Security
Security
San Tran
Dec, 2023
Speakers
San Tran
2
ClickHouse Cloud
01 Security features
journey
3
Timeline
● IP Filtering
● Username & password for
authentication 😅
● Workload isolation &
Security controls inside
K8s & Cloud environment
4
Timeline
● IP Filtering ● MFA
● Username & password ● Private Link
authentication ● SLQConsole using
● Workload isolation & Certificate Authentication
Security controls inside
K8s & Cloud environment
5
Timeline
6
Timeline
7
02 Let’s get to
the details…
8
Workload isolation
9
Workload Isolation - ClickPipes
ClickHouse
ClickPipe
10
Console Certificate Authentication
11
Console Certificate Authentication
SQLConsole/Arctype
12
Say NO to passing client
credentials where we can!
13
14
How cert-auth works end to end with ClickHouse for HTTP Protocol?
Server check against the database for the Fail if CN or username not
username & the common name (CN) of the matching or user does not have
certificate enough grant
15 15
Console Certificate Authentication - high level design
16 16
Customer Managed
Encryption Key aka
BYOK(Bring Your Own Key)
● Support for AWS KMS(Key Management
System) with GKS and AKS support
coming soon.
● Advanced protection over data at rest
by allowing users to manage keys that
control encryption/decryption of data
● Making use of envelope encryption
technique to enable multi-cloud support
& reduce operational overhead
17
Question?
https://trust.clickhouse.com/
18