github trinodb/charts trino-1.44.0

2 hours ago

Upgrading

A default install upgrades in place with nothing to do: rendered output is unchanged apart from the chart version label, and Service and Deployment selectors are identical, so there are no immutable-field conflicts. Pods roll once because the chart version is part of the config checksums.

Two changes do need attention, and only if you use the feature in question:

Metric names change if you scrape with a ServiceMonitor

serviceMonitor now scrapes Trino's own /metrics endpoint, which every node serves on its HTTP port, instead of only the JMX exporter sidecar. OpenMetrics names keep the ObjectName's name= key, which the exporter's rules drop:

trino_execution_ClusterSizeMonitor_RequiredWorkers        # exporter
trino_execution_name_ClusterSizeMonitor_RequiredWorkers   # OpenMetrics

So dashboards, recording rules, alerts, and KEDA queries written against the exporter's names need updating. The KEDA example in values.yaml was itself wrong in this way and is corrected.

To keep the old behavior exactly: serviceMonitor.openMetrics.enabled: false.

Two more things to know if you already run the exporter and a ServiceMonitor: you now get both endpoints, so series count roughly doubles until you turn one off, and the OpenMetrics endpoint is index 0, so anything keyed on the scrape pool name serviceMonitor/<ns>/<name>/0 now refers to a different target. Scraping /metrics is a management read, so it authenticates - by default as admin with no password, which is what Trino's insecure authenticator accepts. On a cluster secured with PASSWORD, set the password on the coordinator alone, since the workers have no authenticator and reject one:

serviceMonitor:
  coordinator:
    openMetrics:
      password: a-real-password

Access control now applies to the workers

Top-level accessControl previously only ever reached the coordinator; it now applies to both roles, which is what the top-level means everywhere else in this chart. A rules document with no system_information section therefore denies worker management reads where they were previously unprotected - including the metrics endpoint above.

The migration is to allow the user you read management endpoints as:

accessControl:
  type: configmap
  rules:
    rules.json: |-
      {"system_information": [{"user": "admin", "allow": ["read"]}]}

accessControl.coordinator and accessControl.worker override the shared block per role if you want them to differ. Enabling worker.gracefulShutdown installs such a rule set on the workers by itself, and it now grants read as well as write, so shutdown and metrics both work; before this release it granted only write, which denied every management read on the workers.

Features

  • Run an Open Policy Agent sidecar on the coordinator with opa.enabled, supplying a Rego policy inline or from a ConfigMap of your own. The chart wires Trino's access-control plugin to it unless you configured accessControl yourself. The engine binds to loopback because its API is unauthenticated and accepts policy updates, and the probes use OPA's read-only diagnostic listener instead - by @tadeha in #428
  • Protect the worker pool during voluntary disruption with worker.podDisruptionBudget, rendered into the budget's spec the way the gateway chart already does, so any field the API supports can be set - by @andrii29 in #429
  • Set the JMX exporter sidecar's environment with jmx.exporter.env and envFrom, per role, which is what it takes to tune the heap it runs under - by @tsamaras in #426
  • Scrape Trino's own metrics endpoint, with serviceMonitor.openMetrics, serviceMonitor.tlsConfig and a serviceMonitor.endpoints escape hatch for a scrape the chart cannot derive - by @nineinchnick in #459
  • Give the workers access control rules of their own, with accessControl.worker, and have graceful shutdown merge the permission it needs into them rather than being the only rule - by @nineinchnick in #460

Fixes

  • The bundled Helm test images are overridable through testImages.* and no longer come from bitnamilegacy: bitnamilegacy/kubectl:latest and bitnamilegacy/postgresql:17.1.0 became alpine/kubectl and the official postgres image, and the hardcoded python:3-slim is configurable too. Anyone mirroring the old references needs to mirror the new ones or set testImages.* - in #426 and #459
  • The JMX test only checked that Prometheus had discovered its targets, so a scrape rejected by lacking credentials or permission to read system information passed it. It now waits for the target to report itself up - in #459

The JMX exporter sidecar still works and is still opt-in. Its image stays on bitnamilegacy/jmx-exporter:1.4.0, the only one that pulls without credentials; values.yaml now points at Docker Hardened Images for anyone who wants a maintained one and can supply an imagePullSecrets. See #435.

helm install my-trino trino/trino --version 1.44.0

Full Changelog: trino-1.43.0...trino-1.44.0

Don't miss a new charts release

NewReleases is sending notifications on new releases.