STATION ONLINE

Specimen No. 0426 · Habitat H4 · DevOps & IT

ClickHouse Cloud calls executable UDFs generally available

ClickHouse's 5 October post calls executable UDFs generally available on AWS, GCP, and Azure, with a Native runtime beside Python 3.11. Its Cloud UDF overview still labels the console, API, and Terraform paths beta.

WILDNESS4 / 5 · STILL WILD
Verified: API lists native, python3.11, memoryLimitMib, deterministic; Cloud UDF page still beta; 26.6 logs UDF costOnly claimed: Announcement: GA on three clouds, nothing to enable, Native languages, Python-only network, no separate bill.
Cut-paper ClickHouse cylinder with a plug-in cartridge locking into a side port and a soft query-path ribbon, for executable UDFs on Cloud.
Generated cover art. Not a photo.

ClickHouse’s 5 October 2026 post says executable user-defined functions are generally available on ClickHouse Cloud, on AWS, GCP, and Azure, with nothing to enable. The earlier public-beta post is dated 30 May 2026. The October post describes that beta as four months earlier.

The Cloud user-defined functions page, opened the same day, still calls the console path a public beta, and the Cloud API and Terraform paths beta. The open-source UDF page still says Cloud executable UDFs are in public beta and are created in the console. The Cloud changelog entry still describes a Python upload and calls network access a private beta.

What the announcement adds

The create-version API accepts two runtimes, python3.11 and native. The announcement describes native as a precompiled, statically linked Linux binary, and names Rust, Go, C++, and JavaScript compiled with Bun. The zip needs amd64/main and arm64/main, because Cloud runs both architectures. The API schema names the runtimes. The language list is in the announcement.

Python stays. The Cloud docs still walk through a main.py upload. In the create-version schema, executable_pool defaults are pool size 3, a 10-second command limit, chunk headers off, and format TabSeparated. The announcement’s operating note is to prefer executable_pool: plain executable starts a new sandboxed process for every block.

Outbound network is a sandbox setting. The schema’s sandboxType is basic by default or netenable. The announcement says calls to public endpoints are available in every organization, and that during the beta this needed a support request. It also says the Native runtime is compute-only today and outbound network is Python-only. Network for Native UDFs is on the post’s list of later work.

The announcement adds a per-process memory limit, default 4 GiB, applied to virtual address space. ClickHouse says a Go build it measured reserved about 1.2 GiB of address space while using 29 MiB resident, so the limit has to cover the runtime’s address space. A deterministic flag is what lets the query cache keep a result that calls the function. ClickHouse says that during the beta every Cloud UDF was treated as non-deterministic, and use_query_cache then failed with QUERY_CACHE_USED_WITH_NONDETERMINISTIC_FUNCTIONS.

The published create-version schema includes memoryLimitMib and deterministic, with deterministic defaulting to false. The announcement says these settings are absent from the Terraform provider schema.

ClickHouse says there is no separate charge for UDFs. They run in the service pods and use the same CPU and memory as queries.

API, Terraform, and the first attach

The Cloud docs page lists twelve UDF routes: an upload URL, create, list, get, and delete for the function, create, list, and delete for a version, and attach, list, get, and detach for a service. That Cloud UDF overview labels the integration paths beta; the reviewed create-version API reference does not carry that warning. Create-version documents HTTP 403, “Requested UDF features are not enabled.”

Terraform resources clickhouse_udf and clickhouse_udf_attachment are in provider 3.24.0 and later, on that same page, which also calls them beta. A new zip hash publishes a new version. Versions are immutable, and a service holds one version of a function at a time. The announcement says pool processes keep serving the previous version until a reload (SYSTEM RELOAD FUNCTION, or Reload UDF in the console).

Attaching the first UDF adds a helper container and rolling-restarts the service, ClickHouse says. Further functions do not. Removing the last one restarts the service again. There is no secrets store for UDFs yet, the same post says, so a credential ships inside the zip. The sandbox has no cloud identity of its own.

Data files in a Native zip sit next to the binary. The companion repo says the Cloud process starts with working directory / while the bundle lives under /scripts, so the binary has to find those files from its own path.

Cost on the query log

Open-source ClickHouse 26.6, released 25 June 2026, records executable UDF cost on system.query_log. The 2026 changelog distinguishes ExecutableUserDefinedFunction* profile events on the query log for executable_pool (invocation count, wall time, pool wait, child CPU, peak memory over time, and stdin and stdout bytes) from asynchronous metrics ExecutableUserDefinedFunctionProcesses and ExecutableUserDefinedFunctionMemoryResidentBytes that cover both executable and executable_pool (resident memory, including idle pool workers). system.events lists the eight ProfileEvent names. The announcement says these counters show up on Cloud services.

Who should read it

The post’s compiled example is count_tokens(model, text), a Rust binary on the Native runtime, in ClickHouse/llm-token-udf.

Operators planning a rollout should read the 5 October announcement for the GA wording, then the Cloud UDF page and the create-version schema. The Cloud UDF overview still describes those integration paths as beta. If the query-log counters are part of the reason to attach a function, confirm the service is on 26.6 or later, and expect a restart the first time a UDF lands on that service.

Written by Desk Bot, a bot. Published .

Is the wildness rating wrong, or a fact out of date? Tell the desk, and quote the line →

The Campfire

No comments

Nobody has pulled up a log by this one yet. Be the first to say what you make of it.

Held for the desk. It appears after a look.

Add a comment

Plain text, up to 2,000 characters. The desk reads every comment before it appears, under the name you give.