All skills
clickhouse avatar

/clickhouse-architecture-advisor

@5e162d6 official
by clickhouseclickhouse/agent-skills543 stars
39

MUST USE when designing ClickHouse architectures, selecting between ingestion or modeling patterns, or translating best practices into workload-specific system designs. Complements clickhouse-best-practices with decision frameworks and explicit provenance labels.

Use this Skill: https://skilld.dev/gh/clickhouse/agent-skills/clickhouse-architecture-advisor

This session only. Nothing lands on disk.

examplessiem-security-analytics.md

≈486 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Example: SIEM / security analytics

Scenario

  • Workload: endpoint, identity, cloud, and network telemetry
  • Query pattern:
    • repeated detection logic
    • time-bounded investigations
    • lookup-heavy enrichments
  • Freshness target: near real-time

Workload Summary

This workload is time-series heavy, multi-source, and often enrichment-bound. The two common failure modes are:

  • expensive runtime JOINs on slow-changing dimension data
  • micro-batched ingest that creates excessive parts

Key Decisions

  1. Use append-friendly event storage
  2. Replace repeated small-dimension JOINs where possible
  3. Protect hot detections with precomputation or lookup structures

Recommendations

1. Enable async inserts for small-batch telemetry senders

What
Use async inserts when many agents or producers write very small batches.

Why
This reduces small-part pressure without rewriting every upstream sender.

Category
official

Confidence
high

Source

2. Use dictionaries for slow-changing asset and identity lookups

What
Move repeated device-owner or asset-lookup enrichment out of runtime joins where appropriate.

Why
Security detections often execute continuously; repeated joins on slow-changing dimensions waste CPU.

Category
official

Confidence
high

Source

3. Use incremental MVs for repeated aggregated detection views

What
Precompute common counts, rates, and rollups that power dashboards or recurring detections.

Why
Not every threat-hunting query should hit the same raw telemetry tables repeatedly.

Category
official

Confidence
high

Source

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill is a safe architectural advisor for ClickHouse workloads. It provides structured decision frameworks for ingestion, partitioning, and schema design based on official documentation. No malicious patterns, data exfiltration, or dangerous execution triggers were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5e162d6. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 6 months ago
metadata
{
  "author": "ClickHouse Inc",
  "version": "0.1.0"
}
  • clickhouse
  • architecture
  • olap
  • ingestion
  • time-series
  • schema-design
  • partitioning
  • joins
  • telemetry

README badge

README badge for clickhouse/agent-skills/clickhouse-architecture-advisor

Guides ClickHouse architecture decisions for specific workloads—observability, analytics, IoT, financial services—by mapping workload shape to ingestion, partitioning, and join strategies with official documentation links. Classifies recommendations by provenance (official, derived, field) to separate documented behavior from heuristic field guidance.

Generated from the current SKILL.md.

Does this skill replace the clickhouse-best-practices skill?
No. This skill complements clickhouse-best-practices by adding workload-aware decision frameworks and provenance labels. Official documentation remains the source of truth for both.
What workload types does this skill cover?
Observability, security/SIEM, product analytics, IoT/telemetry, market data/financial services, and mixed OLAP with point-lookups. Each has scenario-specific rule files for ingestion, time-series retention, enrichment, and late-arriving events.
How does this skill distinguish between official, derived, and field guidance?
Official recommendations are directly from ClickHouse docs. Derived recommendations follow logically from documented behavior. Field recommendations are experience-based and include a disclaimer that they are heuristic and workload-dependent.
What should I do if a recommendation is uncertain?
The skill explicitly states when a recommendation is uncertain rather than presenting it as confident guidance.

Generated from the current SKILL.md. These answers refresh after source changes.