Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/Kubernetes NetworkPolicy Guide
KU

Kubernetes NetworkPolicy

Integration & Setup Manual

Kubernetes NetworkPolicy Integration Guide

Overview

Cup’n’String Guard integrates with Kubernetes NetworkPolicy to enforce AI tool network policies for containerized developer environments and AI agent workloads running in Kubernetes clusters. Guard uses server-side apply (SSA) to declaratively manage NetworkPolicy objects in a designated namespace — it manages only policies assigned to the integration.

Support level

Cloud-Native Rules — Kubernetes server-side apply with field ownership semantics. Identity-aware: Guard can scope policies to specific pod label selectors or service accounts.

Observe to audit current NetworkPolicy coverage in the target namespace, then Enforce to maintain policies automatically.

Known limitations

  • NetworkPolicy enforcement depends entirely on the CNI plugin — Guard creates policies but does not verify the CNI is enforcing them at the data plane.
  • Default-deny-all policies must be explicitly created; Guard creates only the specific allow/deny rules in the desired policy set.
  • Cluster-level (non-namespaced) network restrictions require Cilium CiliumNetworkPolicy or similar CRDs — standard NetworkPolicy objects are namespace-scoped.

Setup outline

  1. Confirm the supported platform and deployment requirements with your administrator.
  2. Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
  3. Review policy in your environment before enabling enforcement, then verify the intended access outcomes.

Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.

Integration Info

Support LevelCloud-Native Rules
CategoryFirewalls
Setup ComplexityMedium
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix