The Keycloak Upgrade Ledger

Every upgrade we have rehearsed, with the environment stated and the clock running.

This is a log of Keycloak upgrades we have actually run, not a blog. One row per rehearsal: the versions, the dataset size, the database, the host, what condition it was run under, and what broke. Every run was performed in our own lab, so there is no customer to protect and the full environment is stated.

The number worth having is migration duration against a stated dataset size — the one you need to size a maintenance window, and the one nobody else publishes. Where a run measured it, it is in the timings. Where a claim was not established, the verification table says so with an unchecked box rather than leaving it out.

The runs

41 rehearsals, newest first. Every one performed in our own lab. Follow a version pair for the full environment, timings and what was verified.

DateUpgradeScaleDatabaseCondition
2026-09-01 26.0.0 → 26.7.3 Oracle Engines other than Postgres · DB user without DDL rights
2026-08-31 26.0.0 → 26.7.3 Oracle Engines other than Postgres · third engine, re-run at 26.7.3
2026-08-31 26.0.0 → 26.7.3 routine
2026-08-31 26.0.0 → 26.7.3 Postgres 16 Kubernetes / Infinispan, re-run at the 26.7.3 target
2026-08-31 26.7.1 → 26.7.3 1,000 users Postgres 16 routine
2026-08-31 26.7.1 → 26.7.3 1,000 users Postgres 16 routine
2026-08-31 26.7.1 → 26.7.3 1,000 users Postgres 16 routine
2026-08-31 26.0.0 → 26.7.3 1,000 users routine
2026-08-31 21.1.2 → 26.7.3 100,006 users routine
2026-08-26 26.0.0 → 26.7.1 100,002 users Postgres 16 routine
2026-08-26 26.0.0 → 26.7.1 1,000 users MySQL 8 DB user without DDL rights
2026-08-26 26.0.0 → 26.7.1 2,000,003 users Postgres 16 statement_timeout mid-flight
2026-08-26 26.0.0 → 26.7.1 2,000,003 users Postgres 16 Disk exhaustion mid-migration
2026-08-26 21.1.2 → 26.7.1 Postgres 16 routine
2026-08-26 26.0.0 → 26.7.1 1,000 users Postgres 16 routine
2026-08-26 26.0.0 → 26.7.1 100,000 users Postgres 16 routine
2026-08-26 21.1.2 → 26.7.1 100,006 users Postgres 16 routine
2026-08-26 26.0.0 → 26.7.1 Oracle Engines other than Postgres
2026-08-26 26.0.0 → 26.7.1 200 users MariaDB 11 Engines other than Postgres · DB user without DDL rights
2026-08-26 26.0.0 → 26.7.1 Postgres 16 Kubernetes and Infinispan
2026-08-26 26.0.0 → 26.7.1 2,000,003 users Postgres 16 routine
2026-08-26 26.0.0 → 26.7.1 200 users Postgres 16 Primary crash + failover, mid-migration
2026-08-25 26.0.0 → 26.7.1 Postgres 16 Real LDAP federation
2026-08-25 26.0.0 → 26.7.1 1,002 users Postgres 16 Pooler in transaction mode
2026-08-25 26.0.0 → 26.7.1 1,002 users Postgres 16 JVM heap too small
2026-08-25 26.0.0 → 26.7.1 1,002 users Postgres 16 DB user without DDL rights
2026-08-25 26.0.0 → 26.7.1 2,000,003 users Postgres 16 statement_timeout mid-flight
2026-08-25 23.0.7 → 24.0.5 Postgres 16 Unmanaged user attributes
2026-08-25 26.0.0 → 26.7.1 100,002 users Postgres 16 Disk exhaustion mid-migration
2026-08-25 26.0.0 → 26.7.1 202 users Postgres 16 Non-default KC_DB_SCHEMA — KC_DB_SCHEMA=kc
2026-08-25 26.0.0 → 26.7.1 202 users Postgres 13 Older Postgres major
2026-08-25 26.0.0 → 26.7.1 2,000,003 users Postgres 16 Theme configured, files absent
2026-08-25 26.0.0 → 26.7.1 100,002 users Postgres 16 routine
2026-08-25 26.0.0 → 26.7.1 2,000,003 users Postgres 16 routine
2026-08-25 26.0.0 → 26.7.1 100,002 users Postgres 16 Admin-event volume
2026-08-25 26.0.0 → 26.7.1 1,000 users Postgres 16 routine
2026-08-25 26.0.0 → 26.7.1 2,000,003 users Postgres 16 routine
2026-08-25 26.0.0 → 26.7.1 1,000 users Postgres 16 routine
2026-08-25 26.0.0 → 26.7.1 100,002 users Postgres 16 routine
2026-08-25 26.0.0 → 26.7.1 1,000 users Postgres 16 routine
2026-08-25 25.0.6 → 26.0.0 1,000 users Postgres 16 routine

Findings

22 rehearsals that were not upgrades. Narrowing a breaking change to the exact version that introduced it, or establishing what a configuration does across majors — no version pair to log, and the reason the runs above can cite a cause rather than a symptom.

Keycloak Advisory Watch — when Keycloak ships a security advisory batch, one email within 72 hours: which advisories affect which configurations, the minimum version that clears them, and what is known to break on the path there.

Typically 1–2 emails a month. Double opt-in. No tracking pixels, no click tracking. Public archive. Unsubscribe in one click.

Subscribe to Keycloak Advisory Watch →