# 使用 Homebrew, apk, MacPorts, Nix, pacman, scoop 安装 ko

查看 ko 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:ko
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install ko
```

  证据: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install ko
```

  证据: MacPorts ports tree: devel/ko/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add ko
```

  证据: Alpine Linux edge package indexes: ko from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- Nix (92%):

```sh
nix profile install nixpkgs#ko
```

  证据: nixpkgs package indexes: pkgs/by-name/ko/ko/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S ko
```

  证据: Arch Linux sync databases: ko from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

### Windows

- Scoop (92%):

```sh
scoop install main/ko
```

  证据: Scoop official bucket manifest trees: bucket/ko.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

## 软件包事实

- **软件包键:** brew:ko
- **软件包管理器:** Homebrew
- **版本:** 0.19.1
- **来源摘要:** Build and deploy Go applications on Kubernetes
- **主页:** <https://ko.build>
- **仓库:** <https://github.com/ko-build/ko>
- **最后更新:** 2026-07-27T21:58:40+02:00
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- ko (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 0.19.1
## 项目历史与用法

ko is a Go-focused container image builder for developers who want OCI images without writing Dockerfiles or running Docker locally. Its Homebrew package is a small CLI, but it sits at the intersection of Go modules, Kubernetes manifests, registries, SBOMs, and supply-chain tooling.

### 项目历史

The project grew out of Google experience building Docker and Kubernetes support for Bazel. Its README describes ko as a simple, fast container image builder that effectively runs `go build` locally, then packages the resulting binary into an image without requiring Docker.

By 2022, the project had moved into the ko-build GitHub organization and the ko.build documentation domain. A 2022-08-19 migration issue laid out the repository move from google/ko to github.com/ko-build, the ko.build vanity import path, image-name changes, and a Slack channel rename. On 2022-10-11, Google announced that it had submitted ko for CNCF Sandbox consideration.

### 采用历史

ko's adoption followed the rise of Go-based cloud-native services that can ship as mostly static binaries. The Google Open Source announcement described growing use by open source and enterprise teams and integration into third-party CI/CD tools.

Package-manager adoption is useful because ko is often installed in developer shells, GitHub Actions, release jobs, and Kubernetes workflows. Its companion setup-ko action made it easy to bootstrap the CLI in CI, while Homebrew, MacPorts, Nix, Arch, Alpine, and Scoop packaging made it available outside a single vendor ecosystem.

### 使用方式

The common workflow is `ko build` or `ko resolve`: build Go packages into images, push them to a registry, and optionally rewrite Kubernetes YAML with the produced image references. The docs emphasize no Docker daemon requirement, multi-platform images, SBOM generation, Kubernetes integration, build cache support, and registry authentication through ko login or surrounding CI credentials.

It is particularly attractive for Go services with few operating-system package dependencies. That constraint is part of the tool's appeal: it turns the boring case of a static Go binary into a very short path from source to signed or traceable container artifact.

### 为什么软件包爱好者会关心

ko is the package-index shorthand for a whole cloud-native philosophy: build the thing the language already knows how to build, then wrap it as an OCI image with minimal ceremony. It competes less with Docker itself than with Dockerfile boilerplate, bespoke CI shell scripts, and build-system plugins.

For maintainers, it is also a clean example of a single-purpose CLI whose value comes from integration points: Go, registries, Kubernetes, SBOMs, GitHub Actions, and module import paths.

### 时间线

- 2022-02-17: ko v0.10.0 was published; ko docs note that before v0.10 the command was called `ko publish`.
- 2022-08-19: The project opened a migration issue for moving from google/ko to github.com/ko-build and ko.build.
- 2022-08-24: ko v0.12.0 was published during the repository/domain migration period.
- 2022-10-11: Google announced that ko had been submitted for CNCF Sandbox consideration.

### Related projects

- ko is related to go-containerregistry, setup-ko, Skaffold's ko builder integration, Docker/BuildKit workflows, Kubernetes deployment tooling, and Bazel container rules that influenced the original design.

### 来源

- <https://api.github.com/repos/ko-build/ko/releases>
- <https://github.com/ko-build/ko>
- <https://github.com/ko-build/ko/issues/791>
- <https://ko.build/>
- <https://ko.build/get-started/>
- <https://opensource.googleblog.com/2022/10/ko-applies-to-become-a-cncf-sandbox-project.html>


## 安全说明

infrastructure mutation or orchestration signal.

- **Geiger 风险:** orange / 中
- infrastructure mutation or orchestration signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: .ko.yaml
## 其他软件包管理器记录

- Nix - ko: normalized package name match | nixpkgs package indexes: pkgs/by-name/ko/ko/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - ko - 0.17.1-r16: normalized package name match | Alpine Linux edge package indexes: ko from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Build containers from Go projects | https://ko.build/
- apk - ko-bash-completion - 0.17.1-r16: normalized package name match | Alpine Linux edge package indexes: ko-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for ko | https://ko.build/
- apk - ko-fish-completion - 0.17.1-r16: normalized package name match | Alpine Linux edge package indexes: ko-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for ko | https://ko.build/
- apk - ko-zsh-completion - 0.17.1-r16: normalized package name match | Alpine Linux edge package indexes: ko-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for ko | https://ko.build/
- pacman - ko - 0.19.1-1: normalized package name match | Arch Linux sync databases: ko from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | Build and deploy Go container images | https://github.com/ko-build/ko
- MacPorts - ko: normalized package name match | MacPorts ports tree: devel/ko/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/ko: normalized package name match | Scoop official bucket manifest trees: bucket/ko.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/ko.yml](https://github.com/mxcl/pkgdb/blob/main/combined/ko.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
