Back to blog

// OSSeva Blog

Operations

Who Provides HashiCorp Consul Support After the BSL Change and IBM?

Matt Reynolds8 min read

The short answer

For Consul 1.21, 1.22 and 2.0, HashiCorp, now part of IBM, supports Consul Enterprise: 1.21 is the last LTS release and runs to 30 April 2027, 1.22 ends on 31 October 2026, and 2.0 follows IBM's Support Cycle-2 with base support to 30 April 2028. For the MPL 2.0 releases, 1.16.3 and earlier, OSSeva publishes patched builds. For the BSL-licensed lines from 1.17 onwards that are already out of support, OSSeva plans and runs the upgrade or a migration rather than patching BSL code. Perforce OpenLogic lists Consul at its Bronze support level. HashiCorp's managed HCP Consul Dedicated reached end of life on 12 November 2025.

Two questions decide most cases: which licence your version is under, and whether you hold a Consul Enterprise subscription. The licence decides who can patch it, and the subscription decides whether HashiCorp's dates apply to you at all.

Which Consul versions HashiCorp still supports

HashiCorp publishes end-of-support dates for Consul Enterprise. Long-term support releases started with 1.15, for the first major release of each calendar year, and require Consul Enterprise.

VersionLicenceConsul Enterprise end of support
2.0BSL 1.1Base support to 30 April 2028, IBM extended support to 30 April 2029, sustained support to 30 April 2032
1.22BSL 1.131 October 2026
1.21 (LTS)BSL 1.130 April 2027, the last LTS release
1.19 and 1.20BSL 1.1Ended
1.18 (LTS)BSL 1.1Ended 30 April 2026
1.17BSL 1.1Ended
1.16MPL 2.0 up to 1.16.3Ended
1.15 (LTS)MPL 2.0 for its early releasesEnded 30 April 2025

The Consul licence names version 1.17.0 and later as the Licensed Work under the Business Source License 1.1, with IBM as licensor. OSSeva treats 1.16.3 as the last MPL 2.0 release and builds only from MPL source up to it. Under IBM's Support Cycle-2, 2.0 gets two years of base support, one year of extended support with critical fixes and limited security patches, and three years of sustained support with access to technical support but no new fixes. The Consul end-of-life chart tracks every line, Consul end of life, BSL and IBM covers the licence change, and Consul vulnerabilities by version lists the advisories.

HashiCorp Consul support providers compared

Each row reflects what the provider publishes on its own site as of 7 October 2026.

ProviderWhat it coversConsul versionsDelivery modelSelf-managed?
HashiCorp (IBM)Consul Enterprise support, with LTS releases to 1.21 and IBM Support Cycle-2 from 2.02.0 to April 2028 (base); 1.21 LTS to 30 April 2027; 1.22 to 31 October 2026Consul Enterprise subscriptionYes, on Consul Enterprise
HCP Consul DedicatedReached end of life on 12 November 2025; HashiCorp's migration path is self-managed Consul Enterprise, not the community editionNoneRetired managed serviceNo
Perforce OpenLogicHashiCorp Consul technical support, listed at the Bronze level onlyNo version list publishedSupport subscriptionYes
OSSevaPatched builds of MPL 2.0 Consul; licence and configuration audit with an upgrade or migration plan on Assure; 24/7 operations and executed upgrades on OperatePatched builds for 1.16.3 and earlier. Supported upgrades and migration for 1.17 and later, without redistributing modified BSL codeSigned binaries, Docker images and packagesYes

The licence shapes the OSSeva row. BSL code can be run in production under its additional use grant, but OSSeva does not ship modified builds of it, so a cluster on 1.17 or later gets help moving to a supported release or to another coordination store rather than a patched build.

How the providers differ

HashiCorp and IBM

If you run Consul Enterprise, HashiCorp is the direct answer. 1.21 is the last LTS release and runs to 30 April 2027, and 2.0 starts IBM's Support Cycle-2 with base support to April 2028 and extended and sustained support phases after that. Version numbers also move to IBM's version, modification and fix scheme from 2.0. HashiCorp's dates are published for Consul Enterprise, so a community-edition cluster gets no support from them without a subscription, and its retired HCP Consul Dedicated customers were pointed to self-managed Consul Enterprise rather than the community edition.

