# Install krane with Homebrew, apk, Nix

Kubernetes deploy tool with rollout verification. Version 3.9.1 via Homebrew; verified from local package data. Also installable with nix: nix profile install nixpkgs#krane.

## Install

```sh
sudo av install brew:krane
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install krane
```

  Evidence: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add krane
```

  Evidence: Alpine Linux edge package indexes: krane from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz

- Nix (92%):

```sh
nix profile install nixpkgs#krane
```

  Evidence: nixpkgs package indexes: pkgs/by-name/kr/krane/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

## Package facts

- **Package key:** brew:krane
- **Package manager:** Homebrew
- **Version:** 3.9.1
- **Source summary:** Kubernetes deploy tool with rollout verification
- **Homepage:** <https://github.com/Shopify/krane>
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- krane (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 3.9.1
## Project history and usage

krane is Shopify's Kubernetes deployment CLI with rollout verification. It occupies the space between raw kubectl apply and heavier deployment systems by giving CI/CD jobs a clearer pass/fail answer and debug context.

### Project history

The project began publicly as Shopify's kubernetes-deploy tooling; the GitHub repository was created on 2017-01-17. Its README explains that krane wraps kubectl apply rather than replacing Kubernetes primitives, with rollout watching, failure diagnostics, predeploy phases, EJSON secret handling, render, run, restart, and global-deploy commands.

The 1.0 migration guide documents the rename from kubernetes-deploy to krane at version 1.0.0. That release redesigned the CLI, renamed the Ruby namespace, moved metrics to the krane prefix, and split behavior such as rendering and global resources into clearer commands.

### Adoption history

Shopify used krane with its open-source Shipit deployment application, which made the tool visible as part of Shopify's Kubernetes deployment story. Packaging through RubyGems and Homebrew made it usable both as a Ruby library/tool and as a standalone CLI in developer and CI environments.

### How it is used

A typical krane deploy command targets an application namespace and Kubernetes context, using kubeconfig credentials from $KUBECONFIG or ~/.kube/config. For Google Cloud authentication, the README documents $GOOGLE_APPLICATION_CREDENTIALS as an additional credentials source.

krane is commonly used where a deploy job needs to apply manifests, wait for workload rollout, print actionable failure information, and optionally run one-off tasks or render templates before deploy.

### Why package nerds care

krane is a useful packaging example because it is a Ruby-origin Kubernetes tool that installs like a CLI but delegates core state changes to kubectl and kubeconfig. Its history also shows a clean package rename from a descriptive old name to a shorter executable and namespace.

### Timeline

- 2017-01-17: The Shopify krane repository was created.
- 2019-11-18: Version 1.0.0 committed the rename from kubernetes-deploy to krane.
- 2024-01-29: Version v3.4.1 was published on GitHub.

### Related projects

- kubectl is the deployment primitive krane uses underneath. Shopify Shipit is the related deployment application named in the README. EJSON is related through krane's encrypted Kubernetes secret workflow.

### Sources

- <https://github.com/Shopify/ejson>
- <https://github.com/Shopify/krane>
- <https://github.com/Shopify/krane/blob/main/1.0-Upgrade.md>
- <https://github.com/Shopify/krane/releases/tag/v3.4.1>
- <https://github.com/Shopify/shipit-engine#kubernetes>


## Security Notes

infrastructure mutation or orchestration signal.

- **Geiger risk:** orange / medium
- infrastructure mutation or orchestration signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: $KUBECONFIG, ~/.kube/config, $GOOGLE_APPLICATION_CREDENTIALS
## Other Package-Manager Records

- Nix - krane: normalized package name match | nixpkgs package indexes: pkgs/by-name/kr/krane/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - krane - 0.20.7-r5: normalized package name match | Alpine Linux edge package indexes: krane from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Drop-in replacement for crane with built-in cloud workload identity auth | https://github.com/google/go-containerregistry/tree/main/cmd/krane


## Combined YAML source

View the package source record on GitHub. [combined/krane.yml](https://github.com/mxcl/pkgdb/blob/main/combined/krane.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
