Skip to content

feat(cli): query Cloud Postgres over HTTP with OAuth - #1025

Open
sdairs wants to merge 3 commits into
codex/1023-postgres-query-apifrom
codex/postgres-query-endpoint
Open

sdairs wants to merge 3 commits into
codex/1023-postgres-query-apifrom
codex/postgres-query-endpoint

Conversation

@sdairs

@sdairs sdairs commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Add cloud postgres query so users can run read-only SQL without installing psql or supplying database credentials. For example: clickhousectl cloud postgres query <id> --query 'SELECT version()'.

Supports service ID or exact name, organization selection, --query/-q, --queries-file (including -), piped stdin, and --database. Human output streams tab-separated columns; JSON and agent output preserve the endpoint's compact array stream, including names and types. API-key authentication fails before input or HTTP with OAuth guidance. Query failures never trigger retries, credential provisioning, or a native-client fallback.

Closes #1023. This PR is stacked on #1024, the separate API-library implementation; merge that first, then retarget this PR to main.

Control-plane #41025 merged on September 28. Production Postgres query support was verified live on September 29 with clickhousectl OAuth credentials. API-key access remains unsupported.

Validation:

  • cargo fmt --all --check
  • cargo clippy -p clickhousectl -- -D warnings
  • cargo test -p clickhousectl
  • cargo check -p clickhousectl --no-default-features
  • cargo clippy -p clickhousectl --all-targets --no-default-features -- -D warnings
  • Library/analyzer clippy and test suites; 95 Python tests
  • New parser, request-builder, input and renderer tests plus 11 subprocess tests covering OAuth, request shape, SQL sources, gzip, typed failures, interrupted streams, and closed stdout

Live validation (2026-09-29, existing evaluation service; no persistent database changes):

  • The repository's live_postgres_query_bearer_smoke passed with both postgres and an existing non-default database.
  • All 12 CLI acceptance checks passed: ID/name selectors, explicit database, human/JSON output, inline/file/implicit and explicit stdin, final-statement script results, empty results, duplicate names, nulls, Unicode, SQL errors, rejected writes, and organization access denial.
  • A separate non-default database check returned the requested database and current_user = chpg_console_readonly.
  • The rollback-protected CREATE TABLE probe was rejected with permission denied for schema public (CLI sql_error, exit 1).
  • Invalid Bearer credentials returned HTTP 401; querying with an unrelated organization returned HTTP 403 (auth_required, exit 4).

No implementation fixes were needed. Updated only the documentation to remove the resolved deployment caveat; formatting and diff checks passed. Draft status is retained. The broader repository Cloud integration CI gate is separate from this direct OAuth verification.

@sdairs
sdairs added this pull request to stack #1026 September 27, 2026 11:59
@sdairs
sdairs marked this pull request as ready for review September 29, 2026 17:49
@sdairs
sdairs requested a review from iskakaushik as a code owner September 29, 2026 17:49
@sdairs
sdairs force-pushed the codex/postgres-query-endpoint branch from fe4dd24 to b208424 Compare October 1, 2026 17:24
@sdairs
sdairs removed this pull request from stack #1026 October 1, 2026 17:26
@sdairs
sdairs added this pull request to stack #1001 October 1, 2026 17:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add read-only Postgres queries through the Cloud Query API

1 participant