Perforce OpenLogic

OpenLogic lists HashiCorp Consul at its Bronze support level only, where it lists technologies such as Hadoop and ZooKeeper at Gold, Silver and Bronze. It suits teams that want Consul covered inside a wider contract. It does not publish patched Consul builds. See OSSeva vs OpenLogic.

OSSeva

OSSeva for Consul ships patched, signed builds of the MPL 2.0 releases, 1.16.3 and earlier, rebuilt on a supported Go toolchain with patched dependencies, for both server and client agents. For the BSL lines, Assure adds a version and licence inventory across every datacenter, an ACL, gossip encryption and TLS audit, a map of every system that coordinates through Consul, such as Patroni or Vitess, and an upgrade or migration plan. Operate adds 24/7 Raft and autopilot monitoring, a 15-minute P1 response, a named Consul engineer, tested snapshot backups, rolling upgrades with quorum preserved and, where it fits, a migration of coordination to etcd or Kubernetes. Operate patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days on the MPL builds. Pricing is per cluster, not per node, agent or registered service.

How to choose

SituationUsual answer
Consul Enterprise on 1.21 or 1.22HashiCorp, with the move to 2.0 planned before October 2026 for 1.22 and April 2027 for 1.21
Former HCP Consul Dedicated customerSelf-managed Consul Enterprise, as HashiCorp directs
Community Consul 1.16.3 or earlier, and the MPL licence mattersOSSeva patched builds
Community Consul 1.17 to 1.20, out of supportAn upgrade to a maintained release, or a move to another coordination store, with OSSeva Assure or Operate running it
Consul used only for leader election or configurationConsider etcd or ZooKeeper, which Patroni and Vitess, for example, also support
Want one contract across many technologiesOpenLogic at Bronze, or OSSeva for the infrastructure layer

The Consul upgrade guide covers the upgrade path, and ZooKeeper vs etcd vs Consul compares the coordination stores.

Where OSSeva fits

OSSeva covers community Consul in two ways: patched builds for the MPL 2.0 releases, and supported upgrades or migrations for the BSL releases that have fallen out of support. Consul extended support covers both in more detail.

Frequently asked questions

Is there commercial support for HashiCorp Consul after the BSL change?

Yes. HashiCorp, now part of IBM, sells Consul Enterprise support, with 1.21 LTS to 30 April 2027 and 2.0 under IBM's Support Cycle-2. Perforce OpenLogic lists Consul at its Bronze level. OSSeva patches the MPL 2.0 releases, 1.16.3 and earlier, and runs upgrades and migrations for the BSL releases.

Which Consul versions are open source?

The releases under MPL 2.0, up to and including 1.16.3. The Consul licence names 1.17.0 and later as the Licensed Work under the Business Source License 1.1, and each BSL version converts to MPL 2.0 four years after it is published.

Who patches Consul 1.16 and older?

OSSeva publishes patched builds of MPL 2.0 Consul, 1.16.3 and earlier. HashiCorp's support for 1.16 and for 1.15 LTS has ended.

Can a third party patch Consul 1.17 or later?

OSSeva does not redistribute modified BSL code, so for 1.17 and later it plans and runs a supported upgrade or a migration to another coordination store instead. Security fixes for the BSL lines come from HashiCorp's own releases.

What replaced HCP Consul Dedicated?

HCP Consul Dedicated reached end of life on 12 November 2025. HashiCorp's migration path is self-managed Consul Enterprise, and it says migrating to community edition clusters is not possible.

What does IBM Support Cycle-2 mean for Consul?

From the April 2026 2.x release, each Consul Enterprise version gets two years of base support, one year of extended support with critical bug fixes and limited security patches, and three years of sustained support with technical support access but no new fixes. For 2.0 those phases end in April 2028, 2029 and 2032.

Tags

ConsulHashiCorpBSLEnd of LifeVendor Comparison

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.