Docker / Docker Desktop
Integration & Setup Manual
Docker & Docker Desktop Integration Guide
Overview
Cup’n’String automatically discovers local container environments running under Docker Engine or Docker Desktop. It allows platform administrators to list active containers, inspect binding ports, and expose internal services via secure outbound tunnels without public ingress.
Support level
Auto-Discovered
What Cup’n’String detects
- Running Docker container endpoints
- Local Docker Compose configurations
- Active port bindings and network mappings
What it governs
- Local-service access policies
- Secure Relay tunnel creation for private containers
- Workstation process and socket isolation
Recommended policies
- Suppress unmanaged container engines running rogue LLMs
- Map discovered local services to verified tenant endpoints
- Track outbound network rules on container networks
Setup outline
- Ensure the Cup’n’String agent is active on the workstation.
- Run your local containers using Docker or Docker Compose.
- The agent scans the Docker socket (
docker.sock) or default host context to inventory local runtimes.
Verification
List active services in the Tenant Admin console to confirm that your running Docker containers are displayed with their correct port mappings.
Troubleshooting
If containers are not discovered, verify that the local user is in the docker group and the Docker socket is accessible at the default path.
Known limitations
Does not support container-internal prompt auditing without an agent wrapper inside the container.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix