docs: update repo references mensfeld/coi -> coipond/coi (org transfer)
docs: document reverse_shell_one_liners knob and one-liner detection change (#842/#846)
- Security-Monitoring: split reverse-shell threats into unambiguous vs
interpreter one-liner classes; add 'Interpreter one-liner policy' section
documenting reverse_shell_one_liners (critical|warn|off) and the network-
indicator gate; add the key to the full config block.
- Troubleshooting: note that benign interpreter one-liners no longer kill the
container, and how to downgrade the class instead of disabling auto-kill.
- Configuration: add reverse_shell_one_liners to the [monitoring] reference.
docs: align wiki to the Karafka writing style
Style-only pass across 39 pages: reduce decorative bold to scannable labels and
callouts, Title Case headings, expand contractions, present tense, US English,
cut filler and --- separators, tag code fences. Commands, code, config,
COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.
docs: point URLs at mensfeld/coi + fix leftover code-on-incus branding
Repo renamed mensfeld/code-on-incus -> mensfeld/coi: update all wiki links
(install.sh raw URL, issues/releases/tree/wiki links) and one leftover
"code-on-incus" prose ref -> Coi.
docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command)
COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)".
Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers
(they document the actual on-disk marker text). Lowercase coi commands unchanged.
docs(config): document per-mount `shift` field on [[mounts]] (#604)
docs(security): document unoverridable git identity lock + strict kernel-surface tier
- Security-Best-Practices: [git] readonly now enforces via three layers
(read-only mount + pinned GIT_* env + root-owned post-commit re-stamp);
document the -c/--author/env override paths it closes and the residual
gaps (repo-local core.hooksPath/husky, GIT_CONFIG_GLOBAL).
- Threat-Model: add the reduce_kernel_surface_strict tier (perf_event_open).
- Configuration: expand the readonly reference and add reduce_kernel_surface
+ reduce_kernel_surface_strict to [security].
docs: [git] strip_attribution — clean commit authorship (#788, PR #789)
- Configuration: the two new [git] keys in the sample block.
- Security best practices: new "Clean commit authorship" subsection under
Git Identity Guard — the global commit-msg hook (strip-don't-reject,
delegates to repo hooks), the Claude managed-settings layer, default
pattern coverage, trust scoping, and the documented limitations
(repo-local core.hooksPath / husky, git commit --no-verify).
Document 0.12 tool-switching, headless prompt runs, and config/profile mount + env_command_timeout symmetry
- Container Lifecycle: new 'Running a different AI tool in the same container'
section (shared session_name across two per-tool profiles; first-switch
credential seeding) (#708)
- Headless Orchestration: new 'Fire-and-forget prompt runs' section covering
coi run --prompt / --prompt-file / --prompt-name and the [prompts] registry
(trusted-scope only) with a cron example (#701)
- Profiles/Configuration: correct the now-false 'profiles use [[mounts]], config
uses [[mounts.default]]' note — both shapes work in both scopes; document
env_command_timeout as profile-settable (#783)
- Configuration: [prompts] stub + capability rows; note coi build works in any
[incus] project (#777)
- Troubleshooting: kitty/xterm-* 'unsuitable terminal' is handled automatically (#772)
- Migration Guide + Supported Tools: surface tool-switching and headless prompts
Document [limits.disk] size quota + clarify tmpfs_size is opt-in RAM /tmp (#728)
docs: split Supported Tools — extract Sandbox Context + Adding New Tools
Supported-Tools.md mixed three audiences. Keep all per-tool sections together
(users compare tools at a glance) and extract the two genuinely independent,
cross-cutting sections into their own pages (page now ~11.5 KB / 272 lines,
down from ~15.6 KB / 379 lines):
- New **Sandbox Context** — the `~/SANDBOX_CONTEXT.md` / `.json` environment
description, auto-context injection per tool, disabling it, and custom/JSON
context files. It's referenced from Architecture and Configuration and isn't
really about *which* tool.
- New **Adding New Tools** — contributor docs: the `Tool` interface and optional
capability interfaces (incl. ToolWithPrompt / ToolWithContainerEnv for
`coi tool spec`) with worked examples.
