> ## Documentation Index
> Fetch the complete documentation index at: https://private-7c7dfe99-parallel-read-in-order-multi-part.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# ClickHouse Cloud architecture

> This page describes the architecture of ClickHouse Cloud

export const PrivatePreviewBadge = () => {
  return <div className="privatePreviewBadge">
            <div className="privatePreviewIcon">
            <svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M5.33301 6.66667V4.66667V4.66667C5.33301 3.194 6.52701 2 7.99967 2V2C9.47234 2 10.6663 3.194 10.6663 4.66667V4.66667V6.66667" stroke="currentColor" strokeLinecap="round" strokeLinejoin="round" />
                <path d="M8.00033 9.33337V11.3334" stroke="currentColor" strokeLinecap="round" strokeLinejoin="round" />
                <path fillRule="evenodd" clipRule="evenodd" d="M11.333 14H4.66634C3.92967 14 3.33301 13.4033 3.33301 12.6666V7.99996C3.33301 7.26329 3.92967 6.66663 4.66634 6.66663H11.333C12.0697 6.66663 12.6663 7.26329 12.6663 7.99996V12.6666C12.6663 13.4033 12.0697 14 11.333 14Z" stroke="currentColor" strokeLinecap="round" strokeLinejoin="round" />
            </svg>
        </div>
            {'Private preview'}
        </div>;
};

export const Image = ({img, alt, size = "lg", background}) => {
  const normalizedSize = ["sm", "md", "lg"].includes(size) ? size : "lg";
  const backgroundColor = background === "white" ? "white" : background === "black" ? "rgb(31 31 28)" : undefined;
  return <div className={`ch-image-${normalizedSize}`}>
      <Frame>
        <img src={img} alt={alt} style={{
    backgroundColor
  }} />
      </Frame>
    </div>;
};

<Image img="https://mintcdn.com/private-7c7dfe99-parallel-read-in-order-multi-part/0fJmlhAIfr-a5jJ9/images/cloud/reference/architecture.webp?fit=max&auto=format&n=0fJmlhAIfr-a5jJ9&q=85&s=3548c8937a100197b708bde81410087d" size="lg" alt="Cloud architecture" width="2048" height="1376" data-path="images/cloud/reference/architecture.webp" />

<h2 id="storage-backed-by-object-store">
  Storage backed by object store
</h2>

* Virtually unlimited storage
* No need to manually shard data
* Significantly lower price point for storing data, especially data that is accessed less frequently

<h2 id="compute">
  Compute
</h2>

* Automatic scaling and idling: No need to size up front, and no need to over-provision for peak use
* Automatic idling and resume: No need to have unused compute running while no one is using it
* Secure and HA by default

<h2 id="administration">
  Administration
</h2>

* Setup, monitoring, backups, and billing are performed for you.
* Cost controls are enabled by default, and can be adjusted by you through the Cloud console.

<h2 id="service-isolation">
  Service isolation
</h2>

<h3 id="network-isolation">
  Network isolation
</h3>

All services are isolated at the network layer.

<h3 id="compute-isolation">
  Compute isolation
</h3>

All services are deployed in separate pods in their respective Kubernetes spaces, with network level isolation.

<h3 id="storage-isolation">
  Storage isolation
</h3>

All services use a separate subpath of a shared bucket (AWS, GCP) or storage container (Azure).

For AWS, access to storage is controlled via AWS IAM, and each IAM role is unique per service. For the Enterprise service, [CMEK](/products/cloud/guides/security/cmek) can be enabled to provide advanced data isolation at rest. CMEK is only supported for AWS services at this time.

For GCP and Azure, services have object storage isolation (all services have their own buckets or storage container).

<h2 id="compute-compute-separation">
  Compute-compute separation
</h2>

[Compute-compute separation](/products/cloud/features/infrastructure/warehouses) lets you create multiple compute node groups, each with their own service URL, that all use the same shared object storage. This allows for compute isolation of different use cases such as reads from writes, that share the same data. It also leads to more efficient resource utilization by allowing for independent scaling of the compute groups as needed.

<h2 id="on-demand-compute">
  On-Demand Compute
</h2>

<PrivatePreviewBadge />

On-Demand Compute temporarily assigns **workers** from a ClickHouse-managed pool to supported workloads through your existing ClickHouse Cloud service. Your service authenticates and coordinates the query, while assigned workers perform the bulk of eligible scan, join, and aggregation work outside the service's compute. The pool is shared across ClickHouse Cloud services, but each worker serves only one service at a time.

During the private preview, On-Demand Compute supports eligible `SELECT` queries only. Availability is best effort, performance varies, and ClickHouse Cloud SLOs and SLAs do not apply.

[Private Preview terms of service](https://clickhouse.com/legal/agreements/private-preview-terms-of-service)

<h2 id="concurrency-limits">
  Concurrency limits
</h2>

There is no limit to the number of queries per second (QPS) in your ClickHouse Cloud service. There is, however, a limit of 1000 concurrent queries per replica. QPS is ultimately a function of your average query execution time and the number of replicas in your service.

A major benefit of ClickHouse Cloud compared to a self-managed ClickHouse instance or other databases/data warehouses is that you can easily increase concurrency by [adding more replicas (horizontal scaling)](/products/cloud/features/autoscaling/horizontal#manual-horizontal-scaling).
