ClickHouse
| Description / name | Input element |
|---|---|
| Container Registry | |
| Container Configuration Root Path | |
| Timezone | |
| User ID | |
| Group ID | |
| ClickHouse Host Port | |
| ClickHouse /var/db/clickhouse Path |
ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real time.
| Port | 8123 |
| Registry | ghcr.io/daemonless/clickhouse |
| Daemonless | daemonless/clickhouse |
| Source | clickhouse.com/ |
| Website | clickhouse.com |
Version Tags
Multi-arch manifests — resolve automatically to the right image for your platform.
| Tag | Description | Best For |
|---|---|---|
pkg |
Installed from the FreeBSD quarterly package repository. | Alternative build. |
pkg-latest |
Installed from the FreeBSD latest package repository. | Most users — recommended. |
| Tag | Description | Best For |
|---|---|---|
pkg-amd64 |
Installed from the FreeBSD quarterly package repository. | Alternative build. |
pkg-latest-amd64 |
Installed from the FreeBSD latest package repository. | Most users — recommended. |
| Tag | Description | Best For |
|---|---|---|
pkg-aarch64 |
Installed from the FreeBSD quarterly package repository. | Alternative build. |
pkg-latest-aarch64 |
Installed from the FreeBSD latest package repository. | Most users — recommended. |
Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.
Deployment
Save as compose.yaml, then run podman-compose up -d.
Warning
Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.
Save the files above, then run appjail-director up.
Experimental
Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.
Save as bastille-compose.yml, then run bastille up.
Access at: http://localhost:8123
Interactive Configuration
Parameters
Environment Variables
| Variable | Default | Description |
|---|---|---|
PUID |
1000 |
User ID for the application process |
PGID |
1000 |
Group ID for the application process |
TZ |
UTC |
Timezone for the container |
CLICKHOUSE_PASSWORD |
changeme |
Password for the default user. Unset = no password (open to anyone who can reach the ports) |
CLICKHOUSE_PASSWORD_FILE |
<CLICKHOUSE_PASSWORD_FILE> |
Read the password from this file instead (secrets) |
Volumes
| Path | Description |
|---|---|
/var/db/clickhouse |
Database data directory |
Ports
| Port | Protocol | Description |
|---|---|---|
8123 |
TCP | HTTP interface and web UI (/play) |
9000 |
TCP | Native TCP client |
First run
Set CLICKHOUSE_PASSWORD. Without it the default user has no password and
anyone who can reach port 8123 or 9000 has full access to the database.
Web UI
The HTTP port serves a query console at /play and a metrics dashboard at
/dashboard. Sign in there with user default and your CLICKHOUSE_PASSWORD.
Configuration
config.xml and users.xml live inside the image. Put your own settings in
files mounted under /usr/local/etc/clickhouse-server/config.d/ and
/usr/local/etc/clickhouse-server/users.d/; ClickHouse merges them on start.
Stopping
ClickHouse on FreeBSD does not exit on its own after flushing storages, so the
container stops it after 30 seconds. Keep stop_grace_period above that.
Implementation Details
- Architectures: amd64, aarch64
- User:
bsd(UID/GID set via PUID/PGID). Defaults to1000:1000. - Base: Built on
ghcr.io/daemonless/base(FreeBSD 15.1).
Need help? Join our Discord community.