Настройка web TLS для Trino в Kubernetes с помощью CLI
В конфигурации кластера Trino группа параметров webTLS позволяет использовать HTTPS на веб-эндпойнте Trino coordinator (порт 8443), в то время как worker-поды и внутреннее обнаружение работают через HTTP (порт 8080).
В отличие от ssl (клиентский truststore/keystore, монтируется на подах координатора и worker-подах), webTLS делает координатор TLS-сервером, используя keystore, таким образом worker-поды не получают доступ к приватному ключу.
webTLS — это альтернатива терминированию TLS на уровне Ingress, а не дополнение к нему. Поддерживаются следующие варианты терминирования TLS:
-
Терминирование TLS на уровне Ingress (по умолчанию). Ingress терминирует TLS-соединение с клиентом и перенаправляет запрос координатору по HTTP. Ingress для
trino-clusterвсегда направляет трафик на портhttpкоординатора, поэтому на этот путь настройкаwebTLSне влияет. -
HTTPS на координаторе (
webTLS). Порт8443открывается напрямую (с использованием SSL-проброса на Ingress или балансировщике нагрузки), а завершение TLS на Ingress не выполняется.
Одновременное включение обоих вариантов приводит к двойному терминированию TLS для одного и того же запроса. Это имеет смысл только в том случае, если вы намеренно хотите использовать повторное шифрование (Ingress терминирует TLS-соединение с клиентом, а затем шифрует трафик заново при передаче координатору на порт 8443); для этого необходимо настроить бэкенд Ingress на использование порта https и указать соответствующую аннотацию для протокола бэкенда.
Требования
-
Кластер Trino, развернутый в Kubernetes согласно инструкции.
-
Keystore, созданный в формате PKCS12:
$ openssl pkcs12 -export \ -in <tls.crt> \ -inkey <tls.key> \ -out <keystore.p12> \ -passout pass:<password>
Обновление конфигурации кластера Trino
-
Отредактируйте конфигурационный файл trino-cluster.yaml, добавив блок настроек
webTLS:trino-cluster.yamlapiVersion: adc.arenadata.io/v1alpha1 kind: TrinoCluster metadata: name: trino namespace: trino (1) spec: image: hub.arenadata.io/adc-enterprise/trino:<tag> (2) ## Image pull secret for a private registry. ## Set 'externalSecretName' to reference an existing Secret, ## or set 'credentials' and optionally 'secretName' to let the CLI create one. #imagePullSecret: # # Use a Secret managed outside ADC. # externalSecretName: existing-registry-secret # # ## Or let ADC create the Secret. # #secretName: custom-registry-secret # # #credentials: # # registry: registry.example.com # # username: user # # password: pass hadoop: (3) core: dfs.client.failover.proxy.provider.adh: org.apache.hadoop.hdfs.server.namenode.ha.ObserverReadProxyProvider dfs.ha.namenodes.adh: nn_tsn-adh-k8s-1,nn_tsn-adh-k8s-3 dfs.namenode.rpc-address.adh.nn_tsn-adh-k8s-1: tsn-adh-k8s-1.ru-central1.internal:8020 dfs.namenode.rpc-address.adh.nn_tsn-adh-k8s-3: tsn-adh-k8s-3.ru-central1.internal:8020 dfs.nameservices: adh fs.defaultFS: hdfs://adh fs.s3a.aws.credentials.provider: org.apache.hadoop.fs.s3a.SimpleAWSCredentialsProvider hadoop.proxyuser.trino.groups: '*' hadoop.proxyuser.trino.hosts: '*' hadoop.security.authentication: simple hdfs: dfs.client.read.shortcircuit: "false" hive: hive.metastore.sasl.enabled: "false" hive.metastore.uris: thrift://tsn-adh-k8s-1.ru-central1.internal:9083 metastore.use.SSL: "false" ozone: ozone.om.address.adh.om_tsn-adh-k8s-1: tsn-adh-k8s-1.ru-central1.internal:9862 ozone.om.address.adh.om_tsn-adh-k8s-2: tsn-adh-k8s-2.ru-central1.internal:9862 ozone.om.address.adh.om_tsn-adh-k8s-3: tsn-adh-k8s-3.ru-central1.internal:9862 ozone.om.nodes.adh: om_tsn-adh-k8s-1,om_tsn-adh-k8s-2,om_tsn-adh-k8s-3 ozone.om.service.ids: adhom ## Kerberos configuration for authentication. #kerberos: # realm: EXAMPLE.COM # # # Service name in the Kerberos principal. Defaults to the product name. # service: trino # # # Hostname in the Kerberos principal. # # Required for a fixed service principal; leave it empty only to derive one principal per pod from the cluster domain. # hostname: kerberos.example.com # keytab: # # true - kerberos-operator creates the keytab Secret. # # false (default) - reference an existing keytab Secret with name keytab.secretName. # create: false # # # Name of the keytab Secret. # # Optional when create: true - names the generated Secret (default: <name>-keytab). # # Required when create: false - must reference an existing Secret. # secretName: kerberos-secret # # # Label selector for the Pod that generates the keytab. # # Required when create: true; ignored when create: false. # labelSelector: # env: prod # #additionalPrincipals: # # - HTTP/kerberos.example.com # # rotation: # interval: 24h # checkInterval: 1h ## LDAP authentication configuration. ## Uncomment and fill url and userBindPattern. ## For ldaps:// URLs the ssl: or ca: section must also be configured (depends on product) #ldap: # # LDAP service url. # url: ldaps://ldap.example.com:636 # # # LDAP user Bind pattern. # userBindPattern: uid=${USER},cn=users,dc=example,dc=com ## Ranger plugin configuration. ## Uncomment and fill the lines below. adc apply derives the rest. #ranger: # # fill ranger.plugin.trino.policy.rest.url below with Ranger endpoint, e.g. https://adps-adc.ru-central1.internal:6182 # # fill