Skip to content

History / Security Best Practices

Revisions

  • docs: align wiki to the Karafka writing style Style-only pass across 39 pages: reduce decorative bold to scannable labels and callouts, Title Case headings, expand contractions, present tense, US English, cut filler and --- separators, tag code fences. Commands, code, config, COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command) COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)". Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers (they document the actual on-disk marker text). Lowercase coi commands unchanged.

    @mensfeld mensfeld committed Sep 29, 2026
  • docs(security): document unoverridable git identity lock + strict kernel-surface tier - Security-Best-Practices: [git] readonly now enforces via three layers (read-only mount + pinned GIT_* env + root-owned post-commit re-stamp); document the -c/--author/env override paths it closes and the residual gaps (repo-local core.hooksPath/husky, GIT_CONFIG_GLOBAL). - Threat-Model: add the reduce_kernel_surface_strict tier (perf_event_open). - Configuration: expand the readonly reference and add reduce_kernel_surface + reduce_kernel_surface_strict to [security].

    @mensfeld mensfeld committed Sep 19, 2026
  • docs: [git] strip_attribution — clean commit authorship (#788, PR #789) - Configuration: the two new [git] keys in the sample block. - Security best practices: new "Clean commit authorship" subsection under Git Identity Guard — the global commit-msg hook (strip-don't-reject, delegates to repo hooks), the Claude managed-settings layer, default pattern coverage, trust scoping, and the documented limitations (repo-local core.hooksPath / husky, git commit --no-verify).

    @mensfeld mensfeld committed Sep 10, 2026
  • Document 0.12.0: egress hardening, per-host ports, Codex CLI, [git] readonly

    @mensfeld mensfeld committed Aug 19, 2026
  • Post-release audit: fix ~50 inaccuracies vs v0.10.0 behavior Triple-check audit of every page against the released binary and code. Systemic: firewalld -> nftables (stale since the v0.9 #405 migration) across Network-Isolation, Linux-Setup-Guide, Architecture-and-Security-Model, Getting-Started, Home, FAQ*, Best-Practices, Troubleshooting, System-Health-Check — including the whole 'Firewalld Setup' section that told users to create the wrong sudoers file (/etc/sudoers.d/coi-firewalld); now documents nftables + /etc/sudoers.d/coi-nft (matching install.sh), the real error string, use_sudo=false, and the real orphan classes and health check names. Distro-default-firewall tips (Fedora/openSUSE) kept but decoupled from COI's own mechanism. Audit-Log: JSONL examples and field reference rewritten to the real ThreatEvent shape (id/timestamp/level/category/title/description/evidence/ action — the old examples used fields that never existed); COI_AUDIT_* tuning corrected (host env is not forwarded; use incus config set). Security-Best-Practices: default protected-paths table matches the 0.10 set; protection-weakening keys documented as trusted-scope only (untrusted project configs are sanitized); #533 linked-worktree support and #556 git identity seeding documented. Command usage: coi update core --check (not coi update --check), coi info <session-id>, coi persist <container>, coi run's interactive build prompt, stop-before-publish in the image workflow, --slot pinning. Config accuracy: memory enforce default is soft; effort_level accepts low/medium/high/xhigh/max/auto (default unset); [limits.disk] values are I/O rates not storage caps (Best-Practices example fixed); protected_paths default list completed; threat levels are INFO/WARNING/HIGH/CRITICAL. Navigation: 0.9->0.10 migration section linked from Home, sidebar, and footer; broken FAQ prompt-injection anchor retargeted.

    @mensfeld mensfeld committed Jul 10, 2026
  • docs: quick-win formatting pass across all wiki pages - Add H1 title to all 16 pages that were missing one - Add FAQ question index with 22 anchor-linked entries grouped by category - Add See Also section to all 19 pages with curated cross-links - Upgrade three high-risk inline warnings to blockquote callouts: allow_local_network_access, mount parent dir, disable_protection

    @mensfeld mensfeld committed May 26, 2026
  • docs: replace em dashes with hyphens across all wiki pages

    @mensfeld mensfeld committed May 26, 2026
  • Document v0.8.1 features and fix minor v0.8.0 gaps v0.8.1 features now documented: - Profile auto-resume: --resume restores original profile (Container-Lifecycle) - `close` command as safe alias for poweroff inside containers (Container-Lifecycle) - Git identity guard: user.useConfigOnly=true prevents "code" commits (Security-Best-Practices) - Auto-trust mise config files via MISE_TRUSTED_CONFIG_PATHS (Image-Management) - Secure env-var forwarding via tmux -e, not shell export (Container-Lifecycle) v0.8.0 minor fixes: - Container-Operations: fix bare `coi` image name → `coi-default` in launch example - Profiles: show built-in `default` profile row in `coi profile list` example output - Security-Best-Practices: renumber summary list after git identity guard insertion

