K3
K3s / K3d
Integration & Setup Manual
K3s & K3d Integration Guide
Overview
K3s and its Docker-wrapped counterpart K3d are popular for local Kubernetes environments. Cup’n’String discovers these clusters, listing active services and binding ports for security monitoring.
Support level
Auto-Discovered
What Cup’n’String detects
- Active K3s service processes and K3d containers
- Local kubeconfig contexts associated with K3s/K3d
- Ingress and service route maps
What it governs
- Egress network policies for cluster runtimes
- Port-forwarding and tunnel relays
- Access to the cluster API endpoint from local IDEs
Recommended policies
- Restrict cluster exposure to the local loopback interface
- Log all API port-forwarding activities to the central audit log
- Suppress cluster creations outside the allowed namespace list
Setup outline
- Ensure the Cup’n’String agent is active.
- Start your K3s cluster or K3d container (
k3d cluster create). - The agent reads context mappings from the default kubeconfig folder.
Verification
Check the local runtimes list in the agent dashboard to see K3s/K3d services mapped with their local endpoints.
Troubleshooting
Verify K3s/K3d config files are readable and cluster nodes are in a healthy state.
Known limitations
Does not enforce network policy internally within the cluster pods.
Integration Info
Support LevelAuto-Discovered
CategoryKubernetes
Setup ComplexityMedium
Governed Safeguards
Network
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix