Govern Podman Pods and Containers
Podman runs containers without a daemon. Cup’n’String provides first-class native integration through Libpod local sockets, Podman system connections, containers.conf, and CONTAINER_HOST/CONTAINER_CONNECTION settings to govern AI agent access.
Support levelNative Integration
CategoryContainer Runtimes
Governance capabilities
DiscoverAttributeOutbound policyAuditShield secrets
What Cup’n’String controls
Discover Podman pods and containers via the Libpod API
Inventory exposed services and ports
Apply policy to AI agent access
Detect risky exposure of local services
Expose approved services through secure tunnels
Record audit evidence
Enforce host firewall controls where applicable
Common risks
Daemonless container tools still expose services that AI agents can reach.
Exposed local ports and services
Local databases and APIs reachable by AI tools
Shadow pods and containers
Developer services shared without policy
Lack of inventory and audit
How it works
- Step 1Install / enroll the Cup’n’String Desktop Agent
- Step 2Discover local resources
- Step 3Classify environment / resource type
- Step 4Apply tenant policy
- Step 5Enforce allowed / blocked behavior
- Step 6Capture audit evidence
- Step 7Expose approved services through controlled access when needed
Recommended policies
Deny unknown local services by default
Require approval for exposing local ports
Block AI agent access to sensitive services
Log access to local databases and APIs
Apply role-based access
Allow only approved AI tools
Frequently asked questions
Can Cup’n’String detect Podman automatically?
Yes. Podman has Native Integration: Cup’n’String resolves local sockets, Podman Machine/system connections, containers.conf, and CONTAINER_HOST/CONTAINER_CONNECTION settings to discover pods and containers.
Does discovery read secrets?
Discovery is read-only and bypasses secrets and environment variables.
Does this replace Podman?
No. It discovers and governs the containers Podman runs.
Can this work self-hosted?
Yes.
Can activity be audited?
Yes.
Govern Podman with Cup’n’String
Discover the environment, apply policy, shield credentials, and capture audit evidence.