You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/integrations/data-ingestion/clickpipes/aws-privatelink.md
+40-21Lines changed: 40 additions & 21 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,8 +1,8 @@
1
1
---
2
-
sidebar_label: 'AWS PrivateLink for ClickPipes'
3
-
description: 'Establish a secure connection between ClickPipes and a data source using AWS PrivateLink.'
2
+
sidebar_label: "AWS PrivateLink for ClickPipes"
3
+
description: "Establish a secure connection between ClickPipes and a data source using AWS PrivateLink."
4
4
slug: /integrations/clickpipes/aws-privatelink
5
-
title: 'AWS PrivateLink for ClickPipes'
5
+
title: "AWS PrivateLink for ClickPipes"
6
6
---
7
7
8
8
import cp_service from '@site/static/images/integrations/data-ingestion/clickpipes/cp_service.png';
@@ -40,9 +40,14 @@ Your VPC resources can be accessed in ClickPipes using PrivateLink.
40
40
Resource configuration can be targeted with a specific host or RDS cluster ARN.
41
41
Cross-region is not supported.
42
42
43
+
It's the preferred choice for Postgres CDC ingesting data from an RDS cluster.
44
+
43
45
See a [getting started](https://docs.aws.amazon.com/vpc/latest/privatelink/resource-configuration.html) guide for more details.
44
46
45
-
It's a preferred choice for Postgres CDC ingesting data from RDS cluster.
47
+
:::info
48
+
VPC resource needs to be shared with a ClickPipes account. Add `072088201116` to the allowed principals to your resource share configuration.
49
+
See AWS guide for [sharing resources](https://docs.aws.amazon.com/ram/latest/userguide/working-with-sharing-create.html) for more details.
50
+
:::
46
51
47
52
### MSK multi-VPC connectivity {#msk-multi-vpc}
48
53
@@ -53,6 +58,11 @@ Cross-region is not supported.
53
58
It is a recommended option for ClickPipes for MSK.
54
59
See the [getting started](https://docs.aws.amazon.com/msk/latest/developerguide/mvpc-getting-started.html) guide for more details.
55
60
61
+
:::info
62
+
Update your MSK cluster policy and add `072088201116` to the allowed principals to your MSK cluster.
63
+
See AWS guide for [attaching a cluster policy](https://docs.aws.amazon.com/msk/latest/developerguide/mvpc-cluster-owner-action-policy.html) for more details.
64
+
:::
65
+
56
66
### VPC endpoint service {#vpc-endpoint-service}
57
67
58
68
VPC service is another approach to share your data source with ClickPipes.
@@ -62,22 +72,30 @@ and configuring the VPC endpoint service to use the NLB.
62
72
VPC endpoint service can be [configured with a private DNS](https://docs.aws.amazon.com/vpc/latest/privatelink/manage-dns-names.html),
63
73
that will be accessible in a ClickPipes VPC.
64
74
65
-
Cross-region is supported.
66
-
67
75
It's a preferred choice for:
68
-
- any on-premise Kafka setup that requires private DNS support
69
-
- cross-region connectivity for Postgres CDC
70
76
71
-
Cross-region MSK cluster connectivity can be set up using VPC endpoint service as well.
72
-
Please reach out to the ClickHouse support team for assistance.
77
+
- Any on-premise Kafka setup that requires private DNS support
78
+
- Cross-region connectivity for Postgres CDC
79
+
- Cross-region connectivity for MSK cluster. Please reach out to the ClickHouse support team for assistance.
80
+
81
+
See the [getting started](https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html) guide for more details.
82
+
83
+
:::info
84
+
Add ClickPipes account ID `072088201116` to the allowed principals to your VPC endpoint service.
85
+
See AWS guide for [managing permissions](https://docs.aws.amazon.com/vpc/latest/privatelink/configure-endpoint-service.html#add-remove-permissions) for more details.
can be configured for ClickPipes. Add [your ClickPipe region](#supported-aws-regions-aws-privatelink-regions) to the allowed regions in your VPC endpoint service.
91
+
:::
73
92
74
93
## Creating a ClickPipe with reverse private endpoint {#creating-clickpipe}
75
94
76
95
1. Access the SQL Console for your ClickHouse Cloud Service.
0 commit comments