PO
Podman
Integration & Setup Manual
Podman Integration Guide
Overview
Podman provides daemonless container execution. Cup’n’String features native integration with Podman, resolving Podman’s own local and remote connection settings and querying Libpod for running containers and pods.
Support level
Native Integration
What Cup’n’String detects
- Active rootless, rootful, Podman Machine, SSH, and TCP Podman service endpoints
CONTAINER_HOST,CONTAINER_CONNECTION,CONTAINER_SSHKEY,containers.conf, and managed Podman system connections- Running Podman containers and pod inventory
- Exposed container ports and network interfaces
What it governs
- Local-network firewall rules for Podman networks
- Outbound secure relay session limits
- Attribution of socket traffic to active container IDs
Recommended policies
- Scan for unmanaged rootless container engines that bypass default Docker daemon audits
- Map Podman services to formal tenant-managed endpoints
- Enable drift protection on user namespaces
Setup outline
- Start the Podman socket helper (
podman system service) or configure a Podman system connection. - Enable the
podmanruntime in Local Services. - The Cup’n’String agent automatically resolves local sockets, Podman Machine connections, and Podman’s configured remote URL settings.
- Container and pod state is read-only queried via the Podman Libpod API.
Verification
Verify running Podman containers appear in the Tenant Admin console under local runtimes.
Troubleshooting
Ensure the Podman system service socket or selected Podman system connection is active and readable by the current user.
Known limitations
Does not support container-internal prompt shielding without custom wrapper binaries.
Integration Info
Support LevelNative Integration
CategoryContainer Runtimes
Setup ComplexityLow
Governed Safeguards
Network
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix