BuildKit
- 1Runs onAPI, Linux, Mac, self-hosted, Windows
- 2CostsFree plan

Overview
BuildKit is a free toolkit for turning source code into build artifacts. It consists of the buildkitd daemon and buildctl client, and uses LLB, a binary format for describing process dependency graphs. Builds can use Dockerfiles or other LLB-compatible frontends, resolve dependencies concurrently, cache instructions, import and export caches, run nested jobs, and collect unused data automatically. BuildKit supports execution without root privileges and OCI (runc) or containerd workers. Results can be exported as images, local directories, tarballs, Docker tarballs, or OCI tarballs. Cache options include inline, registry, local-directory, and GitHub Actions backends; the README marks GitHub Actions, S3, and Azure Blob options experimental. The daemon provides a gRPC API over a Unix socket by default, with TCP sockets also supported. Binaries are available for Linux, macOS, and Windows. The unofficial Homebrew formula for macOS omits buildkitd; the project gives Lima in a Linux virtual machine as one way to run it. BuildKit is licensed under Apache-2.0.
Who it is for
BuildKit suits developers and teams building artifacts from source, especially those needing configurable frontends, cache handling, or rootless execution. It also fits teams using Dockerfiles or other LLB languages.
What is good
- Concurrent dependency resolution and instruction caching.
- Runs builds without root privileges.
- Exports images, directories, and several tarball formats.
- Binaries available for Linux, macOS, and Windows.
What to know first
- The unofficial macOS Homebrew formula omits buildkitd.
- GitHub Actions, S3, and Azure Blob cache options are experimental.
Specifiction review
BuildKit: the full review
BuildKit offers a broad set of build, cache, and output options in a free Apache-2.0 toolkit. macOS users relying on Homebrew need another way to run the daemon.
BuildKit is an open-source toolkit for producing repeatable build artifacts, suited to developers and platform teams who want control over build pipelines. Its flexible caching and output choices are strong; running the daemon is the trade-off, particularly for macOS users.
Overview
BuildKit pairs the buildkitd daemon with the buildctl client. Builds are represented in LLB, a vendor-neutral format for process dependency graphs that supports concurrent execution and cache reuse. Docker Engine 23.0 and later use Buildx and BuildKit by default for docker build, so Docker users may already encounter it as part of their workflow. The project is Apache-2.0 licensed and is used by projects including Moby, Docker, Tekton Pipelines, Gitpod and Dagger.
Key features
Flexible builds and reusable work
Frontends translate build definitions into LLB, with support for Dockerfiles and other LLB languages. Concurrent dependency resolution, instruction caching, and cache import and export can cut repeated build work. Cache exporters include inline, registry, local-directory and GitHub Actions options; GitHub Actions, S3 and Azure Blob cache options are marked experimental, making them less suitable as a critical dependency when stability matters.
Outputs include images, local directories, tarballs, Docker tarballs and OCI tarballs. Automatic garbage collection helps manage accumulated build data, while nested jobs, pluggable architecture and distributable workers give teams room to shape the build system around their infrastructure. The daemon supports OCI (runc) and containerd worker backends.
Execution and security
Rootless execution is supported, and BuildKit describes itself as secure by default and usable with untrusted sources. With the default daemon configuration, the API is confined from the host filesystem outside BuildKit’s state directory; application and frontend containers cannot access the host system, invoke privileged system calls or directly use external devices. This is a useful boundary for build workloads, though it does not replace an operator’s responsibility to configure and run the daemon appropriately.
Pricing
BuildKit is free under the Apache License 2.0: 0.00 USD per free, perpetual, worldwide, non-exclusive, no-charge and royalty-free. There are no paid tiers or seat and usage caps in the stated plan, so it suits teams that can operate their own build infrastructure and do not need a hosted service. The cost is operational effort rather than a subscription.
Platforms
BuildKit supports Linux, Windows and macOS, with binaries for all three and self-hosted deployment. Rootless mode and Windows containers are supported. The important macOS caveat is that the unofficial Homebrew formula omits the buildkitd daemon; Lima running a Linux VM is one suggested way to provide it. The daemon exposes a gRPC API at /run/buildkit/buildkitd.sock by default and can also use TCP sockets.
Who it's for
BuildKit fits developers and platform teams building container-oriented pipelines who value cache control, multiple output formats and support for different build-definition frontends. Its use across Moby, Docker, Tekton Pipelines, Docker buildx, Gitpod, Dagger and other projects points to a place in both local development and CI workflows. It is less compelling for people seeking a turnkey desktop app or managed build service: BuildKit is a daemon-and-client toolkit that the user must integrate and operate.
Pros and cons
- Pros: Concurrent resolution and instruction caching can avoid duplicated work; cache import and export enable reuse across environments.
- Pros: Dockerfile and other LLB frontends, several worker backends and varied export formats accommodate different pipelines.
- Pros: Free Apache-2.0 licensing and rootless execution make it practical for self-managed builds with cost and privilege constraints.
- Cons: macOS Homebrew does not provide the daemon, so Mac users need another route such as a Linux VM.
- Cons: Some cache options are experimental, a drawback for teams depending on those backends in important workflows.
