Carvel kapp-controller

C
C tier on GitOps ToolsScore 6.8 · #12 of 32
Android app
Not listed
Free plan
Yes
Runs on
Linux, self-hosted
carvel.dev
The Carvel kapp-controller homepage

Summary

Carvel kapp-controller provides declarative APIs to customize, install and update Kubernetes applications and packages. Its App resource supports declarative application installation, management and upgrades on a cluster. Package, PackageMetadata, PackageRepository and PackageInstall resources support creating and consuming software packages. It can fetch configuration and OCI images from Git repositories, ConfigMaps, Helm charts and OCI registries, and supports customization with ytt, Helm templates and other tools. For GitOps workflows, Carvel describes a Git repository as a possible single source of truth for package management. The kctrl CLI helps users inspect and interact with resources and helps package consumers get started. kapp-controller can use Mozilla SOPS to decrypt fetched secret material, with GPG and age encryption support. App resources must explicitly name a service account or kubeconfig Secret; references are restricted to the same namespace, supporting multi-tenant use. Packages and repositories can be relocated for air-gapped environments. The project is CNCF sandbox software, available free under the Apache 2.0 license, with community support through GitHub issues and Kubernetes Slack.

Who it is for

kapp-controller suits Kubernetes users who want declarative application and package management, including teams using GitOps or air-gapped environments. Its explicit service-account or kubeconfig requirements may be relevant to teams managing access across namespaces.

What is good

  • Declarative application installs, management and upgrades.
  • Fetches configuration from Git, ConfigMaps, Helm and OCI sources.
  • Supports ytt and Helm templates.
  • Packages can be relocated for air-gapped use.

What to know first

  • Versions at or below v0.36.1 have a Kubernetes v1.24 reconciliation limitation.
  • Support is community-based through GitHub issues and Kubernetes Slack.
  • Requires a service account or kubeconfig Secret for each App resource.

Verdict

kapp-controller offers declarative Kubernetes app and package management, with GitOps support and options for restricted environments. Check the documented version limitation if using Kubernetes v1.24, and account for the required credentials on App resources.

Carvel kapp-controller plans and pricing

All plans
kapp-controller Free Open source · Apache 2.0 license carvel.dev · 4 Oct 2026

Compared on GitOps tools

Free plan
Yescarvel.dev
Reconciliation scope
applicationscarvel.dev
Supported Git sources
Git repositoriescarvel.dev
Supported deployment targets
Kubernetescarvel.dev

Facts

Purpose
kapp-controller provides declarative APIs to customize, install, and update Kubernetes applications and packages.carvel.dev · 4 Oct 2026
Continuous delivery
Its App custom resource supports declarative installation, management, and upgrades of applications on a Kubernetes cluster.carvel.dev · 4 Oct 2026
Package management
Package, PackageMetadata, PackageRepository, and PackageInstall custom resources support authoring and consuming software packages.github.com · 4 Oct 2026
Fetch sources
It can fetch configuration and OCI images from Git repositories, ConfigMaps, Helm charts, and OCI registries.carvel.dev · 4 Oct 2026
Templates
It supports customizing software with ytt templates, Helm templates, and other tools.carvel.dev · 4 Oct 2026
GitOps
Carvel describes kapp-controller as supporting GitOps, including using a Git repository as the single source of truth for Kubernetes package management.github.com · 4 Oct 2026
CLI
The kctrl CLI helps users observe and interact with kapp-controller custom resources and helps package consumers get started faster.carvel.dev · 4 Oct 2026
Integrations
kapp-controller integrates with Mozilla SOPS to decrypt secret material in fetched configuration, with GPG and age encryption support.carvel.dev · 4 Oct 2026
Security model
Each App resource must specify a service account or kubeconfig Secret, making the privileges for managing app resources explicit.carvel.dev · 4 Oct 2026
Multi-tenancy
The security documentation says App resources can reference service accounts or kubeconfig Secrets only from the same namespace, supporting use in multi-tenant environments.carvel.dev · 4 Oct 2026
Air-gapped use
Package repositories and packages can be relocated and run in air-gapped environments.carvel.dev · 4 Oct 2026
Kubernetes compatibility
The install guide says versions at or below v0.36.1 cannot reconcile App and PackageInstall resources with Kubernetes v1.24's default LegacyServiceAccountTokenNoAutoGeneration feature gate.carvel.dev · 4 Oct 2026
Support
Carvel provides community support through GitHub project issues and invites users to its Kubernetes Slack channel.carvel.dev · 4 Oct 2026
Project status
Carvel identifies kapp-controller as a Cloud Native Computing Foundation sandbox project.carvel.dev · 4 Oct 2026

Best Carvel kapp-controller alternatives

See all 20

Where it ranks on Everything Xiaomi

Is Carvel kapp-controller yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources