Skip to main content
POST
Validate BYOC infrastructure prerequisites
Beta Disclaimer: This beta endpoint is evolving; the API contract may change.

Preflight-validates that a cloud account is ready for BYOC infrastructure creation: simulates the cloud permissions ClickHouse needs (and, for BYO-VPC, checks the provided network resources) without creating anything. Takes the same parameters as infrastructure creation, so a payload that passes validation will not be rejected by create for the same inputs.

Permission

The API key must have the control-plane:organization:manage permission.

Authorizations

Authorization
string
header
required

Use key ID and key secret obtained in ClickHouse Cloud console: https://clickhouse.com/docs/cloud/manage/openapi

Path Parameters

organizationId
string<uuid>
required

ID of the requested organization.

Body

application/json
regionId
enum<string>
required

Region in which the BYOC infrastructure will be located

Available options:
ap-northeast-1,
ap-northeast-2,
ap-south-1,
ap-southeast-1,
ap-southeast-2,
ca-central-1,
eu-central-1,
eu-west-1,
eu-west-2,
il-central-1,
us-east-1,
us-east-2,
us-west-2,
us-east1,
us-central1,
europe-west2,
europe-west4,
asia-southeast1,
asia-northeast1,
eastus,
eastus2,
westus3,
germanywestcentral,
centralus
accountId
string
required

Cloud account ID the BYOC infrastructure is configured for: AWS account ID, GCP project ID, or Azure subscription ID

Example:

"123456789012"

availabilityZoneSuffixes
enum<string>[]

List of availability zone suffixes

Available options:
a,
b,
c,
d,
e,
f
vpcCidrRange
string

CIDR range for the ClickHouse-managed VPC. Mutually exclusive with the BYO-VPC fields (vpcId, privateSubnetIds, publicSubnetIds)

Example:

"10.0.0.0/16"

externalId
string

AWS only: ExternalID baked into the ClickHouse management role trust policy in your account

Example:

"ch-0a1b2c3d4e5f6789"

tenantId
string

Azure only (required for Azure regions): Entra tenant ID of the subscription

servicePrincipalClientId
string

Azure only (required for Azure regions): client ID of the service principal ClickHouse uses to manage the infrastructure

vpcId
string

BYO-VPC only (AWS and GCP): ID or network name of the customer-provided VPC to deploy into. Requires privateSubnetIds

Example:

"vpc-0abc1234def567890"

privateSubnetIds
string[]

BYO-VPC only: private subnet IDs or names (1-6 entries on AWS, exactly one on GCP)

publicSubnetIds
string[]

AWS BYO-VPC only: public subnet IDs (at most 6 entries)

gcpPodCidrRangeNames
string[]

GCP BYO-VPC only: secondary IP range names on the subnet to use for pod IPs. Omitted: all secondary ranges are used

gcpSharedVpcHostProjectId
string

GCP BYO-VPC only: Shared VPC host project owning the VPC and subnet, when different from accountId

tags
object

Response

Successful response

status
number

HTTP status code.

Example:

200

requestId
string<uuid>

Unique id assigned to every request. UUIDv4

result
object
Last modified on September 30, 2026