전부 $TRINO_HOME/etc/ 아래에 있다. 설치 직후의 예시는 Trino 설치 에 있다.
| 파일 | 역할 |
|---|---|
config.properties |
서버 설정. coordinator 여부 · 포트 · discovery · TLS · 인증 · 메모리 |
jvm.config |
JVM 옵션. 한 줄에 하나 |
node.properties |
노드 식별. node.environment 는 클러스터 전체가 같고 node.id 는 노드마다 다르다 |
log.properties |
로그 레벨 |
password-authenticator.properties |
패스워드 인증 방식. Trino 인증 |
catalog/*.properties |
데이터 소스. Trino 커넥터 |
설정을 바꾸면 해당 노드를 재시작한다. 카탈로그 파일은 전체 노드에 같은 내용으로 둔다.
Coordinator 와 worker 를 분리한 운영 구성에 TLS 와 패스워드 인증을 더한 예시다.
coordinator=true
node-scheduler.include-coordinator=false
http-server.http.enabled=true
http-server.http.port=8080
discovery.uri=https://trino.example.net:8443
# TLS. 키와 인증서를 합친 PEM 하나를 가리킨다
http-server.https.enabled=true
http-server.https.port=8443
http-server.https.keystore.path=etc/certs/trino.pem
# 패스워드 인증 (파일 또는 LDAP). 방식은 password-authenticator.properties 에서 정한다
http-server.authentication.type=PASSWORD
# 내부 통신 인증. 전체 노드가 같은 값
internal-communication.shared-secret=${SHARED_SECRET}
인증을 켜면 HTTP(8080) 로는 인증 없이 접속할 수 없다. 워커의 내부 통신은 계속 HTTP 로 되므로 8080 은 열어 둔다. HTTP 로도 인증을 받게 하려면 http-server.authentication.allow-insecure-over-http=true 를 넣지만 권장하지 않는다.
Coordinator 가 worker 를 겸하는 소규모 구성은 node-scheduler.include-coordinator=true 로 바꾼다.
node.environment=production
node.id=coordinator01
node.data-dir=/var/trino/data
파일 이름은 jvm.config 다 (jvm.properties 가 아니다). 내용은 Trino 설치 의 것과 같다.
config.properties 와 node.properties 만 다르다. 나머지 파일은 coordinator 와 같다.
coordinator=false
http-server.http.port=8080
discovery.uri=https://trino.example.net:8443
http-server.https.enabled=true
http-server.https.port=8443
http-server.https.keystore.path=etc/certs/trino.pem
internal-communication.shared-secret=${SHARED_SECRET}
node.environment=production
node.id=worker01
node.data-dir=/var/trino/data
Coordinator 에서 직접 TLS 를 끝낸다[1]. 앞에 로드밸런서가 TLS 를 끝내는 구성이면 http-server.process-forwarded=true 를 넣고 https 설정은 뺀다.
| 속성 | 뜻 |
|---|---|
http-server.https.enabled=true |
HTTPS 켜기 |
http-server.https.port=8443 |
HTTPS 포트 |
http-server.https.keystore.path |
PEM(키+인증서) · JKS · PKCS#12 경로 |
http-server.https.keystore.key |
JKS · PKCS#12 의 키스토어 암호. PEM 이면 필요 없다 |
http-server.https.keymanager.password |
키에 따로 암호가 걸려 있을 때 |
PEM 은 개인키와 인증서를 이어 붙인 파일이다.
cat trino.key trino.crt > trino.pem
자체 서명 인증서를 만드는 절차는 Trino 자체 서명 인증서 생성 에 있다.
노드 사이의 통신을 인증하려면 전체 노드에 같은 shared secret 을 둔다[2]. 패스워드 인증을 켜려면 필수다.
openssl rand 512 | base64 -w 0
internal-communication.shared-secret=${SHARED_SECRET}
노드 사이 통신까지 암호화하려면 전체 노드에 다음을 더한다. 이때 discovery.uri 는 호스트명이 아니라 IP 주소여야 한다 — 내부 TLS 인증서를 자동 생성하는 기능이 IP 만 지원한다.
internal-communication.https.required=true
discovery.uri=https://192.168.1.41:8443
http-server.https.enabled=true
http-server.https.port=8443
내부 TLS 는 조인 · 집계 · 윈도 함수처럼 재분배가 큰 쿼리를 10% 에서 100% 이상 늦출 수 있다. 신뢰할 수 있는 내부망이면 shared secret 만 쓴다.
| 속성 | 기본값 | 뜻 |
|---|---|---|
query.max-memory-per-node |
JVM 힙의 30% | 쿼리 하나가 노드 하나에서 쓰는 최대 |
query.max-memory |
20GB | 쿼리 하나가 클러스터 전체에서 쓰는 최대 |
memory.heap-headroom-per-node |
JVM 힙의 30% | 쿼리에 주지 않고 남겨 두는 여유 |
-Xmx 를 정한 뒤 이 세 값을 맞춘다. 워커 수 × query.max-memory-per-node 보다 query.max-memory 를 크게 잡으면 의미가 없다.
TLS and HTTPS — 2026-09-20 확인. https://trino.io/docs/current/security/tls.html ↩︎
Secure internal communication — 2026-09-20 확인. https://trino.io/docs/current/security/internal-communication.html ↩︎