Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / ClickHouse (Arm64)

In Oracle review

DCA Hardened Analytics Database for ClickHouse (Arm64) — Support & Quick Start

A hardened, CVE-patched virtual machine image running ClickHouse® — the open-source, column-oriented OLAP database built for real-time analytics over billions of rows — on Oracle Linux 9 for Arm64, built for OCI's Ampere A1 shapes.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version26.8.6.5
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8123/tcp, 9000/tcp
CategoryDatabases
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. ClickHouse runs as a systemd service bound to loopback (HTTP 8123, native 9000). Check status:
    sudo systemctl status clickhouse-server
  3. The default user's password was generated uniquely for this instance at first boot. Read it (root only):
    sudo cat /root/.clickhouse_default_credentials
  4. Smoke-test from the instance:
    clickhouse-client --password 'YOUR_PASSWORD' -q 'SELECT version()'
    curl -s -u default:'YOUR_PASSWORD' 'http://127.0.0.1:8123/?query=SELECT%201'
  5. To reach the server from your application tier, expose it deliberately with a config.d drop-in and a restart:
    echo 'listen_host: 0.0.0.0' | sudo tee /etc/clickhouse-server/config.d/listen.yaml && sudo systemctl restart clickhouse-server

    Ports 8123 and 9000 are already permitted in the host firewall. Restrict them in your VCN security list to the application tier's CIDR; never expose them to the internet. The MySQL (9004), PostgreSQL (9005) and inter-server (9009) ports remain blocked by the host firewall even after this change.

  6. Data lives in /var/lib/clickhouse. For anything beyond evaluation, attach a block volume and point the path setting at it via /etc/clickhouse-server/config.d/ before loading data.
  7. Rotate the default password at any time by writing a new sha256 hex digest into /etc/clickhouse-server/users.d/default-password.xml and restarting the service, or create named users with clickhouse-client (CREATE USER ...).

The image is CVE-patched at build time. Apply ongoing updates, including ClickHouse LTS fixes, with:

sudo dnf -y update (the -y also accepts the ClickHouse repository signing key on first use)

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

ClickHouse® is a registered trademark of ClickHouse, Inc. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by ClickHouse, Inc.