Cup'n'String
Join Waitlist

© 2026 Cup'n'String

Kubernetes Governance

Govern Local Kubernetes on Developer Workstations

Local clusters created with kind, minikube, k3s, or MicroK8s run services that AI agents and tools can reach. Cup’n’String scans local clusters and maps services for secure, governed endpoint routing — without elevated cluster privileges.

Support levelAuto-Discovered
CategoryKubernetes
Governance capabilities
DiscoverAttributeOutbound policy

What Cup’n’String controls

Discover local clusters via kubeconfig context enumeration
Map cluster services and ingress for routing
Apply policy to AI agent and tool access
Detect risky exposure of cluster services
Expose approved services through secure tunnels
Record audit evidence
Enforce host firewall and NetworkPolicy controls where applicable

Common risks

Developer clusters often run real services with weak local controls.

Cluster services reachable from the workstation
Exposed databases, APIs, and dashboards
Shadow clusters and namespaces
Services shared without policy
Lack of inventory and audit

How it works

  1. Step 1Install / enroll the Cup’n’String Desktop Agent
  2. Step 2Discover local resources
  3. Step 3Classify environment / resource type
  4. Step 4Apply tenant policy
  5. Step 5Enforce allowed / blocked behavior
  6. Step 6Capture audit evidence
  7. Step 7Expose approved services through controlled access when needed

Recommended policies

Deny unknown local services by default
Require approval for exposing cluster services
Block AI agent access to sensitive namespaces
Log access to cluster services
Apply role-based access
Use Kubernetes NetworkPolicy where supported

Frequently asked questions

Can Cup’n’String detect local clusters automatically?
Yes. It auto-discovers local clusters (kind, minikube, k3s/k3d, MicroK8s) through kubeconfig context enumeration.
Does it need elevated cluster privileges?
Local discovery is designed to work without elevated cluster privileges. Kubernetes NetworkPolicy orchestration, where used, is scoped to Guard-owned, labeled policies in a single namespace.
Does this replace Kubernetes?
No. It discovers and governs access to local cluster services.
Can this work self-hosted?
Yes.
Can activity be audited?
Yes.

Govern Local Kubernetes with Cup’n’String

Discover the environment, apply policy, shield credentials, and capture audit evidence.

Related pages