Path

Create a read-only ClickHouse user that Grafana can use, and gather your connection details.

Estimated time: 2 min

Prepare a read-only ClickHouse user

Grafana runs the queries you write exactly as written and does not restrict SQL. To keep your data safe, connect Grafana with a read-only ClickHouse user so a mistaken or malicious query can’t modify or drop tables.

There’s one important nuance: the ClickHouse data source client sets max_execution_time on every query to enforce the query timeout. A plain readonly = 1 user is blocked from changing any setting, so you must also allow that one setting to change in read-only mode. If you skip this, the connection test can pass but queries fail at runtime with Cannot modify 'max_execution_time': Setting is locked.

Before you begin

  • Confirm your ClickHouse server is running and reachable from Grafana Cloud on its query port (Native 9000/9440, or HTTP 8123/8443).
  • You’ll need an account that can create users and alter settings profiles in ClickHouse.

If your ClickHouse administrator has already given you a read-only user and connection details, you can skip ahead to the next milestone.

To prepare a read-only user, complete the following steps.

  1. Connect to your ClickHouse server as an administrative user, for example with clickhouse-client:

    Bash
    clickhouse-client --user default --password
  2. Create a dedicated user for Grafana:

    SQL
    CREATE USER grafana_reader IDENTIFIED BY 'REPLACE_WITH_STRONG_PASSWORD';
  3. Grant read access to the databases you want to query. For example, to grant read access to a single database:

    SQL
    GRANT SELECT ON otel.* TO grafana_reader;
  4. Create a settings profile that keeps the user read-only but lets the plugin change max_execution_time:

    SQL
    CREATE SETTINGS PROFILE grafana_reader_profile
      SETTINGS readonly = 1,
               max_execution_time CHANGEABLE_IN_READONLY
      TO grafana_reader;
  5. Verify the user can run a query with the timeout setting applied:

    Bash
    clickhouse-client --user grafana_reader --password --query "SELECT 1 SETTINGS max_execution_time = 30"

Note the host, port, user name, and password. You’ll enter these when you configure the data source.

In the next milestone, you’ll add the ClickHouse data source in Grafana Cloud.


More to explore (optional)