v0.1.0 — cage core
The walking skeleton: run an AI coding agent (opencode; Claude Code and Copilot CLI as build toggles) inside a fail-closed container cage.
- Internal-only agent network; dual-homed mitmproxy (explicit mode) + CoreDNS with policy-derived zone scoping
- Fail-closed egress policy engine: fixed precedence, encoding-asymmetric matching, fixpoint decoding, no-ReDoS matcher, 3-call-site parity suite
- CONNECT-time + post-MITM enforcement; DNS-rebind/SSRF address guard; constrained per-session CA (pathlen:0)
- Non-root agent at host uid, sha256-gated tool installs, digest-pinned images, cap_drop ALL + no-new-privileges, memory limits
- SSH git remotes auto-rewritten to HTTPS; gh baked in (one-time in-session
gh auth loginfor private/push) - 10-probe adversarial conformance suite — green on Colima (macOS/arm64) and Linux engine (amd64)
- 72 unit/parity tests; CI: unit+parity+lint, 3-harness image matrix, live conformance
Quickstart in the README. Specs: openspec/specs/. Hardened against a 6-reviewer external security review (see commit history).