Skip to content

History / Getting Started

Revisions

  • docs: update repo references mensfeld/coi -> coipond/coi (org transfer)

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: align wiki to the Karafka writing style Style-only pass across 39 pages: reduce decorative bold to scannable labels and callouts, Title Case headings, expand contractions, present tense, US English, cut filler and --- separators, tag code fences. Commands, code, config, COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: point URLs at mensfeld/coi + fix leftover code-on-incus branding Repo renamed mensfeld/code-on-incus -> mensfeld/coi: update all wiki links (install.sh raw URL, issues/releases/tree/wiki links) and one leftover "code-on-incus" prose ref -> Coi.

    @mensfeld mensfeld committed Sep 29, 2026
  • docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command) COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)". Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers (they document the actual on-disk marker text). Lowercase coi commands unchanged.

    @mensfeld mensfeld committed Sep 29, 2026
  • Align wiki with 0.11.1: OrbStack guide, filesystem-first UID mapping, dir-pool health warning, idempotent context injection, version-fix note - macOS Setup Guide: OrbStack is now a first-class documented option (setup steps, how COI handles the FUSE-backed macOS share via raw.idmap, the OrbStack >=2.2.2 silent-breakage background, storage notes); 'How It Works' rewritten around the v0.11.1 filesystem check with the reactive fallback; Manual Override reframed as rarely needed; Colima instructions now install Incus from Zabbly (Ubuntu's 6.0 is below the required 6.1). - Configuration/Architecture/File-Transfer/FAQ pages: UID-mapping mechanism descriptions updated (auto-selected shift vs raw.idmap), disable_shift comment rewritten, Colima-only framing widened to Colima/Lima/OrbStack. - System Health Check/Troubleshooting/Best Practices/Getting Started/ Linux Setup Guide: dir-pool driver warning documented (detection, cost, fix), example output shows the new 'pool (driver)' label, manual-setup example no longer recommends a dir pool, Zabbly note reframed around the automatic raw.idmap recovery, #673 version/update known-issue note added. - Troubleshooting/Supported-Tools/Profiles: idempotent marker-delimited sandbox-context injection documented incl. auto-healing of bloated files; tool interface snippets synced (AlwaysSetupConfig, full effort level list). - nftables internals: NFT monitoring is disabled by default. - Nav (Home/Sidebar/Footer): 0.10.1->0.11.0 migration links; FAQ count fix; IPv6 host-side blocking wording.

    @mensfeld mensfeld committed Aug 10, 2026
  • Post-release audit: fix ~50 inaccuracies vs v0.10.0 behavior Triple-check audit of every page against the released binary and code. Systemic: firewalld -> nftables (stale since the v0.9 #405 migration) across Network-Isolation, Linux-Setup-Guide, Architecture-and-Security-Model, Getting-Started, Home, FAQ*, Best-Practices, Troubleshooting, System-Health-Check — including the whole 'Firewalld Setup' section that told users to create the wrong sudoers file (/etc/sudoers.d/coi-firewalld); now documents nftables + /etc/sudoers.d/coi-nft (matching install.sh), the real error string, use_sudo=false, and the real orphan classes and health check names. Distro-default-firewall tips (Fedora/openSUSE) kept but decoupled from COI's own mechanism. Audit-Log: JSONL examples and field reference rewritten to the real ThreatEvent shape (id/timestamp/level/category/title/description/evidence/ action — the old examples used fields that never existed); COI_AUDIT_* tuning corrected (host env is not forwarded; use incus config set). Security-Best-Practices: default protected-paths table matches the 0.10 set; protection-weakening keys documented as trusted-scope only (untrusted project configs are sanitized); #533 linked-worktree support and #556 git identity seeding documented. Command usage: coi update core --check (not coi update --check), coi info <session-id>, coi persist <container>, coi run's interactive build prompt, stop-before-publish in the image workflow, --slot pinning. Config accuracy: memory enforce default is soft; effort_level accepts low/medium/high/xhigh/max/auto (default unset); [limits.disk] values are I/O rates not storage caps (Best-Practices example fixed); protected_paths default list completed; threat levels are INFO/WARNING/HIGH/CRITICAL. Navigation: 0.9->0.10 migration section linked from Home, sidebar, and footer; broken FAQ prompt-injection anchor retargeted.

    @mensfeld mensfeld committed Jul 10, 2026
  • 0.10.0 release sweep: convert removed flags/env-vars to config-key docs, add 0.9->0.10 migration section PUSH TO MASTER ONLY WHEN v0.10.0 IS TAGGED — this describes 0.10 behavior. - Migration-Guide: full 'Upgrading from 0.9 to 0.10' section (removed-flags table, deleted env-var layers, claude-on-incus retirement, resume persistence conversion, profile-beats-project-config, new opt-in features incl. [[credentials]], hardened profile, use_sudo, ready_timeout, coi run script, list filters) - Configuration: hierarchy table drops the env-var and config-flag layers; env-var section becomes a removed->replacement table; CLI flags section rewritten around operational-only flags with a removed-flags table; [shell] use_tmux added to the reference - Getting-Started, Best-Practices, Architecture, Container-Lifecycle, Container-Operations, Tmux-Automation: --persistent examples converted to [container] persistent = true config; shutdown --timeout -> shutdown_timeout - Image-Management: --image/--persistent/--compression workflows converted to config/profile equivalents (image publish keeps --compression) - Supported-Tools: --tool selection converted to [tool] name / per-tool profiles; new 'Tool Credentials and Third-Party Providers' section covering the credential catalog and [[credentials]] - Profiles: profile create flag list matches 0.10 (--inherits/--user/ --project only); profile-vs-project-config precedence note

    @mensfeld mensfeld committed Jul 10, 2026
  • docs: add Architecture, Getting-Started, and split FAQ into categories - Add Architecture-and-Security-Model.md — conceptual "why COI" page covering the threat model, all defense layers, architecture diagram, and what COI does/does not protect against - Add Getting-Started.md — step-by-step first-session walkthrough covering install, coi build, coi shell, resume, parallel sessions, and persistent mode, with links to next steps - Split FAQ.md into three category files: - FAQ-Platform-Comparisons.md (6 questions + comparison table) - FAQ-Security-and-Trust.md (5 questions) - FAQ-Setup-and-Operation.md (9 questions) - Rewrite FAQ.md as a pure index with category table + troubleshooting quick links - Update Home.md: new Getting-Started and Architecture nav section, point new-user callout to Getting-Started, list FAQ category pages

    @mensfeld mensfeld committed May 26, 2026