Skip to main content

Public IP address in a ClickHouse® cluster

Public IP addresses are static IP addresses that can be connected to cluster nodes in a private network to configure access to them from the internet. Addresses are connected to all nodes in a shard simultaneously, with a separate public IP address for each node. If you add a node to a shard where all nodes already have IP addresses, the new node will also be assigned a public IP address.

To connect a public IP address, a cloud router with internet access is used. The public IP address is associated with the private IP address of the cluster node. Inbound traffic is handled by the cloud router — the router performs 1:1 NAT via an external IP address allocated when connecting the router to the internet. Inbound traffic can be filtered using a cloud firewall or security group.

A public IP address can be connected:

If necessary, you can disconnect the public IP address for the entire shard.

Requirements for a private subnet to connect a public IP address

  • the subnet must contain a cloud router with an internet connection;
  • the cloud router IP address must be the default gateway in the cluster subnet.

If the router is already connected to the cluster subnet, but its IP address does not match the gateway, you will not be able to connect a public IP address. In this case, disconnect the subnet from the cloud router, then connect it again and specify the subnet gateway address.

Prepare a private subnet for connecting a public IP address

  1. Create a cloud router with an internet connection.
  2. Connect the private subnet to the cloud router.

1. Create a cloud router with an internet connection

  1. In the control panel, in the top menu, click Products and select Cloud Servers.
  2. Go to Network → Cloud Routers.
  3. Click Create router.
  4. Select the location where the cloud router will be created.
  5. Select the router type.
  6. Enter the router name.
  7. Select the Connect router to internet checkbox — a public IP address will be allocated for the router.
  8. Click Create.

2. Connect a private subnet to the cloud router

  1. In the control panel, from the top menu, click Products and select Cloud Servers.
  2. Go to the Network section → Cloud Routers tab.
  3. Open the router card.
  4. Click Connect subnet.
  5. Select a private subnet.
  6. Optional: enter the router IP address. If you do not specify an IP address, it will be automatically selected from available subnet addresses. The cloud router IP address must match the default gateway of the private subnet. You can check the gateway in the control panel: from the top menu, click Products → Cloud Servers → Network → the Private Networks tab → network page → the Subnets tab → subnet card → the Automatic network configuration block → the Subnet gateway field.
  7. Click Connect.

Connect a public IP address

  1. In the Control panel, in the top menu, click Products and select Cloud Databases.

  2. Open the tab Active.

  3. Open the database cluster page → tab Settings.

  4. In the shard card, in the Public access line, click .

  5. If the cluster subnet meets the requirements, click Connect.

  6. If the cluster subnet does not meet the requirements:

    6.1.Select an existing cloud router or create a new one. The cluster subnet will be connected to the router. If you select an existing router without internet access or a new router, it will automatically be connected to the internet.

    6.2.Click Connect router and address.

Public IP addresses will be connected to all nodes in the shard simultaneously, with a separate public IP address for each node.

Disconnect a public IP address

  1. In the Control panel, in the top menu, click Products and select Cloud Databases.
  2. Open the tab Active.
  3. Open the database cluster page → tab Settings.
  4. In the shard card, in the Public access line, click .
  5. Click Disconnect. Public IP addresses will be disconnected from all nodes in the shard simultaneously.

ClickHouse® is a registered trademark of ClickHouse, Inc. https://clickhouse.com.