Sitelet https://github.com/Altinity/altinity-oauth-helper/issues/30
Skip to content

ClickHouse version compatibility: track upstream external-role fixes (#79099, #116840) and restore full 24.8 Altinity Stable support #30

Description

@BorisTyshkevich

Summary

ch-oauth-ldap authenticates ephemeral ClickHouse users and maps their roles on every tracked ClickHouse build, but distributed-query authorization with externally assigned roles depends on two upstream ClickHouse bugs. This issue tracks the compatibility matrix, the upstream fixes, and the work to bring 24.8 Altinity Stable back to full support once a bugfix release carries them.

Verified live by integration/clickhouse/run-all-builds.sh (see integration/clickhouse/lib/expectations.sh for the per-build expectations and docs/ch-oauth-ldap-operator-guide.md §1 for the operator-facing statement).

Compatibility matrix (as of 2026-08-29)

Capability 24.8 (24.8.11.51285.altinitystable) 25.3 25.8 (25.8.28.10001.altinitystable) 26.3
Ephemeral-user auth, currentUser(), dynamic currentRoles(), role refresh on reconnect, local-user precedence ✅ ✅ ✅ ✅
Distributed query over base tables keeps the pushed external roles on remote nodes ❌ expected-fail (bug 1) ❌ expected-fail (bug 1) ✅ ✅
Distributed query over a normal VIEW keeps the pushed external roles ❌ (bug 2) ❌ (bug 2) ❌ (bug 2) ❌ (bug 2)
LDAP search_limit overflow (257 mapped roles vs <search_limit>256</search_limit>) auth fails closed (HTTP 403), measured not measured (fixture fails closed on untracked lines) auth fails closed (HTTP 403), measured not measured

24.8 and 25.8 are the tracked builds (run-all-builds.sh); 25.3 and 26.3 were characterized in a one-off sweep and can be run ad hoc via PHASE3_CH_IMAGE.

The two upstream bugs

  1. Pushed external roles are filtered against the ephemeral user's (empty) local grants on the remote node — External roles are not transferred during LDAP authentication when querying a distributed table. ClickHouse/ClickHouse#78791, fixed by Fix passing of external roles in interserver query (and better test) ClickHouse/ClickHouse#79099 ("Fix passing of external roles in interserver query", merged 2025-06-09). 24.8 contains #70332 (the push_external_roles_in_interserver_queries mechanism) so the roles are pushed and the remote logs external_roles applied, but the query is still denied. No 24.8 Altinity Stable release through 24.8.14.10547 carries #79099. Fixed in 25.8+.
  2. Pushed external roles are lost when the remote query reads through a normal VIEW (ContextData copy constructor omits external_roles) — Pushed external roles (push_external_roles_in_interserver_queries) are lost when the remote query reads through a normal VIEW ClickHouse/ClickHouse#116840, filed by us 2026-08-28, open, reproduces on every line through 26.3. The fixture tracks it as an expected-fail canary (scenario H view oracle) so a fix is detected automatically.

What "24.8 fully supported" requires

  • An Altinity Stable 24.8.x bugfix release that backports #79099 (bug 1). Bug 2 (#116840) additionally needs an upstream fix and its backport; until then VIEW-based distributed authorization stays unsupported on every line, and that is documented rather than blocked on.

Work items when such a release exists

  • Add the new 24.8.x image to integration/clickhouse/run-all-builds.sh (keep the current 24.8.11 baseline until the new one is verified, then replace or keep both).
  • Flip H_base_table_propagation:24.8 from expected_fail to must_pass in integration/clickhouse/lib/expectations.sh only after ./integration/clickhouse/run-all-builds.sh shows scenario H passing on that image (the fixture fails closed if an expectation is wrong in either direction).
  • If the release also carries a fix for #116840: flip H_view_propagation:<line> to must_pass for that line (the view canary will start reporting an unexpected pass, which is the signal).
  • Re-measure scenario G' (search_limit overflow consequence) on the new build; search_limit_overflow_expectation_for / search_limit_overflow_wire_tuple in expectations.sh must be extended for any new build line (they die on unknown lines by design).
  • Update the compatibility wording in README.md ("Wiring ClickHouse to ch-oauth-ldap"), docs/ch-oauth-ldap-operator-guide.md §1, integration/clickhouse/README.md, and issue Implement LDAP OAuth helper for ephemeral ClickHouse users and dynamic roles #19's "Compatibility target" — internal/securitytest/docs_contract_test.go enforces the ≥25.8 qualification phrase, so update the test's required-phrase list in the same PR.
  • Re-run ./integration/clickhouse/run-ha.sh on the new build (the HA fixture uses the default ClickHouse image).

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions