docs: align wiki to the Karafka writing style
Style-only pass across 39 pages: reduce decorative bold to scannable labels and
callouts, Title Case headings, expand contractions, present tense, US English,
cut filler and --- separators, tag code fences. Commands, code, config,
COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.
docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command)
COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)".
Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers
(they document the actual on-disk marker text). Lowercase coi commands unchanged.
docs: split Network Isolation into focused pages
Network-Isolation.md had grown to ~20 KB / 365 lines covering four distinct
topics. Extract the two self-contained ones into their own pages, leaving the
core page focused on egress modes + hardening (now ~13.7 KB / 244 lines):
- New **Static Host Entries** — `[[network.hosts]]` config, per-host `ports`,
the per-mode reachability table, trusted-scope rules, and runtime `coi hosts`.
- New **nftables Setup** — the open-mode workaround, install + sudoers steps,
how the FORWARD-chain rules work, and orphaned-rule cleanup.
Network-Isolation keeps short pointer stubs to both; the "(see below)" per-host
ports reference now links the new page. Host Access to Container Services stays
on the core page (it's `allow_local_network_access` firewall content, not
port-publishing). Re-pointed the Container-Operations and Configuration
cross-references to Static Host Entries, and added both pages to Home + _Sidebar
(nested under Network Isolation). All internal links verified.
Document 0.12.0: egress hardening, per-host ports, Codex CLI, [git] readonly
Align wiki with 0.11.1: OrbStack guide, filesystem-first UID mapping, dir-pool health warning, idempotent context injection, version-fix note
- macOS Setup Guide: OrbStack is now a first-class documented option
(setup steps, how COI handles the FUSE-backed macOS share via
raw.idmap, the OrbStack >=2.2.2 silent-breakage background, storage
notes); 'How It Works' rewritten around the v0.11.1 filesystem check
with the reactive fallback; Manual Override reframed as rarely
needed; Colima instructions now install Incus from Zabbly (Ubuntu's
6.0 is below the required 6.1).
- Configuration/Architecture/File-Transfer/FAQ pages: UID-mapping
mechanism descriptions updated (auto-selected shift vs raw.idmap),
disable_shift comment rewritten, Colima-only framing widened to
Colima/Lima/OrbStack.
- System Health Check/Troubleshooting/Best Practices/Getting Started/
Linux Setup Guide: dir-pool driver warning documented (detection,
cost, fix), example output shows the new 'pool (driver)' label,
manual-setup example no longer recommends a dir pool, Zabbly note
reframed around the automatic raw.idmap recovery, #673 version/update
known-issue note added.
- Troubleshooting/Supported-Tools/Profiles: idempotent marker-delimited
sandbox-context injection documented incl. auto-healing of bloated
files; tool interface snippets synced (AlwaysSetupConfig, full effort
level list).
- nftables internals: NFT monitoring is disabled by default.
- Nav (Home/Sidebar/Footer): 0.10.1->0.11.0 migration links; FAQ count
fix; IPv6 host-side blocking wording.
Align wiki with v0.10.2: model→[tool.claude], [[network.hosts]]/coi hosts, [defaults] profile, coi close, COI_TIMING_DEBUG
- Migration-Guide: new 0.10.1→0.10.2 section for the breaking `model` move to
[tool.claude] (wired via ANTHROPIC_MODEL).
- Configuration + Profiles: move `model` docs from the config root/[defaults] to
[tool.claude]; drop the now-invalid root/profile-root `model`.
- Network-Isolation: new "Static Host Entries ([[network.hosts]])" section with
the per-mode reachability table, trusted-scope-only caveat, and `coi hosts`
runtime commands; Configuration + Container-Operations reference/cross-link it.
- Profiles + Configuration: document [defaults] profile (no-flag default profile,
precedence, trusted-scope-only, unknown-name hard error).
- Container-Lifecycle: note `coi close` as an alias for `coi shutdown`.
- Troubleshooting + Configuration: document COI_TIMING_DEBUG / _JSON startup
profiling.
Document [ports] host port publishing (v0.10.1, #558)
New Port Publishing page: pool + map forms, deterministic allocation,
preflight, coi list display, env vars, trust gating, persistent-container
reuse semantics, troubleshooting. Wired into the sidebar, Home, the
Configuration section table + full config reference, and cross-referenced
from Network Isolation (proxy devices don't touch the nft rules).
Post-release audit: fix ~50 inaccuracies vs v0.10.0 behavior
Triple-check audit of every page against the released binary and code.
Systemic: firewalld -> nftables (stale since the v0.9 #405 migration) across
Network-Isolation, Linux-Setup-Guide, Architecture-and-Security-Model,
Getting-Started, Home, FAQ*, Best-Practices, Troubleshooting,
System-Health-Check — including the whole 'Firewalld Setup' section that
told users to create the wrong sudoers file (/etc/sudoers.d/coi-firewalld);
now documents nftables + /etc/sudoers.d/coi-nft (matching install.sh), the
real error string, use_sudo=false, and the real orphan classes and health
check names. Distro-default-firewall tips (Fedora/openSUSE) kept but
decoupled from COI's own mechanism.
Audit-Log: JSONL examples and field reference rewritten to the real
ThreatEvent shape (id/timestamp/level/category/title/description/evidence/
action — the old examples used fields that never existed); COI_AUDIT_*
tuning corrected (host env is not forwarded; use incus config set).
Security-Best-Practices: default protected-paths table matches the 0.10
set; protection-weakening keys documented as trusted-scope only (untrusted
project configs are sanitized); #533 linked-worktree support and #556 git
identity seeding documented.
