ClickHouse
ClickHouse Cloud, on-premises, Altinity Cloud.
Access mode: Read-only (typically)
Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).
Required information
| Field | Details |
|---|---|
| Host / IP | ClickHouse server FQDN or IP. Cloud: endpoint from ClickHouse Cloud console. |
| Ports | HTTP interface: 8123 (plain), 8443 (TLS). Native protocol: 9000 (plain), 9440 (TLS). Cloud uses 8443. |
| Database(s) | ClickHouse databases to access. |
| Credentials | Username + password. ClickHouse Cloud: default user or dedicated service user. |
| SSL | Required for Cloud. On-prem: depends on configuration. |
| Access level | Read-only: SELECT privilege on target databases/tables. SHOW privileges for introspection. |
Network considerations
ClickHouse Cloud: HTTPS over 8443. IP allowlisting configured in Cloud console.
On-premises: VPN or SSH tunnel. Both HTTP (8123/8443) and native (9000/9440) ports may be needed depending on access method.
Altinity Cloud: Managed Kubernetes-based. Standard cloud networking: VPC peering or IP allowlisting.
Cluster topology: If using a ClickHouse cluster with multiple shards/replicas, the load balancer endpoint is preferred over individual node addresses.
Trino access: Flume’s Lakehouse queries ClickHouse via the Trino ClickHouse connector over the native protocol (port 9000/9440).
Credential and auth management
Preferred: Dedicated read-only user. Create a ClickHouse user with READONLY = 1 setting and SELECT grants on target databases.
ClickHouse Cloud: Service user created in Cloud console with scoped privileges.
No OAuth/IAM support natively. Authentication is username + password or certificate-based.
Settings profiles: Assign the Flume user to a settings profile that limits max_execution_time, max_memory_usage, and max_rows_to_read to prevent runaway queries.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | curl https://<host>:8443/ping or clickhouse-client --host <host> --query 'SELECT 1' | Returns Ok. or 1 |
| Authentication | SELECT currentUser() | Returns service account name |
| Database access | SHOW TABLES FROM <db> | Lists tables |
| Read test | SELECT * FROM <db>.<table> LIMIT 1 | Returns a row |
| Introspection | SELECT name, engine FROM system.tables WHERE database = '<db>' | Lists tables with engine types |
| Permission check | SHOW GRANTS FOR <user> | Matches expected grants |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.