# cue-lang/cue: a configuration language that validates before it renders

> CUE is a Go-implemented language for defining schemas and validating configuration, with import and export paths for JSON, YAML, TOML, XML, OpenAPI, Protobuf and JSON Schema. It suits engineers who want one source of truth for data shape and data values.

**cue-lang/cue** — The home of the CUE language! Validate and define text-based and dynamic configuration

- Repository: https://github.com/cue-lang/cue
- Website: https://cuelang.org
- Stars: 6,259 · Forks: 367
- Language: Go
- License: Apache-2.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/cue-lang-cue

## The gap CUE fills between schema and config

Most configuration workflows split into two artifacts: a schema written in JSON Schema or a Go struct, and the actual YAML or TOML that must satisfy it. CUE collapses that split. The README describes the project as making it easy to "validate data, write schemas, and ensure configurations align with policies." The same file holds the type and the value, and the tool checks that the value conforms. The audience is engineers who maintain configuration for systems that already speak JSON, YAML, TOML, XML, OpenAPI, Protobuf or JSON Schema, because CUE lists all of those as formats it works with. If your configuration is a handful of static YAML files that never change shape, the language adds a compile step you do not need. The value appears when the same data shape is repeated across environments, services or generated artifacts.

## How unification and the CUE toolchain work

The name expands to "Configure, Unify, Execute" in the README. Unification is the mechanism: rather than assigning values imperatively, CUE files describe constraints, and combining two constraints produces a value that satisfies both. A field with a type and a field with a concrete value unify into a typed value. That is why the language can carry schemas and data in one file without a separate validation pass.

The repository layout shows the implementation split. The cmd/ directory holds the cue command, cue/ holds the core language packages, encoding/ covers the import and export formats, pkg/ holds builtin packages callable from CUE programs, and mod/ handles module resolution. The go.mod file lists the format dependencies directly: goccy/go-yaml and go.yaml.in/yaml/v3 for YAML, pelletier/go-toml/v2 for TOML, bufbuild/protocompile and emicklei/proto for Protobuf, and tetratelabs/wazero, a WebAssembly runtime, among others. The presence of cuelabs.dev/go/oci/ociregistry and the Open Containers image-spec dependencies indicates the toolchain talks to OCI registries, which is how CUE modules are distributed.

## Installing the cue CLI and validating a first file

The README points to cuelang.org for the full range of installation methods, including an official container image on Docker Hub under the cuelang/cue repository. Release builds are downloadable from the GitHub releases page. For source installs the README requires Go 1.26 or later and gives this command:

```bash
go install cuelang.org/go/cmd/cue@latest
```

After that, the binary should report its version, which the README says is derived from the VCS when built from git tags:

```bash
cue version
```

The README also shows how to build a cloned repository directly:

```bash
go install ./cmd/cue
```

The README does not document rollback or uninstall steps, so removal of a source-installed binary is left to the reader's Go environment. For learning the syntax, the README names the language tour on cuelang.org as the fastest path to the basics, and points to the cue command reference on cuelang.org for the command's interface.

## Where CUE gets in the way

Unification is the feature and the failure mode. When two constraints conflict, you get an error with no partial result, and debugging a conflict across several imported files means reading the error carefully rather than inspecting intermediate state the way you would with a templating engine. Teams used to Helm-style string substitution will find that CUE refuses to render anything until every constraint is satisfied.

The Go requirement is a real constraint. The go.mod file declares go 1.26.0, and the README says installing from source needs Go 1.26 or later. The README also describes a release support policy: the project supports the two most recent major releases of Go, matching Go's security policy. If your build environment is pinned to an older toolchain, a source install will not work, and you are limited to release binaries.

The release list shows v0.18.0-alpha.2 and v0.18.0-alpha.1 alongside the stable v0.17.1. If you need a stable line, the alpha tags are not it. The README does not document a migration path between minor versions, so version upgrades are something to verify against your own files rather than assume.

## CUE against Jsonnet and plain JSON Schema

Jsonnet is the comparison the search data keeps returning, and the difference is structural. Jsonnet is a templating and evaluation language: you write programs that produce JSON, and correctness is whatever the output happens to be. CUE adds a constraint layer to the same problem space, so a value that violates a declared type fails evaluation instead of silently appearing in the output. Jsonnet has no equivalent of unification across files; composition happens through imports and function calls, and the result is data, not a checked type.

JSON Schema sits at the other end. It validates data after the fact and is widely supported by editors and CI tools. CUE can work with JSON Schema as one of its supported formats, but a JSON Schema document cannot express the data itself, so you still maintain two files. CUE's trade-off is a smaller ecosystem and a language to learn. JSON Schema's trade-off is that validation and authoring stay separate concerns.

## Licence, maintenance and upgrade cost

The repository is licensed Apache-2.0, which permits commercial use, modification and redistribution provided the licence and notices are preserved. That is a permissive licence with an explicit patent grant, and it is compatible with the Go module ecosystem the project lives in. This is not legal advice; if you redistribute a modified cue binary, read the LICENSE file in the repository root.

The repository is not archived, and the last push was on 2026-09-18, days before this writing. Releases are frequent: v0.18.0-alpha.2 landed on 2026-09-15, v0.18.0-alpha.1 on 2026-08-04, and v0.17.1 on 2026-07-16. The upgrade cost is the Go toolchain, not the CUE files. Because go.mod pins go 1.26.0 and the README states the two-most-recent-major-releases policy, every Go major release effectively raises the floor for source builds. Downstream packagers should note the README's recommendation to build from git tags rather than source archives so that cue version reports correct version information.

## Conclusion

CUE fits teams that already generate or validate configuration in Go pipelines and want schema and values in one file. It is a poor fit if you only need templating with no type or constraint checking. Before adopting, install the CLI, run cue version, and check that your Go toolchain satisfies the go.mod requirement of Go 1.26.0.

## FAQ

### Is the name CUE pronounced like "queue" or "cue"?

The repository and README use the spelling CUE throughout and the project expands it as "Configure, Unify, Execute". The documentation does not give a pronunciation guide.

### What language is cue-lang/cue implemented in?

The primary language is Go. The go.mod file declares module cuelang.org/go with go 1.26.0, and the README requires Go 1.26 or later to install from source.

### What formats can CUE import and export?

The README lists Go, JSON, YAML, TOML, XML, OpenAPI, Protobuf and JSON Schema as formats the project works with. The encoding/ directory in the repository holds the corresponding packages.

### How do I install the cue command?

The README points to cuelang.org for the full list of installation methods, including an official container image. Release builds come from the GitHub releases page, and a source install uses go install cuelang.org/go/cmd/cue@latest with Go 1.26 or later.

### Does CUE have a stable release I can use in production?

The recent release list shows v0.17.1 as the stable tag, with v0.18.0-alpha.1 and v0.18.0-alpha.2 as pre-releases. The README does not document a migration path between minor versions.

## Sources

- [cue-lang/cue on GitHub](https://github.com/cue-lang/cue)
- [License: Apache-2.0](https://github.com/cue-lang/cue/blob/master/LICENSE)
- [Project website](https://cuelang.org)
- [README](https://github.com/cue-lang/cue/blob/master/README.md)
- [Releases](https://github.com/cue-lang/cue/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/cue-lang-cue
