pkg.soopen package index

brew / rank 5578

Install ksops with Homebrew

Flexible Kustomize Plugin for SOPS Encrypted Resources. Version 4.5.1 via Homebrew; verified 2026-07-27.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install ksops

local Homebrew formula metadata

overview

Package summary

Flexible Kustomize Plugin for SOPS Encrypted Resources

Commands and aliases

  • ksops

history

Project history and usage

KSOPS is a kustomize-SOPS plugin for decrypting SOPS-encrypted Kubernetes resources during kustomize builds. It sits in the GitOps secrets-management niche where teams want encrypted manifests in Git but plain Kubernetes objects at apply time.

Project history

The README says Viaduct built KSOPS after finding no solution compatible with its Kubernetes GitOps stack for managing secrets. The project connects kustomize to SOPS and documents integration with Argo CD so encrypted manifests can be managed like other Kubernetes manifests.

Adoption history

KSOPS is aimed at teams already using kustomize, SOPS, and GitOps workflows rather than at general secret storage. Its adoption footprint is therefore narrow but practical: it is packaged as a Homebrew formula and documented as an installable CLI-style kustomize plugin.

How it is used

Typical use is to define SOPS creation rules in .sops.yaml, add a KSOPS generator to kustomization.yaml, and run kustomize with plugin support so encrypted Secrets or ConfigMaps are decrypted during the build.

Why package nerds care

KSOPS is interesting to package people because it packages a kustomize exec plugin as a normal command-line artifact, bridging Kubernetes configuration tooling, Git-stored encrypted files, and local package-manager installation.

Timeline

  • v1.0: The repository has a public v1.0 tag for the early KSOPS release line.
  • v2.x: Later tags track the second major release line of the kustomize-SOPS plugin.
  • v3.x: The repository tags include a third major release line for the plugin.

Related projects

  • Related projects include kustomize, SOPS, Argo CD, Kubernetes Secrets, and GitOps workflows.

security posture

Risk level: blue

broad file, network, media, or database tool signal.

Risk classifier

blue risk · medium confidence · tool

Why

  • broad file, network, media, or database tool signal

Signals

  • text:encrypt

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.sops.yaml

executables

Installed executables

CommandKindExposureNote
ksopsexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version4.5.1
manager updated2026-07-27
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:ksops
Version4.5.1
Package managerHomebrew
Homepagehttps://github.com/viaduct-ai/kustomize-sops
Repositoryhttps://github.com/viaduct-ai/kustomize-sops
Last updated2026-07-27T21:58:41+02:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • pkg.so package database
  • pkgdb category and tag curation