Apple Container
Integration & Setup Manual
Apple Container Integration Guide
Overview
Cup’n’String provides native integration with Apple Container on supported macOS Apple silicon workstations. It discovers VM-isolated containers, images, networks, volumes, and container machines through the Apple container CLI — without Docker sockets or the Docker Engine API — and allows platform administrators to inventory exposed services and expose approved ports via secure outbound tunnels.
Support level
Native Integration
What Cup’n’String detects
- Running Apple Container workloads and published port bindings
- Container images, networks, volumes, and container machines
- VM isolation, published-port, and risk metadata from container inspect output
What it governs
- Local-service access policies for Apple Container workloads
- Secure Relay tunnel creation for private containers
- Workstation process and network boundaries around container services
Recommended policies
- Enable automatic discovery for the Apple container CLI on enrolled macOS Apple silicon devices
- Map discovered local services to verified tenant endpoints
- Track outbound network rules for VM-isolated container networks
Setup outline
- Ensure the Cup’n’String agent is active on a supported macOS Apple silicon workstation (macOS 26+).
- Install Apple Container and ensure the
containerCLI is available in PATH or at/opt/homebrew/bin/containeror/usr/local/bin/container. - Run your local containers with Apple Container.
- The agent queries the Apple container CLI with JSON output to inventory local runtimes read-only.
Verification
List active services in the Tenant Admin console to confirm that running Apple Container workloads are displayed with their correct port mappings and resource inventory.
Troubleshooting
If containers are not discovered, verify Apple Container is installed, its service is running, the workstation is Apple silicon on macOS 26+, and the container CLI responds to system status.
Known limitations
Apple Container is available only on supported macOS Apple silicon devices. Does not support container-internal prompt auditing without an agent wrapper inside the container.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix