Kerberos realm configuration for Trino Virtual Warehouses

The trino-krb5-config setting defines the Kerberos realm and KDC details that a Trino Virtual Warehouse uses to authenticate connectors such as Oracle.

A connector keytab authenticates to an external Kerberos realm, such as an Oracle or Kudu KDC. This is separate from the internal platform Kerberos settings in Cloudera Data Warehouse. A Trino Virtual Warehouse uses the trino-krb5-config setting to define the realm and KDC parameters for these external systems. At runtime, this configuration is applied to the Trino pods at /etc/trino/krb5.conf.

Configuring trino-krb5-config

Add the [libdefaults], [realms], and [domain_realm] sections needed to reach your external KDC. Edit this setting on the Trino Virtual Warehouse configuration; the coordinator and the worker must use the same setting. For example:

[libdefaults]
default_realm = CUSTOMER.COM
[realms]
CUSTOMER.COM = {
 kdc = kdc.customer.com
 admin_server = kdc.customer.com
}
[domain_realm]
.customer.com = CUSTOMER.COM

What Cloudera Data Warehouse adds automatically

When a connector uses a keytab, Cloudera Data Warehouse automatically performs the following actions:

  • Adds include /etc/krb5.conf as the first line of your trino-krb5-config when it writes the setting to the configmap and file system, so Trino loads the platform Kerberos configuration ahead of your custom realm entries and uses it to authenticate with platform components such as Ranger and the Hive Metastore. Do not add this line yourself; the platform adds it during deployment.
  • Points the Trino JVM at /etc/trino/krb5.conf, so connector Kerberos authentication, such as to Oracle, uses the realm, KDC, and domain settings from your custom trino-krb5-config.

Restrictions on trino-krb5-config

The platform rejects a trino-krb5-config setting that contains either of the following:

allow_weak_crypto
You cannot enable weak cryptography through a custom krb5.conf snippet.
A [plugins] section
Trino connectors cannot load Kerberos plugins this way.