# Free

Free is a complete product, not a trial. It provisions infrastructure, deploys applications, and operates them with no expiry, time-limited features, or Keel account to create. `keel license` reports this edition as the `oss` tier.

Free has no activation, network licence check, or telemetry. The only outbound request Keel makes on its own behalf is a once-daily update check against GitHub's releases endpoint. It skips the check when output is not a terminal, and `KEEL_NO_UPDATE_CHECK` disables it entirely.

## What is included

<FreeHighlights />

**Provisioning.** A VPC with public and private subnets, an Application Load Balancer with HTTPS, ECS services on Fargate, Fargate Spot, or an optional EC2 fleet, scheduled tasks on EventBridge Scheduler, RDS for PostgreSQL, MySQL and Aurora, ElastiCache for Valkey and Redis, ECR repositories, CodeBuild pipelines, AWS WAF, Route 53 and ACM, and static sites on S3 behind CloudFront. Resources Keel does not model can be declared as your own OpenTofu files and folded into the same stack.

**Deploying.** Image builds from a Dockerfile or with Cloud Native Buildpacks, a release command that gates promotion, rolling deploys with a circuit breaker, one-command rollback to a previous task-definition revision, a deploy lock, deploy history, and `keel run` for one-off tasks.

**Operating.** The dashboard, logs, native-protocol `keel exec` into a running container, `keel tunnel` for local access to private resources, `keel db psql` for an interactive database shell, per-task CPU and memory, scaling, CPU/memory/request/queue autoscaling (including queue-driven scale-to-zero), scheduled-task inspection, live resource state, database engine logs, and orphaned-resource reporting.

**Access and security.** Three least-privilege IAM roles, an IAM user per person, MFA enrolment and account-wide enforcement, and eight-hour STS sessions. A CI identity deploys through OIDC federation, with no long-lived AWS key in CI secrets.

**Environments and shared infrastructure.** Declared environments such as staging and production, with per-environment overrides, and a shared VPC and ECS cluster that several applications can run inside. Fargate, Fargate Spot, and an optional EC2 fleet can coexist on a cluster.

**Control plane.** The optional account-local Keel API can cache dashboard reads. Removing it never removes the direct IAM path.

**Cost.** Monthly estimates from configuration alone, with the blind spots listed explicitly, and AWS Budgets with alerts.

**Recovering from interruptions.** `keel rescue` for an apply or destroy that was interrupted, state-lock release, infrastructure apply history, and reconciliation of deploy records left in a non-terminal state.

## What is not included

Eight capability groups require [Pro](./pro):

- A preview environment per branch
- Alarms on application health
- Internal-only services and the login in front of them
- The generated CI workflow that deploys on push
- Auditable production shell sessions
- Attributable, per-person database access
- Locking a shared platform to reviewed changes
- Operators without AWS keys, with per-capability grants and authorization decisions

Keel refuses each capability at the earliest useful point. A paid capability declared in `keel.yml` is refused by `keel up` and `keel infra apply` before anything is provisioned, so Keel never creates resources that the current edition cannot use. `keel cost` and `keel infra plan` remain available because they create nothing and help show the cost of upgrading.

## Team size

Free supports up to three people on the roster. Teams that need to add more people will require [Pro](./pro).

The authentication model itself is not reduced. MFA enforcement, per-person IAM users, role changes, and revocation work the same way at any team size. Free should not mean one administrator using a long-lived access key.

---

- [Get started](../guide/getting-started) — from `keel init` to a running application
- [Editions overview](./) — the comparison table and how licensing works
- [Pro](./pro) — what a licence adds
