docs: update repo references mensfeld/coi -> coipond/coi (org transfer)
docs: align wiki to the Karafka writing style
Style-only pass across 39 pages: reduce decorative bold to scannable labels and
callouts, Title Case headings, expand contractions, present tense, US English,
cut filler and --- separators, tag code fences. Commands, code, config,
COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.
docs: point URLs at mensfeld/coi + fix leftover code-on-incus branding
Repo renamed mensfeld/code-on-incus -> mensfeld/coi: update all wiki links
(install.sh raw URL, issues/releases/tree/wiki links) and one leftover
"code-on-incus" prose ref -> Coi.
docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command)
COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)".
Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers
(they document the actual on-disk marker text). Lowercase coi commands unchanged.
Post-release audit: fix ~50 inaccuracies vs v0.10.0 behavior
Triple-check audit of every page against the released binary and code.
Systemic: firewalld -> nftables (stale since the v0.9 #405 migration) across
Network-Isolation, Linux-Setup-Guide, Architecture-and-Security-Model,
Getting-Started, Home, FAQ*, Best-Practices, Troubleshooting,
System-Health-Check — including the whole 'Firewalld Setup' section that
told users to create the wrong sudoers file (/etc/sudoers.d/coi-firewalld);
now documents nftables + /etc/sudoers.d/coi-nft (matching install.sh), the
real error string, use_sudo=false, and the real orphan classes and health
check names. Distro-default-firewall tips (Fedora/openSUSE) kept but
decoupled from COI's own mechanism.
Audit-Log: JSONL examples and field reference rewritten to the real
ThreatEvent shape (id/timestamp/level/category/title/description/evidence/
action — the old examples used fields that never existed); COI_AUDIT_*
tuning corrected (host env is not forwarded; use incus config set).
Security-Best-Practices: default protected-paths table matches the 0.10
set; protection-weakening keys documented as trusted-scope only (untrusted
project configs are sanitized); #533 linked-worktree support and #556 git
identity seeding documented.
Command usage: coi update core --check (not coi update --check), coi info
<session-id>, coi persist <container>, coi run's interactive build prompt,
stop-before-publish in the image workflow, --slot pinning.
Config accuracy: memory enforce default is soft; effort_level accepts
low/medium/high/xhigh/max/auto (default unset); [limits.disk] values are
I/O rates not storage caps (Best-Practices example fixed); protected_paths
default list completed; threat levels are INFO/WARNING/HIGH/CRITICAL.
Navigation: 0.9->0.10 migration section linked from Home, sidebar, and
footer; broken FAQ prompt-injection anchor retargeted.
docs: add Architecture, Getting-Started, and split FAQ into categories
- Add Architecture-and-Security-Model.md — conceptual "why COI" page
covering the threat model, all defense layers, architecture diagram,
and what COI does/does not protect against
- Add Getting-Started.md — step-by-step first-session walkthrough
covering install, coi build, coi shell, resume, parallel sessions,
and persistent mode, with links to next steps
- Split FAQ.md into three category files:
- FAQ-Platform-Comparisons.md (6 questions + comparison table)
- FAQ-Security-and-Trust.md (5 questions)
- FAQ-Setup-and-Operation.md (9 questions)
- Rewrite FAQ.md as a pure index with category table + troubleshooting
quick links
- Update Home.md: new Getting-Started and Architecture nav section,
point new-user callout to Getting-Started, list FAQ category pages