Customized Setup
Customer-managed VPC (BYO-VPC)
If you prefer to use an existing VPC to deploy ClickHouse BYOC instead of having ClickHouse Cloud provision a new VPC, follow the cloud-specific guide below. This approach provides greater control over your network configuration and allows you to integrate ClickHouse BYOC into your existing network infrastructure.
Customer-managed IAM roles
For organizations with advanced security requirements or strict compliance policies, you can provide your own IAM roles instead of having ClickHouse Cloud create them. This approach gives you complete control over IAM permissions and allows you to enforce your organization's security policies.
Customer-managed IAM roles are currently in private preview. If you require this capability, please contact ClickHouse Support to discuss your specific requirements and timeline.
When available, this feature will allow you to:
- Provide pre-configured IAM roles for ClickHouse Cloud to use
- Remove write permissions to IAM related permissions for
ClickHouseManagementRoleused for cross-account access - Maintain full control over role permissions and trust relationships
For information about the IAM roles that ClickHouse Cloud creates by default, see the BYOC Privilege Reference.