Skip to main content
Skip to main content
Edit this page

Customized Setup

Customer-managed VPC (BYO-VPC)

If you prefer to use an existing VPC to deploy ClickHouse BYOC instead of having ClickHouse Cloud provision a new VPC, follow the cloud-specific guide below. This approach provides greater control over your network configuration and allows you to integrate ClickHouse BYOC into your existing network infrastructure.

Customer-managed IAM roles

For organizations with advanced security requirements or strict compliance policies, you can provide your own IAM roles instead of having ClickHouse Cloud create them. This approach gives you complete control over IAM permissions and allows you to enforce your organization's security policies.

References

Customer-managed IAM roles are currently in private preview. If you require this capability, please contact ClickHouse Support to discuss your specific requirements and timeline.

When available, this feature will allow you to:

  • Provide pre-configured IAM roles for ClickHouse Cloud to use
  • Remove write permissions to IAM related permissions for ClickHouseManagementRole used for cross-account access
  • Maintain full control over role permissions and trust relationships

For information about the IAM roles that ClickHouse Cloud creates by default, see the BYOC Privilege Reference.