    @mensfeld mensfeld committed May 7, 2026
  • Docs audit for 0.8.0: fix [defaults] → [container], coi resume → coi unfreeze, add security features - Fix [defaults] → [container] for image/persistent in Configuration.md, Image-Management.md - Replace all coi resume → coi unfreeze references (Security-Monitoring, Troubleshooting, Lifecycle) - Add host-side immutable protection and guest API sections to Security-Best-Practices.md - Add container aliases section to Container-Lifecycle-and-Sessions.md - Update System-Health-Check.md for multi-pool support - Add host_immutable, alias, storage_pool to config reference

    @mensfeld mensfeld committed Apr 14, 2026
  • Update wiki for 0.8.0 release - Rename default image coi → coi-default - Move config path ~/.config/coi/config.toml → ~/.coi/config.toml - Drop /etc/coi/ and ~/.config/coi/ from config hierarchy - Replace coi build custom with profile-based build workflow - Rename coi profile show → coi profile info - Document profile inheritance (inherits field) - Document coi profile create/edit/delete commands - Remove non-existent coi config --init reference

    @mensfeld mensfeld committed Apr 9, 2026
  • Update wiki for CLI flag removal and readonly mount support Remove references to 21 CLI flags that are now config/profile-only. Replace --network, --monitor, --ssh-agent, --forward-env, --timezone, --mount, --env, --limit-*, --writable-git-hooks examples with config TOML equivalents. Add readonly = true mount documentation and Claude skills/commands/plugins mounting guide (ref #260). Still-valid flags (--format, --capture, --tty, --env on container exec, --timeout, --compression on build) are unchanged.

    @mensfeld mensfeld committed Apr 3, 2026
  • 0.8.0 release updates

    @mensfeld mensfeld committed Apr 2, 2026
  • Update wiki for 0.8.0 unreleased changes System-Health-Check.md: - Rewrite example output with all 27 current checks - Expand "What's Checked" table with all categories and checks - Add Security Posture Details section (status logic table) - Add Version Checks section (Incus >= 6.1, nftables >= 0.9.0, kernel >= 5.15) - Add JSON output example with security_posture details - Update notes for Colima/Lima and privileged profile detection Security-Best-Practices.md: - Add privileged container guard, security posture verification, and kernel version enforcement to defense-in-depth summary (8 → 11 layers) Troubleshooting.md: - Add "COI refuses to start: security.privileged=true" entry with fix - Add "Kernel version warning on startup" entry FAQ.md: - Fix [container] → [paths] for preserve_workspace_path config

    @mensfeld mensfeld committed Mar 29, 2026
  • docs: add Configuration page and document 0.8.0 features across wiki - Create Configuration.md with full config reference (was linked but missing) - Add SSH agent forwarding and env var forwarding to Container-Lifecycle-and-Sessions - Update Network-Isolation with TTL-aware DNS refresh behavior - Add sandbox context file docs to Supported-Tools - Add SSH/env forwarding security considerations to Security-Best-Practices - Fix stale mount_claude_config reference in FAQ - Update env var isolation statement in FAQ for forward_env - Add Configuration link to Home page

    @mensfeld mensfeld committed Mar 15, 2026
  • docs: add permission_mode documentation (#165)

    @mensfeld mensfeld committed Mar 2, 2026
  • docs: add Security Monitoring and Supported Tools pages, update health checks - Add Security-Monitoring.md: real-time threat detection, nftables monitoring, automated response, audit logging - Add Supported-Tools.md: Claude Code vs opencode comparison, tool selection, API key configuration, adding new tools - Update System-Health-Check.md: add Incus storage pool, monitoring checks, container networking checks - Update Security-Best-Practices.md: reference new Security Monitoring page - Update Home.md: add links to new pages

    @mensfeld mensfeld committed Feb 19, 2026
  • Update Security Best Practices with automatic path protection feature - Document automatic read-only mounting of security-sensitive paths - Add table of default protected paths (.git/hooks, .git/config, .husky, .vscode) - Document configuration options (additional_protected_paths, protected_paths, disable_protection) - Explain attack vectors COI protects against - Add symlink security section - Reorganize Home.md with dedicated Security section

    @mensfeld mensfeld committed Feb 11, 2026
  • Add Troubleshooting, Security Best Practices, and Resource Limits pages

    @mensfeld mensfeld committed Feb 9, 2026