The Keycloak Upgrade Ledger

Every upgrade we have rehearsed, with the environment stated and the clock running.

2026-08-31 · run 2026-08-31-21.1.2-to-26.7.3-stepped

21.1.2 → 26.7.3 (stepped ladder, 100k rich)

Upgrade
21.1.2 → 26.7.3
Scale
baseline-21.1.2-rich-100k — 1 realm, 100,006 users, rich fixture
Host
laptop (docker 29.7.2)
Rehearsal
attempt 1 of 3 (ladder at 26.7.3 target) — this lab holds a path to three clean runs, one exercising rollback
Condition
routine — no adverse condition applied

Environment

FieldValue
Keycloak from → to21.1.2 → 26.7.3
Stepping path21.1.2 → 22.0.5 → 23.0.7 → 24.0.5 → 25.0.6 → 26.7.3
Distributionquay.io/keycloak/keycloak
Start modestart w/ external Postgres 16, single node
Datasetbaseline-21.1.2-rich-100k — 1 realm, 100,006 users, rich fixture
Seeding methodpartialImport (baseline pre-built)
Hostlaptop (docker 29.7.2)

Timings

HopDurationIndex audit
21.1.2 → 22.0.547s84 defs: 1 missing, 1 false-mismatch
22.0.5 → 23.0.728s84/84
23.0.7 → 24.0.524s88/88
24.0.5 → 25.0.620s89/89
25.0.6 → 26.7.320s119/119
Total~139s

Outcome

Breakage observed

1. idx_client_att_by_name_value genuinely missing (pre-existing in the 21.1.2 baseline)

2. index-audit.py false positive: varchar vs character varying

Rollback

Not exercised on this path this run (exercised on the patch-hop path in run 3).

← All runs