Skip to content

fix(hosting): deploy ClickHouse from the official image instead of Bitnami#4249

Open
matt-aitken wants to merge 7 commits into
mainfrom
fix/self-hosting-official-clickhouse
Open

fix(hosting): deploy ClickHouse from the official image instead of Bitnami#4249
matt-aitken wants to merge 7 commits into
mainfrom
fix/self-hosting-official-clickhouse

Conversation

@matt-aitken

@matt-aitken matt-aitken commented Jul 13, 2026

Copy link
Copy Markdown
Member

Summary

Self-hosted deployments now run ClickHouse from the official clickhouse/clickhouse-server image instead of bitnamilegacy/clickhouse. Bitnami's free image catalog is EOL and the frozen legacy archive tops out at ClickHouse 25.7.5, below the 25.8 minimum the platform requires since v4.5.0, which broke every ClickHouse insert on chart-bundled deployments. Both stacks now default to 26.2, the same version the platform is developed and tested against.

Existing deployments keep their ClickHouse data with no manual migration.

Fixes #4197.

Details

Docker Compose: the clickhouse service uses the official image with its native env vars, plus the recommended nofile ulimits. It reuses the same named volume as before: a data-paths.xml config override points ClickHouse at the data/ subdirectory of the volume, which is exactly the layout the Bitnami image used, so old volumes work in place (including SQL-created users) and fresh installs get the identical layout. The service follows the required-secrets model: CLICKHOUSE_PASSWORD must be set, matching the other services.

Helm chart: the Bitnami ClickHouse subchart is replaced by a chart-owned single-node StatefulSet and Service running the official image (non-root, HTTP /ping probes, config overrides mounted into config.d, and the same data-paths.xml layout compatibility). On upgrade, the chart automatically adopts the data PVC left behind by the old subchart (data-<release>-clickhouse-shard0-0) via lookup, and fsGroup relabeling handles the uid change on first mount. Both the ClickHouse server and the webapp read the password from the same chart-managed datastore secret (auto-generated and retained across upgrades), so the server credential and the app's connection URL always match. Existing clickhouse.* values keep working: auth (including existingSecret/existingSecretKey), persistence (including global.storageClass), resources, secure, external.*, configdFiles, and now nodeSelector/tolerations/affinity. Bitnami-only keys (shards, replicaCount, keeper, resourcesPreset) are gone; default resources requests/limits match what the old preset applied. The docs state the 25.8 minimum for bring-your-own ClickHouse.

Upgrade caveats

An adversarial review of the upgrade path found a few cohorts that need awareness (all documented):

  • GitOps tools that render with helm template (no cluster access): PVC auto-detection can't run, so clickhouse.persistence.existingClaim must be set to the old PVC name or ClickHouse starts on a fresh empty volume. Documented in the values file and the Kubernetes self-hosting docs. Tools that run real helm installs (e.g. Flux) adopt automatically.
  • A pinned CLICKHOUSE_IMAGE_TAG pointing at a Bitnami tag must be updated to an official image tag; documented in the Docker self-hosting docs.
  • Storage without fsGroup support (NFS, hostPath): set clickhouse.volumePermissions.enabled: true for a one-time ownership-fixing init container.
  • Rollback is not automatic: once the official image has run, file ownership changes and the Bitnami image can no longer read the volume without a manual chown, and ClickHouse does not support downgrades across the version gap.

Verification

  • Full upgrade simulation for Compose, twice (before and after rebasing onto the required-secrets release): booted the ClickHouse service from the old compose file on main (Bitnami), wrote thousands of rows, then brought the same project up with this branch's compose file. The official 26.2 server came up healthy on the same volume with all rows intact, SQL-created users working, and writes succeeding.
  • Adoption scenarios tested against real containers: old volume + root entrypoint (Compose), old volume owned by the Bitnami uid + non-root 101 with fsGroup-style group permissions (Kubernetes), and fresh volumes for both.
  • helm lint, helm template (default values, existingClaim set, external ClickHouse, volumePermissions/scheduling toggles, and the production example) and kubeconform all pass, mirroring the release CI steps. The rendered webapp Deployment and ClickHouse StatefulSet resolve to the same datastore secret key.
  • Inserts using input_format_json_infer_array_of_dynamic_from_array_of_different_types (the setting that fails on 25.7.5) succeed on the upgraded volume.

@changeset-bot

changeset-bot Bot commented Jul 13, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: f7da3f8

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

ClickHouse configuration is updated across self-hosting documentation, Docker Compose, and Helm. Docker now uses the official image, updated credentials and paths, file limits, and a compatible data-path configuration. Helm replaces the Bitnami dependency with custom ClickHouse resources, pinned image settings, explicit ports, probes, persistence, security settings, generated URLs, and updated tests. Documentation records the ClickHouse 25.8+ requirement and external service port key.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The PR meets #4197 by raising ClickHouse to 26.2, documenting the 25.8 floor, and replacing the Bitnami chart/image.
Out of Scope Changes check ✅ Passed The changes stay focused on the ClickHouse image swap, Helm/Compose wiring, and docs/tests needed for that migration.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check ✅ Passed The title clearly matches the main change: replacing Bitnami ClickHouse with the official image.
Description check ✅ Passed The description is detailed and includes the issue, summary, details, upgrade caveats, and verification, though it doesn't follow the exact template sections.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/self-hosting-official-clickhouse

