// OSSeva Blog
OperationsWho Provides HashiCorp Consul Support After the BSL Change and IBM?
The short answer
For Consul 1.21, 1.22 and 2.0, HashiCorp, now part of IBM, supports Consul Enterprise: 1.21 is the last LTS release and runs to 30 April 2027, 1.22 ends on 31 October 2026, and 2.0 follows IBM's Support Cycle-2 with base support to 30 April 2028. For the MPL 2.0 releases, 1.16.3 and earlier, OSSeva publishes patched builds. For the BSL-licensed lines from 1.17 onwards that are already out of support, OSSeva plans and runs the upgrade or a migration rather than patching BSL code. Perforce OpenLogic lists Consul at its Bronze support level. HashiCorp's managed HCP Consul Dedicated reached end of life on 12 November 2025.
Two questions decide most cases: which licence your version is under, and whether you hold a Consul Enterprise subscription. The licence decides who can patch it, and the subscription decides whether HashiCorp's dates apply to you at all.
Which Consul versions HashiCorp still supports
HashiCorp publishes end-of-support dates for Consul Enterprise. Long-term support releases started with 1.15, for the first major release of each calendar year, and require Consul Enterprise.
| Version | Licence | Consul Enterprise end of support |
|---|---|---|
| 2.0 | BSL 1.1 | Base support to 30 April 2028, IBM extended support to 30 April 2029, sustained support to 30 April 2032 |
| 1.22 | BSL 1.1 | 31 October 2026 |
| 1.21 (LTS) | BSL 1.1 | 30 April 2027, the last LTS release |
| 1.19 and 1.20 | BSL 1.1 | Ended |
| 1.18 (LTS) | BSL 1.1 | Ended 30 April 2026 |
| 1.17 | BSL 1.1 | Ended |
| 1.16 | MPL 2.0 up to 1.16.3 | Ended |
| 1.15 (LTS) | MPL 2.0 for its early releases | Ended 30 April 2025 |
The Consul licence names version 1.17.0 and later as the Licensed Work under the Business Source License 1.1, with IBM as licensor. OSSeva treats 1.16.3 as the last MPL 2.0 release and builds only from MPL source up to it. Under IBM's Support Cycle-2, 2.0 gets two years of base support, one year of extended support with critical fixes and limited security patches, and three years of sustained support with access to technical support but no new fixes. The Consul end-of-life chart tracks every line, Consul end of life, BSL and IBM covers the licence change, and Consul vulnerabilities by version lists the advisories.
HashiCorp Consul support providers compared
Each row reflects what the provider publishes on its own site as of 7 October 2026.
| Provider | What it covers | Consul versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| HashiCorp (IBM) | Consul Enterprise support, with LTS releases to 1.21 and IBM Support Cycle-2 from 2.0 | 2.0 to April 2028 (base); 1.21 LTS to 30 April 2027; 1.22 to 31 October 2026 | Consul Enterprise subscription | Yes, on Consul Enterprise |
| HCP Consul Dedicated | Reached end of life on 12 November 2025; HashiCorp's migration path is self-managed Consul Enterprise, not the community edition | None | Retired managed service | No |
| Perforce OpenLogic | HashiCorp Consul technical support, listed at the Bronze level only | No version list published | Support subscription | Yes |
| OSSeva | Patched builds of MPL 2.0 Consul; licence and configuration audit with an upgrade or migration plan on Assure; 24/7 operations and executed upgrades on Operate | Patched builds for 1.16.3 and earlier. Supported upgrades and migration for 1.17 and later, without redistributing modified BSL code | Signed binaries, Docker images and packages | Yes |
The licence shapes the OSSeva row. BSL code can be run in production under its additional use grant, but OSSeva does not ship modified builds of it, so a cluster on 1.17 or later gets help moving to a supported release or to another coordination store rather than a patched build.
How the providers differ
HashiCorp and IBM
If you run Consul Enterprise, HashiCorp is the direct answer. 1.21 is the last LTS release and runs to 30 April 2027, and 2.0 starts IBM's Support Cycle-2 with base support to April 2028 and extended and sustained support phases after that. Version numbers also move to IBM's version, modification and fix scheme from 2.0. HashiCorp's dates are published for Consul Enterprise, so a community-edition cluster gets no support from them without a subscription, and its retired HCP Consul Dedicated customers were pointed to self-managed Consul Enterprise rather than the community edition.
