# 使用 Homebrew, zypper 安装 kwctl

查看 kwctl 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:kwctl
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install kwctl
```

  证据: local Homebrew formula metadata

### Linux

- zypper (92%):

```sh
sudo zypper install kwctl
```

  证据: openSUSE Tumbleweed package metadata: kwctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

## 软件包事实

- **软件包键:** brew:kwctl
- **软件包管理器:** Homebrew
- **软件包管理器页面:** <https://formulae.brew.sh/formula/kwctl>
- **版本:** 1.37.0
- **来源摘要:** CLI tool for the Kubewarden policy engine for Kubernetes
- **主页:** <https://www.kubewarden.io/>
- **仓库:** <https://github.com/kubewarden/adm-controller>
- **上游文档:** <https://www.kubewarden.io/>
- **许可证:** Apache-2.0
- **源码归档:** <https://github.com/kubewarden/adm-controller/archive/refs/tags/v1.37.0.tar.gz>
- **最后更新:** 2026-07-27T15:52:52Z
- **已生成:** 2026-08-04T22:13:35+00:00

## 可执行文件

- kwctl (cli)
- kwctl (别名)

## 构建依赖

- pkgconf
- rust

## 安装行为

- post-install 钩子: 未定义
- Bottle: 可用 于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## 版本和新鲜度

- 页面生成时间: 2026-08-04
- 管理器版本: 1.37.0
- 管理器更新时间: 2026-07-27
- 本地数据: OK
- 上游仓库: https://github.com/kubewarden/adm-controller
- 检测到的最新版本: v1.37.0 (当前)
## 项目历史与用法

kwctl is the command-line tool in the Kubewarden admission-controller ecosystem. It gives policy authors and Kubernetes administrators a local way to inspect, annotate, run, benchmark, pull, push, save, and verify WebAssembly admission policies.

### 项目历史

Kubewarden grew around the idea of using WebAssembly modules as Kubernetes admission policies. In June 2021 the project announced kwctl as a new tool for both policy authors and cluster administrators, and the December 2021 first-year recap described it as an expansion of the Kubewarden toolkit after KubeCon Europe.

The CLI became the developer-facing and operator-facing workbench for Kubewarden policies: it handles OCI registry distribution, metadata annotation, policy inspection, local execution, and scaffolding around the admission-controller components that run inside a cluster.

### 采用历史

kwctl's adoption follows Kubewarden's adoption path rather than a separate ecosystem. It appears in Kubewarden tutorials and how-to material as the default CLI for testing policies before applying them to Kubernetes clusters and for preparing policy artifacts for registries.

### 使用方式

The common package-manager use case is installing kwctl beside kubectl, Helm, and policy build tools so a policy can be pulled or run locally before a cluster admission rule is created. It is also used to annotate WebAssembly modules with Kubewarden metadata and push policies as OCI artifacts.

### 为什么软件包爱好者会关心

For package collectors, kwctl is a small but telling example of the Kubernetes toolchain adopting OCI artifacts and WebAssembly outside normal container images. It is the Kubewarden equivalent of a specialized kubectl for policy packages.

### 时间线

- 2021-06-09: Kubewarden announced kwctl as a command-line utility for policy authors and Kubernetes administrators.
- 2021-12-15: Kubewarden's first-year recap described kwctl as a toolkit addition released shortly after KubeCon Europe.
- 2026-06-22: The 2021 kwctl announcement page carried an update date while retaining the original June 2021 publication date.

### Related projects

- kwctl is part of Kubewarden Admission Controller alongside kubewarden-controller, policy-server, audit-scanner, Kubewarden policies, OCI registries, WebAssembly, Sigstore, and Kubernetes admission webhooks.

### 来源

- <https://docs.kubewarden.io/reference/kwctl-cli>
- <https://github.com/kubewarden/kubewarden-controller>
- <https://www.kubewarden.io/blog/2021/06/kwctl-intro-for-kubernetes-administrators/>
- <https://www.kubewarden.io/blog/2021/12/first-year-of-kubewarden/>


## 安全说明

infrastructure mutation or orchestration signal.

- **Geiger 风险:** orange / 中
- infrastructure mutation or orchestration signal

## 源数据库详情

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** kwctl
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## 其他软件包管理器记录

- zypper - kwctl - 1.31.0-1.6: normalized package name match | openSUSE Tumbleweed package metadata: kwctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | The go-to CLI tool for Kubewarden users | https://kubewarden.io/


## 相关链接

- [Cloud CLI packages](https://pkg.so/zh-hans/cloud-clis/) - Belongs to a cloud or infrastructure command family.
- [Secret-risk packages](https://pkg.so/zh-hans/secret-risk-packages/) - Has protected-tool coverage, approval-gate, or non-low Geiger security signals.
- [Terminal utility packages](https://pkg.so/zh-hans/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Networking and protocol packages](https://pkg.so/zh-hans/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [pkgconf](https://pkg.so/zh-hans/brew/pkgconf/) - Build dependency declared by Homebrew.
- [rust](https://pkg.so/zh-hans/brew/rust/) - Build dependency declared by Homebrew.
- [kyverno](https://pkg.so/zh-hans/brew/kyverno/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes, policy, policy-engine.
- [polaris](https://pkg.so/zh-hans/brew/polaris/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes, policy.
- [kubernetes-cli](https://pkg.so/zh-hans/brew/kubernetes-cli/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes.
- [k9s](https://pkg.so/zh-hans/brew/k9s/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes.
- [k3d](https://pkg.so/zh-hans/brew/k3d/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes.
- [ctlptl](https://pkg.so/zh-hans/brew/ctlptl/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes.
- [openshift-cli](https://pkg.so/zh-hans/brew/openshift-cli/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes.
- [eksctl](https://pkg.so/zh-hans/brew/eksctl/) - Shares pkgdb curated category or tags: cli, cloud-infrastructure, kubernetes.
- [epinio](https://pkg.so/zh-hans/brew/epinio/) - Local package facts share a topical domain. Shared terms: cli, cloud, cloud-infrastructure, engine, infrastructure.

## Combined YAML source

View the package source record on GitHub. [combined/kwctl.yml](https://github.com/mxcl/pkgdb/blob/main/combined/kwctl.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
