MI
MicroK8s
Integration & Setup Manual
MicroK8s Integration Guide
Overview
MicroK8s is a lightweight, zero-ops Kubernetes distribution from Canonical. Cup’n’String discovers MicroK8s installations on Linux workstations, cataloging service endpoints for policy enforcement.
Support level
Auto-Discovered
What Cup’n’String detects
- MicroK8s service states and cluster nodes
- Active kubeconfig contexts for Canonical Kubernetes
- Local services and port mappings
What it governs
- Egress traffic rules for cluster runtimes
- Port-forwarding access to internal microk8s namespaces
- API server access policies
Recommended policies
- Restrict local cluster API exposure to approved developer agents
- Audit all microk8s ingress rules for public exposures
- Log cluster-level outbound requests to untrusted repositories
Setup outline
- Ensure the Cup’n’String agent daemon is active on Linux.
- Start MicroK8s (
microk8s start). - The agent automatically detects cluster contexts from the microk8s config output.
Verification
Confirm that your MicroK8s services are displayed under the Kubernetes category in your central admin console.
Troubleshooting
Verify the current user has access to the microk8s group and the cluster status is active.
Known limitations
Applies network blocks at the host OS boundary (via nftables/iptables), not inside pod network namespaces.
Integration Info
Support LevelAuto-Discovered
CategoryKubernetes
Setup ComplexityMedium
Governed Safeguards
Network
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix