OSSEVA FOR HASHICORP CONSUL
Consul went BSL at 1.17. Your cluster may still be on the other side.
HashiCorp moved Consul from MPL 2.0 to the Business Source License with 1.17.0, and IBM is now the named licensor. Support windows have changed too: 1.18 LTS ended on 30 April 2026 and 1.22 ends on 31 October 2026. OSSeva patched builds for the MPL lines are available today.
Trusted globally by enterprises




Why now
Consul is the Raft-based coordination layer under other systems
Consul servers replicate the catalogue, key/value store and session locks through Raft. Other systems lean on that: Patroni can keep its PostgreSQL leader lock in Consul, and Vitess can use it as its topology service. When a Consul cluster falls out of support, every system that coordinates through it inherits the exposure.
Most Consul lines are already past their support dates
HashiCorp's published dates put 1.15 LTS out of support on 30 April 2025 and 1.18 LTS on 30 April 2026. Standard releases are maintained until they are three releases behind the latest, so 1.16, 1.17, 1.19 and 1.20 are all out. 1.22 ends on 31 October 2026. From the 2.x releases Consul Enterprise follows IBM's Support Cycle-2 model, and 1.21 is the last LTS.
The licence line sits at 1.17.0
HashiCorp announced the move to the Business Source License 1.1 on 10 August 2023. The Consul licence names 1.17.0 and later as the Licensed Work, and on 18 March 2026 the licensor changed from HashiCorp to IBM. Releases up to 1.16.3 were published under MPL 2.0, which is why OSSeva can ship patched builds of them and takes a different route for the lines after.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 1.14.x and older(MPL 2.0. Out of support. OSSeva patched) | EOL | Clean |
| 1.15.x (LTS)(LTS ended 30 Apr 2025. MPL builds OSSeva patched) | EOL | Clean |
| 1.16.x(MPL to 1.16.3. OSSeva patched) | EOL | Clean |
| 1.17.x(BSL. Out of support. OSSeva supported upgrade) | EOL | Clean |
| 1.18.x (LTS)(BSL. LTS ended 30 Apr 2026. OSSeva supported upgrade) | EOL | Clean |
| 1.19.x, 1.20.x(BSL. Out of support. OSSeva supported upgrade) | EOL | Clean |
| 1.21.x (LTS)(Last LTS. Supported to 30 Apr 2027) | Extended | Clean |
| 1.22.x(Supported to 31 Oct 2026) | Extended | Clean |
| 2.0.x(IBM SC2 model. Supported to 30 Apr 2028) | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Patched, signed builds for MPL 2.0 Consul, 1.16.3 and earlier.
- Security backports on the MPL 2.0 Consul source, 1.16.3 and earlier
- Rebuilt on a supported Go toolchain with patched dependencies
- Server and client agent binaries covered
- Binary / Docker / package delivery
- Signed artifacts (GPG)
- BSL upgrade and migration plan
- 24/7 managed operations
OSSeva Assure
Patch plus a licence and support audit, and an upgrade plan for BSL clusters.
- Everything in Patch
- Version and licence inventory across every datacenter
- ACL, gossip encryption and TLS configuration audit
- Map of every system coordinating through Consul (Patroni, Vitess and others)
- SOC 2 / HIPAA attestation package
- Upgrade or migration plan for 1.17 and later clusters
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 cluster monitoring, 15-min SLA, named engineers.
- Everything in Assure
- 24/7 Raft leadership, peer and autopilot health monitoring
- 15-minute P1 incident response SLA
- Named senior Consul engineer
- Scheduled snapshot backups with tested restores
- Rolling upgrade execution with Raft quorum preserved
- Migration execution where you move coordination to etcd or Kubernetes
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
# Version of this agent. 1.17.0 and later are BSL 1.1
consul version
# Every server in the Raft peer set, with leader and voter status
consul operator raft list-peers
# Versions across the whole cluster: the Build column is the Consul version
consul members# Point-in-time snapshot of the catalogue, KV store, sessions and ACLs
consul snapshot save pre-upgrade.snap
# Confirm the snapshot is readable before you touch a server
consul snapshot inspect pre-upgrade.snap# Patched build of MPL 2.0 Consul, same data format
docker pull artifacts.osseva.io/consul:1.16.3-osseva-1
docker run -d --name consul-server \
-p 8500:8500 -p 8300:8300 \
-v /opt/consul/data:/consul/data \
artifacts.osseva.io/consul:1.16.3-osseva-1 agent -serverMigrate from Out-of-support HashiCorp Consul
For clusters on MPL 2.0 Consul (1.16.3 and earlier), OSSeva ships patched builds on the line you run, so the cluster is secured without an upgrade. For clusters on the BSL lines (1.17 and later), OSSeva does not redistribute modified BSL code. It plans and runs a supported upgrade to a maintained Consul release, or a migration of coordination to etcd or Kubernetes where that fits better.
Pricing model
OSSeva for Consul is priced per cluster, not per node, agent or registered service.
Frequently asked questions
Which Consul versions are end of life?
On 29 September 2026: 1.15 LTS (ended 30 April 2025), 1.18 LTS (ended 30 April 2026) and the standard 1.16, 1.17, 1.19 and 1.20 lines, which fell out under the rule that a standard release is maintained until it is three releases behind the latest. 1.22 ends on 31 October 2026. 1.21 LTS runs to 30 April 2027, and 2.0.x to 30 April 2028.
Which Consul versions are open source under MPL 2.0?
Releases up to and including 1.16.3. The Consul licence names 1.17.0 and later as the BSL 1.1 Licensed Work, and later patch releases on the 1.15 and 1.16 branches also carry BSL terms. Each BSL version converts to MPL 2.0 four years after it is published. OSSeva patched builds start from the MPL 2.0 source.
Does OSSeva patch Consul 1.17 or later?
No. OSSeva does not redistribute modified BSL code. For 1.17 and later, OSSeva plans and executes a supported upgrade to a maintained release, with snapshots taken and Raft quorum preserved throughout, or a migration of coordination to another store. Patched builds cover the MPL 2.0 lines.
What changed for Consul Enterprise under IBM?
From the April 2026 2.x release, Consul Enterprise follows the IBM Support Cycle-2 model: two years of base support, one year of critical extended support and three years of sustained support. Versioning moves to IBM's scheme of an April version, an October modification and monthly fixes. HashiCorp states that 1.21 is the last LTS release, and the licence now names IBM as licensor.
What are the alternatives to Consul for coordination?
It depends on what Consul does for you. For leader election and configuration, etcd and ZooKeeper are the common choices: Patroni supports etcd, ZooKeeper and Kubernetes as well as Consul, and Vitess accepts etcd2 and zk2 topology services. Service discovery and mesh features need a different comparison. OSSeva runs either path, from a patched MPL build to a full migration.
Ready to get HashiCorp Consul patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.