Skip to content

Running Lakekeeper in Production

Lakekeeper is the heart of your data platform. The open-source catalog is built to run in production — it holds no local state, scales horizontally behind a load balancer, and upgrades stay online while database migrations run.

Enterprise and regulated production demands more than uptime: governed and provable access control, audited identity, and maintenance run for you. That is what Lakekeeper+ delivers — the production-grade path for the enterprise, backed by Vakamo. For these environments, Lakekeeper+ is what you need.

Production checklist (open source)

Everything you need to run Lakekeeper OSS safely is covered in the docs. In short:

  • High-availability Postgres as the catalog backend, with separate read/write URLs and regular, tested backups.
  • Authentication enabled through your existing OpenID provider (or Kubernetes auth).
  • Authorization configured for your access model.
  • Horizontal scaling with multiple instances — use the Helm chart, which ships readiness/liveness probes and autoscaling.
  • TLS termination at a reverse proxy or ingress — Lakekeeper does not terminate connections itself.
  • Monitoring & observability wired to your stack.

See the full Production Checklist for the complete, up-to-date list.

Lakekeeper+: the production-grade path

Lakekeeper+ builds on the open-source catalog with the capabilities regulated and large-scale platforms need, developed and supported by the team behind Lakekeeper.

  •   Permission-as-code with Cedar


    Express access policy as versioned, reviewable Cedar policies — RBAC, ABAC, and property-based access in one model. Every decision is inspectable, with a per-decision policy trace and audit log, so you can prove why access was granted. Built for regulated industries where access must be governed, testable, and provable.

  •   Autonomous maintenance


    Keep query performance high and storage costs low without operating maintenance jobs yourself. Table maintenance — expiring snapshots and removing orphan files — runs automatically and adaptively, scheduling itself per table based on how fast reclaimable data builds up.

  •   Enterprise identity & governance


    Resolve roles through role providers — Okta, Microsoft Entra ID, and LDAP; gate access with an external admission check; protect provider-synced roles from drift. Structured audit logs make the catalog auditable end to end.

  •   Enterprise support & LTS


    Commercial support from Vakamo for self-hosted and managed deployments, plus hardened Long-Term Support release lines — so you can run Lakekeeper at the heart of your platform with confidence.

Get Lakekeeper+

Talk to the team at Vakamo about running Lakekeeper in production — self-hosted or managed. We help you understand which edition fits, and get you there.

Opens a secure contact form hosted by Zoho on behalf of Vakamo; submitting it shares your details with Vakamo.

Prefer to chat with the community first? Join us on Discord.