Supported-Tools keeps pointer stubs to both. Re-pointed the Configuration
cross-reference to the new Sandbox Context page; credentials/permission-mode
links stay valid (those sections remain). Added both pages to Home + _Sidebar
(nested under Supported Tools). All internal links verified.
docs: split Network Isolation into focused pages
Network-Isolation.md had grown to ~20 KB / 365 lines covering four distinct
topics. Extract the two self-contained ones into their own pages, leaving the
core page focused on egress modes + hardening (now ~13.7 KB / 244 lines):
- New **Static Host Entries** — `[[network.hosts]]` config, per-host `ports`,
the per-mode reachability table, trusted-scope rules, and runtime `coi hosts`.
- New **nftables Setup** — the open-mode workaround, install + sudoers steps,
how the FORWARD-chain rules work, and orphaned-rule cleanup.
Network-Isolation keeps short pointer stubs to both; the "(see below)" per-host
ports reference now links the new page. Host Access to Container Services stays
on the core page (it's `allow_local_network_access` firewall content, not
port-publishing). Re-pointed the Container-Operations and Configuration
cross-references to Static Host Entries, and added both pages to Home + _Sidebar
(nested under Network Isolation). All internal links verified.
docs: cover 0.12.0 capabilities (coi tool spec, coi top, omp, SANDBOX_CONTEXT.json)
Bring the wiki up to date with capabilities added since the last update:
- New page **Headless Orchestration (`coi tool spec`)** — the non-executing
launch-spec API for external orchestrators, incl. --continue / --resume-id /
--resume, the `prompt` field for non-embedding tools, and env/secrets model.
- New page **Resource Usage (`coi top`)** — live per-container/per-process CPU,
memory, disk and network usage; flags, examples, and how it reads cgroups.
- **Supported Tools**: add the omp (Oh My Pi) tool section; document the
~/SANDBOX_CONTEXT.json companion (context_json / context_json_file, trusted
scope only).
- **Configuration**: add context_json / context_json_file to the [tool] reference.
- Wire both new pages into Home + _Sidebar; cross-link Tmux Automation ->
Headless Orchestration.
(codex, tmpfs_size, per-host/per-destination ports, dns_servers, allowed_ports,
and git readonly were already documented.)
Document 0.12.0: egress hardening, per-host ports, Codex CLI, [git] readonly
Release-readiness pass for 0.11.1: session_name cross-references, --resume scoping correction, --container as-is note, named-session limitations
Document [container] session_name: named sessions that survive workspace moves (0.11.1)
Align wiki with 0.11.1: OrbStack guide, filesystem-first UID mapping, dir-pool health warning, idempotent context injection, version-fix note
- macOS Setup Guide: OrbStack is now a first-class documented option
(setup steps, how COI handles the FUSE-backed macOS share via
raw.idmap, the OrbStack >=2.2.2 silent-breakage background, storage
notes); 'How It Works' rewritten around the v0.11.1 filesystem check
with the reactive fallback; Manual Override reframed as rarely
needed; Colima instructions now install Incus from Zabbly (Ubuntu's
6.0 is below the required 6.1).
- Configuration/Architecture/File-Transfer/FAQ pages: UID-mapping
mechanism descriptions updated (auto-selected shift vs raw.idmap),
disable_shift comment rewritten, Colima-only framing widened to
Colima/Lima/OrbStack.
- System Health Check/Troubleshooting/Best Practices/Getting Started/
Linux Setup Guide: dir-pool driver warning documented (detection,
cost, fix), example output shows the new 'pool (driver)' label,
manual-setup example no longer recommends a dir pool, Zabbly note
reframed around the automatic raw.idmap recovery, #673 version/update
known-issue note added.
- Troubleshooting/Supported-Tools/Profiles: idempotent marker-delimited
sandbox-context injection documented incl. auto-healing of bloated
files; tool interface snippets synced (AlwaysSetupConfig, full effort
level list).
- nftables internals: NFT monitoring is disabled by default.
- Nav (Home/Sidebar/Footer): 0.10.1->0.11.0 migration links; FAQ count
fix; IPv6 host-side blocking wording.
Correct release version to 0.11.0 (breaking change → minor bump, not 0.10.2)
The model→[tool.claude] move is a breaking change, so the release is v0.11.0
under semver, not a 0.10.2 patch. Updates the Migration-Guide heading/body,
the [[network.hosts]] config comment, and the coi close alias note.
