macOS
brew install kwctllocal Homebrew formula metadata
brew / rank 5531
CLI tool for the Kubewarden policy engine for Kubernetes. Version 1.37.0 via Homebrew; verified 2026-07-27. Also installable with zypper: sudo zypper install kwctl.
install
brew install kwctllocal Homebrew formula metadata
sudo zypper install kwctlopenSUSE Tumbleweed package metadata · kwctl · source: download.opensuse.org
overview
CLI tool for the Kubewarden policy engine for Kubernetes
history
kwctl is the command-line tool in the Kubewarden admission-controller ecosystem. It gives policy authors and Kubernetes administrators a local way to inspect, annotate, run, benchmark, pull, push, save, and verify WebAssembly admission policies.
Kubewarden grew around the idea of using WebAssembly modules as Kubernetes admission policies. In June 2021 the project announced kwctl as a new tool for both policy authors and cluster administrators, and the December 2021 first-year recap described it as an expansion of the Kubewarden toolkit after KubeCon Europe.
The CLI became the developer-facing and operator-facing workbench for Kubewarden policies: it handles OCI registry distribution, metadata annotation, policy inspection, local execution, and scaffolding around the admission-controller components that run inside a cluster.
kwctl's adoption follows Kubewarden's adoption path rather than a separate ecosystem. It appears in Kubewarden tutorials and how-to material as the default CLI for testing policies before applying them to Kubernetes clusters and for preparing policy artifacts for registries.
The common package-manager use case is installing kwctl beside kubectl, Helm, and policy build tools so a policy can be pulled or run locally before a cluster admission rule is created. It is also used to annotate WebAssembly modules with Kubewarden metadata and push policies as OCI artifacts.
For package collectors, kwctl is a small but telling example of the Kubernetes toolchain adopting OCI artifacts and WebAssembly outside normal container images. It is the Kubewarden equivalent of a specialized kubectl for policy packages.
security posture
infrastructure mutation or orchestration signal.
orange risk · medium confidence · infrastructure
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
kwctl | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:kwctl |
|---|---|
| Version | 1.37.0 |
| Package manager | Homebrew |
| Homepage | https://www.kubewarden.io/ |
| Repository | https://github.com/kubewarden/adm-controller |
| Last updated | 2026-07-27T15:52:52Z |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
kwctl 1.31.0-1.6
The go-to CLI tool for Kubewarden users
sudo zypper install kwctlsource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.