This guide applies only to ClickHouse Cloud services on AWS. For self-hosted ClickHouse in your own AWS network, follow the AWS PrivateLink guide.
Requirements
To follow the steps in this guide, you’ll need Organization Admin permissions in Omni, plus the following in ClickHouse Cloud:- A service deployed on AWS
- Permissions that allow you to view the service’s PrivateLink settings and manage private endpoints for your organization
Regions
Your ClickHouse Cloud service doesn’t have to be in the same region as your Omni instance. However, PrivateLink isn’t available inap-east-2 and mx-central-1 regions. These regions don’t support cross-region PrivateLink, and Omni has no AWS environment in either region.
Setup
Retrieve your ClickHouse PrivateLink details
Omni needs two values from your ClickHouse Cloud service:
- VPC Endpoint Service (
endpointServiceId), which starts withcom.amazonaws.vpce - Private DNS hostname (
privateDnsHostname), which looks likeabc123.eu-west-1.vpce.aws.clickhouse.cloud
Contact Omni support
Contact Omni support with the following information:
- The VPC endpoint service name, for example
com.amazonaws.vpce.eu-west-1.vpce-svc-XXXXXXXXXX - The private DNS hostname, for example
abc123.eu-west-1.vpce.aws.clickhouse.cloud - The AWS region where your ClickHouse Cloud service is deployed
- The port your service will be listening on, typically
8443 - Technical contact details, in case of connection difficulties
What’s next?
We will need you to authorize Omni’s endpoint after we create it. The endpoint ID doesn’t exist until then, so there’s nothing to add to ClickHouse before you contact us.-
Omni creates the VPC endpoint and sends you the endpoint ID, which starts with
vpce-. - Register the endpoint ID for your ClickHouse Cloud organization.
- Add the registered endpoint to the private endpoint allowlist of each ClickHouse service Omni should reach. In the ClickHouse Cloud console, this is under the service’s Settings > Set up private endpoint.
- Omni finishes wiring up the connection and adds it to your Omni instance.

