2026-08-31 · run 2026-08-31-26.7.1-to-26.7.3-1
26.7.1 → 26.7.3
Upgrade 26.7.1 → 26.7.3
Scale 1 realm (lab), 1,000 users, 11 clients (5 seeded + 6 default), 1 group (corp + 3 children), 2 IdP brokers, 1 LDAP component, 1 organization, 1 fine-grained-authz client
Database Postgres 16, single node
Topology single container
Host laptop (Arch Linux, docker 29.7.2 / compose 5.5.0)
Rehearsal attempt 1 of 3 — this lab holds a path to three clean runs, one exercising rollback
Condition routine — no adverse condition applied
Elapsed 24s (stop → ready)
Environment
Field Value
Keycloak from → to 26.7.1 → 26.7.3
Stepping path (if multi-hop) direct (patch hop, no stepping)
Distribution quay.io/keycloak/keycloak (official image)
Start mode start w/ external Postgres — never start-dev
Database Postgres 16, single node
Postgres tuning stock defaults (no shared_buffers / maintenance_work_mem / statement_timeout override)
Adverse scenario none — routine patch hop, motivated by the 2026-08 advisory batch
Dataset scale 1 realm (lab), 1,000 users , 11 clients (5 seeded + 6 default), 1 group (corp + 3 children), 2 IdP brokers, 1 LDAP component, 1 organization, 1 fine-grained-authz client
Seeding method partialImport (1,000 users in 69s)
Fixture profile kitchen-sink
Topology single container
Host laptop (Arch Linux, docker 29.7.2 / compose 5.5.0)
JVM heap -Xms1g -Xmx4g
Elapsed clock 24s (stop → ready)
Procedure
./bin/lab-up.sh 26.7.1
./bin/seed-realm.sh --profile kitchen-sink --users 1000
./bin/upgrade.sh 26.7.3 # stop → pg_dump backup → image swap → up → wait-ready → index-audit
Timings
Phase Duration Notes
Container start → DB connect — not isolated this run
Liquibase / schema migration 0 changesets no migration log lines emitted; see Finding
Cache/realm warm — not isolated
First successful token issue — admin-cli token issued immediately after ready
Total to ready 24s includes image pull for 26.7.3
Outcome
Breakage observed
None attributable to the migration. One pre-existing seed-time issue (not a
migration result):
seed-realm --user-profile 400 on 26.7.1
Symptom: declarative user-profile PUT rejected with
[Validator 'username_prohibited_characters' defined for attribute 'username' doesn't exist].
Evidence: seed-realm.sh output, before the upgrade ran.
Cause: the seed fixture names a validator that no longer exists at 26.7.1.
Fix or workaround: correct the validator name in bin/seed-realm.sh
(or drop it for 26.7.x). Not chased this run — out of scope for the patch hop.
Would this hit a customer? No — fixture-only, no bearing on migration.
Rollback
Exercised this run? no
Method: snapshot restore — backup pre-upgrade-26.7.1-to-26.7.3-20260831T212644Z (pg_dump -Fc)
Time to restore: not measured
Data loss / divergence: n/a
Verdict: backup taken; restore path unexercised (must be exercised on one
of the remaining two clean runs per launch-plan §6).
Verification
Claim Primary source Checked
26.7.1 already carries the 2026-08-06 advisory batch (7 CVEs, all keycloak-services) GHSA-95cx-vmr5-3cmr etc.; affected range < 26.7.1, patched 26.7.1 yes
26.7.3 adds the 26.7.2 + 26.7.3 security batches (~27 fixes) missing from 26.7.1 26.7.2 / 26.7.3 release notes (github.com/keycloak/keycloak/releases) yes
26.7.1 → 26.7.3 emits no Liquibase changesets this run's log (no liquibase/changelog lines) yes
Schema indexes correct at 26.7.3 index-audit.sh 26.7.3: 119/119 correct, 0 missing/wrongyes
26.7.2 → 26.7.3 removes 4 SPI signatures reports/diffs/api-26.7.2-to-26.7.3.txtyes
(empty — internal; needs the two remaining clean runs + rollback before a
ledger entry can be derived.)
← All runs
Maintained by MLabs . Every run here was
performed in our own lab — there is no customer to protect, so the full environment
and everything that broke is stated.
This page counts visits with Umami , self-hosted
on our own server. No cookies, no cross-site identifier, no third party, and nothing
about you leaves mlabs.city.
Atom feed