> ## Documentation Index
> Fetch the complete documentation index at: https://private-7c7dfe99-parallel-read-in-order-multi-part.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create BYOC Infrastructure

> Create a new BYOC Infrastructure in the organization. Returns the configuration of the newly created infrastructure

Create a new BYOC Infrastructure in the organization. Returns the configuration of the newly created infrastructure

<div data-permissions class="api-section">
  <div class="api-section-heading flex flex-col gap-y-4 w-full">
    <div class="flex items-baseline border-b pb-2.5 border-gray-100 dark:border-gray-800 w-full">
      <h4 class="api-section-heading-title flex-1 mb-0">Permission</h4>
    </div>
  </div>

  <div class="py-6">
    The API key must have the `control-plane:organization:manage` permission.
  </div>
</div>


## OpenAPI

````yaml /_specs/cloud-openapi.json post /v1/organizations/{organizationId}/byocInfrastructure
openapi: 3.1.1
info:
  title: OpenAPI spec for ClickHouse Cloud
  version: '1.0'
  contact:
    name: ClickHouse Support
    url: >-
      https://clickhouse.com/docs/en/cloud/manage/openapi?referrer=openapi-1222280
    email: support@clickhouse.com
servers:
  - url: https://api.clickhouse.cloud
security:
  - basicAuth: []
tags:
  - name: Organization
  - name: Notifications
  - name: User management
  - name: Billing
  - name: Role Management
  - name: Service
  - name: Backup
  - name: Snapshot
  - name: API keys
  - name: Prometheus
  - name: ClickPipes
  - name: ClickStack
  - name: Postgres
  - name: UDF
  - name: Query API endpoints
  - name: Saved queries
paths:
  /v1/organizations/{organizationId}/byocInfrastructure:
    post:
      tags:
        - Organization
      summary: Create BYOC Infrastructure
      description: >-
        Create a new BYOC Infrastructure in the organization. Returns the
        configuration of the newly created infrastructure
      operationId: organizationByocInfrastructureCreate
      parameters:
        - in: path
          name: organizationId
          description: ID of the requested organization.
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ByocInfrastructurePostRequest'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: number
                    description: HTTP status code.
                    example: 200
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
                  result:
                    $ref: '#/components/schemas/ByocConfig'
        '400':
          description: >-
            The request cannot be processed due to a client error. Please verify
            your request parameters and try again.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: number
                    description: HTTP status code.
                    example: 400
                  error:
                    type: string
                    description: Detailed error description.
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
        '500':
          description: >-
            An internal server error has occurred. If this issue persists,
            please contact ClickHouse Cloud support for assistance.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: integer
                    description: HTTP status code.
                    example: 500
                  error:
                    type: string
                    description: Detailed error description.
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
components:
  schemas:
    ByocInfrastructurePostRequest:
      properties:
        regionId:
          description: Region in which the BYOC infrastructure will be located
          type: string
          enum:
            - ap-northeast-1
            - ap-northeast-2
            - ap-south-1
            - ap-southeast-1
            - ap-southeast-2
            - ca-central-1
            - eu-central-1
            - eu-west-1
            - eu-west-2
            - il-central-1
            - us-east-1
            - us-east-2
            - us-west-2
            - us-east1
            - us-central1
            - europe-west2
            - europe-west4
            - asia-southeast1
            - asia-northeast1
            - eastus
            - eastus2
            - westus3
            - germanywestcentral
            - centralus
        accountId:
          description: >-
            Cloud account ID the BYOC infrastructure is configured for: AWS
            account ID, GCP project ID, or Azure subscription ID
          type: string
          example: '123456789012'
        availabilityZoneSuffixes:
          type: array
          description: List of availability zone suffixes
          items:
            type: string
            enum:
              - a
              - b
              - c
              - d
              - e
              - f
        vpcCidrRange:
          description: >-
            CIDR range for the ClickHouse-managed VPC. Mutually exclusive with
