macOS
brew install kubesharklocal Homebrew formula metadata
brew / rank 2619
API Traffic Analyzer providing real-time visibility into Kubernetes network. Version 53.3.0 via Homebrew; verified 2026-07-27. Also installable with nix: nix profile install nixpkgs#kubeshark.
install
brew install kubesharklocal Homebrew formula metadata
nix profile install nixpkgs#kubesharknixpkgs package indexes · pkgs/by-name/ku/kubeshark/package.nix · source: api.github.com
scoop install main/kubesharkScoop official bucket manifest trees · bucket/kubeshark.json · source: api.github.com
overview
API Traffic Analyzer providing real-time visibility into Kubernetes network
history
Kubeshark is a Kubernetes network observability tool that indexes cluster-wide traffic with Kubernetes, API, and network context. The project presents itself as eBPF-powered observability for SREs and AI agents.
Kubeshark's repository describes a tool that captures and indexes network traffic at the kernel level, exposes filtered PCAP downloads, visual dashboards, TLS and mTLS visibility, protocol parsing, and MCP access for AI-driven incident response. Its documentation packages the product around Helm deployment plus a CLI installed through Homebrew or downloaded from GitHub releases.
The late-2025 and 2026 release notes show an active transition into a V2 architecture: v52.11.0 on December 16, 2025 described the first release in preparation for V2.00 and a backend refactor, while v53.3.0 on May 19, 2026 highlighted TLSX dissector behavior, authorization refactoring, L7 data boundaries, snapshots, and AI skills.
Kubeshark fits into the Kubernetes observability niche for teams that need packet-level or protocol-level visibility without changing application code. The package-manager angle is important because the CLI drives local workflows such as tapping traffic, cleaning deployments, connecting MCP clients, and installing the Helm chart.
Users install Kubeshark with Helm or Homebrew, port-forward the frontend service, and query live or retained traffic through the dashboard, KFL filters, PCAP exports, APIs, or MCP integrations.
Kubeshark is notable because it packages a cluster-resident observability system behind a developer-friendly CLI. It also bridges traditional packet-analysis workflows with Kubernetes metadata and newer MCP-based AI-agent workflows.
security posture
infrastructure mutation or orchestration signal.
orange risk · medium confidence · infrastructure
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
kubeshark | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:kubeshark |
|---|---|
| Version | 53.3.0 |
| Package manager | Homebrew |
| Homepage | https://kubeshark.com |
| Repository | https://github.com/kubeshark/kubeshark |
| Last updated | 2026-07-27T21:58:47+02:00 |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
kubeshark
nix profile install nixpkgs#kubesharkmain/kubeshark
scoop install main/kubesharksource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.