pkg.soopen package index

brew / rank 5531

Install kwctl with Homebrew, zypper

CLI tool for the Kubewarden policy engine for Kubernetes. Version 1.37.0 via Homebrew; verified 2026-07-27. Also installable with zypper: sudo zypper install kwctl.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install kwctl

local Homebrew formula metadata

overview

Package summary

CLI tool for the Kubewarden policy engine for Kubernetes

Commands and aliases

  • kwctl

history

Project history and usage

kwctl is the command-line tool in the Kubewarden admission-controller ecosystem. It gives policy authors and Kubernetes administrators a local way to inspect, annotate, run, benchmark, pull, push, save, and verify WebAssembly admission policies.

Project history

Kubewarden grew around the idea of using WebAssembly modules as Kubernetes admission policies. In June 2021 the project announced kwctl as a new tool for both policy authors and cluster administrators, and the December 2021 first-year recap described it as an expansion of the Kubewarden toolkit after KubeCon Europe.

The CLI became the developer-facing and operator-facing workbench for Kubewarden policies: it handles OCI registry distribution, metadata annotation, policy inspection, local execution, and scaffolding around the admission-controller components that run inside a cluster.

Adoption history

kwctl's adoption follows Kubewarden's adoption path rather than a separate ecosystem. It appears in Kubewarden tutorials and how-to material as the default CLI for testing policies before applying them to Kubernetes clusters and for preparing policy artifacts for registries.

How it is used

The common package-manager use case is installing kwctl beside kubectl, Helm, and policy build tools so a policy can be pulled or run locally before a cluster admission rule is created. It is also used to annotate WebAssembly modules with Kubewarden metadata and push policies as OCI artifacts.

Why package nerds care

For package collectors, kwctl is a small but telling example of the Kubernetes toolchain adopting OCI artifacts and WebAssembly outside normal container images. It is the Kubewarden equivalent of a specialized kubectl for policy packages.

Timeline

  • 2021-06-09: Kubewarden announced kwctl as a command-line utility for policy authors and Kubernetes administrators.
  • 2021-12-15: Kubewarden's first-year recap described kwctl as a toolkit addition released shortly after KubeCon Europe.
  • 2026-06-22: The 2021 kwctl announcement page carried an update date while retaining the original June 2021 publication date.

Related projects

  • kwctl is part of Kubewarden Admission Controller alongside kubewarden-controller, policy-server, audit-scanner, Kubewarden policies, OCI registries, WebAssembly, Sigstore, and Kubernetes admission webhooks.

security posture

Risk level: orange

infrastructure mutation or orchestration signal.

Risk classifier

orange risk · medium confidence · infrastructure

Why

  • infrastructure mutation or orchestration signal

Signals

  • text:kubernetes

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
kwctlexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version1.37.0
manager updated2026-07-27
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:kwctl
Version1.37.0
Package managerHomebrew
Homepagehttps://www.kubewarden.io/
Repositoryhttps://github.com/kubewarden/adm-controller
Last updated2026-07-27T15:52:52Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

zypper95%

kwctl 1.31.0-1.6

The go-to CLI tool for Kubewarden users

https://kubewarden.io/

sudo zypper install kwctl
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: kwctl
  • 4 dependencies
  • 2 provides
  • normalized package name match
  • Matched by: Kwctl
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: kwctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation