Air-Gapped AWS集群中通过代理实现ClickHouse与GCS集成的问题求助
当前环境配置
- 环境:无外网访问权限的AWS集群(Air-gapped)
- 代理:运行在具备公网访问权限的EC2实例上的自定义Golang代理
- 代理配置:已配置环境变量
HTTPS_PROXY=http://10.0.x.x:8080
待执行的ClickHouse查询
我们尝试通过以下SQL查询将GCS存储桶中的Parquet数据插入到ClickHouse表中:
INSERT INTO my_clickhouse_table ( column_1, column_2, column_3 ... column_n ) SELECT column_1, column_2, column_3 ... column_n FROM gcs( 'https://storage.googleapis.com/test_bucket/my_folder/16-01-2025_18:08:35/data-127823782.parquet', 'access_key_id', 'secret_access_key' )
遇到的问题
代理配置在Pod内的Python应用中可以正常创建BigQuery和GCS客户端,但执行上述ClickHouse查询时,却无法访问目标GCS存储桶。对storage.googleapis.com的API请求没有走指定的代理,直接被网络策略拦截阻断。
核心需求
我需要让该ClickHouse查询能够正常执行,成功从GCS文件中获取数据。由于是无外网环境,所有对storage.googleapis.com的请求必须通过指定的代理进行转发。
我在ClickHouse官方文档中未找到针对该场景的特定配置项,仅找到关于Python客户端代理支持的说明,但该内容对当前查询的执行没有帮助:
HTTP Proxy Support
ClickHouse Connect adds basic HTTP proxy support using the urllib 3
library. It recognizes the standard HTTP_PROXY and HTTPS_PROXY
environment variables. Note that using these environment variables
will apply to any client created with the
clickhouse_connect.get_client method. Alternatively, to configure per
client, you can use the http_proxy or https_proxy` arguments to the
get_client method. For details on the implementation of HTTP Proxy
support, see the urllib3 documentation.
补充环境说明
- AWS侧(无外网,仅通过代理访问外部服务):
- 业务应用部署在K8S Pod中
- ClickHouse服务器以K8S集群模式部署
- GCP侧:
- 存放待导入数据的GCS存储桶
- 核心业务场景:通过代理将GCS中的数据导入到ClickHouse集群
已尝试的解决方案(均未生效)
- 在Python的ClickHouse Connect客户端中显式指定代理参数:
ch_client = clickhouse_connect.get_client( host = 'localhost', port = 8123, username = 'default', password = '', http_proxy='http://10.0.x.x:8080', https_proxy='http://10.0.x.x:8080' ) query = """ select * FROM gcs('https://storage.googleapis.com/test_bucket/my_folder/16-01-2025_18:08:35/data-127823782.parquet', 'access-key', 'secret-key') """ result = ch_client.query(query)
- 在Python代码中设置系统环境变量:
os.environ['HTTPS_PROXY'] = "http://10.0.x.x:8080"
备注:内容来源于stack exchange,提问作者Abhinavece