Align wiki with v0.10.2: model→[tool.claude], [[network.hosts]]/coi hosts, [defaults] profile, coi close, COI_TIMING_DEBUG
- Migration-Guide: new 0.10.1→0.10.2 section for the breaking `model` move to
[tool.claude] (wired via ANTHROPIC_MODEL).
- Configuration + Profiles: move `model` docs from the config root/[defaults] to
[tool.claude]; drop the now-invalid root/profile-root `model`.
- Network-Isolation: new "Static Host Entries ([[network.hosts]])" section with
the per-mode reachability table, trusted-scope-only caveat, and `coi hosts`
runtime commands; Configuration + Container-Operations reference/cross-link it.
- Profiles + Configuration: document [defaults] profile (no-flag default profile,
precedence, trusted-scope-only, unknown-name hard error).
- Container-Lifecycle: note `coi close` as an alias for `coi shutdown`.
- Troubleshooting + Configuration: document COI_TIMING_DEBUG / _JSON startup
profiling.
Document [ports] host port publishing (v0.10.1, #558)
New Port Publishing page: pool + map forms, deterministic allocation,
preflight, coi list display, env vars, trust gating, persistent-container
reuse semantics, troubleshooting. Wired into the sidebar, Home, the
Configuration section table + full config reference, and cross-referenced
from Network Isolation (proxy devices don't touch the nft rules).
Post-release audit: fix ~50 inaccuracies vs v0.10.0 behavior
Triple-check audit of every page against the released binary and code.
Systemic: firewalld -> nftables (stale since the v0.9 #405 migration) across
Network-Isolation, Linux-Setup-Guide, Architecture-and-Security-Model,
Getting-Started, Home, FAQ*, Best-Practices, Troubleshooting,
System-Health-Check — including the whole 'Firewalld Setup' section that
told users to create the wrong sudoers file (/etc/sudoers.d/coi-firewalld);
now documents nftables + /etc/sudoers.d/coi-nft (matching install.sh), the
real error string, use_sudo=false, and the real orphan classes and health
check names. Distro-default-firewall tips (Fedora/openSUSE) kept but
decoupled from COI's own mechanism.
Audit-Log: JSONL examples and field reference rewritten to the real
ThreatEvent shape (id/timestamp/level/category/title/description/evidence/
action — the old examples used fields that never existed); COI_AUDIT_*
tuning corrected (host env is not forwarded; use incus config set).
Security-Best-Practices: default protected-paths table matches the 0.10
set; protection-weakening keys documented as trusted-scope only (untrusted
project configs are sanitized); #533 linked-worktree support and #556 git
identity seeding documented.
Command usage: coi update core --check (not coi update --check), coi info
<session-id>, coi persist <container>, coi run's interactive build prompt,
stop-before-publish in the image workflow, --slot pinning.
Config accuracy: memory enforce default is soft; effort_level accepts
low/medium/high/xhigh/max/auto (default unset); [limits.disk] values are
I/O rates not storage caps (Best-Practices example fixed); protected_paths
default list completed; threat levels are INFO/WARNING/HIGH/CRITICAL.
Navigation: 0.9->0.10 migration section linked from Home, sidebar, and
footer; broken FAQ prompt-injection anchor retargeted.
0.10.0 release sweep: convert removed flags/env-vars to config-key docs, add 0.9->0.10 migration section
PUSH TO MASTER ONLY WHEN v0.10.0 IS TAGGED — this describes 0.10 behavior.