Command usage: coi update core --check (not coi update --check), coi info
<session-id>, coi persist <container>, coi run's interactive build prompt,
stop-before-publish in the image workflow, --slot pinning.
Config accuracy: memory enforce default is soft; effort_level accepts
low/medium/high/xhigh/max/auto (default unset); [limits.disk] values are
I/O rates not storage caps (Best-Practices example fixed); protected_paths
default list completed; threat levels are INFO/WARNING/HIGH/CRITICAL.
Navigation: 0.9->0.10 migration section linked from Home, sidebar, and
footer; broken FAQ prompt-injection anchor retargeted.
docs(wiki): document [network] use_sudo (non-sudoers mode, #508)
- Configuration: add use_sudo to the network config reference
- Network-Isolation: new 'Running without sudo' section (open mode + use_sudo=false;
restricted/allowlist fail-closed; health warning behavior)
docs: complete structural, content, and style improvements (S4-S6, C1-C5, F5)
Structural:
- S4: Add Slot System section to Container-Lifecycle-and-Sessions explaining
container naming, auto-allocation, per-slot isolation, and alias suffixes
- S5: Merge Self-Update into System-Health-Check (update commands, how-it-works,
post-update steps); Self-Update.md becomes a redirect
- S6: Add Migration-Guide.md covering .coi.toml → .coi/config.toml move and
[[mounts]] vs [[mounts.default]] syntax difference
Content:
- C1: Add Best-Practices.md covering session mode selection, network mode
guide, monitoring recommendations, long-running tasks, team workflows,
AI-generated code handling, and storage cleanup
- C2: Expand Snapshot-Management.md with context opener (stateless vs stateful
tradeoffs, restore requirement) and Best Practices section
- C3: Add Troubleshooting section to Image-Management.md (image not found,
build failures, wrong image applied, stale image after update) and
Best Practices section
- C4: Document coi run in Container-Operations.md with use cases, flags,
and differences from coi shell
- C5: Add JSONL field schema tables to Security-Monitoring.md (common fields,
type-specific fields, NFT-specific fields)
Formatting:
- F5: Add Best Practices sections to Network-Isolation, Profiles,
Image-Management, and Snapshot-Management
Navigation:
- Home.md updated with Best-Practices and Migration-Guide in nav
docs: quick-win formatting pass across all wiki pages
- Add H1 title to all 16 pages that were missing one
- Add FAQ question index with 22 anchor-linked entries grouped by category
- Add See Also section to all 19 pages with curated cross-links
- Upgrade three high-risk inline warnings to blockquote callouts:
allow_local_network_access, mount parent dir, disable_protection
docs: replace em dashes with hyphens across all wiki pages
Update wiki for 0.8.0 release
- Rename default image coi → coi-default
- Move config path ~/.config/coi/config.toml → ~/.coi/config.toml
- Drop /etc/coi/ and ~/.config/coi/ from config hierarchy
- Replace coi build custom with profile-based build workflow
- Rename coi profile show → coi profile info
- Document profile inheritance (inherits field)
- Document coi profile create/edit/delete commands
- Remove non-existent coi config --init reference
Update wiki for CLI flag removal and readonly mount support
Remove references to 21 CLI flags that are now config/profile-only.
Replace --network, --monitor, --ssh-agent, --forward-env, --timezone,
--mount, --env, --limit-*, --writable-git-hooks examples with config
TOML equivalents. Add readonly = true mount documentation and Claude
skills/commands/plugins mounting guide (ref #260).
Still-valid flags (--format, --capture, --tty, --env on container exec,
--timeout, --compression on build) are unchanged.
docs: add Configuration page and document 0.8.0 features across wiki
- Create Configuration.md with full config reference (was linked but missing)
- Add SSH agent forwarding and env var forwarding to Container-Lifecycle-and-Sessions
- Update Network-Isolation with TTL-aware DNS refresh behavior
- Add sandbox context file docs to Supported-Tools
- Add SSH/env forwarding security considerations to Security-Best-Practices
- Fix stale mount_claude_config reference in FAQ
- Update env var isolation statement in FAQ for forward_env
- Add Configuration link to Home page
docs: update wiki with recent fixes and improvements
Security Monitoring:
- Add large file write detection, gateway IP RFC1918 exclusion
- Document dropped event tracking and orphan NFT rule cleanup
- Add alert deduplication and NFT error routing details
Troubleshooting (6 new entries):
- Docker Compose fails in session containers
- Permission denied / UID/GID mismatch
- Security settings silently disabled (config merge bug)
- Firewall rules accumulating
- Settings.json overwritten
- Cross-device link session save errors
Supported Tools:
- Add Claude effort level configuration
- Fix opencode config path to XDG-compliant location
- Update Go interfaces (ToolWithConfigDirFiles, ToolWithEffortLevel)
Network Isolation:
- Clarify gateway IP auto-exclusion from RFC1918 checks
- Document cleanup on all termination paths including nftables
- Remove duplicated container access section
Container Lifecycle:
- Add coi persist and coi resume commands
- Document Docker/Compose support in sessions
- Note sync.Once cleanup protection
Container Operations:
- Document three-step launch sequence for Docker support
- Add UID/GID remapping and extra mount documentation
FAQ: Add Docker Compose and preserve_workspace_path entries
Resource Limits: Add tmpfs_size to disk limits config
docs: document automatic firewall cleanup for orphaned veth zone bindings
Add documentation about the automatic cleanup of orphaned firewalld zone
bindings that was added in PR #130. This includes:
- Automatic cleanup when containers are deleted
- Detection and removal of orphaned veth zone bindings
- Manual cleanup commands
This prevents firewalld from accumulating stale interface bindings over time.
Add Network Isolation guide