Menu ▾ ▴

#23 [Security/High] dbt profile uses plaintext ClickHouse (secure:false, verify:false) + ports exposed

closed
nobody
None
2026-06-13
2026-06-12
Anonymous
No

Originally created by: pyy3

Severity: High (depends on deployment topology) · Type: security

Summary

The dbt ClickHouse profile disables TLS and certificate verification, and the stack publishes ClickHouse ports to the host. Combined with plaintext HTTP in the app sync client (see grynn-in/konsol#11), all ClickHouse traffic — including credentials — can travel unencrypted.

Location

dbt_project/profiles.yml:

secure: false
verify: false

docker-compose.yml:

ports:

  - "${CLICKHOUSE_HTTP_PORT:-8123}:8123"
  - "${CLICKHOUSE_NATIVE_PORT:-9000}:9000"
  - "${EXCEL_ODBC_PORT:-15432}:15432"

Docker publishes these on 0.0.0.0 by default.

Impact

Acceptable for single-host local dev; risky for any deployment where ClickHouse is reachable off-box. The security-architecture.md doc claims ClickHouse is "private network only — no public endpoint," which this configuration does not enforce (tracked separately).

Suggested fix

  • Offer a secure: true / verify: true profile target for non-local deployments.
  • Bind published ports to 127.0.0.1: by default; expose ClickHouse only via the Caddy reverse proxy when remote access is needed.
  • Document the local-only vs. networked deployment modes explicitly.

Related

Tickets: #34
Tickets: #35

Discussion

  • Anonymous

    Anonymous - 2026-06-13

    Ticket changed by: pyy3

    • status: open --> closed
     
  • Anonymous

    Anonymous - 2026-06-13

    Originally posted by: pyy3

    Fixed in [#34] (merged to main).

     

    Related

    Tickets: #34


Log in to post a comment.