Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / ClickHouse

Live

DCA Hardened Analytics Database for ClickHouse — Support & Quick Start

A hardened, CVE-patched virtual machine image running ClickHouse® — the open-source, column-oriented OLAP database built for real-time analytics over billions of rows — on Oracle Linux 9.

At a glance

StatusLive on Oracle Cloud Marketplace
Version26.8.6.5
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8123/tcp, 9000/tcp
CategoryDatabases
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. ClickHouse runs as a systemd service bound to loopback (HTTP 8123, native 9000). Check status:
    sudo systemctl status clickhouse-server
  3. The default user's password was generated uniquely for this instance at first boot. Read it (root only):
    sudo cat /root/.clickhouse_default_credentials
  4. Smoke-test from the instance:
    clickhouse-client --password '<password>' -q 'SELECT version()'
    curl -s -u default:'<password>' 'http://127.0.0.1:8123/?query=SELECT%201'
  5. To reach the server from your application tier, expose it deliberately — create /etc/clickhouse-server/config.d/listen.xml containing:
    <clickhouse><listen_host>0.0.0.0</listen_host></clickhouse>
    then: sudo systemctl restart clickhouse-server

    Ports 8123 and 9000 are already permitted in the host firewall. Restrict them in your VCN security list to the application tier's CIDR; never expose them to the internet. The MySQL (9004), PostgreSQL (9005) and inter-server (9009) ports remain blocked by the host firewall even after this change.

  6. Data lives in /var/lib/clickhouse. For anything beyond evaluation, attach a block volume and point the path setting at it via /etc/clickhouse-server/config.d/ before loading data.
  7. Rotate the default password at any time by writing a new sha256 hex digest into /etc/clickhouse-server/users.d/default-password.xml and restarting the service, or create named users with clickhouse-client (CREATE USER ...).

The image is CVE-patched at build time. Apply ongoing updates, including ClickHouse LTS fixes, with:

sudo dnf -y update (the -y also accepts the ClickHouse repository signing key on first use)

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

ClickHouse® is a registered trademark of ClickHouse, Inc. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by ClickHouse, Inc.