Acceldata
ODP

Last updated: Sep 19, 2026 11:59 UTC

Configure Trino Authentication and Resource Groups

Configure Trino to authenticate directory users, resolve their group memberships, and assign their queries to resource groups.

The configuration includes the following files:

  • password-authenticator.properties
  • group-provider.properties
  • resource-groups.json
  • resource-groups.properties

Replace all placeholders with values appropriate for your environment.

Note

Manual configuration:  Complete the following steps directly on the Trino host. Ambari does not currently manage these configuration settings.


Configure Directory Authentication

Configure /etc/trino/password-authenticator.properties:

password-authenticator.name=ldap
 
ldap.url=<ldaps-or-ldap>://<directory-server-host>:<directory-server-port>
ldap.allow-insecure=<true-or-false>
 
ldap.bind-dn=<service-account-dn>
ldap.bind-password=<service-account-password>
 
ldap.user-bind-pattern=uid=${USER},ou=users,<your-base-dn>

For Active Directory, adjust ldap.user-bind-pattern to match your directory configuration.

Note

For production environments, use LDAPS and avoid storing directory credentials as plaintext in configuration files.

Configure Group Resolution

Configure /etc/trino/conf/group-provider.properties:

group-provider.name=ldap
ldap.url=<ldaps-or-ldap>://<directory-server-host>:<directory-server-port>
 
ldap.group-search-base=ou=groups,<your-base-dn>
ldap.group-member-attribute=<memberUid-or-member-depending-on-schema>
ldap.group-name-attribute=cn
ldap.user-id-attribute=uid

For Active Directory, ldap.group-member-attribute is typically member instead of memberUid. Verify the appropriate attributes for your directory schema.

Configure Resource Groups

Configure /etc/trino/conf/resource-groups.json to define the resource groups and map directory groups to them.

For example:

{
  "rootGroups": [
    {
      "name": "global",
      "softMemoryLimit": "80%",
      "hardConcurrencyLimit": 100,
      "maxQueued": 1000,
      "subGroups": [
        {
          "name": "<pool_1_name>",
          "softMemoryLimit": "50%",
          "hardConcurrencyLimit": 20,
          "maxQueued": 100
        },
        {
          "name": "<pool_2_name>",
          "softMemoryLimit": "30%",
          "hardConcurrencyLimit": 5,
          "maxQueued": 50
        }
      ]
    }
  ],
  "selectors": [
    {
      "group": "global.<pool_1_name>",
      "userGroups": ["<directory_group_1>"]
    },
    {
      "group": "global.<pool_2_name>",
      "userGroups": ["<directory_group_2>"]
    }
  ],
  "cpuQuotaPeriod": "1h"
}

The selectors map directory groups to the corresponding Trino resource groups.

Enable File-Based Resource Group Configuration

Configure /etc/trino/conf/resource-groups.properties:

resource-groups.configuration-manager=file
resource-groups.config-file=etc/resource-groups.json

Restart the Trino coordinator and any relevant services for the configuration changes to take effect.