Kubernetes NetworkPolicy
Integration & Setup Manual
Kubernetes NetworkPolicy Integration Guide
Overview
Cup’n’String Guard integrates with Kubernetes NetworkPolicy to enforce AI tool network policies for containerized developer environments and AI agent workloads running in Kubernetes clusters. Guard uses server-side apply (SSA) to declaratively manage NetworkPolicy objects in a designated namespace — it manages only policies assigned to the integration.
Support level
Cloud-Native Rules — Kubernetes server-side apply with field ownership semantics. Identity-aware: Guard can scope policies to specific pod label selectors or service accounts.
Recommended Guard mode
Observe to audit current NetworkPolicy coverage in the target namespace, then Enforce to maintain policies automatically.
Known limitations
- NetworkPolicy enforcement depends entirely on the CNI plugin — Guard creates policies but does not verify the CNI is enforcing them at the data plane.
- Default-deny-all policies must be explicitly created; Guard creates only the specific allow/deny rules in the desired policy set.
- Cluster-level (non-namespaced) network restrictions require Cilium
CiliumNetworkPolicyor similar CRDs — standardNetworkPolicyobjects are namespace-scoped.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix