catalog_type | Type of catalog: glue, unity (Delta, or Delta and Iceberg with use_unity_catalog_v2), rest (Iceberg), hive, onelake (Iceberg), delta_sharing (Iceberg, flat namespaces), horizon (Snowflake Horizon Iceberg REST) |
warehouse | The warehouse/database name to use in the catalog. |
catalog_credential | Authentication credential for the catalog (e.g., API key or token) |
use_unity_catalog_v2 | For catalog_type = 'unity': use the new implementation, which serves both Delta Lake and Iceberg tables. Default: false. Set it on CREATE, or change it for an existing database with ALTER DATABASE ... MODIFY SETTING. |
auth_header | Custom HTTP header for authentication with the catalog service |
auth_scope | OAuth2 scope for authentication (if using OAuth) |
storage_endpoint | Endpoint URL for the underlying storage |
oauth_server_uri | URI of the OAuth2 authorization server for authentication |
vended_credentials | Boolean indicating whether to use vended credentials from the catalog (supports AWS S3 and Azure ADLS Gen2) |
aws_access_key_id | AWS access key ID for S3/Glue access (if not using vended credentials) |
aws_secret_access_key | AWS secret access key for S3/Glue access (if not using vended credentials) |
aws_role_arn | ARN of the IAM role to assume for AWS/Glue access. When set, ClickHouse uses AWS STS AssumeRole with base credentials from aws_access_key_id and aws_secret_access_key when both are provided, or from the default AWS credential chain otherwise (the role must trust the identity the server runs under). |
aws_role_session_name | Session name used for the AWS STS AssumeRole call. Optional; defaults to ClickHouseSession. |
aws_external_id | External ID passed to AWS STS AssumeRole, matching the sts:ExternalId condition on the role’s trust policy. Use this when the role is owned by a third party, such as ClickHouse Cloud. |
region | AWS region for the service (e.g., us-east-1) |
dlf_access_key_id | Access key ID for DLF access |
dlf_access_key_secret | Access key Secret for DLF access |
force_add_bucket | When constructing object-storage URLs from the catalog-provided table location and storage_endpoint, prepend the bucket/container name even if the endpoint already contains it. Default: false. Set to true for catalogs that hand back paths without the bucket and require it to be added at the URL-construction step (Polaris-style paths). |