Infrastructure
Describe the app, not the resource graph
Turn services, databases, caches, domains, and policies into reviewable AWS infrastructure.
Appearance
Free is a complete product, not a trial. It provisions infrastructure, deploys applications, and operates them with no expiry, time-limited features, or Keel account to create. keel license reports this edition as the oss tier.
Free has no activation, network licence check, or telemetry. The only outbound request Keel makes on its own behalf is a once-daily update check against GitHub's releases endpoint. It skips the check when output is not a terminal, and KEEL_NO_UPDATE_CHECK disables it entirely.
Included in Free
One workflow from configuration to operations
keel.ymlDescribe the app→02keel upProvision AWS→03keel deployBuild and release→04keel dashboardOperate liveInfrastructure
Turn services, databases, caches, domains, and policies into reviewable AWS infrastructure.
Delivery
Use one deployment path with release gates, circuit breaking, history, and one-command rollback.
Operations
Inspect services, deployments, logs, metrics, infrastructure, and resources from the dashboard.
Security
Use individual IAM users, MFA, short-lived sessions, and least-privilege roles without sharing keys.
Resources
Bind services to storage, queues, databases, and caches with scoped IAM and network access.
Reliability
Estimate the monthly baseline, configure budgets, and recover interrupted infrastructure operations.
Provisioning. A VPC with public and private subnets, an Application Load Balancer with HTTPS, ECS services on Fargate, Fargate Spot, or an optional EC2 fleet, scheduled tasks on EventBridge Scheduler, RDS for PostgreSQL, MySQL and Aurora, ElastiCache for Valkey and Redis, ECR repositories, CodeBuild pipelines, AWS WAF, Route 53 and ACM, and static sites on S3 behind CloudFront. Resources Keel does not model can be declared as your own OpenTofu files and folded into the same stack.
Deploying. Image builds from a Dockerfile or with Cloud Native Buildpacks, a release command that gates promotion, rolling deploys with a circuit breaker, one-command rollback to a previous task-definition revision, a deploy lock, deploy history, and keel run for one-off tasks.
Operating. The dashboard, logs, native-protocol keel exec into a running container, keel tunnel for local access to private resources, keel db psql for an interactive database shell, per-task CPU and memory, scaling, CPU/memory/request/queue autoscaling (including queue-driven scale-to-zero), scheduled-task inspection, live resource state, database engine logs, and orphaned-resource reporting.
Access and security. Three least-privilege IAM roles, an IAM user per person, MFA enrolment and account-wide enforcement, and eight-hour STS sessions. A CI identity deploys through OIDC federation, with no long-lived AWS key in CI secrets.
Environments and shared infrastructure. Declared environments such as staging and production, with per-environment overrides, and a shared VPC and ECS cluster that several applications can run inside. Fargate, Fargate Spot, and an optional EC2 fleet can coexist on a cluster.
Control plane. The optional account-local Keel API can cache dashboard reads. Removing it never removes the direct IAM path.
Cost. Monthly estimates from configuration alone, with the blind spots listed explicitly, and AWS Budgets with alerts.
Recovering from interruptions. keel rescue for an apply or destroy that was interrupted, state-lock release, infrastructure apply history, and reconciliation of deploy records left in a non-terminal state.
Eight capability groups require Pro:
Keel refuses each capability at the earliest useful point. A paid capability declared in keel.yml is refused by keel up and keel infra apply before anything is provisioned, so Keel never creates resources that the current edition cannot use. keel cost and keel infra plan remain available because they create nothing and help show the cost of upgrading.
Free supports up to three people on the roster. Teams that need to add more people will require Pro.
The authentication model itself is not reduced. MFA enforcement, per-person IAM users, role changes, and revocation work the same way at any team size. Free should not mean one administrator using a long-lived access key.
keel init to a running application