
ClickHouse
Protect ClickHouse HTTP endpoints and native database connections with separate Pomerium routes.
Overview
ClickHouse is an open-source column-oriented database system. It exposes an HTTP interface on ports such as 8123 or 8443 and a native TCP interface on ports such as 9000 or 9440. Each interface needs a route that matches its protocol.
ClickHouse can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to ClickHouse. ClickHouse remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.
Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.
Create one HTTPS route for the HTTP interface and a separate TCP route for the native interface. Confirm the exact secure ports and certificates used by the deployment.
Example
Analysts use a Pomerium HTTPS route for the ClickHouse HTTP interface. A database client uses a separate Pomerium TCP tunnel for the native protocol. ClickHouse keeps database users, roles, and query permissions.
Considerations
- Do not point HTTP clients and native clients at one route. Their protocols and ports are different.
- Preserve ClickHouse TLS and database authentication. Unattended clients need a reviewed noninteractive Pomerium flow.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
Sources and official resources
- ClickHouseOfficial website
- ClickHouse HTTP interfaceOfficial documentation
- ClickHouse native TCP interfacePrimary source
- ClickHouse network portsPrimary source
- Pomerium HTTP routingPomerium documentation
- Pomerium non-HTTP accessPomerium documentation
- Pomerium clientsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
