> ## Documentation Index
> Fetch the complete documentation index at: https://private-7c7dfe99-vortex-format.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate BYOC infrastructure prerequisites

> **Disclaimer:** This beta endpoint is evolving; the API contract may change. <br /><br /> Preflight-validates that a cloud account is ready for BYOC infrastructure creation: simulates the cloud permissions ClickHouse needs (and, for BYO-VPC, checks the provided network resources) without creating anything. Takes the same parameters as infrastructure creation, so a payload that passes validation will not be rejected by create for the same inputs.

<span data-endpoint-badge="Beta"><Badge color="blue">Beta</Badge></span>

**Disclaimer:** This beta endpoint is evolving; the API contract may change. <br /><br /> Preflight-validates that a cloud account is ready for BYOC infrastructure creation: simulates the cloud permissions ClickHouse needs (and, for BYO-VPC, checks the provided network resources) without creating anything. Takes the same parameters as infrastructure creation, so a payload that passes validation will not be rejected by create for the same inputs.

<div data-permissions class="api-section">
  <div class="api-section-heading flex flex-col gap-y-4 w-full">
    <div class="flex items-baseline border-b pb-2.5 border-gray-100 dark:border-gray-800 w-full">
      <h4 class="api-section-heading-title flex-1 mb-0">Permission</h4>
    </div>
  </div>

  <div class="py-6">
    The API key must have the `control-plane:organization:manage` permission.
  </div>
</div>


