Govern OrbStack Containers and Domains
OrbStack runs containers and Kubernetes with *.orb.local domains on macOS. Cup’n’String provides first-class integration that scans OrbStack contexts and governs AI agent access to the services it runs.
Support levelNative Integration
CategoryContainer Runtimes
Governance capabilities
DiscoverAttributeOutbound policyAuditShield secrets
What Cup’n’String controls
Discover OrbStack contexts and *.orb.local services
Inventory exposed services and ports
Apply policy to AI agent access
Detect risky exposure of local services
Expose approved services through secure tunnels
Record audit evidence
Enforce host firewall controls where applicable
Common risks
OrbStack makes local services easy to reach by friendly domains, which also makes them easy for agents to reach.
Local services reachable via *.orb.local
Exposed databases and APIs
Shadow containers and stacks
Developer services shared without policy
Lack of inventory and audit
How it works
- Step 1Install / enroll the Cup’n’String Desktop Agent
- Step 2Discover local resources
- Step 3Classify environment / resource type
- Step 4Apply tenant policy
- Step 5Enforce allowed / blocked behavior
- Step 6Capture audit evidence
- Step 7Expose approved services through controlled access when needed
Recommended policies
Deny unknown local services by default
Require approval for exposing local ports
Block AI agent access to sensitive services
Log access to local databases and APIs
Apply role-based access
Allow only approved AI tools
Frequently asked questions
Can Cup’n’String detect OrbStack automatically?
Yes. OrbStack has Native Integration: Cup’n’String scans OrbStack contexts and attributes *.orb.local domains as display metadata (macOS).
Does discovery read secrets?
Discovery is read-only and bypasses secrets and environment variables.
Does this replace OrbStack?
No. It discovers and governs the services OrbStack runs.
Can this work self-hosted?
Yes.
Can activity be audited?
Yes.
Govern OrbStack with Cup’n’String
Discover the environment, apply policy, shield credentials, and capture audit evidence.