// Bitnami drop-in images

Still pulling from bitnamilegacy?
Those images stopped getting security updates in 2025.

When Broadcom retired the free Bitnami catalogue, pinned versions moved to the bitnamilegacy archive, which receives no security updates, yet still sees heavy use: roughly 17 million pulls of bitnamilegacy/postgresql, 15 million of redis and 14 million of kafka by September 2026. The official replacement images use different environment variables, paths and entrypoints, so switching breaks charts. OSSeva ships patched images that keep the Bitnami layout, including for versions that are past end of life.

postgresql 11–14redis 6–7.2kafka 3.xzookeeper 3.xrabbitmq 3.xmongodb 4.4–6.0elasticsearch 7.x

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why teams are still on bitnamilegacy

Moving off Bitnami looks like a registry change. In practice it touches every chart and every values file that assumed Bitnami's conventions.

The official images are not drop-in

Bitnami images use their own environment variables (POSTGRESQL_*, REDIS_PASSWORD, KAFKA_CFG_*), their own data paths under /bitnami, and non-root defaults. The official images differ on all three, so charts and operators that were written for Bitnami break on the switch.

The versions you pinned are exactly the ones nobody patches

Production pins versions for good reasons: an application certified on PostgreSQL 13, a Kafka cluster still on ZooKeeper, a RabbitMQ 3.x estate mid-migration. The free alternatives publish current versions; the end-of-life versions you actually run are the gap.

Legacy pulls keep working, which hides the problem

Images in the bitnamilegacy archive still pull, so deployments keep succeeding. Scanners report the growing CVE count, but nothing breaks, so the migration keeps slipping.

The dates that matter

  1. 2025-07-16

    Bitnami announces the catalogue change on its containers repository.

  2. 2025-08-28

    Versioned tags move to docker.io/bitnamilegacy, which gets no further updates. Brownouts of the public catalogue begin.

  3. 2025-09-29

    The public catalogue is removed. Older images move to the bitnamilegacy archive, which receives no further security updates.

  4. 2026-08-31

    Bitnami Secure Images becomes part of Broadcom's TrueSource portfolio.

  5. 2026-10-22

    Minimus, another drop-in image provider, shuts down its registry as the company ceases operations.

What OSSeva delivers

1

Bitnami-compatible images

The same environment variables, paths, users and entrypoint behaviour as the Bitnami images you run, so existing charts and values files work after a registry change.

Drop-inNon-rootSame env vars
2

Patched EOL versions

Security fixes backported into the application and the base image for versions past community end of life, rebuilt when new advisories land, and signed.

EOL versionsSignedSBOM included
3

Chart migration

An inventory of every bitnami and bitnamilegacy reference across your clusters and a repoint to OSSeva images, chart by chart.

HelmRegistry repointInventory

Your options, compared

OptionWhat you getTrade-off
Official upstream imagesFree, maintained images for current versionsDifferent conventions mean chart changes, and EOL versions are not maintained.
Bitnami Secure ImagesMaintained Bitnami images from BroadcomA commercial subscription, now packaged with TrueSource; versions follow upstream support.
Docker Hardened ImagesFree hardened current images; a paid Extended Lifecycle Support tier adds five years past upstream EOLDocker's own image layout, so Bitnami charts still need changes.
Other hardened-image vendorsMinimal, hardened current-version imagesMost focus on current releases and their own image layout.
OSSeva drop-in imagesBitnami-compatible, patched images including EOL versionsA subscription per image family.
Stay on bitnamilegacyNothing newEvery advisory since the archive froze stays open in production.

Dates from the Bitnami containers repository announcement and Broadcom's TrueSource announcement.

Frequently asked questions

What replaces bitnamilegacy images?

For current versions, the official upstream images or Bitnami Secure Images. For end-of-life versions, and for teams that want to keep Bitnami's layout so charts keep working, OSSeva ships patched drop-in images.

Do OSSeva images work with Bitnami Helm charts?

Yes. They keep Bitnami's environment variables, paths, users and entrypoint behaviour, so you change image.registry and image.repository in your values and leave the rest.

Are bitnamilegacy images still getting security updates?

No. The legacy archive receives no further updates, with few exceptions. The images still pull, so deployments keep working while vulnerabilities accumulate.

Which images are covered?

The data and messaging images OSSeva already patches: PostgreSQL, Redis, Kafka, ZooKeeper, RabbitMQ, MongoDB and Elasticsearch, including end-of-life versions. Tell us what you pull and we will scope the rest.

How are the images delivered?

From a private registry, signed, with an SBOM for each image, or mirrored into your own registry.

Repoint the registry, keep the charts.

Send us your image list. We scope coverage and a migration plan within five working days.