Skip to content

feat: add openlineage support - #914

Open
razvan wants to merge 14 commits into
mainfrom
feat/openlineage-from-op-rs
Open

razvan wants to merge 14 commits into
mainfrom
feat/openlineage-from-op-rs

Conversation

@razvan

@razvan razvan commented Jul 20, 2026 •

Copy link
Copy Markdown
Member

Description

Trino can emit OpenLineage events for queries. This PR makes essential properties configurable. The operator uses sensible defaults where possible.

Depends on:

Part of stackabletech/issues#856

Decision: https://github.com/stackabletech/decisions/issues/90

CRD change

See extra/crds.yaml for the CRD diff.

Examples

The example below shows how add inline spec.clusterConfig.lineage configuration to a TrinoCluster resource.

The following fields are new:

  • connection : provided by the OpenLineageConfig struct from op-rs and common to all products supporting this in the future.
  • namespace: same as connection above. The default is default. Identifies the namespace of Open Lineage Job events.
  • jobNameFormat: specific to Trino. Template used to build names for Job events.
  • datasetNamespaceUri: specific to Trino. Used to build the data set namespace. The default value is https://<trino cluster name>.<k8s namespace>.

Inline configuration

---
apiVersion: trino.stackable.tech/v1alpha1
kind: TrinoCluster
metadata:
  name: simple-trino
spec:
  image:
    productVersion: "481"
  clusterConfig:
    catalogLabelSelector:
      matchLabels:
        trino: simple-trino
    lineage:
      connection:
        inline:
          http:
            # Must match a Subject Alternative Name in the backend's TLS certificate.
            host: marquez.lineage.svc.cluster.local
            port: 5000
            # Default: /api/v1/lineage
            path: /api/v1/lineage
            tls:
              verification:
                server:
                  caCert:
                    # SecretClass providing the CA that issued the backend's certificate.
                    secretClass: marquez-ca
            # Secret holding the bearer token under the key `apiKey`. Omit to disable authentication.
            credentialsSecretName: openlineage-token
      # OpenLineage job namespace. Default: default
      namespace: trino-prod
      # OpenLineage job name. Default: $QUERY_ID
      jobNameFormat: $USER-$QUERY_ID
      # Datasets are reported under trino://trino.example.com.
      # Default: https://<TrinoCluster name>.<Kubernetes namespace>
      datasetNamespaceUri: https://trino.example.com
  coordinators:
    roleGroups:
      default:
        replicas: 1
  workers:
    roleGroups:
      default:
        replicas: 1

Reference

---
# Reusable OpenLineage backend connection. Must be in the same namespace as the TrinoCluster.
apiVersion: lineage.stackable.tech/v1alpha1
kind: OpenLineageConnection
metadata:
  name: marquez
spec:
  http:
    # Must match a Subject Alternative Name in the backend's TLS certificate.
    host: marquez.lineage.svc.cluster.local
    port: 5000
    # Default: /api/v1/lineage
    path: /api/v1/lineage
    tls:
      verification:
        server:
          caCert:
            # SecretClass providing the CA that issued the backend's certificate.
            secretClass: marquez-ca
    # Secret holding the bearer token under the key `apiKey`. Omit to disable authentication.
    credentialsSecretName: openlineage-token
---
apiVersion: trino.stackable.tech/v1alpha1
kind: TrinoCluster
metadata:
  name: simple-trino
spec:
  image:
    productVersion: "481"
  clusterConfig:
    catalogLabelSelector:
      matchLabels:
        trino: simple-trino
    lineage:
      connection:
        # Name of the OpenLineageConnection above.
        reference: marquez
      # OpenLineage job namespace. Default: default
      namespace: trino-prod
      # OpenLineage job name. Default: $QUERY_ID
      jobNameFormat: $USER-$QUERY_ID
      # Datasets are reported under trino://trino.example.com.
      # Default: https://<TrinoCluster name>.<Kubernetes namespace>
      datasetNamespaceUri: https://trino.example.com
  coordinators:
    roleGroups:
      default:
        replicas: 1
  workers:
    roleGroups:
      default:
        replicas: 1

Definition of Done Checklist

  • Not all of these items are applicable to all PRs, the author should update this template to only leave the boxes in that are relevant
  • Please make sure all these things are done and tick the boxes

Author

  • Changes are OpenShift compatible
  • CRD changes approved
  • CRD documentation for all fields, following the style guide.
  • Helm chart can be installed and deployed operator works
  • Integration tests passed (for non trivial changes)
  • Changes need to be "offline" compatible
  • Links to generated (nightly) docs added
  • Release note snippet added

