ClickHouse Cloud
Connect ClickHouse Cloud as your access review source using a CloudAPI key ID and secret so that the platform can list your organization’s members.
The platform reads your ClickHouse Cloud organization members through ClickHouse CloudAPI so you can check who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- The Admin organizational role in ClickHouse Cloud (Admin performs all administrative tasks for the organization, including the creation of API keys)
- A key whose assigned role carries access to the organizational level so that it can list the members of the organization. Member organization role, cannot read them
- The two halves of the key. Key ID şi a Key secretwhich the console displays only once
Collected Fields
Section entitled “Collected Fields”| the platform field | ClickHouse Cloud field | Notes |
|---|---|---|
| Name | name |
Return to email address |
email |
A member without an email address is ignored | |
| Role | assignedRoles[].roleName |
System and custom roles assigned to the member. Returns to the depreciated field role for a member with no one: admin → Admin, developer → Development |
| Admin | assignedRoles[].roleName |
Flags as administrator when a assigned role is named Admin. No assigned roles, flags when depreciated role is admin. Match is on the exact name, so a particular role such as Billing Admin does not matter |
| Status | Not supported | |
| MFA | Not supported | |
| Last login | Not supported | |
| External ID | userId |
Stable ID used to track the account during reviews. remains the same when a user belongs to several organizations |
| Created at | joinedAt |
When a member joins the organization |
ClickHouse Cloud marks role as depreciated and indicates customersAPIla assignedRoles. For an organization that has migrated to custom roles, role is frozen to its pre-migration value, which is why ZebraBytecals first assignedRoles.
Step 1: Create a ClickHouse Cloud API Key
Section titled “Step 1: Create a ClickHouse CloudAPIKey”- In the ClickHouse Cloud consoleSigned as an organization Admin, open the API Keys tab in the left menu.
- Click New API Key (until the organization has the first key, the page displays a creation prompt instead of the button), names it (e.g., ___ZBT_I18N_RUNTIME_BLOCK_189__), assigns an access role at the organization level, and sets an expiration date.
- Click Generate API Key, then copy the Key ID şi a Key secretThey are only displayed on this screen.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find ClickHouse Cloud, click API Key, paste the Key ID şi a Key secret Added by a column (
keyId:keySecret), and click on Connect.
Name of Source ClickHouse Cloud And attract members of your organization to your campaigns.
Troubleshooting
Section “Troubleshooting”- Key rejected. Put both halves united by a column,
keyId:keySecret, without spaces. the key ID alone or the key secret alone fails to authenticate HTTP Basic, as does a key that has been disabled or passed the expiration date. - “It is not associated with any organization.” A key belongs exactly to an organization, and ClickHouse only returns that key.
- No members appear. A key limited to a service role, such as
Basic service API reader, reaches the services, but not the members of the organization. - Applications fail from the platform, but the key works locally. If the key is created with Specific locations under Allow access to this key, only the IP addresses you have listed can use it. Remove the restriction for ZebraByteCloud. For a self-hosted deployment, you can instead permit the fixed addresses of the deployment.