Skip to content

History / Profiles

Revisions

  • docs: update repo references mensfeld/coi -> coipond/coi (org transfer)

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: align wiki to the Karafka writing style Style-only pass across 39 pages: reduce decorative bold to scannable labels and callouts, Title Case headings, expand contractions, present tense, US English, cut filler and --- separators, tag code fences. Commands, code, config, COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: point URLs at mensfeld/coi + fix leftover code-on-incus branding Repo renamed mensfeld/code-on-incus -> mensfeld/coi: update all wiki links (install.sh raw URL, issues/releases/tree/wiki links) and one leftover "code-on-incus" prose ref -> Coi.

    @mensfeld mensfeld committed Sep 29, 2026
  • docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command) COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)". Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers (they document the actual on-disk marker text). Lowercase coi commands unchanged.

    @mensfeld mensfeld committed Sep 29, 2026
  • docs: reflect merged kernel-surface hardening PR (#787) final state - Threat model: fail-closed guarantee for profile-pinned keys, new Kernel mitigations health check, Incus recommended-floor now advisory (stays OK), hardened profile's 4h session cap. - Profiles: hardened preset table gains reduce_kernel_surface and limits.runtime.max_duration rows; wording updated (the preset now carries new enforcement, not only pre-existing controls). - System health check: SYSTEM sample output + What's Checked cover kernel build age, kernel mitigations, and distro support; Incus row notes the 6.7+ advisory.

    @mensfeld mensfeld committed Sep 10, 2026
  • Document 0.12 tool-switching, headless prompt runs, and config/profile mount + env_command_timeout symmetry - Container Lifecycle: new 'Running a different AI tool in the same container' section (shared session_name across two per-tool profiles; first-switch credential seeding) (#708) - Headless Orchestration: new 'Fire-and-forget prompt runs' section covering coi run --prompt / --prompt-file / --prompt-name and the [prompts] registry (trusted-scope only) with a cron example (#701) - Profiles/Configuration: correct the now-false 'profiles use [[mounts]], config uses [[mounts.default]]' note — both shapes work in both scopes; document env_command_timeout as profile-settable (#783) - Configuration: [prompts] stub + capability rows; note coi build works in any [incus] project (#777) - Troubleshooting: kitty/xterm-* 'unsuitable terminal' is handled automatically (#772) - Migration Guide + Supported Tools: surface tool-switching and headless prompts

    @mensfeld mensfeld committed Sep 8, 2026
  • Release-readiness pass for 0.11.1: session_name cross-references, --resume scoping correction, --container as-is note, named-session limitations

    @mensfeld mensfeld committed Aug 11, 2026
  • Align wiki with 0.11.1: OrbStack guide, filesystem-first UID mapping, dir-pool health warning, idempotent context injection, version-fix note - macOS Setup Guide: OrbStack is now a first-class documented option (setup steps, how COI handles the FUSE-backed macOS share via raw.idmap, the OrbStack >=2.2.2 silent-breakage background, storage notes); 'How It Works' rewritten around the v0.11.1 filesystem check with the reactive fallback; Manual Override reframed as rarely needed; Colima instructions now install Incus from Zabbly (Ubuntu's 6.0 is below the required 6.1). - Configuration/Architecture/File-Transfer/FAQ pages: UID-mapping mechanism descriptions updated (auto-selected shift vs raw.idmap), disable_shift comment rewritten, Colima-only framing widened to Colima/Lima/OrbStack. - System Health Check/Troubleshooting/Best Practices/Getting Started/ Linux Setup Guide: dir-pool driver warning documented (detection, cost, fix), example output shows the new 'pool (driver)' label, manual-setup example no longer recommends a dir pool, Zabbly note reframed around the automatic raw.idmap recovery, #673 version/update known-issue note added. - Troubleshooting/Supported-Tools/Profiles: idempotent marker-delimited sandbox-context injection documented incl. auto-healing of bloated files; tool interface snippets synced (AlwaysSetupConfig, full effort level list). - nftables internals: NFT monitoring is disabled by default. - Nav (Home/Sidebar/Footer): 0.10.1->0.11.0 migration links; FAQ count fix; IPv6 host-side blocking wording.

    @mensfeld mensfeld committed Aug 10, 2026
  • Align wiki with v0.10.2: model→[tool.claude], [[network.hosts]]/coi hosts, [defaults] profile, coi close, COI_TIMING_DEBUG - Migration-Guide: new 0.10.1→0.10.2 section for the breaking `model` move to [tool.claude] (wired via ANTHROPIC_MODEL). - Configuration + Profiles: move `model` docs from the config root/[defaults] to [tool.claude]; drop the now-invalid root/profile-root `model`. - Network-Isolation: new "Static Host Entries ([[network.hosts]])" section with the per-mode reachability table, trusted-scope-only caveat, and `coi hosts` runtime commands; Configuration + Container-Operations reference/cross-link it. - Profiles + Configuration: document [defaults] profile (no-flag default profile, precedence, trusted-scope-only, unknown-name hard error). - Container-Lifecycle: note `coi close` as an alias for `coi shutdown`. - Troubleshooting + Configuration: document COI_TIMING_DEBUG / _JSON startup profiling.

    @mensfeld mensfeld committed Jul 29, 2026
  • 0.10.0 release sweep: convert removed flags/env-vars to config-key docs, add 0.9->0.10 migration section PUSH TO MASTER ONLY WHEN v0.10.0 IS TAGGED — this describes 0.10 behavior. - Migration-Guide: full 'Upgrading from 0.9 to 0.10' section (removed-flags table, deleted env-var layers, claude-on-incus retirement, resume persistence conversion, profile-beats-project-config, new opt-in features incl. [[credentials]], hardened profile, use_sudo, ready_timeout, coi run script, list filters) - Configuration: hierarchy table drops the env-var and config-flag layers; env-var section becomes a removed->replacement table; CLI flags section rewritten around operational-only flags with a removed-flags table; [shell] use_tmux added to the reference - Getting-Started, Best-Practices, Architecture, Container-Lifecycle, Container-Operations, Tmux-Automation: --persistent examples converted to [container] persistent = true config; shutdown --timeout -> shutdown_timeout - Image-Management: --image/--persistent/--compression workflows converted to config/profile equivalents (image publish keeps --compression) - Supported-Tools: --tool selection converted to [tool] name / per-tool profiles; new 'Tool Credentials and Third-Party Providers' section covering the credential catalog and [[credentials]] - Profiles: profile create flag list matches 0.10 (--inherits/--user/ --project only); profile-vs-project-config precedence note

    @mensfeld mensfeld committed Jul 10, 2026
  • Align docs with recent changes: list status filters, ready_timeout, [[credentials]], disk-IO value fixes - Configuration: [container] gains shutdown_timeout/ready_timeout in the reference; new [[credentials]] block + sections-table row (the README already points here for the credential trust model); [limits.disk] comments drop the invalid '/s' suffix - Resource-and-Time-Limits: '10MiB/s' examples were rejected by validation since v0.9.0 (e6e4af1) — now '10MiB' with the no-/s rule and SI/IEC casing spelled out; new caveat that a pathological read rate throttles the BOOT and can fail readiness (with the ready_timeout escape hatch) - Container-Operations & Container-Lifecycle: coi list --running/--stopped/ --status documented (full state vocabulary, mutual exclusion, --all interaction) - Tmux-Automation: fix broken jq path ('.[0].name' -> '.active_containers[0].name'; output has been an object since before v0.9.0) - Profiles: [[credentials]] row + new [container] keys in the key table

    @mensfeld mensfeld committed Jul 10, 2026
  • docs(wiki): broaden hardened profile secret_paths list (#496)

    Maciej Mensfeld committed Jun 30, 2026
  • docs(wiki): rename built-in review profile -> hardened (#496)

    Maciej Mensfeld committed Jun 29, 2026
  • docs(wiki): document built-in review profile (safe-open for untrusted repos, #496)

    Maciej Mensfeld committed Jun 29, 2026
  • docs(wiki): add Profile JSON Schema section (moved from README)

    Maciej Mensfeld committed Jun 17, 2026
  • docs: complete structural, content, and style improvements (S4-S6, C1-C5, F5) Structural: - S4: Add Slot System section to Container-Lifecycle-and-Sessions explaining container naming, auto-allocation, per-slot isolation, and alias suffixes - S5: Merge Self-Update into System-Health-Check (update commands, how-it-works, post-update steps); Self-Update.md becomes a redirect - S6: Add Migration-Guide.md covering .coi.toml → .coi/config.toml move and [[mounts]] vs [[mounts.default]] syntax difference Content: - C1: Add Best-Practices.md covering session mode selection, network mode guide, monitoring recommendations, long-running tasks, team workflows, AI-generated code handling, and storage cleanup - C2: Expand Snapshot-Management.md with context opener (stateless vs stateful tradeoffs, restore requirement) and Best Practices section - C3: Add Troubleshooting section to Image-Management.md (image not found, build failures, wrong image applied, stale image after update) and Best Practices section - C4: Document coi run in Container-Operations.md with use cases, flags, and differences from coi shell - C5: Add JSONL field schema tables to Security-Monitoring.md (common fields, type-specific fields, NFT-specific fields) Formatting: - F5: Add Best Practices sections to Network-Isolation, Profiles, Image-Management, and Snapshot-Management Navigation: - Home.md updated with Best-Practices and Migration-Guide in nav

