All skills
clickhouse avatar

/clickhouse-js-node-troubleshooting

@faa5b11 official
by clickhouseclickhouse/agent-skills543 stars
39

Troubleshoot and resolve common issues with the ClickHouse Node.js client (@clickhouse/client). Use this skill whenever a user reports errors, unexpected behavior, or configuration questions involving the Node.js client specifically — including socket hang-up errors, Keep-Alive problems, stream handling issues, data type mismatches, read-only user restrictions, proxy/TLS setup problems, or long-running query timeouts. Trigger even when the user hasn't precisely named the issue; vague symptoms like "my inserts keep failing" or "connection drops randomly" in a Node.js context are strong signals to use this skill. Do NOT use for browser/Web client issues.

Use this Skill: https://skilld.dev/gh/clickhouse/agent-skills/clickhouse-js-node-troubleshooting

This session only. Nothing lands on disk.

referencetls.md

≈782 tokens on demand. Your agent reads this file only when SKILL.md points to it.

TLS / Certificate Errors

Requires: >= 0.0.8 (basic and mutual TLS support added in 0.0.8). For custom HTTP agent with TLS, see >= 1.2.0 (http_agent option); note that when using a custom agent, the tls config option is ignored.

Basic TLS (CA certificate only)

import fs from "fs";
import { createClient } from "@clickhouse/client";

const client = createClient({
  url: "https://<hostname>:<port>",
  username: "<user>",
  password: "<pass>",
  tls: {
    ca_cert: fs.readFileSync("certs/CA.pem"),
  },
});

Mutual TLS (client certificate + key)

import fs from "fs";
import { createClient } from "@clickhouse/client";

const client = createClient({
  url: "https://<hostname>:<port>",
  username: "<user>",
  tls: {
    ca_cert: fs.readFileSync("certs/CA.pem"),
    cert: fs.readFileSync("certs/client.crt"),
    key: fs.readFileSync("certs/client.key"),
  },
});

Tip (>= 1.2.0): If you need a custom HTTP(S) agent, use the http_agent option. Only set set_basic_auth_header: false if you must avoid sending the basic-auth Authorization header (for example, due to a header conflict); in that case, provide alternative auth headers such as X-ClickHouse-User / X-ClickHouse-Key via http_headers.

Common TLS errors

UNABLE_TO_VERIFY_LEAF_SIGNATURE / UNABLE_TO_GET_ISSUER_CERT_LOCALLY

Scenario A — Private/internal CA (most common for self-hosted): The server's certificate was issued by a private CA that Node.js doesn't trust. Pass the CA certificate explicitly:

tls: {
  ca_cert: fs.readFileSync('certs/CA.pem'),
}

Scenario B — ClickHouse Cloud: The CA is a well-known public CA; this error typically means the system CA bundle is outdated or the URL/hostname is wrong. Updating Node.js or the system certificates usually resolves it.

self signed certificate / self signed certificate in certificate chain

The server uses a self-signed cert (the certificate is its own CA). Options in order of preference:

  1. Pass the self-signed cert as the CA:

    tls: {
      ca_cert: fs.readFileSync("certs/server.crt"),
    }
  2. For development only — disable verification via a custom agent (>= 1.2.0):

    import https from "https";
    import { createClient } from "@clickhouse/client";
    
    const client = createClient({
      url: "https://<hostname>:<port>",
      username: "<user>",
      password: "<pass>",
      http_agent: new https.Agent({ rejectUnauthorized: false }),
      // Optional: only disable the basic-auth Authorization header if you need to
      // provide alternative auth headers instead.
      set_basic_auth_header: false,
      http_headers: {
        "X-ClickHouse-User": "<user>",
        "X-ClickHouse-Key": "<pass>",
      },
    });

    ⚠️ Never use rejectUnauthorized: false in production — it disables all certificate verification.

ERR_SSL_WRONG_VERSION_NUMBER / ECONNREFUSED on HTTPS URL

The client is connecting with HTTPS but the server is listening on plain HTTP. Change the URL scheme to http:// or enable TLS on the ClickHouse server.

Source: SKILL.md on GitHub

No alerts17d3 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides comprehensive troubleshooting documentation for the ClickHouse Node.js client. It includes security best practices, such as using parameterized queries to prevent SQL injection and clear warnings against insecure TLS configurations in production environments. No malicious patterns or security risks were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

Signed by skilld at faa5b11. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 3 months ago
  • clickhouse
  • nodejs
  • troubleshooting
  • client
  • socket
  • tls
  • compression
  • data-types
  • connection

README badge

README badge for clickhouse/agent-skills/clickhouse-js-node-troubleshooting

Diagnose and resolve common issues with the ClickHouse Node.js client (@clickhouse/client), including socket hang-ups, data type mismatches, TLS configuration problems, compression failures, and read-only user restrictions. Applies only to Node.js runtime environments, not browser or edge runtimes.

Generated from the current SKILL.md.

Does this skill work with the browser/Web client or just Node.js?
This skill covers only the Node.js runtime (@clickhouse/client), including Next.js Node API routes and Server Actions. For browser, Edge runtime, Cloudflare Workers, or Web Worker environments, use @clickhouse/client-web instead.
What kinds of errors does this skill help troubleshoot?
Socket hang-ups, ECONNRESET, data type mismatches, read-only user restrictions, proxy/TLS setup, compression issues, query timeouts, and query parameter interpolation problems with the ClickHouse Node.js client.
Do I need to know the exact error message to use this skill?
No. Vague symptoms like 'my inserts keep failing' or 'connection drops randomly' in a Node.js context are strong enough signals to trigger this skill.
Will this skill help with version compatibility issues?
Yes. The skill flags if a fix requires a minimum client version and will ask for your version if it's needed to recommend the right solution.

Generated from the current SKILL.md. These answers refresh after source changes.