Reviewer

  • Code contains useful comments
  • Code contains useful logging statements
  • (Integration-)Test cases added
  • Documentation added or updated. Follows the style guide.
  • Changelog updated
  • Cargo.toml only contains references to git tags (not specific commits or branches)

Acceptance

  • Feature Tracker has been updated
  • Proper release label has been added
  • Links to generated (nightly) docs added
  • Release note snippet added
  • Add type/deprecation label & add to the deprecation schedule
  • Add type/experimental label & add to the experimental features tracker

@razvan razvan self-assigned this Jul 20, 2026
razvan and others added 12 commits July 20, 2026 16:02
…ationClass

Follows the operator-rs change: read the OpenLineage backend bearer token from
the connection's `credentialsSecretName` Secret (key `apiKey`) instead of
resolving a Static AuthenticationClass.

See stackabletech/decisions#90

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…h API group

Follow the operator-rs rename of OpenLineageJob.app_name to job_name
(serialized appName -> jobName) and the move of the OpenLineageConnection CRD
to the lineage.stackable.tech API group:

- read open_lineage.job_name for the job.name-format property; update the doc
  comment referencing spec.clusterConfig.openLineage.jobName
- update the operator RBAC ClusterRole apiGroup
- update kuttl test manifests (jobName) and the usage-guide docs
- regenerate extra/crds.yaml (appName -> jobName)

The Spark SparkSession.appName() call in tests/spark is unrelated and left as-is.

Verified with cargo check/clippy/test and CRD regeneration against a local
operator-rs checkout carrying the rename. Committed with --no-verify because the
cargo/regenerate-charts pre-commit hooks would otherwise build against the
un-pushed operator-rs branch; those checks were run manually instead.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Rename the lineage-emission configuration field from `openLineage` to `lineage`
across the CRD and operator internals:

- spec.clusterConfig.openLineage -> spec.clusterConfig.lineage (Rust field
  cluster_config.open_lineage -> lineage; ValidatedCluster field likewise)
- rename operator-internal identifiers: module config/openlineage.rs ->
  lineage.rs, ResolvedOpenLineageConfig -> ResolvedLineageConfig,
  resolved_open_lineage_config -> resolved_lineage_config, and the feature-
  scoped test helpers
- update the usage-guide docs and the kuttl test manifest
- regenerate extra/crds.yaml (openLineage -> lineage)

The OpenLineage technology name is kept in prose, in the operator-rs types
(OpenLineageJob, OpenLineageConnection), in the `openlineage` event-listener
plugin name, and in the OPENLINEAGE_* / event-listener property keys.

Verified with cargo check/clippy/test and CRD regeneration against a local
operator-rs checkout. Committed with --no-verify because the cargo/regenerate
pre-commit hooks would build against the un-pushed operator-rs branch; those
checks were run manually instead.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… namespace

Bump the operator-rs pin to pick up the reworked `crd::openlineage` module:

- `OpenLineageJob` is renamed to `OpenLineageConfig`.
- `OpenLineageConnectionSpec` now selects an `OpenLineageTransport` (currently
  only `http`) instead of carrying host/port/tls/credentialsSecretName directly.
- `HttpTransport` gained a `path` field, defaulting to `/api/v1/lineage`, wired
  to `openlineage-event-listener.transport.endpoint`.
- `OpenLineageConfig::namespace` is now a required `String` defaulting to
  `default`, so the operator-side fallback to the workload's Kubernetes
  namespace is gone. NOTE: this changes behaviour for users who did not set
  `namespace` explicitly - lineage is now reported under `default` rather than
  the cluster's Kubernetes namespace.

The pin also brings in operator-rs' removal of `product-config`.

Update the usage guide, the kuttl manifests and extra/crds.yaml for the nested
transport schema.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Main bumps stackable-operator to 0.119.0, which requires the newer
feat/openlineage-crd operator-rs commit. Adapt to its reviewed API:
- HttpTransport::transport_url() is replaced by url(); keep emitting
  the origin as transport.url and the path as transport.endpoint.
- OpenLineageConfig::job_name was removed upstream, so drop jobName
  support (property, docs, kuttl assertion).
- The transport scheme is now https whenever tls is set.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@razvan
razvan marked this pull request as ready for review October 6, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: In Progress

Development

Successfully merging this pull request may close these issues.

1 participant