- Migration-Guide: full 'Upgrading from 0.9 to 0.10' section (removed-flags
table, deleted env-var layers, claude-on-incus retirement, resume
persistence conversion, profile-beats-project-config, new opt-in features
incl. [[credentials]], hardened profile, use_sudo, ready_timeout, coi run
script, list filters)
- Configuration: hierarchy table drops the env-var and config-flag layers;
env-var section becomes a removed->replacement table; CLI flags section
rewritten around operational-only flags with a removed-flags table;
[shell] use_tmux added to the reference
- Getting-Started, Best-Practices, Architecture, Container-Lifecycle,
Container-Operations, Tmux-Automation: --persistent examples converted to
[container] persistent = true config; shutdown --timeout ->
shutdown_timeout
- Image-Management: --image/--persistent/--compression workflows converted
to config/profile equivalents (image publish keeps --compression)
- Supported-Tools: --tool selection converted to [tool] name / per-tool
profiles; new 'Tool Credentials and Third-Party Providers' section
covering the credential catalog and [[credentials]]
- Profiles: profile create flag list matches 0.10 (--inherits/--user/
--project only); profile-vs-project-config precedence note
Align docs with recent changes: list status filters, ready_timeout, [[credentials]], disk-IO value fixes
- Configuration: [container] gains shutdown_timeout/ready_timeout in the
reference; new [[credentials]] block + sections-table row (the README
already points here for the credential trust model); [limits.disk]
comments drop the invalid '/s' suffix
- Resource-and-Time-Limits: '10MiB/s' examples were rejected by validation
since v0.9.0 (e6e4af1) — now '10MiB' with the no-/s rule and SI/IEC
casing spelled out; new caveat that a pathological read rate throttles
the BOOT and can fail readiness (with the ready_timeout escape hatch)
- Container-Operations & Container-Lifecycle: coi list --running/--stopped/
--status documented (full state vocabulary, mutual exclusion, --all
interaction)
- Tmux-Automation: fix broken jq path ('.[0].name' -> '.active_containers[0].name';
output has been an object since before v0.9.0)
- Profiles: [[credentials]] row + new [container] keys in the key table
docs(wiki): document [network] use_sudo (non-sudoers mode, #508)
- Configuration: add use_sudo to the network config reference
- Network-Isolation: new 'Running without sudo' section (open mode + use_sudo=false;
restricted/allowlist fail-closed; health warning behavior)
docs: 0.9 updates — upgrade guide (0.8→0.9), sockets, env_commands, pi
- Migration-Guide: add 'Upgrading from 0.8 to 0.9' (trust gate, network
sanitize, read-only .coi, protected git paths, allowlist/IPv6 tightening;
new features: sockets, env_commands, coi trust/audit, pi)
- Configuration: document [[sockets]] and [defaults.env_commands]; fix default
protected_paths list; add pi to tool name
- Supported-Tools: add pi section
- Home: link the 0.8→0.9 upgrade guide
docs: fix bugs and fill content gaps from re-analysis
Bug fixes:
- Linux-Setup-Guide: fix usermod command (incus,incus-admin not
'incus incus-admin $USER' which passed incus-admin as a username)
- Image-Management: clarify Best Practices item 4 — coi image publish
captures filesystem state, not process memory; stateful = snapshots only
Content improvements:
- Home.md: add one-sentence description of what COI is before the callout
- Tmux-Automation: replace non-deterministic sleep-based CI examples with
polling helpers; add Note callout explaining why fixed sleeps are unreliable
- FAQ.md: expand Troubleshooting Quick Links from 2 to 7 entries covering
container pause/kill, privileged=true error, Docker Compose, DNS build issues
- Resource-and-Time-Limits: add prose section explaining what each limit
actually does (CPU enforce/priority, memory hard vs soft, swap semantics,
disk I/O cgroup blkio, tmpfs, runtime auto-stop)
- File-Transfer: add UID shifting note explaining automatic ownership mapping
and when to chown after pushing to system paths
- Security-Monitoring: clarify [monitoring] vs [monitoring.nft] as two
independent subsystems with separate prerequisites
- Configuration: note that forward_env is top-level in profiles vs under
[defaults] in main config
- Migration-Guide: add 4 more entries from Troubleshooting content (bool
pointer fix, settings.json deep merge, Docker Compose three-step launch,
EXDEV session save fix, UID/GID remapping)
docs: quick-win formatting pass across all wiki pages
- Add H1 title to all 16 pages that were missing one
- Add FAQ question index with 22 anchor-linked entries grouped by category
- Add See Also section to all 19 pages with curated cross-links
- Upgrade three high-risk inline warnings to blockquote callouts:
allow_local_network_access, mount parent dir, disable_protection
docs: replace em dashes with hyphens across all wiki pages
Reduce documentation duplication and improve structure
- Deduplicate Sandbox Context: Configuration.md now links to Supported-Tools.md
instead of repeating the full auto-context section
- Move mount how-to from FAQ to Configuration.md "Mounting Additional Files" section;
FAQ entry replaced with short pointer
- Add "Getting Started" callout to Home.md for new users
- Trim Configuration.md Profiles section to a pointer (was duplicating Profiles.md)
Fix --debug flag description in Configuration wiki