Perforce OpenLogic
OpenLogic lists HashiCorp Consul at its Bronze support level only, where it lists technologies such as Hadoop and ZooKeeper at Gold, Silver and Bronze. It suits teams that want Consul covered inside a wider contract. It does not publish patched Consul builds. See OSSeva vs OpenLogic.
OSSeva
OSSeva for Consul ships patched, signed builds of the MPL 2.0 releases, 1.16.3 and earlier, rebuilt on a supported Go toolchain with patched dependencies, for both server and client agents. For the BSL lines, Assure adds a version and licence inventory across every datacenter, an ACL, gossip encryption and TLS audit, a map of every system that coordinates through Consul, such as Patroni or Vitess, and an upgrade or migration plan. Operate adds 24/7 Raft and autopilot monitoring, a 15-minute P1 response, a named Consul engineer, tested snapshot backups, rolling upgrades with quorum preserved and, where it fits, a migration of coordination to etcd or Kubernetes. Operate patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days on the MPL builds. Pricing is per cluster, not per node, agent or registered service.
How to choose
| Situation | Usual answer |
|---|---|
| Consul Enterprise on 1.21 or 1.22 | HashiCorp, with the move to 2.0 planned before October 2026 for 1.22 and April 2027 for 1.21 |
| Former HCP Consul Dedicated customer | Self-managed Consul Enterprise, as HashiCorp directs |
| Community Consul 1.16.3 or earlier, and the MPL licence matters | OSSeva patched builds |
| Community Consul 1.17 to 1.20, out of support | An upgrade to a maintained release, or a move to another coordination store, with OSSeva Assure or Operate running it |
| Consul used only for leader election or configuration | Consider etcd or ZooKeeper, which Patroni and Vitess, for example, also support |
| Want one contract across many technologies | OpenLogic at Bronze, or OSSeva for the infrastructure layer |
The Consul upgrade guide covers the upgrade path, and ZooKeeper vs etcd vs Consul compares the coordination stores.
Where OSSeva fits
OSSeva covers community Consul in two ways: patched builds for the MPL 2.0 releases, and supported upgrades or migrations for the BSL releases that have fallen out of support. Consul extended support covers both in more detail.
Frequently asked questions
Is there commercial support for HashiCorp Consul after the BSL change?
Yes. HashiCorp, now part of IBM, sells Consul Enterprise support, with 1.21 LTS to 30 April 2027 and 2.0 under IBM's Support Cycle-2. Perforce OpenLogic lists Consul at its Bronze level. OSSeva patches the MPL 2.0 releases, 1.16.3 and earlier, and runs upgrades and migrations for the BSL releases.
Which Consul versions are open source?
The releases under MPL 2.0, up to and including 1.16.3. The Consul licence names 1.17.0 and later as the Licensed Work under the Business Source License 1.1, and each BSL version converts to MPL 2.0 four years after it is published.
Who patches Consul 1.16 and older?
OSSeva publishes patched builds of MPL 2.0 Consul, 1.16.3 and earlier. HashiCorp's support for 1.16 and for 1.15 LTS has ended.
Can a third party patch Consul 1.17 or later?
OSSeva does not redistribute modified BSL code, so for 1.17 and later it plans and runs a supported upgrade or a migration to another coordination store instead. Security fixes for the BSL lines come from HashiCorp's own releases.
What replaced HCP Consul Dedicated?
HCP Consul Dedicated reached end of life on 12 November 2025. HashiCorp's migration path is self-managed Consul Enterprise, and it says migrating to community edition clusters is not possible.
What does IBM Support Cycle-2 mean for Consul?
From the April 2026 2.x release, each Consul Enterprise version gets two years of base support, one year of extended support with critical bug fixes and limited security patches, and three years of sustained support with technical support access but no new fixes. For 2.0 those phases end in April 2028, 2029 and 2032.
Tags
Related articles
How to Document End-of-Life Software Risk: Risk Register, Exceptions and Compensating Controls
October 7, 2026ComplianceEnd-of-Life Software Policy Template for Open Source Infrastructure
October 7, 2026OperationsWho Provides Support for Apache Hadoop 2.x and 3.x After End of Life?
October 7, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.