# ClickHouse

> Connect ClickHouse to sanda: what to prepare, the fields the connection form asks for, and how its data lands in your warehouse.

## Connect ClickHouse

:::steps
1. **Open the catalogue.** In the console, go to **Data · Connections** and press **New connection**.
2. **Choose ClickHouse.** It is listed under databases; you can also search for it by name.
3. **Fill in the form.** Enter the fields below. Credentials go straight to sanda’s sync engine and are never stored in sanda’s database.
4. **Choose what to sync.** Pick the tables you want, and a sync mode for each. See [choose what to sync](https://docs.sanda-os.com.au/connections/choose-tables).
5. **Run the first sync.** sanda tests the connection, then lands each table you chose in your warehouse.
:::

## Configuration fields

What the connection form asks for. Required fields are marked; the rest are optional.

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **Host** | string | Yes | The host endpoint of the Clickhouse cluster. |
| **Port** | integer | Yes | The port of the database. Default `8123`. |
| **Database** | string | Yes | The name of the database. |
| **Username** | string | Yes | The username which is used to access the database. |
| **Password** | string, secret | No | The password associated with this username. |
| **JDBC URL Parameters (Advanced)** | string | No | Additional properties to pass to the JDBC URL string when connecting to the database formatted as 'key=value' pairs separated by the symbol '&'. (Eg. key1=value1&key2=value2&key3=value3). |
| **SSL Connection** | boolean | No | Encrypt data using SSL. Default `true`. |
| **SSH Tunnel Method** | one of 3 options | No | Whether to initiate an SSH tunnel before connecting to the database, and if so, which kind of authentication to use. |

### SSH Tunnel Method

Whether to initiate an SSH tunnel before connecting to the database, and if so, which kind of authentication to use.

Choose one of the following. Each asks for its own fields.

**No Tunnel**

No further fields.

**SSH Key Authentication**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **SSH Tunnel Jump Server Host** | string | Yes | Hostname of the jump server host that allows inbound ssh tunnel. |
| **SSH Connection Port** | integer | Yes | Port on the proxy/jump server that accepts inbound ssh connections. Default `22`. |
| **SSH Login Username** | string | Yes | OS-level username for logging into the jump server host. |
| **SSH Private Key** | string, secret | Yes | OS-level user account ssh key credentials in RSA PEM format ( created with ssh-keygen -t rsa -m PEM -f myuser_rsa ). |

**Password Authentication**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **SSH Tunnel Jump Server Host** | string | Yes | Hostname of the jump server host that allows inbound ssh tunnel. |
| **SSH Connection Port** | integer | Yes | Port on the proxy/jump server that accepts inbound ssh connections. Default `22`. |
| **SSH Login Username** | string | Yes | OS-level username for logging into the jump server host. |
| **Password** | string, secret | Yes | OS-level password for logging into the jump server host. |


## Related

:::links
- [Sync modes](https://docs.sanda-os.com.au/connections/sync-modes): How sanda reads each table on every run.
- [Sync schedules](https://docs.sanda-os.com.au/connections/schedules): How often a connection runs.
- [Allowlist sanda’s address](https://docs.sanda-os.com.au/connections/allowlist): For a system behind a firewall.
- [Troubleshoot connections](https://docs.sanda-os.com.au/connections/troubleshooting): What an error means and how to fix it.
:::
