Skip to content
ClickHouse Docs
ClickHouse DocsClickHouse Docs

Get reverse private endpoint

GET/v1/organizations/{organizationId}/services/{serviceId}/clickpipesReversePrivateEndpoints/{reversePrivateEndpointId}
API playground

Returns the reverse private endpoint with the specified ID.

Permission

The API key must have the control-plane:service:manage-clickpipes permission.

Authorizations

Path parameters

  • organizationIdstringrequired

    ID of the organization that owns the service.

    format: uuid
  • serviceIdstringrequired

    ID of the service that owns the Reverse Private Endpoint.

    format: uuid
  • reversePrivateEndpointIdstringrequired

    ID of the reverse private endpoint to get.

    format: uuid

Response

JSON

200

Successful response

JSON
  • statusoptionalnumber

    HTTP status code.

    Example: 200
  • requestIdoptionalstring

    Unique id assigned to every request. UUIDv4

    format: uuid
  • resultoptionalobject
    17 properties
    • descriptionoptionalstring

      Reverse private endpoint description. Maximum length is 255 characters.

      Example: "My reverse private endpoint"
    • typeoptionalVPC_ENDPOINT_SERVICEorVPC_RESOURCEorMSK_MULTI_VPCorGCP_PSC_SERVICE_ATTACHMENT

      Reverse private endpoint type.

      Example: "VPC_ENDPOINT_SERVICE"
    • vpcEndpointServiceNameoptionalstring | null

      VPC endpoint service name.

      Example: "com.amazonaws.vpce.us-east-1.vpce-svc-12345678901234567"
    • vpcResourceConfigurationIdoptionalstring | null

      VPC resource configuration ID. Required for VPC_RESOURCE type.

      Example: "rcfg-12345678901234567"
    • vpcResourceShareArnoptionalstring | null

      VPC resource share ARN. Required for VPC_RESOURCE type.

      Example: "arn:aws:ram:us-east-1:123456789012:resource-share/share-12345678901234567"
    • mskClusterArnoptionalstring | null

      MSK cluster ARN. Required for MSK_MULTI_VPC type.

      Example: "arn:aws:kafka:us-east-1:123456789012:cluster/my-cluster"
    • mskAuthenticationoptionalSASL_IAMorSASL_SCRAM

      MSK cluster authentication type. Required for MSK_MULTI_VPC type.

      Example: "SASL_IAM"
    • gcpServiceAttachmentoptionalstring | null

      Private Preview. GCP PSC service attachment URI. Required for GCP_PSC_SERVICE_ATTACHMENT type. Format: projects/{project}/regions/{region}/serviceAttachments/{name}.

      Example: "projects/my-project/regions/us-central1/serviceAttachments/my-service"
    • customPrivateDnsMappingsoptionalarray ofobject

      Optional private DNS names for Reverse Private Endpoint. Can be used as data source destination address. Must be unique across the ClickHouse service. Generally available for Google Private Service Connect (PSC). For AWS PrivateLink (VPC endpoint service and VPC resource), available in Private Preview; contact ClickHouse support to enable it for your service. Not supported for MSK multi-VPC. Supports exact names and leading wildcard names such as *.example.com

      Example: [{"privateDnsName":"my-service.example.com"},{"privateDnsName":"*.example.com"}]
      2 properties
      • privateDnsNameoptionalstring

        Optional private DNS names for Reverse Private Endpoint. Can be used as data source destination address. Must be unique across the ClickHouse service. Generally available for Google Private Service Connect (PSC). For AWS PrivateLink (VPC endpoint service and VPC resource), available in Private Preview; contact ClickHouse support to enable it for your service. Not supported for MSK multi-VPC. Supports exact names and leading wildcard names such as *.example.com

        Example: "*.my-service.example.com"
      • targetIdoptionalstring

        Optional DNS target ID. Supported only for VPC_RESOURCE, where it is the CHILD resource configuration ID (rcfg-…), or the configuration ID for a single resource. Set it at create time to route a custom DNS name to that resource. If the target is not reported in dnsTargets yet, the mapping is not served until it appears; it does not fall back to the default target. If omitted, the default target is used. Once dnsTargets is non-empty, adding or changing a targetId requires an ID in that list; unchanged target IDs are not re-checked.

        Example: "rcfg-097648d8068504966"
    • idoptionalstring

      Reverse private endpoint ID.

      format: uuid
      Example: "12345678-1234-1234-1234-123456789012"
    • serviceIdoptionalstring

      ClickHouse service ID reverse private endpoint is associated with.

      format: uuid
      Example: "12345678-1234-1234-1234-123456789012"
    • endpointIdoptionalstring

      Reverse private endpoint endpoint ID.

      Example: "vpce-12345678901234567"
    • dnsNamesoptionalarray ofstring

      Reverse private endpoint internal DNS names.

      Example: ["vpce-12345678901234567-abcdefg.execute-api.us-east-1.vpce.amazonaws.com"]
    • privateDnsNamesoptionalarray ofstring

      Reverse private endpoint private DNS names.

      Example: ["vpce-12345678901234567-abcdefg.execute-api.us-east-1.vpce.amazonaws.com"]
    • privateDnsMappingsoptionalarray ofobject

      Read-only provider private DNS names and their internal DNS targets reported by the Reverse Private Endpoint. For VPC_RESOURCE, this list can be empty when CHILD resources have no provider private DNS.

      Example: [{"privateDnsName":"my-service.example.com","internalDnsName":"internal.example.com"}]
      2 properties
      • privateDnsNameoptionalstring

        Provider private DNS name reported by the Reverse Private Endpoint.

        Example: "my-service.example.com"
      • internalDnsNameoptionalstring

        Internal DNS target for the provider private DNS name.

        Example: "vpce-0123456789abcdef0-abcdefg.vpce-svc-0123456789abcdef0.us-east-1.vpce.amazonaws.com"
    • dnsTargetsoptionalarray ofobject

      Read-only DNS targets the Reverse Private Endpoint currently reports. For VPC_RESOURCE, there is one RESOURCE_CONFIGURATION target per resource configuration association, identified by its CHILD resource configuration ID, or the configuration ID for a single resource. Other endpoint types report an empty list. Targets can appear over time; a custom mapping with a targetId that is not reported yet is not served until it appears.

      Example: [{"id":"rcfg-097648d8068504966","kind":"RESOURCE_CONFIGURATION","internalDnsName":"internal.example.com"}]
      3 properties
      • idoptionalstring

        DNS target ID. For VPC_RESOURCE, the associated CHILD resource configuration ID, or the configuration ID for a single resource.

        Example: "rcfg-097648d8068504966"
      • kindoptionalRESOURCE_CONFIGURATION

        DNS target kind.

        Example: "RESOURCE_CONFIGURATION"
      • internalDnsNameoptionalstring

        Internal DNS name currently reported for this target. To select a target for a custom private DNS mapping, use its id as targetId.

        Example: "vpce-052ef252671124ada.rcfg-097648d8068504966.4232ccc.vpc-lattice-rsc.us-east-1.on.aws"
    • statusoptionalUnknownorProvisioningorDeletingorReadyorFailedorPendingAcceptance+2 more

      Reverse private endpoint status.

      Example: "Ready"