            the BYO-VPC fields (`vpcId`, `privateSubnetIds`, `publicSubnetIds`)
          type: string
          example: 10.0.0.0/16
        externalId:
          description: >-
            AWS only: ExternalID baked into the ClickHouse management role trust
            policy in your account
          type: string
          example: ch-0a1b2c3d4e5f6789
        tenantId:
          description: >-
            Azure only (required for Azure regions): Entra tenant ID of the
            subscription
          type: string
        servicePrincipalClientId:
          description: >-
            Azure only (required for Azure regions): client ID of the service
            principal ClickHouse uses to manage the infrastructure
          type: string
        vpcId:
          description: >-
            BYO-VPC only (AWS and GCP): ID or network name of the
            customer-provided VPC to deploy into. Requires `privateSubnetIds`
          type: string
          example: vpc-0abc1234def567890
        privateSubnetIds:
          type: array
          description: >-
            BYO-VPC only: private subnet IDs or names (1-6 entries on AWS,
            exactly one on GCP)
          items:
            type: string
        publicSubnetIds:
          type: array
          description: 'AWS BYO-VPC only: public subnet IDs (at most 6 entries)'
          items:
            type: string
        gcpPodCidrRangeNames:
          type: array
          description: >-
            GCP BYO-VPC only: secondary IP range names on the subnet to use for
            pod IPs. Omitted: all secondary ranges are used
          items:
            type: string
        gcpSharedVpcHostProjectId:
          description: >-
            GCP BYO-VPC only: Shared VPC host project owning the VPC and subnet,
            when different from `accountId`
          type: string
        tags:
          $ref: '#/components/schemas/ByocInfrastructureTags'
        displayName:
          description: Human readable name for infrastructure
          type: string
      required:
        - regionId
        - accountId
    ByocConfig:
      properties:
        id:
          description: Unique identifier of the BYOC configuration
          type: string
        state:
          description: State of the infrastructure
          type: string
          enum:
            - infra-provisioning
            - infra-terminated
            - infra-terminating
            - infra-ready
            - infra-degraded
            - infra-upgrading
          example: infra-ready
        accountId:
          description: >-
            Cloud account ID the BYOC infrastructure is bound to: AWS account
            ID, GCP project ID, or Azure subscription ID
          type: string
          example: '123456789012'
        accountName:
          description: >-
            DEPRECATED. Use `accountId` instead. Cloud account ID the BYOC
            infrastructure is bound to
          type: string
          deprecated: true
        regionId:
          description: >-
            Region for which the BYOC has been configured and where it is
            possible to create services
          type: string
          enum:
            - ap-northeast-1
            - ap-northeast-2
            - ap-south-1
            - ap-southeast-1
            - ap-southeast-2
            - ca-central-1
            - eu-central-1
            - eu-west-1
            - eu-west-2
            - il-central-1
            - us-east-1
            - us-east-2
            - us-west-2
            - us-east1
            - us-central1
            - europe-west2
            - europe-west4
            - asia-southeast1
            - asia-northeast1
            - eastus
            - eastus2
            - westus3
            - germanywestcentral
            - centralus
        cloudProvider:
          description: Cloud provider of the region
          type: string
          enum:
            - gcp
            - aws
            - azure
        displayName:
          description: Human readable name for infrastructure
          type: string
    ByocInfrastructureTags:
      type: object
      additionalProperties:
        type: string
      maxProperties: 50
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: >-
        Use key ID and key secret obtained in ClickHouse Cloud console:
        https://clickhouse.com/docs/cloud/manage/openapi
      x-permission-scopes: >-
        The scope list of a `security` requirement holds ClickHouse Cloud API
        key permission ids (for example `control-plane:organization:view`), not
        OAuth scopes. OpenAPI has no field for API key permissions, so this is
        the closest available place. A key must hold every permission listed on
        an operation to call it; an operation with no scopes needs none beyond a
        valid key. Every operation declares at most one requirement object,
        always for this scheme, so the list is only ever conjunctive —
        alternative sets of permissions are never expressed.

````