Configure Trino Authentication and Resource Groups

Configure Trino to authenticate directory users, resolve their group memberships, and assign their queries to resource groups.

The configuration includes the following files:

  • password-authenticator.properties

  • group-provider.properties

  • resource-groups.json

  • resource-groups.properties

Replace all placeholders with values appropriate for your environment.

Manual configuration: Complete the following steps directly on the Trino host. Ambari does not currently manage these configuration settings.


Configure Directory Authentication

Configure /etc/trino/password-authenticator.properties:

password-authenticator.name=ldap ldap.url=<ldaps-or-ldap>://<directory-server-host>:<directory-server-port> ldap.allow-insecure=<true-or-false> ldap.bind-dn=<service-account-dn> ldap.bind-password=<service-account-password> ldap.user-bind-pattern=uid=${USER},ou=users,<your-base-dn>

For Active Directory, adjust ldap.user-bind-pattern to match your directory configuration.

For production environments, use LDAPS and avoid storing directory credentials as plaintext in configuration files.

Configure Group Resolution

Configure /etc/trino/conf/group-provider.properties:

group-provider.name=ldap ldap.url=<ldaps-or-ldap>://<directory-server-host>:<directory-server-port> ldap.group-search-base=ou=groups,<your-base-dn> ldap.group-member-attribute=<memberUid-or-member-depending-on-schema> ldap.group-name-attribute=cn ldap.user-id-attribute=uid

For Active Directory, ldap.group-member-attribute is typically member instead of memberUid. Verify the appropriate attributes for your directory schema.

Configure Resource Groups

Configure /etc/trino/conf/resource-groups.json to define the resource groups and map directory groups to them.

For example:

{ "rootGroups": [ { "name": "global", "softMemoryLimit": "80%", "hardConcurrencyLimit": 100, "maxQueued": 1000, "subGroups": [ { "name": "<pool_1_name>", "softMemoryLimit": "50%", "hardConcurrencyLimit": 20, "maxQueued": 100 }, { "name": "<pool_2_name>", "softMemoryLimit": "30%", "hardConcurrencyLimit": 5, "maxQueued": 50 } ] } ], "selectors": [ { "group": "global.<pool_1_name>", "userGroups": ["<directory_group_1>"] }, { "group": "global.<pool_2_name>", "userGroups": ["<directory_group_2>"] } ], "cpuQuotaPeriod": "1h" }

The selectors map directory groups to the corresponding Trino resource groups.

Enable File-Based Resource Group Configuration

Configure /etc/trino/conf/resource-groups.properties:

resource-groups.configuration-manager=file resource-groups.config-file=etc/resource-groups.json

Restart the Trino coordinator and any relevant services for the configuration changes to take effect.

  Last updated