoordinator.enabled is true (see Chart.yaml). An optional single-node coordinator running catalog.management=dynamic with a WRITABLE catalog dir, used by the backend to connection-test user catalogs (CREATE CATALOG / SHOW SCHEMAS / DROP CATALOG) before they are synced to the production coordinator. Mirrors the production coordinator's image, certs, TLS, and PASSWORD auth so the backend's admin credentials and discovery work identically.Default
accessControl: configFile: rules.json refreshPeriod: 10s rules: rules.json: |- { "catalogs": [ { "group": "admin", "catalog": ".*", "allow": "owner" }, { "catalog": "system", "allow": "none" } ], "schemas": [ { "group": "admin", "schema": ".*", "owner": true } ], "tables": [ { "group": "admin", "privileges": [ "SELECT", "INSERT", "DELETE", "UPDATE", "OWNERSHIP" ] } ], "queries": [ { "group": "admin", "allow": ["execute", "kill", "view"] } ] } type: configmap additionalCatalogs: {} additionalConfigProperties: - internal-communication.shared-secret=${ENV:TRINO_SHARED_SECRET} - http-server.process-forwarded=true - catalog.management=dynamic auth: groupsAuthSecret: trino-groups-file passwordAuthSecret: trino-password-file refreshPeriod: 5s catalogs: [] coordinator: additionalJVMConfig: - --add-opens=java.base/java.nio=ALL-UNNAMED additionalVolumeMounts: - mountPath: /certs name: certs readOnly: true - mountPath: /etc/trino/catalog name: catalog-volume - mountPath: /opt/hopsworks/mounts mountPropagation: HostToContainer name: mountable-secrets readOnly: true additionalVolumes: - emptyDir: {} name: certs - emptyDir: {} name: catalog-volume - emptyDir: {} name: mountable-secrets config: nodeScheduler: includeCoordinator: true configMounts: - configMap: hopsfs-config name: hdfs-site path: /etc/hadoop/hdfs-site.xml subPath: hdfs-site.xml - configMap: hopsfs-config name: core-site path: /etc/hadoop/core-site.xml subPath: core-site.xml secretMounts: - name: super-crypto-kstore path: /srv/hops/super_crypto/trino secretName: hopsworks-trino-test-crypto-material coordinatorNameOverride: hopsworks-trino-test-coordinator env: - name: SSL_CERT_KEY_PASSWORD valueFrom: secretKeyRef: key: trino__passwd name: hopsworks-trino-test-crypto-material - name: TRINO_SHARED_SECRET valueFrom: secretKeyRef: key: shared-secret name: trino-internal-secret image: pullPolicy: IfNotPresent registry: docker.hops.works repository: hopsworks/trino tag: 480-v10 initContainers: coordinator: - command: - /bin/sh - -c - | # Never hang and never fail. This is an init container, so it runs before Trino, and a # probe that exists to improve an error message must not be able to delay or block the # query engine. Both outcomes are swallowed and the line is always printed. URL='{{ .Values.global._hopsworks.trino.egressProbe.echoUrl }}' if [ -z "$URL" ]; then echo "trino-egress-address=disabled" exit 0 fi echo "trino-egress-address=$(curl -s --max-time 5 "$URL" || echo unknown)" image: '{{ .Values.image.registry }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}' imagePullPolicy: IfNotPresent name: egress-probe resources: limits: cpu: 500m memory: 256Mi requests: cpu: 10m memory: 32Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL - command: - sh - -c - cat /srv/hops/super_crypto/trino/trino_priv.pem /srv/hops/super_crypto/trino/trino_certificate_bundle.pem > /certs/keystore.pem image: '{{ .Values.image.registry }}/hopsworks/hwutils:{{ .Values.global._hopsworks.toolbox.tag }}' imagePullPolicy: IfNotPresent name: init-coordinator-cert resources: limits: cpu: 500m memory: 256Mi requests: cpu: 50m memory: 64Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL volumeMounts: - mountPath: /certs name: certs - mountPath: /srv/hops/super_crypto/trino name: super-crypto-kstore - command: - /bin/bash - -c - | set -euo pipefail export HADOOP_CONF_DIR=/etc/hadoop CERTS=/srv/hops/super_crypto/trino mkdir -p {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} /tmp/.hopsfs-mount-staging # Foreground: this is a sidecar, it must not exit. No startupProbe gates Trino on the # mount, deliberately: a mount that never comes up must not keep the query engine down. # A catalog whose bundle is missing fails its own connection instead. exec hopsfs-mount \ --logLevel warning \ --stageDir /tmp/.hopsfs-mount-staging \ --readOnly \ --srcDir {{ .Values.global._hopsworks.trino.mountableSecrets.storeRoot }} \ --hopsFSUserName trino \ -allowOther=true \ -tls \ -rootCABundle "$CERTS/hops_root_ca.pem" \ -clientCertificate "$CERTS/trino_certificate_bundle.pem" \ -clientKey "$CERTS/trino_priv.pem" \ namenode.service.{{ .Values.global._hopsworks.consulDomainName | default "consul" }}:8020 \ {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} image: '{{ $img := printf "%s/%s:%s" .Values.image.registry .Values.global._hopsworks.trino.mountableSecrets.image.repository .Values.global._hopsworks.trino.mountableSecrets.image.tag }}{{ $img }}{{ include "hopsworkslib.imageDigest" (dict "global" .Values.global "entry" $img) }}' imagePullPolicy: IfNotPresent lifecycle: preStop: exec: command: - /bin/bash - -c - umount -l {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} || true name: mountable-secrets resources: limits: cpu: 500m memory: 512Mi requests: cpu: 100m memory: 128Mi restartPolicy: Always securityContext: privileged: true runAsGroup: 0 runAsNonRoot: false runAsUser: 0 volumeMounts: - mountPath: '{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}' mountPropagation: Bidirectional name: mountable-secrets - mountPath: /srv/hops/super_crypto/trino name: super-crypto-kstore - mountPath: /etc/hadoop/core-site.xml name: core-site subPath: core-site.xml - mountPath: /etc/hadoop/hdfs-site.xml name: hdfs-site subPath: hdfs-site.xml nameOverride: hopsworks-trino-test securityContext: runAsGroup: 1000 runAsNonRoot: true runAsUser: 1000 seccompProfile: type: RuntimeDefault server: config: authenticationType: PASSWORD https: enabled: true keystore: path: /certs/keystore.pem port: 8443 workers: 0 service: type: ClusterIP serviceAccount: annotations: {} create: true name: hopsworks-trino-test workerNameOverride: hopsworks-trino-test-worker trino.trinotest.initContainers.coordinator[2].name#- Type
string, default"mountable-secrets". readOnly is not optional. Without it the query engine gains a write channel into HopsFS as the trino service user. --srcDir bounds what the mount exposes to the backend-owned tree; the mount authenticates as trino, which is in the hdfs superuser group, so srcDir is the only thing containing it. The preStop unmount is also not optional. Without it the container cannot terminate, the pod ends 0/2 Error,kubectl delete podhangs, and force-deleting leaks fuse.hopsfs mounts onto the node that must then be cleared by hand with nsenter.
