LI
Linux nftables & iptables
Integration & Setup Manual
Linux nftables & iptables Integration Guide
Overview
On Linux systems, Cup’n’String orchestrates kernel-level packets via nftables (and legacy iptables where necessary). It dynamically injects rule chains to bind local processes to specific tenant egress gateways.
Support level
Kernel-Level Enforcement
What Cup’n’String detects
- Active Netfilter tables, chains, and rulesets
- System network namespaces
- Process-to-socket socket mappings
What it governs
- Ingress/egress rules for specific user IDs (UIDs) or group IDs (GIDs)
- Port forwarding and proxy redirection (DNAT/REDIRECT)
- Fallback/fail-closed states if the agent terminates
Recommended policies
- Redirect all outgoing HTTP/HTTPS model traffic to the local proxy port
- Keep all local-network loopback ports secure from container bridge escape
- Continuously scan nftables configuration for rule drift
Known limitations
Does not override custom raw routing tables (rt_tables) unless configured.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Support LevelKernel-Level Enforcement
CategoryFirewalls
Setup ComplexityMedium
Governed Safeguards
Network
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix