# Install ksops with Homebrew

Flexible Kustomize Plugin for SOPS Encrypted Resources. Version 4.5.1 via Homebrew; verified 2026-07-27.

## Install

```sh
sudo av install brew:ksops
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install ksops
```

  Evidence: local Homebrew formula metadata

## Package facts

- **Package key:** brew:ksops
- **Package manager:** Homebrew
- **Version:** 4.5.1
- **Source summary:** Flexible Kustomize Plugin for SOPS Encrypted Resources
- **Homepage:** <https://github.com/viaduct-ai/kustomize-sops>
- **Repository:** <https://github.com/viaduct-ai/kustomize-sops>
- **Last updated:** 2026-07-27T21:58:41+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- ksops (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 4.5.1
## Project history and usage

KSOPS is a kustomize-SOPS plugin for decrypting SOPS-encrypted Kubernetes resources during kustomize builds. It sits in the GitOps secrets-management niche where teams want encrypted manifests in Git but plain Kubernetes objects at apply time.

### Project history

The README says Viaduct built KSOPS after finding no solution compatible with its Kubernetes GitOps stack for managing secrets. The project connects kustomize to SOPS and documents integration with Argo CD so encrypted manifests can be managed like other Kubernetes manifests.

### Adoption history

KSOPS is aimed at teams already using kustomize, SOPS, and GitOps workflows rather than at general secret storage. Its adoption footprint is therefore narrow but practical: it is packaged as a Homebrew formula and documented as an installable CLI-style kustomize plugin.

### How it is used

Typical use is to define SOPS creation rules in .sops.yaml, add a KSOPS generator to kustomization.yaml, and run kustomize with plugin support so encrypted Secrets or ConfigMaps are decrypted during the build.

### Why package nerds care

KSOPS is interesting to package people because it packages a kustomize exec plugin as a normal command-line artifact, bridging Kubernetes configuration tooling, Git-stored encrypted files, and local package-manager installation.

### Timeline

- v1.0: The repository has a public v1.0 tag for the early KSOPS release line.
- v2.x: Later tags track the second major release line of the kustomize-SOPS plugin.
- v3.x: The repository tags include a third major release line for the plugin.

### Related projects

- Related projects include kustomize, SOPS, Argo CD, Kubernetes Secrets, and GitOps workflows.

### Sources

- <https://github.com/viaduct-ai/kustomize-sops>
- <https://github.com/viaduct-ai/kustomize-sops/releases>
- <https://github.com/viaduct-ai/kustomize-sops/tags>


## Security Notes

broad file, network, media, or database tool signal.

- **Geiger risk:** blue / medium
- broad file, network, media, or database tool signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: .sops.yaml

## Combined YAML source

View the package source record on GitHub. [combined/ksops.yml](https://github.com/mxcl/pkgdb/blob/main/combined/ksops.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