auth#
Defaults as YAML
trino:
auth:
adminUserPwd: Tr1n0_Admin_ChangeMe_!2345
adminUserPwdHash: $2y$10$wu8UEOW.3A9rBautqh98zuwZTxgM85QhS8Mfl8hDKcLazIy0LpWfK
adminUsername: trino
createSecrets: true
createSharedSecret: true
monitoringUser: prometheus
monitoringUserPwd: Tr1n0_Monitoring_ChangeMe_!2345
monitoringUserPwdHash: $2y$10$tE7wiYz2XqiIg.E9DlqTfuqBqnQa42cqYog6frsxd5yj5WOH0r802
trino.auth.adminUserPwd#- Type
string, default"Tr1n0_Admin_ChangeMe_!2345". trino.auth.adminUserPwdHash#- Type
string, default"$2y$10$wu8UEOW.3A9rBautqh98zuwZTxgM85QhS8Mfl8hDKcLazIy0LpWfK". trino.auth.adminUsername#- Type
string, default"trino". Trino admin username. Should not be changed. Used in hadoop.proxyuser.trino trino.auth.createSecrets#- Type
bool, defaulttrue. If createSecrets is false, you must manually create the following Kubernetes Secrets: 1. trino-admin-credentials, plus the password-file and group-file Secrets used by Trino's password-file authentication. By default, these are namedtrino-password-fileandtrino-groups-file, but their names are configurable via.Values.trino.auth.passwordAuthSecretand.Values.trino.auth.groupsAuthSecret. 2. trino-monitoring-credentials using the monitoring username/password defined below. Passwords stored in the password-file Secret (default:trino-password-file) must be securely hashed using bcrypt or PBKDF2. See https://trino.io/docs/current/security/password-file.html#password-files for details. When createSecrets is false, add the labelbackup.hops.works/include: "true"to the manually created trino-admin-credentials, trino-monitoring-credentials, password-file and group-file Secrets, otherwise the built-in Velero backup schedule does not capture them and Trino authentication cannot be restored. ArgoCD: the password-file and group-file Secrets are mutated at runtime (Hopsworks writes project users/groups into them). On ArgoCD-managed installs, and required when automated selfHeal is enabled, set ignoreDifferences on /data for the four Trino auth Secrets andRespectIgnoreDifferences=truein the Application syncPolicy, or ArgoCD will overwrite the runtime-managed data with the chart defaults on every sync. trino-internal-secret is also non-deterministic under ArgoCD: the template falls back to a freshrandBytesvalue whenever the lookup cannot read the existing Secret (everyhelm template/ non-auto render), so ArgoCD would rotate it on each sync and churn Trino's internal TLS. It is deliberately excluded from the backup (safely regenerated on a fresh install); if ArgoCD manages it, give it the same ignoreDifferences on /data, or setcreateSharedSecret: falseand manage it from an external DR source. - Type
bool, defaulttrue. IfcreateSharedSecretis set tofalse, you must generate aninternal-communication.shared-secretvalue and store it in a Kubernetes Secret namedtrino-internal-secretunder the keyshared-secret. trino-internal-secret is intentionally NOT captured by the Velero backup (it has no coupling to user state and is regenerated on a fresh install). With createSharedSecret=false it is operator-managed, so disaster recovery must restore it from an independent source, followed by a coordinated restart of all Trino pods so coordinator and workers share the same value. trino.auth.monitoringUser#- Type
string, default"prometheus". Username used by Prometheus for scraping Trino metrics. If you override this value, you MUST also: 1. Update Trino access control to grant this user the required permissions (e.g. adjustaccessControl.rules.rules.jsonaccordingly). 2. Update the Prometheus scrape configuration so that the same username is used: set.Values.prometheus.prometheus.serverFiles.prometheus.yml.scrape_configs[*].basic_auth.usernamefor the scrape job withjob_name: "trino"to match this value. trino.auth.monitoringUserPwd#- Type
string, default"Tr1n0_Monitoring_ChangeMe_!2345". trino.auth.monitoringUserPwdHash#- Type
string, default"$2y$10$tE7wiYz2XqiIg.E9DlqTfuqBqnQa42cqYog6frsxd5yj5WOH0r802".
dependencies#
Defaults as YAML
trino.dependencies.hive.consulServiceName#- Type
string, default"hive". trino.dependencies.hive.consulServiceTag#- Type
string, default"metastore". trino.dependencies.hive.port#- Type
int, default9083. trino.dependencies.mysql.consulServiceName#- Type
string, default"mysql". trino.dependencies.mysql.port#- Type
int, default3306.
externalLoadBalancer#
Defaults as YAML
trino.externalLoadBalancer.annotations#- Type
object, default{}. annotations for load balancer trino.externalLoadBalancer.class#- Type
string, defaultnil. load balancer class name trino.externalLoadBalancer.enabled#- Type
string, defaultnil. Enable External Load Balancers for the Trino coordinator/service. If not set the .global._hopsworks.externalLoadBalancers.enabled will be used instead trino.externalLoadBalancer.managed#- Type
string, defaultnil. Cloud provider provisions Load Balancers. If not set the .global._hopsworks.externalLoadBalancers.managed will be used instead trino.externalLoadBalancer.nodeSelector#- Type
object, default{}. selector for nodes the load balancer can use to route traffic
trino#
Defaults as YAML
trino:
trino:
accessControl:
configFile: rules.json
refreshPeriod: 10s
rules:
rules.json: |-
{
"system_information": [
{
"user": "prometheus",
"allow": ["read"]
}
],
"catalogs": [
{
"group": "admin",
"catalog": ".*",
"allow": "all"
},
{
"catalog": "tpch",
"allow": "read-only"
},
{
"catalog": "tpcds",
"allow": "read-only"
},
{
"catalog": "iceberg",
"allow": "all"
},
{
"catalog": "delta",
"allow": "all"
},
{
"catalog": "hive",
"allow": "all"
},
{
"catalog": "hudi",
"allow": "all"
},
{
"group": "(.*)__data_owner",
"catalog": "$1__.*",
"allow": "all"
},
{
"group": "(.*)__data_scientist",
"catalog": "$1__.*",
"allow": "read-only"
},
{
"group": "(.*)__shared__(.*)",
"catalog": "$1__$2",
"allow": "read-only"
},
{
"catalog": "system",
"allow": "read-only"
}
],
"schemas": [
{
"group": "admin",
"schema": ".*",
"owner": true
},
{
"group": "(.*)__data_owner",
"schema": "($1|$1_featurestore)",
"owner": true
},
{
"group": "(.*)__data_owner",
"catalog": "$1__.*",
"schema": ".*",
"owner": true
}
],
"tables": [
{
"group": "admin",
"privileges": [
"SELECT",
"INSERT",
"DELETE",
"UPDATE",
"OWNERSHIP",
"GRANT_SELECT"
]
},
{
"group": "(.*)__data_owner",
"schema": "($1|$1_featurestore)",
"privileges": ["SELECT", "INSERT", "DELETE", "UPDATE", "OWNERSHIP"]
},
{
"group": "(.*)__data_owner",
"catalog": "$1__.*",
"schema": ".*",
"privileges": ["SELECT", "INSERT", "DELETE", "UPDATE", "OWNERSHIP"]
},
{
"group": "(.*)__data_scientist",
"schema": "($1|$1_featurestore)",
"privileges": ["SELECT"]
},
{
"group": "(.*)__data_scientist",
"catalog": "$1__.*",
"schema": ".*",
"privileges": ["SELECT"]
},
{
"group": "(.*)__shared_hivedb",
"schema": "$1",
"privileges": ["SELECT"]
},
{
"group": "(.*)__shared_featurestore",
"schema": "$1_featurestore",
"privileges": ["SELECT"]
},
{
"catalog": "tpch",
"privileges": ["SELECT"]
},
{
"catalog": "tpcds",
"privileges": ["SELECT"]
},
{
"catalog": "system",
"schema": "metadata",
"privileges": ["SELECT"]
}
],
"queries": [
{
"group": "admin",
"allow": ["execute", "kill", "view"]
},
{
"group": "(.*)__data_owner",
"queryOwner": "$1__.*",
"allow": ["kill", "view"]
},
{
"user": "(.*)__.*",
"queryOwner": "$1__.*",
"allow": ["view"]
},
{
"allow": ["execute"]
}
]
}
type: configmap
additionalCatalogs: {}
additionalConfigProperties:
- internal-communication.shared-secret=${ENV:TRINO_SHARED_SECRET}
- http-server.process-forwarded=true
- event-listener.config-files=etc/mysql-event-listener.properties
auth:
groupsAuthSecret: trino-groups-file
passwordAuthSecret: trino-password-file
refreshPeriod: 5s
catalogs: []
configMounts: []
coordinator:
additionalConfigFiles:
mysql-event-listener.properties: |
event-listener.name=mysql
mysql-event-listener.db.url={{ include "trino.mysql.eventListener.db.url" . }}
additionalJVMConfig:
- --add-opens=java.base/java.nio=ALL-UNNAMED
additionalVolumeMounts:
- mountPath: /certs
name: certs
readOnly: true
- mountPath: /opt/hopsworks/mounts
mountPropagation: HostToContainer
name: mountable-secrets
readOnly: true
- mountPath: /etc/trino/catalog
name: catalog-volume
additionalVolumes:
- emptyDir: {}
name: certs
- emptyDir: {}
name: mountable-secrets
- name: catalog-volume
projected:
sources:
- configMap:
name: hopsworks-trino-catalogs
- secret:
name: hopsworks-trino-catalogs-user-0
optional: true
- secret:
name: hopsworks-trino-catalogs-user-1
optional: true
configMounts:
- configMap: hopsfs-config
name: hdfs-site
path: /etc/hadoop/hdfs-site.xml
subPath: hdfs-site.xml
- configMap: hopsfs-config
name: core-site
path: /etc/hadoop/core-site.xml
subPath: core-site.xml
secretMounts:
- name: super-crypto-kstore
path: /srv/hops/super_crypto/trino
secretName: hopsworks-trino-crypto-material
coordinatorNameOverride: hopsworks-trino-coordinator
defaultCatalogs:
delta.properties: |
connector.name=delta_lake
fs.hadoop.enabled=true
hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml
hive.metastore.username=trino
hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }}
hive.metastore.thrift.client.ssl.enabled=true
hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks
hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD}
hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks
hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD}
hive.hdfs.impersonation.enabled=true
delta.enable-non-concurrent-writes=true
hive.properties: |
connector.name=hive
fs.hadoop.enabled=true
hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml
hive.metastore.username=trino
hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }}
hive.metastore.thrift.client.ssl.enabled=true
hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks
hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD}
hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks
hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD}
hive.hdfs.impersonation.enabled=true
hudi.properties: |
connector.name=hudi
fs.hadoop.enabled=true
hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml
hive.metastore.username=trino
hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }}
hive.metastore.thrift.client.ssl.enabled=true
hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks
hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD}
hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks
hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD}
hive.hdfs.impersonation.enabled=true
iceberg.properties: |
connector.name=iceberg
fs.hadoop.enabled=true
hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml
hive.metastore.username=trino
hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }}
hive.metastore.thrift.client.ssl.enabled=true
hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks
hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD}
hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks
hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD}
iceberg.catalog.type=hive_metastore
iceberg.file-format=PARQUET
iceberg.compression-codec=ZSTD
iceberg.hive-catalog.locking-enabled=false
hive.hdfs.impersonation.enabled=true
env:
- name: SSL_CERT_KEY_PASSWORD
valueFrom:
secretKeyRef:
key: trino__passwd
name: hopsworks-trino-crypto-material
- name: HOPS_USE_LOGIN_USER
value: 'true'
- name: TRINO_SHARED_SECRET
valueFrom:
secretKeyRef:
key: shared-secret
name: trino-internal-secret
- name: MYSQL_DB
value: hopsworks
- name: MYSQL_USER
value: hopsworksroot
- name: MYSQL_PASSWORD
valueFrom:
secretKeyRef:
key: hopsworksroot
name: mysql-users-secrets
envFrom:
- configMapRef:
name: '{{ .Values.nameOverride }}-mysql-conn-env'
eventListenerProperties: []
image:
pullPolicy: IfNotPresent
registry: docker.hops.works
repository: hopsworks/trino
tag: 480-v10
initContainers:
coordinator:
- command:
- /bin/sh
- -c
- |
# Never hang and never fail. This is an init container, so it runs before Trino, and a
# probe that exists to improve an error message must not be able to delay or block the
# query engine. Both outcomes are swallowed and the line is always printed.
URL='{{ .Values.global._hopsworks.trino.egressProbe.echoUrl }}'
if [ -z "$URL" ]; then
echo "trino-egress-address=disabled"
exit 0
fi
echo "trino-egress-address=$(curl -s --max-time 5 "$URL" || echo unknown)"
image: '{{ .Values.image.registry }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}'
imagePullPolicy: IfNotPresent
name: egress-probe
resources:
limits:
cpu: 500m
memory: 256Mi
requests:
cpu: 10m
memory: 32Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
- command:
- sh
- -c
- cat /srv/hops/super_crypto/trino/trino_priv.pem /srv/hops/super_crypto/trino/trino_certificate_bundle.pem > /certs/keystore.pem
image: '{{ .Values.image.registry }}/hopsworks/hwutils:{{ .Values.global._hopsworks.toolbox.tag }}'
imagePullPolicy: IfNotPresent
name: init-coordinator-cert
resources:
limits:
cpu: 500m
memory: 256Mi
requests:
cpu: 50m
memory: 64Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
volumeMounts:
- mountPath: /certs
name: certs
- mountPath: /srv/hops/super_crypto/trino
name: super-crypto-kstore
- command:
- /bin/bash
- -c
- |
set -euo pipefail
export HADOOP_CONF_DIR=/etc/hadoop
CERTS=/srv/hops/super_crypto/trino
mkdir -p {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} /tmp/.hopsfs-mount-staging
# Foreground: this is a sidecar, it must not exit. No startupProbe gates Trino on the
# mount, deliberately: a mount that never comes up must not keep the query engine down.
# A catalog whose bundle is missing fails its own connection instead.
exec hopsfs-mount \
--logLevel warning \
--stageDir /tmp/.hopsfs-mount-staging \
--readOnly \
--srcDir {{ .Values.global._hopsworks.trino.mountableSecrets.storeRoot }} \
--hopsFSUserName trino \
-allowOther=true \
-tls \
-rootCABundle "$CERTS/hops_root_ca.pem" \
-clientCertificate "$CERTS/trino_certificate_bundle.pem" \
-clientKey "$CERTS/trino_priv.pem" \
namenode.service.{{ .Values.global._hopsworks.consulDomainName | default "consul" }}:8020 \
{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}
image: '{{ $img := printf "%s/%s:%s" .Values.image.registry .Values.global._hopsworks.trino.mountableSecrets.image.repository .Values.global._hopsworks.trino.mountableSecrets.image.tag }}{{ $img }}{{ include "hopsworkslib.imageDigest" (dict "global" .Values.global "entry" $img) }}'
imagePullPolicy: IfNotPresent
lifecycle:
preStop:
exec:
command:
- /bin/bash
- -c
- umount -l {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} || true
name: mountable-secrets
resources:
limits:
cpu: 500m
memory: 512Mi
requests:
cpu: 100m
memory: 128Mi
restartPolicy: Always
securityContext:
privileged: true
runAsGroup: 0
runAsNonRoot: false
runAsUser: 0
volumeMounts:
- mountPath: '{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}'
mountPropagation: Bidirectional
name: mountable-secrets
- mountPath: /srv/hops/super_crypto/trino
name: super-crypto-kstore
- mountPath: /etc/hadoop/core-site.xml
name: core-site
subPath: core-site.xml
- mountPath: /etc/hadoop/hdfs-site.xml
name: hdfs-site
subPath: hdfs-site.xml
worker:
- command:
