Secure Reverse Tunnel for Private Developer Services
Developers often need to share a local API, database, or demo with a teammate or service. Cup’n’String establishes secure outbound-only reverse tunnels so approved services can be reached without opening inbound ports.
Why this matters
Traditional exposure methods are risky or operationally heavy: open ports, ad-hoc tunnels, and unmanaged reverse proxies create attack surface and leave no audit trail.
Opening inbound ports increases attack surface
Ad-hoc tunnels bypass policy and audit
Unmanaged reverse proxies are hard to govern
Local databases and APIs get shared without controls
There is no record of who exposed what, or for how long
The Cup’n’String approach
Cup’n’String turns service exposure into a governed action: discovered locally, approved by policy, and reachable through a controlled tunnel.
Establishes outbound-only gRPC/WebSocket tunnels over TLS — no inbound ports
Converts discovered local services into governed, tenant-managed endpoints
Applies policy and, where configured, approval before exposure
Supports time-bound and role-based access to exposed services
Records exposure as audit evidence
How it works
- Step 1Local private service
- Step 2Cup’n’String discovery & policy
- Step 3Approval (where configured)
- Step 4Outbound-only secure tunnel
- Step 5Controlled access & audit
Checklist
- Can you expose a service without opening inbound ports?
- Can exposure require approval?
- Can access be time-bound and role-based?
- Can you discover the service first?
- Can you audit who exposed what?
- Can you self-host?
Frequently asked questions
How does the tunnel avoid inbound ports?
The agent establishes a secure outbound-only session (gRPC/WebSocket over TLS), so traffic is bridged without opening inbound ports on the workstation or behind restrictive NATs and firewalls.
Is exposure governed?
Yes. Discovered services can be converted into formal tenant-governed endpoints, with policy and, where configured, approval before they are exposed.
Can access be temporary?
Yes. Access can be time-bound and role-based, which suits demos, contractor access, and support scenarios.
Is exposure audited?
Yes. Exposure and access can be recorded as audit evidence.
Expose private services the governed way
Share approved local services through secure, audited tunnels — without inbound ports.