default user’s password depends on how the cluster was given it.
Rotate a password stored in a Secret
For clusters deployed withaccount.passwordSecretRef, point the cluster at a new Secret rather than editing the current one. The change then goes through Helm, so it stays in your IaC instead of being reverted by the next sync, and the old Secret is your rollback until you remove it.
- Create the new Secret alongside the current one:
-
Point
account.passwordSecretRef.nameatclickhouse-admin-password-v2in your Helm values, then runhelm upgradeto apply it. The operator applies the new password within seconds of the CR changing. - Confirm a login with the new password, then delete the old Secret:
Rotate a password supplied inline
The steps below apply to clusters that supply the password with theaccount.hashedPassword value.
Prerequisites
- ClickHouse Private API installed and accessible (e.g., via port-forward to
http://localhost:8080/) - At least one ClickHouse cluster deployed (this guide uses
default-xx-01)
1. Generate a Hashed Password
Hash the new password using SHA-256 and base64-encode the result:2. Create the Request Body
Create a JSON file with the hashed password:password_reset.json.