- /bin/sh
- -c
- |
# Never hang and never fail. This is an init container, so it runs before Trino, and a
# probe that exists to improve an error message must not be able to delay or block the
# query engine. Both outcomes are swallowed and the line is always printed.
URL='{{ .Values.global._hopsworks.trino.egressProbe.echoUrl }}'
if [ -z "$URL" ]; then
echo "trino-egress-address=disabled"
exit 0
fi
echo "trino-egress-address=$(curl -s --max-time 5 "$URL" || echo unknown)"
image: '{{ .Values.image.registry }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}'
imagePullPolicy: IfNotPresent
name: egress-probe
resources:
limits:
cpu: 500m
memory: 256Mi
requests:
cpu: 10m
memory: 32Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
- command:
- /bin/bash
- -c
- |
set -euo pipefail
export HADOOP_CONF_DIR=/etc/hadoop
CERTS=/srv/hops/super_crypto/trino
mkdir -p {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} /tmp/.hopsfs-mount-staging
# Foreground: this is a sidecar, it must not exit. No startupProbe gates Trino on the
# mount, deliberately: a mount that never comes up must not keep the query engine down.
# A catalog whose bundle is missing fails its own connection instead.
exec hopsfs-mount \
--logLevel warning \
--stageDir /tmp/.hopsfs-mount-staging \
--readOnly \
--srcDir {{ .Values.global._hopsworks.trino.mountableSecrets.storeRoot }} \
--hopsFSUserName trino \
-allowOther=true \
-tls \
-rootCABundle "$CERTS/hops_root_ca.pem" \
-clientCertificate "$CERTS/trino_certificate_bundle.pem" \
-clientKey "$CERTS/trino_priv.pem" \
namenode.service.{{ .Values.global._hopsworks.consulDomainName | default "consul" }}:8020 \
{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}
image: '{{ $img := printf "%s/%s:%s" .Values.image.registry .Values.global._hopsworks.trino.mountableSecrets.image.repository .Values.global._hopsworks.trino.mountableSecrets.image.tag }}{{ $img }}{{ include "hopsworkslib.imageDigest" (dict "global" .Values.global "entry" $img) }}'
imagePullPolicy: IfNotPresent
lifecycle:
preStop:
exec:
command:
- /bin/bash
- -c
- umount -l {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} || true
name: mountable-secrets
resources:
limits:
cpu: 500m
memory: 512Mi
requests:
cpu: 100m
memory: 128Mi
restartPolicy: Always
securityContext:
privileged: true
runAsGroup: 0
runAsNonRoot: false
runAsUser: 0
volumeMounts:
- mountPath: '{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}'
mountPropagation: Bidirectional
name: mountable-secrets
- mountPath: /srv/hops/super_crypto/trino
name: super-crypto-kstore
- mountPath: /etc/hadoop/core-site.xml
name: core-site
subPath: core-site.xml
- mountPath: /etc/hadoop/hdfs-site.xml
name: hdfs-site
subPath: hdfs-site.xml
moreCatalogs:
tpcds.properties: |
connector.name=tpcds
tpcds.splits-per-node=4
tpch.properties: |
connector.name=tpch
tpch.splits-per-node=4
nameOverride: hopsworks-trino
securityContext:
runAsGroup: 1000
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
server:
config:
authenticationType: PASSWORD
https:
enabled: true
keystore:
path: /certs/keystore.pem
port: 8443
coordinatorExtraConfig: |
web-ui.preview.enabled=true
service:
coordinator:
annotations:
consul.hashicorp.com/service-name: trino
consul.hashicorp.com/service-port: '8443'
consul.hashicorp.com/service-tags: coordinator
prometheus.io/path: /metrics
prometheus.io/port: '8443'
prometheus.io/scheme: https
prometheus.io/scrape: 'true'
type: ClusterIP
serviceAccount:
annotations: {}
create: true
name: hopsworks-trino
worker:
additionalConfigFiles:
mysql-event-listener.properties: |
event-listener.name=mysql
mysql-event-listener.db.url={{ include "trino.mysql.eventListener.db.url" . }}
additionalJVMConfig:
- --add-opens=java.base/java.nio=ALL-UNNAMED
additionalVolumeMounts:
- mountPath: /etc/trino/catalog
name: catalog-volume
- mountPath: /opt/hopsworks/mounts
mountPropagation: HostToContainer
name: mountable-secrets
readOnly: true
additionalVolumes:
- name: catalog-volume
projected:
sources:
- configMap:
name: hopsworks-trino-catalogs
- secret:
name: hopsworks-trino-catalogs-user-0
optional: true
- secret:
name: hopsworks-trino-catalogs-user-1
optional: true
- emptyDir: {}
name: mountable-secrets
configMounts:
- configMap: hopsfs-config
name: hdfs-site
path: /etc/hadoop/hdfs-site.xml
subPath: hdfs-site.xml
- configMap: hopsfs-config
name: core-site
path: /etc/hadoop/core-site.xml
subPath: core-site.xml
secretMounts:
- name: super-crypto-kstore
path: /srv/hops/super_crypto/trino
secretName: hopsworks-trino-crypto-material
workerNameOverride: hopsworks-trino-worker
trino.trino#-
Type
object, passed to thetrino1.41.0 chart, whose other values are documented there. override trino valuesDefault
accessControl: configFile: rules.json refreshPeriod: 10s rules: rules.json: |- { "system_information": [ { "user": "prometheus", "allow": ["read"] } ], "catalogs": [ { "group": "admin", "catalog": ".*", "allow": "all" }, { "catalog": "tpch", "allow": "read-only" }, { "catalog": "tpcds", "allow": "read-only" }, { "catalog": "iceberg", "allow": "all" }, { "catalog": "delta", "allow": "all" }, { "catalog": "hive", "allow": "all" }, { "catalog": "hudi", "allow": "all" }, { "group": "(.*)__data_owner", "catalog": "$1__.*", "allow": "all" }, { "group": "(.*)__data_scientist", "catalog": "$1__.*", "allow": "read-only" }, { "group": "(.*)__shared__(.*)", "catalog": "$1__$2", "allow": "read-only" }, { "catalog": "system", "allow": "read-only" } ], "schemas": [ { "group": "admin", "schema": ".*", "owner": true }, { "group": "(.*)__data_owner", "schema": "($1|$1_featurestore)", "owner": true }, { "group": "(.*)__data_owner", "catalog": "$1__.*", "schema": ".*", "owner": true } ], "tables": [ { "group": "admin", "privileges": [ "SELECT", "INSERT", "DELETE", "UPDATE", "OWNERSHIP", "GRANT_SELECT" ] }, { "group": "(.*)__data_owner", "schema": "($1|$1_featurestore)", "privileges": ["SELECT", "INSERT", "DELETE", "UPDATE", "OWNERSHIP"] }, { "group": "(.*)__data_owner", "catalog": "$1__.*", "schema": ".*", "privileges": ["SELECT", "INSERT", "DELETE", "UPDATE", "OWNERSHIP"] }, { "group": "(.*)__data_scientist", "schema": "($1|$1_featurestore)", "privileges": ["SELECT"] }, { "group": "(.*)__data_scientist", "catalog": "$1__.*", "schema": ".*", "privileges": ["SELECT"] }, { "group": "(.*)__shared_hivedb", "schema": "$1", "privileges": ["SELECT"] }, { "group": "(.*)__shared_featurestore", "schema": "$1_featurestore", "privileges": ["SELECT"] }, { "catalog": "tpch", "privileges": ["SELECT"] }, { "catalog": "tpcds", "privileges": ["SELECT"] }, { "catalog": "system", "schema": "metadata", "privileges": ["SELECT"] } ], "queries": [ { "group": "admin", "allow": ["execute", "kill", "view"] }, { "group": "(.*)__data_owner", "queryOwner": "$1__.*", "allow": ["kill", "view"] }, { "user": "(.*)__.*", "queryOwner": "$1__.*", "allow": ["view"] }, { "allow": ["execute"] } ] } type: configmap additionalCatalogs: {} additionalConfigProperties: - internal-communication.shared-secret=${ENV:TRINO_SHARED_SECRET} - http-server.process-forwarded=true - event-listener.config-files=etc/mysql-event-listener.properties auth: groupsAuthSecret: trino-groups-file passwordAuthSecret: trino-password-file refreshPeriod: 5s catalogs: [] configMounts: [] coordinator: additionalConfigFiles: mysql-event-listener.properties: | event-listener.name=mysql mysql-event-listener.db.url={{ include "trino.mysql.eventListener.db.url" . }} additionalJVMConfig: - --add-opens=java.base/java.nio=ALL-UNNAMED additionalVolumeMounts: - mountPath: /certs name: certs readOnly: true - mountPath: /opt/hopsworks/mounts mountPropagation: HostToContainer name: mountable-secrets readOnly: true - mountPath: /etc/trino/catalog name: catalog-volume additionalVolumes: - emptyDir: {} name: certs - emptyDir: {} name: mountable-secrets - name: catalog-volume projected: sources: - configMap: name: hopsworks-trino-catalogs - secret: name: hopsworks-trino-catalogs-user-0 optional: true - secret: name: hopsworks-trino-catalogs-user-1 optional: true configMounts: - configMap: hopsfs-config name: hdfs-site path: /etc/hadoop/hdfs-site.xml subPath: hdfs-site.xml - configMap: hopsfs-config name: core-site path: /etc/hadoop/core-site.xml subPath: core-site.xml secretMounts: - name: super-crypto-kstore path: /srv/hops/super_crypto/trino secretName: hopsworks-trino-crypto-material coordinatorNameOverride: hopsworks-trino-coordinator defaultCatalogs: delta.properties: | connector.name=delta_lake fs.hadoop.enabled=true hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml hive.metastore.username=trino hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }} hive.metastore.thrift.client.ssl.enabled=true hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD} hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD} hive.hdfs.impersonation.enabled=true delta.enable-non-concurrent-writes=true hive.properties: | connector.name=hive fs.hadoop.enabled=true hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml hive.metastore.username=trino hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }} hive.metastore.thrift.client.ssl.enabled=true hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD} hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD} hive.hdfs.impersonation.enabled=true hudi.properties: | connector.name=hudi fs.hadoop.enabled=true hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml hive.metastore.username=trino hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }} hive.metastore.thrift.client.ssl.enabled=true hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD} hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD} hive.hdfs.impersonation.enabled=true iceberg.properties: | connector.name=iceberg fs.hadoop.enabled=true hive.config.resources=/etc/hadoop/hdfs-site.xml,/etc/hadoop/core-site.xml hive.metastore.username=trino hive.metastore.uri=thrift://{{ include "trino.consul.hiveMetastoreAddress" . }} hive.metastore.thrift.client.ssl.enabled=true hive.metastore.thrift.client.ssl.key=/srv/hops/super_crypto/trino/trino__kstore.jks hive.metastore.thrift.client.ssl.key-password=${ENV:SSL_CERT_KEY_PASSWORD} hive.metastore.thrift.client.ssl.trust-certificate=/srv/hops/super_crypto/trino/trino__tstore.jks hive.metastore.thrift.client.ssl.trust-certificate-password=${ENV:SSL_CERT_KEY_PASSWORD} iceberg.catalog.type=hive_metastore iceberg.file-format=PARQUET iceberg.compression-codec=ZSTD iceberg.hive-catalog.locking-enabled=false hive.hdfs.impersonation.enabled=true env: - name: SSL_CERT_KEY_PASSWORD valueFrom: secretKeyRef: key: trino__passwd name: hopsworks-trino-crypto-material - name: HOPS_USE_LOGIN_USER value: 'true' - name: TRINO_SHARED_SECRET valueFrom: secretKeyRef: key: shared-secret name: trino-internal-secret - name: MYSQL_DB value: hopsworks - name: MYSQL_USER value: hopsworksroot - name: MYSQL_PASSWORD valueFrom: secretKeyRef: key: hopsworksroot name: mysql-users-secrets envFrom: - configMapRef: name: '{{ .Values.nameOverride }}-mysql-conn-env' eventListenerProperties: [] image: pullPolicy: IfNotPresent registry: docker.hops.works repository: hopsworks/trino tag: 480-v10 initContainers: coordinator: - command: - /bin/sh - -c - | # Never hang and never fail. This is an init container, so it runs before Trino, and a # probe that exists to improve an error message must not be able to delay or block the # query engine. Both outcomes are swallowed and the line is always printed. URL='{{ .Values.global._hopsworks.trino.egressProbe.echoUrl }}' if [ -z "$URL" ]; then echo "trino-egress-address=disabled" exit 0 fi echo "trino-egress-address=$(curl -s --max-time 5 "$URL" || echo unknown)" image: '{{ .Values.image.registry }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}' imagePullPolicy: IfNotPresent name: egress-probe resources: limits: cpu: 500m memory: 256Mi requests: cpu: 10m memory: 32Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL - command: - sh - -c - cat /srv/hops/super_crypto/trino/trino_priv.pem /srv/hops/super_crypto/trino/trino_certificate_bundle.pem > /certs/keystore.pem image: '{{ .Values.image.registry }}/hopsworks/hwutils:{{ .Values.global._hopsworks.toolbox.tag }}' imagePullPolicy: IfNotPresent name: init-coordinator-cert resources: limits: cpu: 500m memory: 256Mi requests: cpu: 50m memory: 64Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL volumeMounts: - mountPath: /certs name: certs - mountPath: /srv/hops/super_crypto/trino name: super-crypto-kstore - command: - /bin/bash - -c - | set -euo pipefail export HADOOP_CONF_DIR=/etc/hadoop CERTS=/srv/hops/super_crypto/trino mkdir -p {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} /tmp/.hopsfs-mount-staging # Foreground: this is a sidecar, it must not exit. No startupProbe gates Trino on the # mount, deliberately: a mount that never comes up must not keep the query engine down. # A catalog whose bundle is missing fails its own connection instead. exec hopsfs-mount \ --logLevel warning \ --stageDir /tmp/.hopsfs-mount-staging \ --readOnly \ --srcDir {{ .Values.global._hopsworks.trino.mountableSecrets.storeRoot }} \ --hopsFSUserName trino \ -allowOther=true \ -tls \ -rootCABundle "$CERTS/hops_root_ca.pem" \ -clientCertificate "$CERTS/trino_certificate_bundle.pem" \ -clientKey "$CERTS/trino_priv.pem" \ namenode.service.{{ .Values.global._hopsworks.consulDomainName | default "consul" }}:8020 \ {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} image: '{{ $img := printf "%s/%s:%s" .Values.image.registry .Values.global._hopsworks.trino.mountableSecrets.image.repository .Values.global._hopsworks.trino.mountableSecrets.image.tag }}{{ $img }}{{ include "hopsworkslib.imageDigest" (dict "global" .Values.global "entry" $img) }}' imagePullPolicy: IfNotPresent lifecycle: preStop: exec: command: - /bin/bash - -c - umount -l {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} || true name: mountable-secrets resources: limits: cpu: 500m memory: 512Mi requests: cpu: 100m memory: 128Mi restartPolicy: Always securityContext: privileged: true runAsGroup: 0 runAsNonRoot: false runAsUser: 0 volumeMounts: - mountPath: '{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}' mountPropagation: Bidirectional name: mountable-secrets - mountPath: /srv/hops/super_crypto/trino name: super-crypto-kstore - mountPath: /etc/hadoop/core-site.xml name: core-site subPath: core-site.xml - mountPath: /etc/hadoop/hdfs-site.xml name: hdfs-site subPath: hdfs-site.xml worker: - command: - /bin/sh - -c - | # Never hang and never fail. This is an init container, so it runs before Trino, and a # probe that exists to improve an error message must not be able to delay or block the # query engine. Both outcomes are swallowed and the line is always printed. URL='{{ .Values.global._hopsworks.trino.egressProbe.echoUrl }}' if [ -z "$URL" ]; then echo "trino-egress-address=disabled" exit 0 fi echo "trino-egress-address=$(curl -s --max-time 5 "$URL" || echo unknown)" image: '{{ .Values.image.registry }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}' imagePullPolicy: IfNotPresent name: egress-probe resources: limits: cpu: 500m memory: 256Mi requests: cpu: 10m memory: 32Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL - command: - /bin/bash - -c - | set -euo pipefail export HADOOP_CONF_DIR=/etc/hadoop CERTS=/srv/hops/super_crypto/trino mkdir -p {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} /tmp/.hopsfs-mount-staging # Foreground: this is a sidecar, it must not exit. No startupProbe gates Trino on the # mount, deliberately: a mount that never comes up must not keep the query engine down. # A catalog whose bundle is missing fails its own connection instead. exec hopsfs-mount \ --logLevel warning \ --stageDir /tmp/.hopsfs-mount-staging \ --readOnly \ --srcDir {{ .Values.global._hopsworks.trino.mountableSecrets.storeRoot }} \ --hopsFSUserName trino \ -allowOther=true \ -tls \ -rootCABundle "$CERTS/hops_root_ca.pem" \ -clientCertificate "$CERTS/trino_certificate_bundle.pem" \ -clientKey "$CERTS/trino_priv.pem" \ namenode.service.