dhi.io/trino
Distributed SQL query engine for big data
All examples in this guide use the public image. If you've mirrored the repository for your own use (for example, to your Docker Hub namespace), update your commands to reference the mirrored image instead of the public one.
For example:
dhi.io/trino:<tag><your-namespace>/dhi-trino:<tag>For the examples, you must first use docker login dhi.io to authenticate to the registry to pull the images.
This Docker Hardened Trino image includes:
/usr/lib/trino/bin/, including run-trino, launcher, and health-check/usr/bin/trino/usr/lib/trino/bin/run-trinoNote: By default, only the server-core plugin set is included in the runtime and dev variants. The compat variant
includes the full set of optional Trino plugins. See Image variants for details.
The ranger plugin is currently not present in this image as it cannot be properly hardened.
Before you can use any Docker Hardened Image, you must mirror the image repository from the catalog to your organization. To mirror the repository, select either Mirror to repository or View in repository > Mirror to repository, and then follow the on-screen instructions.
Run the following command and replace <your-namespace> with your organization's namespace and <tag> with the image
variant you want to run.
docker run -d --name my-trino -p 8080:8080 <your-namespace>/dhi-trino:<tag>
Verify the server is running and connect using the Trino CLI:
docker exec -it my-trino trino
Use the Trino CLI to connect to a running Trino server instance and run queries interactively.
docker exec -it my-trino trino
By default, only the server-core plugin set is included in this image. If your application requires additional
plugins, follow Trino's guide for
installing and configuring additional plugins.
To use all optional plugins without manual installation, use the compat image variant, which includes the full plugin set that ships with Trino.
docker run -d --name my-trino -p 8080:8080 <your-namespace>/dhi-trino:<compat-tag>
| Feature | Docker Official Trino | Docker Hardened Trino |
|---|---|---|
| Security | Standard base, less frequently patched | Minimal, hardened base with active security patches |
| Shell access | bash available | bash available |
| Package manager | Not available | Not available in runtime variants |
| User | trino (nonroot) | trino (nonroot) |
| Attack surface | Larger due to less hardened base | Minimal, actively maintained with CVE fixes |
| Compliance | None | CIS benchmark compliant |
| Debugging | Traditional shell debugging | Docker Debug or shell debugging |
Docker Hardened Images prioritize security through active patching and a minimal base:
For debugging, you can use Docker Debug to attach to containers:
docker debug <container-name>
Docker Hardened Images come in different variants depending on their intended use. To view all available image variants and their tags, select the Tags tab for this repository.
Runtime variant is designed to run Trino in production. This image:
trino nonroot userbash shellserver-core plugin setDev variant is intended for use in the first stage of a multi-stage Dockerfile. This image:
root userbash shell and apt-get package managerCompat variant is designed to support more seamless usage as a drop-in replacement for the upstream Trino image. This image:
trino nonroot userbash shellCompat-dev variant combines the compat plugin set with dev tooling. This image:
root userbash shell and apt-get package managerFIPS variant is available for environments requiring FIPS 140 validated cryptographic modules. This image:
trino nonroot userbash shellTo migrate your application to a Docker Hardened Image, you must update your Dockerfile. At minimum, you must update the base image in your existing Dockerfile to a Docker Hardened Image. This and a few other common changes are listed in the following table of migration notes:
| Item | Migration note |
|---|---|
| Base image | Replace your base images in your Dockerfile with a Docker Hardened Image. |
| Package management | Only dev variants include a package manager. Use dev variants in build stages and runtime variants for production. |
| Non-root user | Runtime and compat variants run as the trino nonroot user. Ensure that necessary files and directories are accessible to that user. |
| TLS certificates | Docker Hardened Images contain standard TLS certificates by default. There is no need to install TLS certificates. |
| Ports | Runtime and compat variants run as a nonroot user by default. As a result, applications in these images can't bind to privileged ports (below 1024) when running in Docker Engine versions older than 20.10. Configure your application to listen on port 1025 or higher inside the container. |
| Entry point | All variants use run-trino as the default CMD rather than ENTRYPOINT, meaning it can be overridden easily. Inspect entry points and update your Dockerfile if necessary. |
| Plugins | The runtime variant includes only the server-core plugin set. Use the compat variant if you require the full plugin set. |
The following steps outline the general migration process.
Find hardened images for your app.
A hardened image may have several variants. Inspect the image tags and find the image variant that meets your needs.
Update the base image in your Dockerfile.
Update the base image in your application's Dockerfile to the hardened image you found in the previous step. For
build stages, use a dev variant as it includes the tools needed to install packages and dependencies.
For multi-stage Dockerfiles, update the runtime image.
To ensure that your final image is as minimal as possible, use a multi-stage build. Intermediary stages typically use
dev variants, while your final runtime stage should use a non-dev variant.
Install additional packages.
Docker Hardened Images contain minimal packages to reduce the potential attack surface. Install any additional
packages in the build stage using a dev variant, then copy necessary artifacts to the runtime stage.
Select the right plugin set.
If your application requires plugins beyond server-core, either install them manually following Trino's
plugin guide, or use the compat variant which includes the
full plugin set.
The recommended method for debugging applications built with Docker Hardened Images is to use Docker Debug to attach to these containers. Docker Debug provides a shell, common debugging tools, and lets you install other tools in an ephemeral, writable layer that only exists during the debugging session.
docker debug <container-name>
By default, runtime and compat variants run as the trino nonroot user. Ensure that necessary files and directories are
accessible to that user. You may need to copy files to different directories or change permissions so your application
can access them.
To view the user for an image variant, select the Tags tab for this repository.
Runtime and compat variants run as a nonroot user by default. As a result, applications in these images can't bind to
privileged ports (below 1024) when running in Docker Engine versions older than 20.10. To avoid issues, configure your
application to listen on port 1025 or higher inside the container, even if you map it to a lower port on the host. For
example, docker run -p 80:8080 my-image will work because the port inside the container is 8080, and
docker run -p 80:81 my-image won't work because the port inside the container is 81.
All variants use run-trino as the default CMD rather than ENTRYPOINT. This means the command can be overridden easily.
Use docker inspect to verify the entry point and update your Dockerfile if necessary.