macOS
brew install kolocal Homebrew formula metadata
sudo port install koMacPorts ports tree · devel/ko/Portfile · source: api.github.com
brew / rank 2704
Build and deploy Go applications on Kubernetes. Version 0.19.1 via Homebrew; verified 2026-07-27. Also installable with nix: nix profile install nixpkgs#ko.
install
brew install kolocal Homebrew formula metadata
sudo port install koMacPorts ports tree · devel/ko/Portfile · source: api.github.com
sudo apk add koAlpine Linux edge package indexes · ko · source: dl-cdn.alpinelinux.org
nix profile install nixpkgs#konixpkgs package indexes · pkgs/by-name/ko/ko/package.nix · source: api.github.com
sudo pacman -S koArch Linux sync databases · ko · source: geo.mirror.pkgbuild.com
scoop install main/koScoop official bucket manifest trees · bucket/ko.json · source: api.github.com
overview
Build and deploy Go applications on Kubernetes
history
ko is a Go-focused container image builder for developers who want OCI images without writing Dockerfiles or running Docker locally. Its Homebrew package is a small CLI, but it sits at the intersection of Go modules, Kubernetes manifests, registries, SBOMs, and supply-chain tooling.
The project grew out of Google experience building Docker and Kubernetes support for Bazel. Its README describes ko as a simple, fast container image builder that effectively runs `go build` locally, then packages the resulting binary into an image without requiring Docker.
By 2022, the project had moved into the ko-build GitHub organization and the ko.build documentation domain. A 2022-08-19 migration issue laid out the repository move from google/ko to github.com/ko-build, the ko.build vanity import path, image-name changes, and a Slack channel rename. On 2022-10-11, Google announced that it had submitted ko for CNCF Sandbox consideration.
ko's adoption followed the rise of Go-based cloud-native services that can ship as mostly static binaries. The Google Open Source announcement described growing use by open source and enterprise teams and integration into third-party CI/CD tools.
Package-manager adoption is useful because ko is often installed in developer shells, GitHub Actions, release jobs, and Kubernetes workflows. Its companion setup-ko action made it easy to bootstrap the CLI in CI, while Homebrew, MacPorts, Nix, Arch, Alpine, and Scoop packaging made it available outside a single vendor ecosystem.
The common workflow is `ko build` or `ko resolve`: build Go packages into images, push them to a registry, and optionally rewrite Kubernetes YAML with the produced image references. The docs emphasize no Docker daemon requirement, multi-platform images, SBOM generation, Kubernetes integration, build cache support, and registry authentication through ko login or surrounding CI credentials.
It is particularly attractive for Go services with few operating-system package dependencies. That constraint is part of the tool's appeal: it turns the boring case of a static Go binary into a very short path from source to signed or traceable container artifact.
ko is the package-index shorthand for a whole cloud-native philosophy: build the thing the language already knows how to build, then wrap it as an OCI image with minimal ceremony. It competes less with Docker itself than with Dockerfile boilerplate, bespoke CI shell scripts, and build-system plugins.
For maintainers, it is also a clean example of a single-purpose CLI whose value comes from integration points: Go, registries, Kubernetes, SBOMs, GitHub Actions, and module import paths.
security posture
infrastructure mutation or orchestration signal.
orange risk · medium confidence · infrastructure
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
.ko.yamlexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
ko | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:ko |
|---|---|
| Version | 0.19.1 |
| Package manager | Homebrew |
| Homepage | https://ko.build |
| Repository | https://github.com/ko-build/ko |
| Last updated | 2026-07-27T21:58:40+02:00 |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
ko
nix profile install nixpkgs#koko 0.17.1-r16
Build containers from Go projects
sudo apk add koko-bash-completion 0.17.1-r16
Bash completions for ko
sudo apk add ko-bash-completionko-fish-completion 0.17.1-r16
Fish completions for ko
sudo apk add ko-fish-completionko-zsh-completion 0.17.1-r16
Zsh completions for ko
sudo apk add ko-zsh-completionko 0.19.1-1
Build and deploy Go container images
https://github.com/ko-build/ko
sudo pacman -S koko
sudo port install komain/ko
scoop install main/kosource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.