Product Support Lifecycle
This page explains how long we support Icinga, how our release and update model works, which component versions are currently supported, and which operating systems and dependencies we support. It applies to the Icinga product and all of its components.
Our support commitment
We commit to maintaining Icinga by handling vulnerabilities and providing security updates in line with our security policy at least until January, 2032.
This date is a minimum. We review it at least once a year and extend it for as long as Icinga remains under active development. The current minimum date is always shown here, so this page is the authoritative source.
How our support model works
Icinga is developed as a rolling release. Rather than freezing old versions for years, we keep the platform current and support a moving window of recent versions of each component:
- The latest version of each component receives full updates (new features, bug fixes, and security fixes).
- The previous version of each component receives security updates only.
- Older versions are no longer maintained.
Security fixes are delivered through new releases within this window. To stay protected, run a version that is within the supported window below. Where technically feasible we ship security fixes as separate patch releases on the maintained branches, so you can apply a security fix without adopting new features.
This page describes the product lifecycle and explains how long the Icinga software receives updates. This is separate from a paid Icinga support subscription, which provides commercial services such as guaranteed response times and direct assistance.
Supported component versions
The minimum stack to run Icinga consists of the core components listed below. All other components are optional modules that require at least one core component.
Core components
| Full updates | Security updates | |
|---|---|---|
| Icinga 2 | v2.16 | v2.15 |
| Icinga Web | v2.14 | v2.13 |
| Icinga DB | v1.4 | v1.3 |
| Icinga DB Web | v1.2 | v1.1 |
Modules and integrations
| Full updates | Security updates | |
|---|---|---|
| Icinga Director | v1.11 | v1.10 |
| Icinga for Windows | v1.14 | v1.13 |
| Icinga Reporting | v1.1 | v1.0 |
| Icinga Cube | v1.4 | v1.3 |
| Icinga SSO | v1.0 | - |
| Icinga TOTP | v1.0 | - |
| Icinga Business Process Modeling | v2.6 | v2.5 |
| Icinga Certificate Monitoring | v1.4 | v1.3 |
| Icinga vSphere Integration | v1.8 | v1.7 |
| Icinga Web JIRA Integration | v1.5 | v1.4 |
| Icinga Web Graphite Integration | v1.3 | v1.2 |
| Icinga Dependency Views | v1.0 | - |
Every module requires at least one core component, many require a specific minimum Icinga Web version. Please check each component’s documentation for its exact requirements before upgrading.
Supported operating systems
We build packages for an operating system release for as long as its vendor provides standard, no-cost security support for it. When that phase ends, we stop building packages for that release and recommend upgrading to a currently supported one.
We do not build packages for the paid extended-support tiers that some vendors offer beyond their standard phase. Those tiers require a separate paid subscription with the OS vendor and typically narrow their package coverage; they are outside what we build for.
Ending package builds for an end-of-life operating system does not reduce our support commitment for Icinga itself. It only means new packages for that platform are no longer produced. The Icinga support commitment above continues to apply on supported platforms.
Support phases per distribution
| Phase | Do we build for it? | |
|---|---|---|
| Debian | Regular security support (Debian Security Team, full archive) | ✓ |
| LTS (Long Term Support, reduced package set) | ✓ | |
| ELTS (Extended Long Term Support) | ✗ | |
| Ubuntu | Standard security maintenance (Main repository) | ✓ |
| Expanded Security Maintenance (ESM, via Ubuntu Pro) | ✗ | |
| Legacy add-on | ✗ | |
| RHEL¹ | Full Support | ✓ |
| Maintenance Support | ✓ | |
| Extended Life Cycle Support (ELS) | ✗ | |
| Extended Life Phase | ✗ | |
| SLES | General Support | ✓ |
| Long Term Service Pack Support (LTSS) | ✗ | |
| Amazon Linux | Standard support | ✓ |
| Maintenance support | ✓ | |
| openSUSE | Community maintenance | ✓ |
| Fedora | Maintenance | ✓ |
| Windows Server | Mainstream Support | ✓ |
| Extended Support | ✓ | |
| Extended Security Updates (ESU) | ✗ |
¹ RHEL packages may also be used on binary-compatible alternatives (Oracle Linux, Rocky Linux, AlmaLinux), which follow comparable lifecycles.