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

🧭 Helm Chart Prerelease Published

Version: 4.5.7-pr4249.f7da3f8

Install:

helm upgrade --install trigger \
  oci://ghcr.io/triggerdotdev/charts/trigger \
  --version "4.5.7-pr4249.f7da3f8"

⚠️ This is a prerelease for testing. Do not use in production.

devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

@matt-aitken
matt-aitken force-pushed the fix/self-hosting-official-clickhouse branch from e2e7e33 to 4608012 Compare July 13, 2026 16:01
coderabbitai[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

…tnami

The Bitnami free image catalog is EOL and its frozen bitnamilegacy
archive tops out at ClickHouse 25.7.5, below the 25.8 floor the
platform requires since v4.5.0. The Docker Compose stack and the Helm
chart now run the official clickhouse/clickhouse-server image at 26.2,
the same version the platform is developed and tested against. The Helm
chart deploys ClickHouse with a chart-owned StatefulSet instead of the
Bitnami subchart.

Existing deployments keep their data with no manual steps: a config
override keeps the on-disk layout compatible with volumes created by
the Bitnami-based setup, Compose reuses the same named volume, and the
Helm chart automatically adopts the data PVC left behind by the old
subchart.
…e inline credentials

The chart-deployed ClickHouse now reads CLICKHOUSE_PASSWORD from a
chart-owned Secret instead of a plaintext env value in the pod spec, and
the CLICKHOUSE_URL helpers percent-encode inline usernames and passwords
so special characters no longer produce an unparseable URL.
…ntials

urlquery encodes spaces as plus signs, which URL userinfo decoding keeps
literal. A shared urlencode helper rewrites them to %20 (a real plus
already encodes as %2B), so passwords containing spaces now work.
… restart checksum

The data-paths.xml default now lives in a shared helper used by both the
ConfigMap and the pod checksum annotation, so changing it in a future
chart version restarts the pod (subPath mounts do not update in place).
@matt-aitken
matt-aitken force-pushed the fix/self-hosting-official-clickhouse branch from ea85282 to 228c4a3 Compare July 24, 2026 12:30
@pkg-pr-new

pkg-pr-new Bot commented Jul 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@trigger.dev/build

npm i https://pkg.pr.new/@trigger.dev/build@228c4a3

trigger.dev

npm i https://pkg.pr.new/trigger.dev@228c4a3

@trigger.dev/core

npm i https://pkg.pr.new/@trigger.dev/core@228c4a3

@trigger.dev/python

npm i https://pkg.pr.new/@trigger.dev/python@228c4a3

@trigger.dev/react-hooks

npm i https://pkg.pr.new/@trigger.dev/react-hooks@228c4a3

@trigger.dev/redis-worker

npm i https://pkg.pr.new/@trigger.dev/redis-worker@228c4a3

@trigger.dev/rsc

npm i https://pkg.pr.new/@trigger.dev/rsc@228c4a3

@trigger.dev/schema-to-json

npm i https://pkg.pr.new/@trigger.dev/schema-to-json@228c4a3

@trigger.dev/sdk

npm i https://pkg.pr.new/@trigger.dev/sdk@228c4a3

commit: 228c4a3

devin-ai-integration[bot]

This comment was marked as resolved.

…lickHouse chart

Keeps existing self-hosted deployments working without manual steps:

- Default resource requests/limits match the preset the Bitnami subchart
  applied, so the ClickHouse pod doesn't silently become BestEffort.
- nodeSelector, tolerations, and affinity pass through to the StatefulSet
  for deployments that schedule ClickHouse onto dedicated nodes.
- Optional volumePermissions init container fixes data-volume ownership
  on storage without fsGroup support (NFS, hostPath).
- The helm test reads the password from the datastore secret instead of
  the usually-empty values key, and the pinned-password restart checksum
  is omitted when the password is auto-generated.
- Docs cover updating a pinned CLICKHOUSE_IMAGE_TAG to an official tag
  and the GitOps existingClaim step in more detail.
devin-ai-integration[bot]

This comment was marked as resolved.

Adds the recovery path for GitOps renders that missed existingClaim,
the pinned Bitnami image note for the Helm chart, the single-node
clustering note, and the one-way rollback caveat for Docker Compose.
devin-ai-integration[bot]

This comment was marked as resolved.

…rtup probe

The webapp now resolves CLICKHOUSE_PASSWORD through the same
auth.existingSecret/existingSecretKey values the bundled server uses,
so pointing the chart at a custom credentials secret keeps both sides
on the same password. A startup probe gives ClickHouse up to ten
minutes to load metadata on first boot with a large adopted data
volume before liveness checks begin.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

v4.5.0 ClickHouse writers require CH ≥25.8, but the Helm chart still bundles ClickHouse 25.7.5 → every insert fails with UNKNOWN_SETTING

1 participant