Skip to main content
How you rotate the default user’s password depends on how the cluster was given it.

Rotate a password stored in a Secret

For clusters deployed with account.passwordSecretRef, point the cluster at a new Secret rather than editing the current one. The change then goes through Helm, so it stays in your IaC instead of being reverted by the next sync, and the old Secret is your rollback until you remove it.
  1. Create the new Secret alongside the current one:
  1. Point account.passwordSecretRef.name at clickhouse-admin-password-v2 in your Helm values, then run helm upgrade to apply it. The operator applies the new password within seconds of the CR changing.
  2. Confirm a login with the new password, then delete the old Secret:
Existing connections are unaffected; the new password applies to subsequent logins.

Rotate a password supplied inline

The steps below apply to clusters that supply the password with the account.hashedPassword value.

Prerequisites

  • ClickHouse Private API installed and accessible (e.g., via port-forward to http://localhost:8080/)
  • At least one ClickHouse cluster deployed (this guide uses default-xx-01)

1. Generate a Hashed Password

Hash the new password using SHA-256 and base64-encode the result:

2. Create the Request Body

Create a JSON file with the hashed password:
Save this as password_reset.json.

3. Send the Request

A successful response:

4. Verify the Change

The password reset takes effect after the operator processes the change. Verify by connecting to the cluster with the new password. You can also monitor the operation via the status endpoint:

Limitation for Compute-Compute Separation

Password resets cannot be performed on child instances. To reset the password for a child instance, reset it on the parent instance instead.
Last modified on October 7, 2026