Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Managed Service for ClickHouse®
  • Getting started
    • Resource relationships
    • High availability clusters
    • Host classes
    • Networking in Managed Service for ClickHouse®
    • Quotas and limits
    • Storage
    • Backups
    • Replication
    • Coordination services
    • Dictionaries
    • Sharding
    • Maintenance
    • Managing users and access permissions
    • Supported clients
    • Memory management
    • ClickHouse® versioning policy
    • ClickHouse® settings
  • Access management
  • Pricing policy
  • Terraform reference
  • Yandex Monitoring metrics
  • Audit Trails events
  • Public materials
  • Release notes

In this article:

  • Host name and FQDN
  • Public access to a host
  • Security groups
  • Use cases
  1. Concepts
  2. Networking in Managed Service for ClickHouse®

Network and database clusters in Managed Service for ClickHouse®

Written by
Yandex Cloud
Updated at June 29, 2026
View in Markdown
  • Host name and FQDN
  • Public access to a host
  • Security groups
  • Use cases

When creating a ClickHouse® cluster, you can:

  • Specify a network for the cluster.

  • Specify subnets for each host in the cluster.

  • Request public access to connect to the cluster from outside Yandex Cloud.

You can create a cluster without specifying any subnets for hosts if the availability zone for each host contains only one subnet of the cluster network.

Host name and FQDNHost name and FQDN

Managed Service for ClickHouse® generates a name for each cluster host when creating it. This name will be the host's fully qualified domain name (FQDN). You cannot change the host name and, consequently, FQDN.

For how to get a host FQDN, see this guide.

To access a host within a single cloud network, use its FQDN. For more information, see this Yandex Virtual Private Cloud guide.

Public access to a hostPublic access to a host

You can make any cluster host accessible from outside Yandex Cloud by requesting public access when creating the host.

You cannot request a public address after creating the host; however, you can replace one of the existing hosts with a new one that has a public address.

When deleting a publicly accessible host, the allocated IP address is revoked.

Security groupsSecurity groups

Security groups follow the rule that all traffic is denied unless you explicitly allow it. To connect to a cluster, configure security group rules. These rules allow traffic from certain ports, IP addresses, or other security groups. For example, a VM will not be able to connect to a cluster in the following cases:

  • The VM is in the 10.128.0.0/16 subnet, whereas the inbound rules only allow 10.133.0.0/24.
  • The VM is in the 10.133.0.0/24 subnet but attempts to access a port not exposed in the security group rules.

For information on how to configure security groups, see Configuring security groups.

Tip

When connecting to a cluster from the same cloud network it resides in, configure security groups not just for the cluster but also for the host you are connecting from.

Features of using security groups:

  • Even if the cluster and host share the same security group, you still need rules allowing traffic between them to be able to connect to the cluster from the host. By default, such rules are included in the security group created along with the cloud network. These are the Self rules that allow unlimited traffic within the security group.

  • Security group settings only determine whether connecting to the cluster is possible. They do not affect cluster features, such as replication, sharding, and backups.

For more information, see this Virtual Private Cloud article.

Use casesUse cases

  • Setting up Yandex Cloud DNS to access managed database clusters from other cloud networks

ClickHouse® is a registered trademark of ClickHouse, Inc.

Was the article helpful?

Previous
Using deprecated host classes
Next
Quotas and limits
© 2026 Direct Cursus Technology L.L.C.