---
title: "Deploy ClickHouse | (Just Updated) Analytics DB, User Management On, Logs Capped"
description: "ClickHouse analytics DB. SQL users and grants on, system logs capped 7 days"
category: "Storage"
url: https://railway.com/deploy/clickhouse-or-just-updated-analytics-db-
---

# Deploy ClickHouse | (Just Updated) Analytics DB, User Management On, Logs Capped

ClickHouse analytics DB. SQL users and grants on, system logs capped 7 days

**[Deploy ClickHouse | (Just Updated) Analytics DB, User Management On, Logs Capped on Railway](https://railway.com/template/clickhouse-or-just-updated-analytics-db-)**

Machine-readable deploy manifest (JSON, validated by TemplateCI): https://railway.com/deploy/clickhouse-or-just-updated-analytics-db-/manifest.json

- **Creator:** SuperSlowSloth
- **Category:** Storage

## Template content

### clickhouse

- **Image:** clickhouse/clickhouse-server:26.8.13.2@sha256:d3cdda9b2137852b20b96b1262b043dbedbe78c2b2c7063a3da60781a29e3463
- **Start command:** `/bin/sh -c 'set -e; P=${PORT:-8123}; T="event_date + INTERVAL 7 DAY DELETE"; X="<clickhouse><http_port>$P</http_port><logger><level>information</level><size>100M</size><count>3</count></logger>"; for t in query_log trace_log query_thread_log query_views_log part_log background_schedule_pool_log metric_log error_log instrumentation_trace_log query_metric_log asynchronous_metric_log crash_log backup_log s3queue_log iceberg_metadata_log delta_lake_metadata_log; do X="$X<$t><ttl>$T</ttl></$t>"; done; echo "$X<text_log><ttl>$T</ttl><level>warning</level></text_log></clickhouse>" > /etc/clickhouse-server/config.d/90-railway.xml; echo "[railway] http_port=$P, system log tables capped at 7 days, text_log at warning, SQL user management on"; export CLICKHOUSE_DEFAULT_ACCESS_MANAGEMENT=1; exec /entrypoint.sh'`
- **Health check:** /ping
- **Public domain:** Yes

## Documentation

# Deploy and Host ClickHouse on Railway

ClickHouse is the open-source column-oriented database for real-time analytics. It runs SQL over
billions of rows in milliseconds and backs product analytics, observability stacks, log search and
event pipelines.

This template runs ClickHouse 26.8 as a single service from a digest-pinned official image: the
HTTP interface on an HTTPS domain, the native protocol on the private network, and all data on a
Railway volume.

## About Hosting ClickHouse

ClickHouse runs on Railway only after a few things are handled for you:

- **SQL user management is on.** The default user can run `CREATE USER`, `CREATE ROLE` and
  `GRANT`, so you can give each app its own read-only or scoped account. A stock deploy leaves
  access management off and every `CREATE USER` fails with `Not enough privileges`, which leaves
  one shared admin password for every client.
- **System logs cannot fill your volume.** ClickHouse writes its own metrics and query history into
  system tables that never expire by default; on an idle server `asynchronous_metric_log` alone
  gains millions of rows an hour. Here every system log table keeps 7 days and then deletes itself,
  and the server text log is kept at warning level instead of trace, so the disk you pay for holds
  your data.
- **Server log files are capped** at three 100 MB files.
- **A password is generated per deploy**, and anonymous requests are rejected.
- **Data survives redeploys.** Tables, users and grants live on the attached volume.
- **Memory is sized to your plan.** ClickHouse reads the container's cgroup limit and keeps its
  memory ceiling at 90% of it.

## Common Use Cases

- Product and web analytics (a self-hosted backend for event tracking and dashboards)
- Log, trace and metrics storage for observability stacks
- Real-time dashboards over event streams in Grafana, Metabase or Superset
- Fast aggregation for AI and data pipelines over large append-only tables

## Dependencies for ClickHouse Hosting

- One Railway volume for the data directory (created by the template)

### Deployment Dependencies

- ClickHouse documentation: https://clickhouse.com/docs
- Official image: https://hub.docker.com/r/clickhouse/clickhouse-server

### Implementation Details

| Variable | Purpose |
| --- | --- |
| `CLICKHOUSE_PASSWORD` | Password of the `default` user, generated per deploy. |
| `DATABASE_URL` | HTTP URL with credentials over the private network, for services in the same project. |
| `PUBLIC_DATABASE_URL` | HTTPS URL with credentials over the public domain. |
| `CLICKHOUSE_NATIVE_PRIVATE_URL` | `clickhouse://` URL on the native protocol (port 9000), private network. |
| `CLICKHOUSE_URL` | Public HTTPS address (Play UI at `/play`). |
| `CLICKHOUSE_PRIVATE_URL` | Private HTTP address. |

Reference it from another service with `${{clickhouse.DATABASE_URL}}`.

Create a scoped user for an app:

```sql
CREATE USER app IDENTIFIED BY 'change-me';
GRANT SELECT ON default.* TO app;
```

## Why Deploy ClickHouse on Railway?

Railway is a singular platform to deploy your infrastructure stack. Railway will host your
infrastructure so you don't have to deal with configuration, while allowing you to vertically and
horizontally scale it.

By deploying ClickHouse on Railway, you are one step closer to supporting a complete full-stack
application with minimal burden. Host your servers, databases, AI agents, and more on Railway.


## Similar templates

- [Garage S3 Storage](https://railway.com/deploy/garage-s3-storage) — Ultra-light S3 server: fast, open-source, plug-and-play.
- [Redis](https://railway.com/deploy/redis-1) — Self Host Latest Redis with Railway
- [EasyImg](https://railway.com/deploy/easyimg) — Simple self-hostable Nuxt.js personal image hosting system.

Open this page in a browser: https://railway.com/deploy/clickhouse-or-just-updated-analytics-db-