Supported operating system releases
An Icinga setup has two kinds of installation, supported differently:
Server components run your monitoring centrally: the monitoring core, web interface, and database components (Icinga 2, Icinga Web, Icinga DB, Icinga DB Web, and modules). Because they depend on databases, a web server, and PHP, we build server packages only for LTS / long-term releases.
Agents are lightweight installations on the hosts you monitor. An agent is Icinga 2 in a reduced role, just executing checks and reporting results (checker, API, and logging features), so it needs much less from its operating system, and we support it on a wider range of platforms.
For both, we build packages as long as the OS vendor provides standard security support for the release, and stop when that phase ends and only paid extended-support tiers remain (see the tables above).
| Server components | Agents | |
|---|---|---|
| Debian | 13, 12, 11 | 13, 12, 11 |
| Ubuntu | 26.04, 24.04, 22.04 | 26.04, 25.10, 25.04, 24.04, 22.04 |
| RHEL | 10, 9, 8 | 10, 9, 8 |
| Amazon Linux | 2023 | 2023 |
| SLES | 16.0, 15.7, 15.6 | 16.0, 15.7, 15.6 |
| openSUSE | - | 16.0, 15.6 |
| Fedora | - | 44, 43, 42 |
| Windows Server | - | 2025, 2022, 2019, 2016 |
Dependency requirements
Icinga server components depend on third-party software. We ensure our official packages meet these requirements, but please verify your environment before installing or upgrading.
| Supported versions | |
|---|---|
| PHP (Icinga Web and modules) | ≥ 8.2 |
| MySQL | ≥ 8.0 |
| MariaDB | ≥ 10.2.2 |
| PostgreSQL | ≥ 9.6 |
| Redis® | as shipped in our packages |
OpenSSL is not listed separately because it is tied to your operating system. On Linux it is provided and updated by your OS vendor; on Windows it is bundled with our packages and updated together with them.
What “supported” means
- Full updates: The version receives new features, bug fixes and security fixes.
- Security updates: The version receives security fixes only; upgrade to the latest version for features and non-security fixes.
- Deprecated: We have signalled that a version or component should no longer be used in new deployments. Deprecation is a signal, not the end of support: a deprecated version or component stops receiving full (feature and bug-fix) updates from the moment it is deprecated, but continues to receive security updates for the period stated below.
- End of support: the version no longer receives any updates. Continuing to run it may expose you to unpatched vulnerabilities; upgrade to a supported version.
Component lifecycle
- Entering the support lifecycle: A new component enters the support commitment when it reaches v1.0.
- The rolling window: Once a component is supported, its latest version receives full updates and its previous version receives security updates, in line with the product commitment above.
- Deprecating a version: When a new version is released, the version two steps back leaves the security-update window.
- Deprecating an optional component: When we decide to retire an optional component, we mark it as deprecated immediately (noted in the component and its documentation) so that it is no longer used in new deployments and existing users are aware. From that point the component receives security updates only (no further features or non-security fixes), for at least one year. Where relevant, we describe a migration path.
- Deprecating core components: The core components are required for Icinga to function and are not deprecated individually while the product exists. If a core component is ever replaced by a successor, the successor takes over its role. From that point the replaced core component receives security updates only (no further features or non-security fixes), for at least one year. Where relevant, we describe a migration path. The support commitment for the product continues unchanged. Discontinuation of the Icinga product as a whole would be announced separately. In that case we continue to provide security updates for the versions already released until at least the published support end date above.
FAQ
My operating system reached end of life, what now?
I'm running an older Icinga version, am I still supported?
Where do I report a security vulnerability?
Please follow our coordinated vulnerability disclosure process, not the public issue tracker.
