Kerberos realm configuration for Trino Virtual Warehouses
The trino-krb5-config setting defines the Kerberos realm and KDC details that a Trino Virtual Warehouse uses to authenticate connectors such as Oracle.
A connector keytab authenticates to an external Kerberos realm, such as an Oracle or Kudu KDC. This is separate from the internal platform Kerberos settings in Cloudera Data Warehouse. A Trino Virtual Warehouse uses the trino-krb5-config setting to define the realm and KDC parameters for these external systems. At runtime, this configuration is applied to the Trino pods at /etc/trino/krb5.conf.
Configuring trino-krb5-config
Add the [libdefaults], [realms], and
[domain_realm] sections needed to reach your external KDC. Edit this setting
on the Trino Virtual Warehouse configuration; the coordinator and the worker must use the same
setting. For example:
[libdefaults]
default_realm = CUSTOMER.COM
[realms]
CUSTOMER.COM = {
kdc = kdc.customer.com
admin_server = kdc.customer.com
}
[domain_realm]
.customer.com = CUSTOMER.COM
What Cloudera Data Warehouse adds automatically
When a connector uses a keytab, Cloudera Data Warehouse automatically performs the following actions:
- Adds include /etc/krb5.conf as the first line of your trino-krb5-config when it writes the setting to the configmap and file system, so Trino loads the platform Kerberos configuration ahead of your custom realm entries and uses it to authenticate with platform components such as Ranger and the Hive Metastore. Do not add this line yourself; the platform adds it during deployment.
- Points the Trino JVM at /etc/trino/krb5.conf, so connector Kerberos
authentication, such as to Oracle, uses the realm, KDC, and domain settings from your custom
t
rino-krb5-config.
Restrictions on trino-krb5-config
The platform rejects a trino-krb5-config setting that contains either of the following:
allow_weak_crypto- You cannot enable weak cryptography through a custom krb5.conf snippet.
- A
[plugins]section - Trino connectors cannot load Kerberos plugins this way.
