OSSEVA FOR CLICKHOUSE
Your ClickHouse release left support months ago. So did its ZooKeeper.
ClickHouse ships a stable release roughly every month and supports only the latest three, plus two LTS lines for a year each. Analytics clusters are rarely upgraded that often, and the ZooKeeper ensemble holding their replication metadata is usually older still. OSSeva patched builds are available today for both.
Trusted globally by enterprises




Why now
Only a handful of releases are supported at any time
Stable releases arrive roughly monthly and the three latest are supported. LTS releases ship twice a year, in March and August, and are supported for one year. On 29 September 2026 the supported list is 26.9, 26.8, 26.7 and 26.3. Every 25.x release, including the 25.3 and 25.8 LTS lines, is outside it.
The ZooKeeper under your replicated tables is a time bomb
ReplicatedMergeTree keeps parts, merges and the replication log in ZooKeeper or ClickHouse Keeper. ClickHouse accepts any ZooKeeper from 3.4.5, so nothing warns you when the ensemble sits on a line that has been end of life since 2020. ZooKeeper 3.4, 3.5 and 3.6 never received a fix for CVE-2023-44981, a critical SASL quorum authentication bypass. Without a configured coordination service, existing replicated tables are read-only.
Moving to ClickHouse Keeper takes a maintenance window
Keeper speaks the ZooKeeper client protocol, but its snapshot, log and interserver formats are different, so a mixed ZooKeeper and Keeper ensemble is impossible. The documented migration stops ingestion and background merges, stops ZooKeeper, converts its data with clickhouse-keeper-converter and starts Keeper from the converted snapshot. It is a planned change, not a rolling one.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 24.x and older(Out of community support. OSSeva patched) | EOL | Clean |
| 25.x (incl. 25.3, 25.8 LTS)(Out of community support. OSSeva patched) | EOL | Clean |
| 26.1, 26.2, 26.4 to 26.6(Dropped from the stable window. OSSeva patched) | EOL | Clean |
| 26.3 LTS(LTS released 27 Mar 2026. Upstream maintained) | Extended | Clean |
| 26.7, 26.9(Stable. Upstream maintained) | Current | Clean |
| 26.8 LTS(LTS released 30 Aug 2026. Upstream maintained) | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Patched, signed builds for ClickHouse releases outside the community window, and for the ZooKeeper under them.
- Security backports on the ClickHouse release you run, same on-disk format
- Patched ZooKeeper 3.4, 3.5, 3.6 and 3.7 builds for the coordination ensemble
- Bundled library and toolchain CVE coverage
- Deb / RPM / Docker / tarball delivery
- Signed artifacts (GPG)
- ClickHouse Keeper migration plan
- 24/7 managed operations
OSSeva Assure
Patch plus a cluster and coordination audit, and a Keeper migration plan.
- Everything in Patch
- Replication, sharding and coordination topology review
- ZooKeeper ensemble ACL, SASL and exposure audit
- ClickHouse Keeper migration plan with a tested runbook
- SOC 2 / HIPAA attestation package, including VEX for scanner findings
- Upgrade plan to a supported stable or LTS release
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 cluster monitoring, 15-min SLA, named engineers.
- Everything in Assure
- 24/7 replication queue, merge and Keeper quorum monitoring
- 15-minute P1 incident response SLA
- Named senior ClickHouse engineer
- ZooKeeper to ClickHouse Keeper cutover, run in your maintenance window
- Release upgrades executed shard by shard
- Quarterly capacity and query performance reviews
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
-- Server release. Compare with the supported list in SECURITY.md
SELECT version();
-- Rows here mean a ZooKeeper-compatible service is configured
SELECT * FROM system.zookeeper_connection;
-- Then ask the ensemble itself which version it runs:
-- echo srvr | nc zk1.internal 2181 | head -1
-- Anything on 3.7 or below receives no upstream security fixes.# Run on the ZooKeeper leader after ingestion, merges and ZooKeeper are stopped
clickhouse-keeper-converter \
--zookeeper-logs-dir /var/lib/zookeeper/version-2 \
--zookeeper-snapshots-dir /var/lib/zookeeper/version-2 \
--output-dir /var/lib/clickhouse/coordination/snapshots
# Copy the snapshot to every Keeper node before any node starts,
# then point ClickHouse at the Keeper cluster and restart it.# Same release line, same on-disk format, patched
docker pull artifacts.osseva.io/clickhouse-server:24.8-osseva-1
docker run -d --name clickhouse \
-p 8123:8123 -p 9000:9000 \
-v /var/lib/clickhouse:/var/lib/clickhouse \
artifacts.osseva.io/clickhouse-server:24.8-osseva-1Migrate from Out-of-support community ClickHouse releases
OSSeva ships patched builds on the ClickHouse release you already run, so table formats, settings and query behaviour stay as they are while the cluster becomes secure. The same contract patches the ZooKeeper ensemble under your replicated tables and, when you are ready, moves coordination to ClickHouse Keeper in a planned maintenance window.
Pricing model
OSSeva for ClickHouse is priced per cluster, not per node, shard or replica.
Frequently asked questions
How long is a ClickHouse release supported?
Stable releases ship roughly monthly, and the three latest get bug fix backports. LTS releases ship twice a year and are supported for one year after their first release. The project's SECURITY.md lists the versions that receive security updates: on 29 September 2026 that is 26.9, 26.8, 26.7 and the 26.3 LTS. Every 25.x release and older is marked unsupported.
Can I move from ZooKeeper to ClickHouse Keeper without downtime?
No. ClickHouse documents the migration as an offline change. You stop ingestion and background tasks, stop ZooKeeper, convert its logs and snapshots with clickhouse-keeper-converter, copy the snapshot to every Keeper node and then start Keeper. Keeper cannot join a ZooKeeper ensemble, because the interserver protocol and storage formats differ. OSSeva runs this cutover as a rehearsed runbook inside your maintenance window.
Do my ZooKeeper clients work against ClickHouse Keeper?
Yes. Keeper implements the ZooKeeper client-server protocol, so ClickHouse and standard ZooKeeper clients connect to it unchanged. It supports the same world, auth and digest ACL schemes. Keeper is written in C++ and uses Raft through the NuRaft library rather than ZooKeeper's ZAB protocol.
The ZooKeeper ensemble also serves Kafka or Solr. What then?
Then moving ClickHouse to Keeper does not retire the ensemble. OSSeva patched builds for ZooKeeper 3.4, 3.5, 3.6 and 3.7 are available today, so the shared ensemble can be secured in place while each system above it moves on its own timetable.
Where does OSSeva fit alongside Altinity Stable builds?
Altinity publishes Altinity Stable builds, which it describes as LTS-certified binaries with three years of support. If you run one of those inside its window, that is a sound patch source. OSSeva covers the releases outside any support window, including community stable releases that were never LTS, and the ZooKeeper ensemble underneath them.
Ready to get ClickHouse patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.