- Cons: The daemon/client architecture requires setup and operation rather than offering a managed workflow.
Alternatives
Docker Desktop is the more natural choice for readers who want a freemium option across desktop platforms; its free Docker Personal plan is limited to one user, one Docker Scout-enabled repository, 100 Docker Hub pulls per hour and one private Docker Hub repository.
Incus is another free Apache 2 licensed option for readers seeking an alternative in this wider container and infrastructure space. LXD offers open-source KVM-based virtual machines and system containers with self-hosted deployment, so choose it when those are the workloads you need. Apptainer is a free open-source container platform, with commercial support available through partners.
gVisor is a Linux-only open-source sandbox requiring Linux 5.6 or later on x86_64 or ARM64; it is the alternative to consider when that sandbox role is the priority. Podman provides free container, pod and image management alongside Podman Desktop. containerd is a free Apache 2.0-licensed open-source container runtime, while crun is a free OCI container runtime with source builds and release binaries.
Browse Container Build Tools for more build-focused options, or Container Engines for tools centered on running containers.
Verdict
Choose BuildKit if you want a free, extensible build toolkit with serious caching, multiple outputs and control over execution. Its main advantage is flexibility across build definitions and infrastructure; look elsewhere if you need a managed workflow or a straightforward macOS daemon installation.
BuildKit plans and pricing
All plansCompared on container build tools
- Free plan
- Yesgithub.com
Facts
- Purpose
- BuildKit converts source code into build artifacts efficiently and repeatably.github.com · 30 Sept 2026
- Build features
- Features include concurrent dependency resolution, instruction caching, cache import and export, multiple output formats, and automatic garbage collection.github.com · 30 Sept 2026
- Extensible builds
- BuildKit uses frontends to convert build definitions into LLB, and supports Dockerfiles and other LLB languages.github.com · 30 Sept 2026
- Execution
- BuildKit supports execution without root privileges.github.com · 30 Sept 2026
- Workers
- The daemon supports OCI (runc) and containerd worker backends.github.com · 30 Sept 2026
- Integrations
- The repository lists Moby and Docker, Tekton Pipelines, Docker buildx, Gitpod, Dagger, and other projects as BuildKit users.github.com · 30 Sept 2026
- Cache backends
- Cache exporters include inline, registry, local directory, and GitHub Actions cache; the README marks GitHub Actions, S3, and Azure Blob cache options experimental in its contents list.github.com · 30 Sept 2026
- Outputs
- Build results can be exported as images, local directories, tarballs, Docker tarballs, or OCI tarballs.github.com · 30 Sept 2026
- Platforms
- The buildctl client is available for Linux, macOS, and Windows, while buildkitd is available for Linux and Windows.github.com · 30 Sept 2026
- macOS limitation
- The README says the unofficial Homebrew formula for macOS does not include the buildkitd daemon and gives Lima in a Linux VM as an example way to run it.github.com · 30 Sept 2026
- API
- The daemon listens on a gRPC API at /run/buildkit/buildkitd.sock by default and can also use TCP sockets.github.com · 30 Sept 2026
- Support
- The README directs users to the #buildkit channel on Docker Community Slack.github.com · 30 Sept 2026
- Docker availability
- The README says Docker Engine 23.0 and later use Buildx and BuildKit by default for docker build.github.com · 30 Sept 2026
- License
- The repository identifies its license as Apache-2.0.github.com · 30 Sept 2026
- Architecture
- BuildKit is composed of the buildkitd daemon and the buildctl client.github.com · 30 Sept 2026
- Binaries
- The latest BuildKit binaries are available for Linux, macOS, and Windows.github.com · 30 Sept 2026
- Adopters
- The project lists Moby and Docker, img, OpenFaaS Cloud, Tekton Pipelines, Docker buildx, Gitpod, Dagger, Depot, and other projects as users.github.com · 30 Sept 2026
- LLB
- BuildKit builds use a binary intermediate format called LLB for defining process dependency graphs, and LLB is concurrently executable, efficiently cacheable, and vendor-neutral.github.com · 30 Sept 2026
- Security model
- BuildKit describes itself as secure by default and usable with untrusted sources.github.com · 30 Sept 2026
- Security reporting
- Security issues should be reported privately to [email protected], and the project currently does not offer a paid security bounty program.github.com · 30 Sept 2026
- Latest release
- The repository’s releases page lists v0.33.1 as the latest release dated September 30, 2026.github.com · 30 Sept 2026
Best BuildKit alternatives
See all 20Where it ranks on Specifiction
- Best Container Build Tools in 2026#2 of 32
- Best Container Engines in 2026#1 of 31
Is BuildKit yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/moby/buildkit· checked 30 Sept 2026
- github.com/moby/buildkit/blob/master/README.md· checked 30 Sept 2026
- github.com/moby/buildkit/blob/master/PROJECT.md· checked 30 Sept 2026
- github.com/moby/buildkit/security· checked 30 Sept 2026
- github.com/moby/buildkit/releases· checked 30 Sept 2026
- github.com/moby/buildkit/blob/master/LICENSE· checked 30 Sept 2026



