Skip to main content
See All Integrations

ClickHouse

Protect ClickHouse HTTP endpoints and native database connections with separate Pomerium routes.

Separate standard routes by protocol

Categories
AI and Data, Databases

Overview

ClickHouse is an open-source column-oriented database system. It exposes an HTTP interface on ports such as 8123 or 8443 and a native TCP interface on ports such as 9000 or 9440. Each interface needs a route that matches its protocol.

ClickHouse can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to ClickHouse. ClickHouse remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.

Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.

Create one HTTPS route for the HTTP interface and a separate TCP route for the native interface. Confirm the exact secure ports and certificates used by the deployment.

Example

Analysts use a Pomerium HTTPS route for the ClickHouse HTTP interface. A database client uses a separate Pomerium TCP tunnel for the native protocol. ClickHouse keeps database users, roles, and query permissions.

Considerations

  • Do not point HTTP clients and native clients at one route. Their protocols and ports are different.
  • Preserve ClickHouse TLS and database authentication. Unattended clients need a reviewed noninteractive Pomerium flow.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect access to PostgreSQL services through Pomerium TCP routes.

  • Protect access to MySQL services through Pomerium TCP routes.

  • Protect access to Apache Superset dashboards and data exploration as an upstream web application.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo