Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/Linux nftables & iptables Guide
LI

Linux nftables & iptables

Integration & Setup Manual

Linux nftables & iptables Integration Guide

Overview

On Linux systems, Cup’n’String orchestrates kernel-level packets via nftables (and legacy iptables where necessary). It dynamically injects rule chains to bind local processes to specific tenant egress gateways.

Support level

Kernel-Level Enforcement

What Cup’n’String detects

  • Active Netfilter tables, chains, and rulesets
  • System network namespaces
  • Process-to-socket socket mappings

What it governs

  • Ingress/egress rules for specific user IDs (UIDs) or group IDs (GIDs)
  • Port forwarding and proxy redirection (DNAT/REDIRECT)
  • Fallback/fail-closed states if the agent terminates
  • Redirect all outgoing HTTP/HTTPS model traffic to the local proxy port
  • Keep all local-network loopback ports secure from container bridge escape
  • Continuously scan nftables configuration for rule drift

Known limitations

Does not override custom raw routing tables (rt_tables) unless configured.

Setup outline

  1. Confirm the supported platform and deployment requirements with your administrator.
  2. Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
  3. Review policy in your environment before enabling enforcement, then verify the intended access outcomes.

Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.

Integration Info

Support LevelKernel-Level Enforcement
CategoryFirewalls
Setup ComplexityMedium
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix