Originally created by: pyy3
Severity: High (depends on deployment topology) · Type: security
The dbt ClickHouse profile disables TLS and certificate verification, and the stack publishes ClickHouse ports to the host. Combined with plaintext HTTP in the app sync client (see grynn-in/konsol#11), all ClickHouse traffic — including credentials — can travel unencrypted.
dbt_project/profiles.yml:
secure: false
verify: false
docker-compose.yml:
ports:
- "${CLICKHOUSE_HTTP_PORT:-8123}:8123"
- "${CLICKHOUSE_NATIVE_PORT:-9000}:9000"
- "${EXCEL_ODBC_PORT:-15432}:15432"
Docker publishes these on 0.0.0.0 by default.
Acceptable for single-host local dev; risky for any deployment where ClickHouse is reachable off-box. The security-architecture.md doc claims ClickHouse is "private network only — no public endpoint," which this configuration does not enforce (tracked separately).
secure: true / verify: true profile target for non-local deployments.127.0.0.1: by default; expose ClickHouse only via the Caddy reverse proxy when remote access is needed.
Ticket changed by: pyy3
Originally posted by: pyy3
Fixed in [#34] (merged to
main).Related
Tickets:
#34