Step 1: Create a User and a Sandbox Database
Create a dedicated database user that Pavo will use.
Run the following as an admin (the
default user on ClickHouse Cloud, or any user with ACCESS MANAGEMENT). Use a strong password: 12+ characters, upper and lower case, a number or symbol.
pavo_analysisis Pavo’s analysis database: the only place Pavo writes (scratch tables during analysis), the same role as the analysis schema on Databricks.VALID UNTILis optional but recommended. Pick your rotation date; the connector will start failing auth after it and Pavo will alert.- To rotate:
ALTER USER pavo_analytics IDENTIFIED BY '<new-password>';then update the password in Pavo. To revoke:DROP USER pavo_analytics;
Step 2: Grant ClickHouse Permissions
Grant the role read access to the databases Pavo should see, write access confined to the sandbox, and (Cloud only) the ability to read query history from every replica.- To limit Pavo to specific databases, replace
SELECT ON *.*with oneGRANT SELECT ON <database>.* TO pavo_analytics_role;per database, plusGRANT SELECT ON pavo_analysis.* TO pavo_analytics_role;(so Pavo can read back what it writes there),GRANT SELECT ON system.query_log* TO pavo_analytics_role;(the wildcard coversquery_log_0,query_log_1, … that upgrades leave behind, so older history is not lost) andGRANT SELECT ON system.clusters TO pavo_analytics_role;— one statement each, ClickHouse does not accept a comma list with a wildcard - Without the
system.query_loggrant Pavo still syncs tables and columns and skips query history. - Without
REMOTE, Pavo still reads query history from the node it connects to. Multi-replica Cloud services then show partial history. system.clusterslets Pavo detect which cluster to read query history across. If the user cannot read it, or the server belongs to more than one cluster, set the Cluster field in Step 5 instead.
Step 3: Allow Network Access
ClickHouse Cloud: new services default to “Allow from anywhere”. To confirm:- Open the service in the ClickHouse Cloud console → Settings → Security → IP access list
- “Allow from anywhere” means nothing to do. If it lists specific addresses, tell your Pavo contact
Step 4: Verify the User (optional)
From any machine withcurl:
- A number comes back → the user works.
Authentication failed→ check user / password (Step 1).- Connection timeout → check network access (Step 3).
Not enough privileges→ theREMOTEgrant is missing (Step 2).
Step 5: Share Connection Details
In Pavo, go to Connectors → ClickHouse, fill in the fields below and click Connect. Pavo runsSELECT 1 on save and rejects the connector if it cannot connect.
To find your host on ClickHouse Cloud:
- Open the service → Connect
- Select HTTPS
- Copy the hostname (without
https://and port)