## OpenAPI

````yaml _specs/cloud-openapi.json POST /v1/organizations/{organizationId}/byocInfrastructure/validate
openapi: 3.1.1
info:
  title: OpenAPI spec for ClickHouse Cloud
  version: '1.0'
  contact:
    name: ClickHouse Support
    url: >-
      https://clickhouse.com/docs/en/cloud/manage/openapi?referrer=openapi-1186669
    email: support@clickhouse.com
servers:
  - url: https://api.clickhouse.cloud
security:
  - basicAuth: []
tags:
  - name: Organization
  - name: User management
  - name: Billing
  - name: Role Management
  - name: Service
  - name: Backup
  - name: Snapshot
  - name: API keys
  - name: Prometheus
  - name: ClickPipes
  - name: ClickStack
  - name: Postgres
  - name: UDF
  - name: Query API endpoints
  - name: Saved queries
paths:
  /v1/organizations/{organizationId}/byocInfrastructure/validate:
    post:
      tags:
        - Organization
      summary: Validate BYOC infrastructure prerequisites
      description: >-
        **Disclaimer:** This beta endpoint is evolving; the API contract may
        change. <br /><br /> Preflight-validates that a cloud account is ready
        for BYOC infrastructure creation: simulates the cloud permissions
        ClickHouse needs (and, for BYO-VPC, checks the provided network
        resources) without creating anything. Takes the same parameters as
        infrastructure creation, so a payload that passes validation will not be
        rejected by create for the same inputs.
      operationId: organizationByocInfrastructureValidate
      parameters:
        - in: path
          name: organizationId
          description: ID of the requested organization.
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ByocInfrastructureValidatePostRequest'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: number
                    description: HTTP status code.
                    example: 200
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
                  result:
                    $ref: '#/components/schemas/ByocInfrastructureValidation'
        '400':
          description: >-
            The request cannot be processed due to a client error. Please verify
            your request parameters and try again.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: number
                    description: HTTP status code.
                    example: 400
                  error:
                    type: string
                    description: Detailed error description.
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
        '500':
          description: >-
            An internal server error has occurred. If this issue persists,
            please contact ClickHouse Cloud support for assistance.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: integer
                    description: HTTP status code.
                    example: 500
                  error:
                    type: string
                    description: Detailed error description.
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
components:
  schemas:
    ByocInfrastructureValidatePostRequest:
      properties:
        regionId:
          description: Region in which the BYOC infrastructure will be located
          type: string
          enum:
            - ap-northeast-1
            - ap-northeast-2
            - ap-south-1
            - ap-southeast-1
            - ap-southeast-2
            - ca-central-1
            - eu-central-1
            - eu-west-1
            - eu-west-2
            - il-central-1
            - us-east-1
            - us-east-2
            - us-west-2
            - us-east1
            - us-central1
            - europe-west2
            - europe-west4
            - asia-southeast1
            - asia-northeast1
            - eastus
            - eastus2
            - westus3
            - germanywestcentral
            - centralus
        accountId:
          description: >-
            Cloud account ID the BYOC infrastructure is configured for: AWS
            account ID, GCP project ID, or Azure subscription ID
          type: string
          example: '123456789012'
        availabilityZoneSuffixes:
          type: array
          description: List of availability zone suffixes
          items:
            type: string
            enum:
              - a
              - b
              - c
              - d
              - e
              - f
        vpcCidrRange:
          description: >-
            CIDR range for the ClickHouse-managed VPC. Mutually exclusive with
            the BYO-VPC fields (`vpcId`, `privateSubnetIds`, `publicSubnetIds`)
          type: string
          example: 10.0.0.0/16
        externalId:
          description: >-
            AWS only: ExternalID baked into the ClickHouse management role trust
            policy in your account
          type: string
          example: ch-0a1b2c3d4e5f6789
        tenantId:
          description: >-
            Azure only (required for Azure regions): Entra tenant ID of the
            subscription
          type: string
        servicePrincipalClientId:
          description: >-
            Azure only (required for Azure regions): client ID of the service
            principal ClickHouse uses to manage the infrastructure
          type: string
        vpcId:
          description: >-
            BYO-VPC only (AWS and GCP): ID or network name of the
            customer-provided VPC to deploy into. Requires `privateSubnetIds`
          type: string
          example: vpc-0abc1234def567890
        privateSubnetIds:
          type: array
          description: >-
            BYO-VPC only: private subnet IDs or names (1-6 entries on AWS,
            exactly one on GCP)
          items:
            type: string
        publicSubnetIds:
          type: array
          description: 'AWS BYO-VPC only: public subnet IDs (at most 6 entries)'
          items:
            type: string
        gcpPodCidrRangeNames:
          type: array
          description: >-
            GCP BYO-VPC only: secondary IP range names on the subnet to use for
            pod IPs. Omitted: all secondary ranges are used
          items:
            type: string
        gcpSharedVpcHostProjectId:
          description: >-
            GCP BYO-VPC only: Shared VPC host project owning the VPC and subnet,
            when different from `accountId`
          type: string
        tags:
          $ref: '#/components/schemas/ByocInfrastructureTags'
      required:
        - regionId
        - accountId
    ByocInfrastructureValidation:
      properties:
        cloudProvider:
          description: Cloud provider of the requested region
          type: string
          enum:
            - gcp
            - aws
            - azure
        allPassed:
          description: True when every check passed
          type: boolean
        anyPassed:
          description: True when at least one check passed
          type: boolean
        supported:
          description: >-
            Whether preflight validation is implemented for the requested cloud
            and configuration. When false, an empty check list means nothing was
            verified rather than everything passed
          type: boolean
        checks:
          type: array
          description: Individual permission checks with their outcomes
          items:
            $ref: '#/components/schemas/ByocInfrastructureValidationCheck'
    ByocInfrastructureTags:
      type: object
      additionalProperties:
        type: string
      maxProperties: 50
    ByocInfrastructureValidationCheck:
      properties:
        name:
          description: Human readable name of the check
          type: string
          example: Create EKS cluster
        action:
          description: Cloud permission or action the check simulated
          type: string
          example: eks:CreateCluster
        allowed:
          description: Whether the account allowed the simulated action
          type: boolean
        reason:
          description: >-
            Cloud-provider detail for a denied check, e.g. an IAM decision
            reason
          type: string
          example: implicitDeny
        group:
          description: >-
            Free-form grouping of related checks, e.g. base or vpc-write.
            Groupings may change as validations evolve
          type: string
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: >-
        Use key ID and key secret obtained in ClickHouse Cloud console:
        https://clickhouse.com/docs/cloud/manage/openapi
      x-permission-scopes: >-
        The scope list of a `security` requirement holds ClickHouse Cloud API
        key permission ids (for example `control-plane:organization:view`), not
        OAuth scopes. OpenAPI has no field for API key permissions, so this is
        the closest available place. A key must hold every permission listed on
        an operation to call it; an operation with no scopes needs none beyond a
        valid key. Every operation declares at most one requirement object,
        always for this scheme, so the list is only ever conjunctive —
        alternative sets of permissions are never expressed.

````