    @mensfeld mensfeld committed May 26, 2026
  • docs: quick-win formatting pass across all wiki pages - Add H1 title to all 16 pages that were missing one - Add FAQ question index with 22 anchor-linked entries grouped by category - Add See Also section to all 19 pages with curated cross-links - Upgrade three high-risk inline warnings to blockquote callouts: allow_local_network_access, mount parent dir, disable_protection

    @mensfeld mensfeld committed May 26, 2026
  • docs: replace em dashes with hyphens across all wiki pages

    @mensfeld mensfeld committed May 26, 2026
  • Document v0.8.1 features and fix minor v0.8.0 gaps v0.8.1 features now documented: - Profile auto-resume: --resume restores original profile (Container-Lifecycle) - `close` command as safe alias for poweroff inside containers (Container-Lifecycle) - Git identity guard: user.useConfigOnly=true prevents "code" commits (Security-Best-Practices) - Auto-trust mise config files via MISE_TRUSTED_CONFIG_PATHS (Image-Management) - Secure env-var forwarding via tmux -e, not shell export (Container-Lifecycle) v0.8.0 minor fixes: - Container-Operations: fix bare `coi` image name → `coi-default` in launch example - Profiles: show built-in `default` profile row in `coi profile list` example output - Security-Best-Practices: renumber summary list after git identity guard insertion

    @mensfeld mensfeld committed May 7, 2026
  • Fix remaining documentation inconsistencies for 0.8.0 - Image-Management: migrate profile example from deprecated [build] to [container.build] - Configuration: remove "aider" from tool name comment (not yet registered), move --tool from global flags to shell-only section - Security-Monitoring: clarify write threshold mirrors read threshold (no separate config key) - Profiles: add missing extended fields to Available Fields table (model, paths, incus, git, ssh, security, monitoring, timezone, inherits)

    @mensfeld mensfeld committed Apr 14, 2026
  • Fix documentation inconsistencies for 0.8.0 release - Profiles: migrate all examples from deprecated top-level image/persistent/[build] to [container]/[container.build] nesting (0.8.0 rejects the old format) - Resource-and-Time-Limits: replace obsolete [profiles.X] flat syntax with directory-based profile config.toml examples - Security-Monitoring: fix phantom config keys (rate_limit → rate_limit_per_second, remove non-existent suspicious_unlimited, file_write_threshold_mb, file_write_rate_mb_per_sec) - FAQ: move Aider from "currently supported" to "coming soon" (not yet registered) - Troubleshooting: fix tmpfs_size default comment (empty string, not 4GiB), remove phantom file_write_threshold_mb reference - File-Transfer: fix /root/.claude paths to /home/code/.claude - Container-Operations: document coi info, coi version, coi clean --pools/--orphans/--dry-run - Profiles: add note explaining [[mounts]] (profiles) vs [[mounts.default]] (main config)

    @mensfeld mensfeld committed Apr 14, 2026
  • Update wiki for 0.8.0 release - Rename default image coi → coi-default - Move config path ~/.config/coi/config.toml → ~/.coi/config.toml - Drop /etc/coi/ and ~/.config/coi/ from config hierarchy - Replace coi build custom with profile-based build workflow - Rename coi profile show → coi profile info - Document profile inheritance (inherits field) - Document coi profile create/edit/delete commands - Remove non-existent coi config --init reference

    @mensfeld mensfeld committed Apr 9, 2026
  • Update wiki for CLI flag removal and readonly mount support Remove references to 21 CLI flags that are now config/profile-only. Replace --network, --monitor, --ssh-agent, --forward-env, --timezone, --mount, --env, --limit-*, --writable-git-hooks examples with config TOML equivalents. Add readonly = true mount documentation and Claude skills/commands/plugins mounting guide (ref #260). Still-valid flags (--format, --capture, --tty, --env on container exec, --timeout, --compression on build) are unchanged.

    @mensfeld mensfeld committed Apr 3, 2026
  • Add Profiles wiki page, update Configuration and Home - New Profiles.md page covering directory structure, config reference, context files, build scripts, commands, and examples - Update Configuration.md: replace outdated inline profiles section with link to new page, update config reference - Update Home.md: add Profiles link to navigation

    @mensfeld mensfeld committed Apr 2, 2026