{{ .Values.global._hopsworks.consulDomainName | default "consul" }}:8020 \ {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} image: '{{ $img := printf "%s/%s:%s" .Values.image.registry .Values.global._hopsworks.trino.mountableSecrets.image.repository .Values.global._hopsworks.trino.mountableSecrets.image.tag }}{{ $img }}{{ include "hopsworkslib.imageDigest" (dict "global" .Values.global "entry" $img) }}' imagePullPolicy: IfNotPresent lifecycle: preStop: exec: command: - /bin/bash - -c - umount -l {{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }} || true name: mountable-secrets resources: limits: cpu: 500m memory: 512Mi requests: cpu: 100m memory: 128Mi restartPolicy: Always securityContext: privileged: true runAsGroup: 0 runAsNonRoot: false runAsUser: 0 volumeMounts: - mountPath: '{{ .Values.global._hopsworks.trino.mountableSecrets.mountPath }}' mountPropagation: Bidirectional name: mountable-secrets - mountPath: /srv/hops/super_crypto/trino name: super-crypto-kstore - mountPath: /etc/hadoop/core-site.xml name: core-site subPath: core-site.xml - mountPath: /etc/hadoop/hdfs-site.xml name: hdfs-site subPath: hdfs-site.xml moreCatalogs: tpcds.properties: | connector.name=tpcds tpcds.splits-per-node=4 tpch.properties: | connector.name=tpch tpch.splits-per-node=4 nameOverride: hopsworks-trino securityContext: runAsGroup: 1000 runAsNonRoot: true runAsUser: 1000 seccompProfile: type: RuntimeDefault server: config: authenticationType: PASSWORD https: enabled: true keystore: path: /certs/keystore.pem port: 8443 coordinatorExtraConfig: | web-ui.preview.enabled=true service: coordinator: annotations: consul.hashicorp.com/service-name: trino consul.hashicorp.com/service-port: '8443' consul.hashicorp.com/service-tags: coordinator prometheus.io/path: /metrics prometheus.io/port: '8443' prometheus.io/scheme: https prometheus.io/scrape: 'true' type: ClusterIP serviceAccount: annotations: {} create: true name: hopsworks-trino worker: additionalConfigFiles: mysql-event-listener.properties: | event-listener.name=mysql mysql-event-listener.db.url={{ include "trino.mysql.eventListener.db.url" . }} additionalJVMConfig: - --add-opens=java.base/java.nio=ALL-UNNAMED additionalVolumeMounts: - mountPath: /etc/trino/catalog name: catalog-volume - mountPath: /opt/hopsworks/mounts mountPropagation: HostToContainer name: mountable-secrets readOnly: true additionalVolumes: - name: catalog-volume projected: sources: - configMap: name: hopsworks-trino-catalogs - secret: name: hopsworks-trino-catalogs-user-0 optional: true - secret: name: hopsworks-trino-catalogs-user-1 optional: true - emptyDir: {} name: mountable-secrets configMounts: - configMap: hopsfs-config name: hdfs-site path: /etc/hadoop/hdfs-site.xml subPath: hdfs-site.xml - configMap: hopsfs-config name: core-site path: /etc/hadoop/core-site.xml subPath: core-site.xml secretMounts: - name: super-crypto-kstore path: /srv/hops/super_crypto/trino secretName: hopsworks-trino-crypto-material workerNameOverride: hopsworks-trino-worker trino.trino.coordinator.additionalJVMConfig#- Type
list, default["--add-opens=java.base/java.nio=ALL-UNNAMED"]. add-opens for java.nio, and the failure is a CONFIGURATION error raised while the catalog is being loaded. On this coordinator that is fatal rather than local, because Trino runs catalog.management=static and exits when a catalog file fails to load -- so one project's Snowflake catalog would stop the whole cluster from starting. Set here rather than left to the operator because the connector is in TRINO_CONNECTORS, i.e. the backend offers it to every project. Other Arrow-based connectors need the same opens, so this is not Snowflake-specific. trino.trino.image.registry#- Type
string, default"docker.hops.works". Image registry, defaults to empty, which results in DockerHub usage trino.trino.image.repository#- Type
string, default"hopsworks/trino". Repository location of the Trino image, typicallyorganization/imagename trino.trino.image.tag#- Type
string, default"480-v10". Image tag for the Trino image. This value is explicitly pinned here and overrides any defaulting toappVersionfrom Chart.yaml. trino.trino.initContainers.coordinator[2].name#- Type
string, default"mountable-secrets". readOnly is not optional. Without it the query engine gains a write channel into HopsFS as the trino service user. --srcDir bounds what the mount exposes to the backend-owned tree; the mount authenticates as trino, which is in the hdfs superuser group, so srcDir is the only thing containing it. The preStop unmount is also not optional. Without it the container cannot terminate, the pod ends 0/2 Error,kubectl delete podhangs, and force-deleting leaks fuse.hopsfs mounts onto the node that must then be cleared by hand with nsenter. trino.trino.initContainers.worker[1].name#- Type
string, default"mountable-secrets". readOnly is not optional. Without it the query engine gains a write channel into HopsFS as the trino service user. --srcDir bounds what the mount exposes to the backend-owned tree; the mount authenticates as trino, which is in the hdfs superuser group, so srcDir is the only thing containing it. The preStop unmount is also not optional. Without it the container cannot terminate, the pod ends 0/2 Error,kubectl delete podhangs, and force-deleting leaks fuse.hopsfs mounts onto the node that must then be cleared by hand with nsenter.