Automic VaultAutomic Vault

brew

kyverno mit Homebrew, Nix, zypper, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für kyverno in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install kyverno

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#kyverno

nixpkgs package indexes · pkgs/by-name/ky/kyverno/package.nix · Quelle: api.github.com

openSUSE zypperverifiziert · 92%
sudo zypper install kyverno

openSUSE Tumbleweed package metadata · kyverno · Quelle: download.opensuse.org

Windows

Windows Package Managerverifiziert · 92%
winget install --id kyverno.kyverno -e

Windows Package Manager source index · kyverno.kyverno · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

Kubernetes Native Policy Management

Verlauf

Projektgeschichte und Nutzung

Kyverno is a Kubernetes-native policy engine for validation, mutation, generation, cleanup, image verification, and policy reporting. Its defining choice is to express policy as Kubernetes resources, letting teams use YAML, kubectl, GitOps, and admission-controller workflows instead of learning a separate policy language.

It became one of the central tools in the Kubernetes policy-management ecosystem, especially for platform and security teams that want policy-as-code aligned with Kubernetes resource models.

Projektgeschichte

Nirmata introduced Kyverno in 2019 as an open source Kubernetes-native policy-management project. The project was built for Kubernetes governance and security use cases such as validating resources, mutating defaults, generating supporting resources, and reporting violations.

Kyverno entered CNCF as a sandbox project on November 10, 2020, moved to incubation on July 13, 2022, and graduated on March 16, 2026. CNCF project data lists February 4, 2019 as the first commit, matching the project's 2019 origin story.

Adoptionsgeschichte

Kyverno adoption grew with Kubernetes platform engineering and DevSecOps practices. Its policy library, Helm charts, CLI, reports, and admission-controller model made it usable both in clusters and in pre-admission workflows such as CI checks.

CNCF project data in 2026 showed thousands of contributors and over a thousand contributing organizations, along with public case studies. That governance path and visible contributor base made Kyverno a mainstream cloud-native policy project rather than a vendor-only utility.

Wie es verwendet wird

Operators install Kyverno into Kubernetes clusters to validate, mutate, generate, or clean up resources through admission controls and background scans. Policies are stored as Kubernetes custom resources and can be managed with kubectl, kustomize, Helm, and Git workflows.

The `kyverno` CLI is used for testing and applying policies outside the cluster, which made the Homebrew package useful to developers building policy libraries or checking manifests before deployment.

Warum Paket-Nerds sich dafür interessieren

Kyverno is significant to package and CLI catalogues because it bridges a cluster controller and a local developer tool. Installing the CLI gives package-manager users access to the same policy language that governs production clusters.

Its companion projects broadened the package surface around the core engine, including Chainsaw for end-to-end tests, Kyverno JSON for non-Kubernetes JSON payloads, Policy Reporter, and the Kyverno Envoy plugin.

Zeitleiste

  • 2019: Nirmata introduced Kyverno as Kubernetes-native policy management.
  • 2020: CNCF accepted Kyverno as a sandbox project on November 10.
  • 2022: Kyverno moved to CNCF incubation on July 13.
  • 2023: Kyverno published third-party security audit work as part of project hardening.
  • 2026: Kyverno graduated in CNCF on March 16.
  • 2026: Kyverno 1.18 was announced on April 24 as the first release after CNCF graduation.

Related projects

  • OPA Gatekeeper is the most common comparison point for Kubernetes admission policy, with a different policy-language and ecosystem model.
  • Chainsaw, Kyverno JSON, Policy Reporter, and the Kyverno Envoy plugin are companion projects named by the Kyverno project as separate tools around the core engine.
  • Sigstore, Cosign, Helm, Kustomize, and Kubernetes ValidatingAdmissionPolicy features are adjacent technologies in Kyverno's supply-chain and policy workflows.

Sicherheitslage

Risikostufe: orange

infrastructure mutation or orchestration signal.

Risikoklassifikator

orange Risiko · mittel Konfidenz · infrastructure

Warum

  • infrastructure mutation or orchestration signal

Signale

  • text:kubernetes

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
kyvernocliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-26
Manager-Version1.18.2
Manager aktualisiert2026-07-10
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv1.18.2

https://github.com/kyverno/kyverno

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:kyverno
Version1.18.2
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/kyverno
Homepagehttps://kyverno.io/
Repositoryhttps://github.com/kyverno/kyverno
Upstream-Dokumentationhttps://kyverno.io/docs
LizenzApache-2.0
Quellarchivhttps://github.com/kyverno/kyverno/archive/refs/tags/v1.18.2.tar.gz
Zuletzt aktualisiert2026-07-10T07:06:42Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namekyverno
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

kyverno

nix profile install nixpkgs#kyverno
  • normalized package name match
  • Abgeglichen nach: Kyverno
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ky/kyverno/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
zypper95%

kyverno 1.18.1-1.1

CLI and kubectl plugin for Kyverno

https://github.com/kyverno/kyverno

sudo zypper install kyverno
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: kyverno
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Kyverno
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: kyverno from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

kyverno-bash-completion 1.18.1-1.1

Bash Completion for kyverno

https://github.com/kyverno/kyverno

sudo zypper install kyverno-bash-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: kyverno
  • 2 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Kyverno
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: kyverno-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

kyverno-fish-completion 1.18.1-1.1

Fish Completion for kyverno

https://github.com/kyverno/kyverno

sudo zypper install kyverno-fish-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: kyverno
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Kyverno
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: kyverno-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

kyverno-zsh-completion 1.18.1-1.1

Zsh Completion for kyverno

https://github.com/kyverno/kyverno

sudo zypper install kyverno-zsh-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: kyverno
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Kyverno
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: kyverno-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
winget95%

kyverno.kyverno

winget install --id kyverno.kyverno -e
  • normalized package name match
  • Abgeglichen nach: Kyverno
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: kyverno.kyverno from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment