Automic VaultAutomic Vault

brew

kubeseal を Homebrew, apk, MacPorts, Nix, pacman, zypper, scoop でインストール

kubeseal のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

エージェント安全性

エージェント安全性の回答

kubeseal transforms Kubernetes secrets and is tied to cluster secret-management workflows.

認証情報アクセス

Handles secret manifests and cluster public keys; input files may contain sensitive values.

リモート変更

Does not usually mutate clusters directly, but output is intended for cluster application.

公開/成果物リスク

Can produce sealed secret artifacts committed or deployed to clusters.

推奨コントロール

Gate commands that read plaintext secret files or write deployable sealed secrets.

エージェント利用ガイダンス

Allow public-key fetches; require approval before processing plaintext secrets or writing manifests.

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install kubeseal

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install kubeseal

MacPorts ports tree · sysutils/kubeseal/Portfile · ソース: api.github.com

Linux

Alpine Linux apk確認済み · 92%
sudo apk add kubeseal

Alpine Linux edge package indexes · kubeseal · ソース: dl-cdn.alpinelinux.org

Nix確認済み · 92%
nix profile install nixpkgs#kubeseal

nixpkgs package indexes · pkgs/by-name/ku/kubeseal/package.nix · ソース: api.github.com

Arch Linux pacman確認済み · 92%
sudo pacman -S kubeseal

Arch Linux sync databases · kubeseal · ソース: geo.mirror.pkgbuild.com

openSUSE zypper確認済み · 92%
sudo zypper install kubeseal

openSUSE Tumbleweed package metadata · kubeseal · ソース: download.opensuse.org

Windows

Scoop確認済み · 92%
scoop install main/kubeseal

Scoop official bucket manifest trees · bucket/kubeseal.json · ソース: api.github.com

概要

パッケージ概要

Kubernetes controller and tool for one-way encrypted Secrets

コマンドとエイリアス

  • kubeseal

履歴

プロジェクトの歴史と使われ方

kubeseal is the client-side utility for Bitnami Sealed Secrets, a Kubernetes controller and custom resource pattern for storing encrypted Secrets safely in Git.

プロジェクトの歴史

Sealed Secrets addresses the GitOps-era problem of managing Kubernetes configuration in version control while keeping Secret values encrypted. The project is split into a cluster-side controller/operator and the kubeseal CLI. kubeseal uses asymmetric cryptography to encrypt a Kubernetes Secret into a SealedSecret custom resource that only the target cluster's controller can decrypt.

採用の歴史

kubeseal became a common companion tool for teams that wanted declarative Kubernetes deployments without introducing an external secret store into every workflow. Its release notes and README document distribution through Homebrew, MacPorts, Nixpkgs, Linux binaries, and controller manifests.

使われ方

A typical workflow creates or exports a Kubernetes Secret manifest, pipes it through kubeseal, commits the resulting SealedSecret YAML, and lets the in-cluster controller unseal it back into a normal Kubernetes Secret.

パッケージ好きにとっての重要性

kubeseal is package-nerd interesting because the CLI is only half of the product: the packaged binary must line up with a CRD/controller deployed in the cluster. It also turned a security-sensitive Kubernetes workflow into a small Unix-friendly command-line transform.

タイムライン

  • 2026: The v0.38.1 release page listed controller installation YAML and kubeseal client binaries, including Homebrew instructions for macOS.

Related projects

  • Related tools and patterns include Kubernetes Secrets, GitOps controllers such as Argo CD and Flux, external-secrets operators, SOPS, and cloud KMS-backed secret-management workflows.

セキュリティ状態

リスクレベル: orange

broad file, network, media, or database tool signal. infrastructure mutation or orchestration signal.

リスク分類器

リスク orange · 信頼度 中 · infrastructure

理由

  • broad file, network, media, or database tool signal
  • infrastructure mutation or orchestration signal

信号

  • text:encrypt
  • text:kubernetes

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • ビルドメタデータには 1 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
kubesealcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版0.38.4
マネージャ更新日2026-07-04
ローカルデータOK
上流not checked
検出された最新未検出

https://github.com/bitnami/sealed-secrets

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:kubeseal
バージョン0.38.4
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/kubeseal
ホームページhttps://github.com/bitnami/sealed-secrets
リポジトリhttps://github.com/bitnami/sealed-secrets
上流ドキュメントhttps://github.com/bitnami-labs/sealed-secrets/blob/main/README.md
ライセンスApache-2.0
ソースアーカイブhttps://github.com/bitnami/sealed-secrets.git
最終更新2026-07-04T16:53:43+09:00
Pulseupdated
ビルド依存関係go
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namekubeseal
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

kubeseal

nix profile install nixpkgs#kubeseal
  • normalized package name match
  • 一致条件: Kubeseal
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ku/kubeseal/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

kubeseal 0.37.0-r0

A Kubernetes controller and tool for one-way encrypted Secrets

https://github.com/bitnami-labs/sealed-secrets

sudo apk add kubeseal
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: kubeseal
  • 1 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Kubeseal
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: kubeseal from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

kubeseal-doc 0.37.0-r0

A Kubernetes controller and tool for one-way encrypted Secrets (documentation)

https://github.com/bitnami-labs/sealed-secrets

sudo apk add kubeseal-doc
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: kubeseal
  • normalized package name match
  • 一致条件: Kubeseal
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: kubeseal-doc from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

kubeseal 0.35.0-2

A Kubernetes controller and tool for one-way encrypted Secrets

https://github.com/bitnami-labs/sealed-secrets

sudo pacman -S kubeseal
  • License: Apache
  • Architecture: x86_64
  • 1 依存関係
  • normalized package name match
  • 一致条件: Kubeseal
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: kubeseal from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

kubeseal 0.37.0-1.1

CLI for encrypting secrets to SealedSecrets

https://github.com/bitnami-labs/sealed-secrets

sudo zypper install kubeseal
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: kubeseal
  • 1 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Kubeseal
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: kubeseal from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
MacPorts95%

kubeseal

sudo port install kubeseal
  • normalized package name match
  • 一致条件: Kubeseal
MacPorts ports tree · api.github.com · MacPorts ports tree: sysutils/kubeseal/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/kubeseal

scoop install main/kubeseal
  • normalized package name match
  • 一致条件: Kubeseal
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/kubeseal.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment