Prepare a read-only ClickHouse user
Grafana runs the queries you write exactly as written and does not restrict SQL. To keep your data safe, connect Grafana with a read-only ClickHouse user so a mistaken or malicious query can’t modify or drop tables.
There’s one important nuance: the ClickHouse data source client sets max_execution_time on every query to enforce the query timeout. A plain readonly = 1 user is blocked from changing any setting, so you must also allow that one setting to change in read-only mode. If you skip this, the connection test can pass but queries fail at runtime with Cannot modify 'max_execution_time': Setting is locked.
Before you begin
- Confirm your ClickHouse server is running and reachable from Grafana Cloud on its query port (Native
9000/9440, or HTTP8123/8443). - You’ll need an account that can create users and alter settings profiles in ClickHouse.
If your ClickHouse administrator has already given you a read-only user and connection details, you can skip ahead to the next milestone.
To prepare a read-only user, complete the following steps.
Connect to your ClickHouse server as an administrative user, for example with
clickhouse-client:clickhouse-client --user default --passwordCreate a dedicated user for Grafana:
CREATE USER grafana_reader IDENTIFIED BY 'REPLACE_WITH_STRONG_PASSWORD';Grant read access to the databases you want to query. For example, to grant read access to a single database:
GRANT SELECT ON otel.* TO grafana_reader;Create a settings profile that keeps the user read-only but lets the plugin change
max_execution_time:CREATE SETTINGS PROFILE grafana_reader_profile SETTINGS readonly = 1, max_execution_time CHANGEABLE_IN_READONLY TO grafana_reader;Verify the user can run a query with the timeout setting applied:
clickhouse-client --user grafana_reader --password --query "SELECT 1 SETTINGS max_execution_time = 30"
Note the host, port, user name, and password. You’ll enter these when you configure the data source.
In the next milestone, you’ll add the ClickHouse data source in Grafana Cloud.