docs: document reverse_shell_one_liners knob and one-liner detection change (#842/#846)
- Security-Monitoring: split reverse-shell threats into unambiguous vs
interpreter one-liner classes; add 'Interpreter one-liner policy' section
documenting reverse_shell_one_liners (critical|warn|off) and the network-
indicator gate; add the key to the full config block.
- Troubleshooting: note that benign interpreter one-liners no longer kill the
container, and how to downgrade the class instead of disabling auto-kill.
- Configuration: add reverse_shell_one_liners to the [monitoring] reference.
docs: align wiki to the Karafka writing style
Style-only pass across 39 pages: reduce decorative bold to scannable labels and
callouts, Title Case headings, expand contractions, present tense, US English,
cut filler and --- separators, tag code fences. Commands, code, config,
COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.
docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command)
COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)".
Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers
(they document the actual on-disk marker text). Lowercase coi commands unchanged.
docs: [monitoring] forensics_on_kill — preserve a killed container for forensics (#792)
New 'Preserving a killed container for forensics' subsection under Automated
Response: what forensics_on_kill does (copy-before-kill to a stopped
*-forensics-* container), how to inspect/dispose of the copy, the 3-copy cap
and COW-reflink note, and why it is opt-in (default off). Config key added to
the [monitoring] block.
Add nftables Monitoring Internals page (ported from repo docs/NFT-MONITORING.md)
Moves the nftables monitoring technical deep-dive out of the code repo and into
the wiki as a dedicated internals page, cross-linked from Security-Monitoring
and the sidebar. Fixed a stale detail from the original: LOG rules are inserted
at the top of the ip filter FORWARD chain (priority 0 + nft insert), not placed
via a per-rule priority -5/-10 (nftables has no per-rule priority).
docs(wiki): extract audit log + coi audit into dedicated Audit-Log page
Security-Monitoring was the largest page (~500 lines). Move the on-disk audit
log format, field reference, and the full 'coi audit' command docs into a new
Audit-Log page (Security-Monitoring now links to it with a short stub). Retarget
inbound links (Session-Logs, Migration-Guide, Home, sidebar). Security-Monitoring
328 lines; all internal links verified.
fix: update session log docs to reflect SessionLogger migration
- Session-Logs.md: remove stale "Related Background Logs" table that
still referenced network-refresh-<container>.log (no longer created);
replace with a "What Goes Into Session Logs" table showing which
subsystem output lands in which file (.stdout.log vs .stderr.log)
- Security-Monitoring.md: fix the Limitations note about NFT OnError
callbacks — errors now go to <container>.stderr.log (viewable via
`coi logs`), not silently discarded or sent to audit logs
docs: add coi audit and coi logs documentation
- Security-Monitoring.md: add full 'coi audit' section covering both
dump and follow modes, event format/types, all five event sources,
heartbeat liveness detection, jq filtering examples, agent tuning
env vars, and resource overhead
- Session-Logs.md: new page documenting 'coi logs', log file locations,
follow mode, output format, and the network-refresh background log
- Home.md: link to Session-Logs from the Security nav section; update
Security-Monitoring description to mention coi audit
Closes #390
docs: fix bugs and fill content gaps from re-analysis
Bug fixes:
- Linux-Setup-Guide: fix usermod command (incus,incus-admin not
'incus incus-admin $USER' which passed incus-admin as a username)
- Image-Management: clarify Best Practices item 4 — coi image publish
captures filesystem state, not process memory; stateful = snapshots only
Content improvements:
- Home.md: add one-sentence description of what COI is before the callout
- Tmux-Automation: replace non-deterministic sleep-based CI examples with
polling helpers; add Note callout explaining why fixed sleeps are unreliable
- FAQ.md: expand Troubleshooting Quick Links from 2 to 7 entries covering
container pause/kill, privileged=true error, Docker Compose, DNS build issues
- Resource-and-Time-Limits: add prose section explaining what each limit
actually does (CPU enforce/priority, memory hard vs soft, swap semantics,
disk I/O cgroup blkio, tmpfs, runtime auto-stop)
- File-Transfer: add UID shifting note explaining automatic ownership mapping
and when to chown after pushing to system paths
- Security-Monitoring: clarify [monitoring] vs [monitoring.nft] as two
independent subsystems with separate prerequisites
- Configuration: note that forward_env is top-level in profiles vs under
[defaults] in main config
- Migration-Guide: add 4 more entries from Troubleshooting content (bool
pointer fix, settings.json deep merge, Docker Compose three-step launch,
EXDEV session save fix, UID/GID remapping)
docs: complete structural, content, and style improvements (S4-S6, C1-C5, F5)
Structural:
- S4: Add Slot System section to Container-Lifecycle-and-Sessions explaining
container naming, auto-allocation, per-slot isolation, and alias suffixes
