Overview
Trino is a distributed SQL query engine that queries data where it lives. This template deploys a Trino cluster — one coordinator plus a scalable worker tier — that connects to PostgreSQL, MySQL, ClickHouse, MongoDB and many other sources through catalogs, and joins across them in a single query without copying any data. Databases you already run on Control Plane are reachable over internal DNS, and Iceberg tables in object storage are reachable through the Polaris template. Trino stores nothing itself, so the template has no volume set: a restart costs only the queries in flight, and uninstalling never touches the databases it queries.What Gets Created
Prerequisites
None for a default install. The image ships thetpch, tpcds, memory and jmx catalogs, so the cluster is queryable the moment it is ready.
Two features need secrets that must exist before you install or upgrade with them on. Secrets are org-level, so no --gvc flag is involved.
Catalog credentials (to query your own data sources)
password key, so you can reference that same secret instead of creating a new one. Set catalogs[].secrets[].secretName (and secretKey for a dictionary) to this name — see Catalogs.Login secrets (to enable authentication and public access)
auth.passwordFileSecretName and auth.sharedSecretName to these names — see Authentication.Installation
A default install needs no values — it runs unauthenticated, reachable only from inside the GVC, with the built-in demo catalogs:-f) — see Configuration.
UI
CLI
Terraform
Pulumi
Configuration
Image
Coordinator
Workers
workers.replicas for more query capacity and to keep capacity through a rolling restart. For both tiers the chart refuses to render unless maxMemory is whole GiB and at least 2Gi, minMemory does not exceed maxMemory, and maxCpu:minCpu is at most 4:1; the error names the value to fix. Worker resources are only checked when workers.replicas is above 0.
JVM
maxMemory (allowed range 40–80). Trino derives its per-node query memory (30% of heap) and headroom (30% of heap) from it, so maxMemory is normally the only number you change. Capacity AI is off on both workloads, because the JVM sizes its heap once from the container limit at startup.
Catalogs
/etc/trino/catalog/NAME.properties on the coordinator and every worker. Credentials never go into properties: the file holds only a ${ENV:NAME} placeholder, and the secrets list injects the value from a secret you created as that environment variable.
Authentication
auth.enabled turns on password-file login on the coordinator and the shared secret the nodes use to authenticate to each other. Both secret names are required when it is on — create them first, as shown in Prerequisites.
Access
none is rejected at render: the coordinator reaches itself through this same path, so it would fail every query. The worker tier always keeps its own firewall — only the coordinator and sibling workers may reach a worker, whatever you set here. Allow several minutes after changing an access setting before concluding it did not apply.
Connecting
http://localhost:8080/ui/; with no authentication configured, Trino asks only for a user name:
Connecting Data Sources
Point a catalog at any database Trino can reach. A sibling template in the same GVC is reachable at its fully qualified internal name,WORKLOAD_NAME.GVC_NAME.cpln.local:
connection-user. With several catalogs configured, one statement spans all of them — including the built-in tpch data — and Trino performs the join itself:
iceberg catalog entry its page gives — Trino then creates, writes and queries Iceberg tables there. Hive and Delta Lake catalogs are not offered.
Operations
Adding or Changing a Catalog
Add the entry to your values and upgrade the release; create any secret it references first. Adding or removing a catalog changes both workloads, so they restart and the new catalog appears inSHOW CATALOGS:
properties of an existing catalog changes only the content of its catalog secret, which a running replica does not re-read. After the upgrade, force a redeployment of both workloads:
Rotating a Catalog Credential
Change the value by applying the whole secret —cpln secret update does not change values. For a dictionary secret:
type: opaque with data.encoding: plain and data.payload: NEW-VALUE. A running replica keeps the old value until it restarts, so force a redeployment of RELEASE_NAME-trino and RELEASE_NAME-trino-worker as shown above. The same applies to the two login secrets.
Scaling and Availability
- Workers are interchangeable: raise
workers.replicasfor capacity, and keep it at2or more if queries must keep running through a rolling restart. At the default of1, a worker restart empties the execution tier for its duration. - The coordinator is a single point of failure — open-source Trino has one coordinator and no failover. Restarting it briefly interrupts all querying.
- Queries are not retried. A query running on a node that restarts or is replaced fails and must be resubmitted by the client.
- Single node —
workers.replicas: 0removes the worker workload and the coordinator executes queries itself. Suitable for small or development installs.
Troubleshooting
Deployment never becomes ready and the logs are empty
Deployment never becomes ready and the logs are empty
status.versions[].message with cpln workload get-deployments RELEASE_NAME-trino --gvc GVC_NAME -o yaml (and for RELEASE_NAME-trino-worker) — it names the missing secret. Create it; the deployment recovers on its own after several minutes, or force a redeployment.Install fails with auth.enabled requires publicAccess.enabled
Install fails with auth.enabled requires publicAccess.enabled
publicAccess.enabled requires auth.enabled, means the opposite half is missing.Fix: Set both auth.enabled and publicAccess.enabled to true with both login secret names, or leave both off.Clients get 401 Password not allowed for insecure authentication
Clients get 401 Password not allowed for insecure authentication
443 with SSL=true.An internal client cannot reach the coordinator
An internal client cannot reach the coordinator
internalAccess.type allows — for example not listed under workload-list, or in another GVC under same-gvc.Fix: Add the client’s workload link to internalAccess.workloads, or widen internalAccess.type, and upgrade. Allow several minutes for the change to apply.A catalog password does not work
A catalog password does not work
secrets[].secretKey does not match a key in the dictionary secret, a dictionary secret is referenced without secretKey, or the secret was rotated without a redeployment.Fix: Compare the key names with cpln secret reveal SECRET_NAME -o yaml, correct the catalog entry, and force a redeployment of both workloads.Coordinator restarts after adding a catalog
Coordinator restarts after adding a catalog
Configuration property 'NAME' was not used.Fix: Find the property in the coordinator logs, then correct the properties block against the connector’s documentation page:Queries fail with out-of-memory errors
Queries fail with out-of-memory errors
jvm.maxRAMPercentage of maxMemory.Fix: Raise maxMemory on the tier doing the work first, then add workers. Raising jvm.maxRAMPercentage above about 75 makes it worse — the JVM needs the remainder outside the heap.Important Notes
- Authentication and public access are enabled together or not at all; with authentication on, every client signs in over the public HTTPS endpoint.
- Never put a password in a catalog’s
properties— reference it as${ENV:NAME}from a secret you created before installing. - A rotated secret or an edited catalog takes effect only after a forced redeployment of both workloads.
- The coordinator is a single point of failure and in-flight queries are not retried; keep
workers.replicasat2or more for restart tolerance. - The built-in
jmxcatalog exposes JVM internals to anyone who can run a query. - Uninstalling removes only the cluster — the databases it queried and the secrets you created are left in place.
External References
Trino Documentation
Connectors
JDBC Driver
Password File Authentication
Secrets in Properties Files
${ENV:NAME} substitution used by catalog credentials