Skip to main content
Connect Supaboard to a ClickHouse database for direct querying, schema discovery, and AI-powered analysis.

Before you connect

Network access — Supaboard connects from a fixed set of egress IPs. Add them to your ClickHouse server or ClickHouse Cloud service’s IP allow-list before attempting a connection. The current IP list is shown inside the connector form under Whitelist IPs. Database user permissions — The user you provide needs at minimum:
  • SELECT privilege on the target database and tables
See Recommended database user permissions for the exact SQL.

Connection fields

Port note — Supaboard connects over the native TCP protocol on port 9000. This is different from the HTTP interface (port 8123) and the HTTPS interface (port 8443). ClickHouse Cloud uses port 9440 for secure native TCP — check your Cloud service details if 9000 does not connect.

Finding your connection details

ClickHouse Cloud

  1. Open clickhouse.cloud and select your service.
  2. On the service detail page, go to Connect.
  3. Select Native as the connection method.
  4. Copy the Host (format: xxxxx.clickhouse.cloud) and Port (typically 9440 for secure native TCP on ClickHouse Cloud).
  5. Use the default user or a custom user you have created.
  6. Under Security → IP Access List, add each Supaboard egress IP to allow connections.
ClickHouse Cloud uses port 9440 (TLS-enabled native TCP), not 9000. Update the Port field accordingly.
Documentation: ClickHouse Cloud connection details · IP access list

Self-hosted ClickHouse

  1. Your Host is the server’s IP address or hostname.
  2. The default native TCP Port is 9000.
  3. Check /etc/clickhouse-server/config.xml (or config.d/) for any custom port configuration.
  4. Ensure the server’s firewall allows inbound TCP on port 9000 from Supaboard egress IPs.
Documentation: ClickHouse server configuration · Access control and account management

IPsec Site-to-Site VPN

If your database lives on a private network, you can peer your VPN gateway with Supaboard over IKEv2 IPsec instead of exposing the database or running a bastion host. Enable the Use IPsec site-to-site VPN toggle in the connector form. Checklist:
  • Your VPN gateway has one IKEv2 + pre-shared-key tunnel per Supaboard IP (the IPs shown under Whitelist IPs)
  • The gateway allows UDP 500, UDP 4500, and ESP (IP protocol 50) from those IPs
  • The Host field is the database’s private IP address — private DNS names don’t resolve from Supaboard
  • Enter the database name manually — auto-discovery doesn’t run through the VPN before the connection is saved
Gateway settings, supported ciphers, a strongSwan example, and troubleshooting: IPsec Site-to-Site VPN guide.

Recommended database user permissions

Replace your_database with the target database name. For multiple databases, repeat the GRANT SELECT line for each one.

Troubleshooting

Last modified on September 2, 2026