ranger.plugin.trino.service.name below with Ranger service name you want to use for product, e.g. adc_trino_id_1 # security: # ranger.plugin.trino.policy.rest.url: "" # ranger.plugin.trino.service.name: "" # # # fill xasecure.audit.destination.solr.zookeepers below with Zookeepers endpoints to resolve solr service, e.g. adps-adc.ru-central1.internal:2181/Arenadata.Hadoop-2.solr.server # audit: # xasecure.audit.destination.solr.zookeepers: "" # # # Local Ranger files 'adc apply' writes into the configs Secret. # # Relative paths are resolved against the config file. # files: # jceksStorePath: /path/to/ranger.jceks ## Java KeyStore/TrustStore certificate configuration. ## Set externalSecretName to reference an existing Secret, ## or set files and optional secretName to have ADC create it. #ssl: # ## Name of the Secret containing Java keystores. # #secretName: custom-ssl-secret # externalSecretName: existing-ssl-secret # # # Key in the Secret containing the truststore file. # trustStoreKey: truststore.jks # # ## Password for the truststore (optional). # #trustStorePassword: bigdata # # ## Key in the Secret containing the keystore file (optional). # #keyStoreKey: keystore.jks # # ## Password for the keystore (optional). # #keyStorePassword: bigdata # # ## Alias of the key entry inside the keystore. Required by the Trino JMX exporter when scrape TLS is enabled. # #keyStoreAlias: trino # # ## Local files 'adc apply' puts into the Secret named by ssl.secretName. # ## Relative paths are resolved against the config file. # #files: # # trustStorePath: /path/to/truststore.jks # # #keyStorePath: /path/to/keystore.jks ## Use an external complete configs Secret instead of the one rendered by ADC. #configsSecret: # # Use a Secret managed outside ADC. # externalSecretName: existing-trino-configs # # ## Or let ADC create the Secret. # #secretName: custom-trino-configs coordinator: replicas: 1 #resources: # limits: # cpu: 500m # memory: 4Gi # requests: # cpu: 250m # memory: 512Mi ## Component arguments. Key-value pairs passed to the component configuration. #args: # http-server.http.port: "8080" ## Environment variables passed to the component container. #envs: # - name: JAVA_TOOL_OPTIONS # value: |- # -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks # -Djavax.net.ssl.trustStorePassword=bigdata worker: replicas: 1 #resources: # limits: # cpu: 500m # memory: 4Gi # requests: # cpu: 250m # memory: 512Mi ## Component arguments. Key-value pairs passed to the component configuration. #args: # http-server.http.port: "8080" ## Environment variables passed to the component container. #envs: # - name: JAVA_TOOL_OPTIONS # value: |- # -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks # -Djavax.net.ssl.trustStorePassword=bigdata ## Trino catalogs (one entry per .properties file). ## adc apply derives Kerberos/SSL fields for iceberg catalogs from the surrounding cluster config. catalogs: (4) iceberg.properties: connector.name: iceberg fs.hadoop.enabled: "true" hive.config.resources: /opt/trino-server/etc/catalog/core-site.xml hive.hdfs.impersonation.enabled: "true" hive.metastore.thrift.impersonation.enabled: "true" hive.metastore.uri: thrift://tsn-adh-k8s-1.ru-central1.internal:9083 ## Monitoring configuration. #monitoring: # # Enables Prometheus metrics export from this product's pods. # exportMetrics: true ## HTTPS on the Trino coordinator web endpoint. ## Set externalSecretName to reference a keystore Secret, ## or set files and optional secretName to have ADC create it. webTLS: (5) secretName: trino-web-tls # externalSecretName: existing-trino-web-tls keystoreKey: keystore.p12 keystorePassword: bigdata # # ## Local keystore 'adc apply' puts into the Secret named by webTLS.secretName. # ## A relative path is resolved against the config file. files: keystorePath: ./keystore.p12 ## Controls whether Secret/ConfigMap changes restart pods. ## Set enabled: false to update referenced Secrets without restarting ## the workload; pods keep running the previous configuration until ## the policy is re-enabled. Defaults to enabled. #configurationRollout: # enabled: false1 Пространство имен, используемое кластером Trino. 2 Настройки для загрузки образа кластера Trino. 3 Настройки Hadoop, взятые из ранее созданного файла hadoop_conf.yaml. 4 Настройки каталога. 5 Настройки web TLS. -
Примените конфигурацию и разверните кластер Trino:
$ ./adc apply -f trino-cluster.yamlОжидаемый вывод содержит сообщение с подтверждением успеха:
time="20260928084833UTC" level="info" msg="cluster trino applied to namespace trino"
-
Проверьте работоспособность подов кластера Trino:
$ kubectl get pods -n trinoОжидаемый вывод должен быть похож на следующий:
NAME READY STATUS RESTARTS AGE trino-coordinator-0 1/1 Running 0 52s trino-worker-0 1/1 Running 0 52s
Проверка JDBC-соединения
-
Подключитесь к кластеру Trino через JDBC, например, с помощью DBeaver. После активации web TLS строка подключения JDBC имеет следующий вид:
jdbc:trino://trino-cloud.ru-central1.internal:8443?SSL=true&SSLTrustStorePath=<truststore_path>&SSLTrustStorePassword=<password>
-
Установив подключение, выполните тестовую команду для проверки работоспособности кластера:
SHOW CATALOGS;Ожидаемый вывод:
Catalog | ----------+ iceberg | system |