- S5: Merge Self-Update into System-Health-Check (update commands, how-it-works,
post-update steps); Self-Update.md becomes a redirect
- S6: Add Migration-Guide.md covering .coi.toml → .coi/config.toml move and
[[mounts]] vs [[mounts.default]] syntax difference
Content:
- C1: Add Best-Practices.md covering session mode selection, network mode
guide, monitoring recommendations, long-running tasks, team workflows,
AI-generated code handling, and storage cleanup
- C2: Expand Snapshot-Management.md with context opener (stateless vs stateful
tradeoffs, restore requirement) and Best Practices section
- C3: Add Troubleshooting section to Image-Management.md (image not found,
build failures, wrong image applied, stale image after update) and
Best Practices section
- C4: Document coi run in Container-Operations.md with use cases, flags,
and differences from coi shell
- C5: Add JSONL field schema tables to Security-Monitoring.md (common fields,
type-specific fields, NFT-specific fields)
Formatting:
- F5: Add Best Practices sections to Network-Isolation, Profiles,
Image-Management, and Snapshot-Management
Navigation:
- Home.md updated with Best-Practices and Migration-Guide in nav
docs: quick-win formatting pass across all wiki pages
- Add H1 title to all 16 pages that were missing one
- Add FAQ question index with 22 anchor-linked entries grouped by category
- Add See Also section to all 19 pages with curated cross-links
- Upgrade three high-risk inline warnings to blockquote callouts:
allow_local_network_access, mount parent dir, disable_protection
docs: replace em dashes with hyphens across all wiki pages
Fix remaining documentation inconsistencies for 0.8.0
- Image-Management: migrate profile example from deprecated [build] to [container.build]
- Configuration: remove "aider" from tool name comment (not yet registered),
move --tool from global flags to shell-only section
- Security-Monitoring: clarify write threshold mirrors read threshold (no separate config key)
- Profiles: add missing extended fields to Available Fields table
(model, paths, incus, git, ssh, security, monitoring, timezone, inherits)
Fix documentation inconsistencies for 0.8.0 release
- Profiles: migrate all examples from deprecated top-level image/persistent/[build]
to [container]/[container.build] nesting (0.8.0 rejects the old format)
- Resource-and-Time-Limits: replace obsolete [profiles.X] flat syntax with
directory-based profile config.toml examples
- Security-Monitoring: fix phantom config keys (rate_limit → rate_limit_per_second,
remove non-existent suspicious_unlimited, file_write_threshold_mb, file_write_rate_mb_per_sec)
- FAQ: move Aider from "currently supported" to "coming soon" (not yet registered)
- Troubleshooting: fix tmpfs_size default comment (empty string, not 4GiB),
remove phantom file_write_threshold_mb reference
- File-Transfer: fix /root/.claude paths to /home/code/.claude
- Container-Operations: document coi info, coi version, coi clean --pools/--orphans/--dry-run
- Profiles: add note explaining [[mounts]] (profiles) vs [[mounts.default]] (main config)
Docs audit for 0.8.0: fix [defaults] → [container], coi resume → coi unfreeze, add security features
- Fix [defaults] → [container] for image/persistent in Configuration.md, Image-Management.md
- Replace all coi resume → coi unfreeze references (Security-Monitoring, Troubleshooting, Lifecycle)
- Add host-side immutable protection and guest API sections to Security-Best-Practices.md
- Add container aliases section to Container-Lifecycle-and-Sessions.md
- Update System-Health-Check.md for multi-pool support
- Add host_immutable, alias, storage_pool to config reference
Update wiki for 0.8.0 release
- Rename default image coi → coi-default
- Move config path ~/.config/coi/config.toml → ~/.coi/config.toml
- Drop /etc/coi/ and ~/.config/coi/ from config hierarchy
- Replace coi build custom with profile-based build workflow
- Rename coi profile show → coi profile info
- Document profile inheritance (inherits field)
- Document coi profile create/edit/delete commands
- Remove non-existent coi config --init reference
Update wiki for CLI flag removal and readonly mount support
Remove references to 21 CLI flags that are now config/profile-only.
Replace --network, --monitor, --ssh-agent, --forward-env, --timezone,
--mount, --env, --limit-*, --writable-git-hooks examples with config
TOML equivalents. Add readonly = true mount documentation and Claude
skills/commands/plugins mounting guide (ref #260).
Still-valid flags (--format, --capture, --tty, --env on container exec,
--timeout, --compression on build) are unchanged.
fix: replace non-existent coi monitor audit references with actual commands
The `coi monitor audit` subcommand is not implemented (commented out in
code). Replace all references with the actual working approach: reading
audit JSONL files directly from ~/.coi/audit/.
Pages updated:
- Security-Monitoring.md (4 references)
- Troubleshooting.md (2 references)
- FAQ.md (1 reference)
docs: update wiki with recent fixes and improvements
Security Monitoring:
- Add large file write detection, gateway IP RFC1918 exclusion
- Document dropped event tracking and orphan NFT rule cleanup
- Add alert deduplication and NFT error routing details
Troubleshooting (6 new entries):
- Docker Compose fails in session containers
- Permission denied / UID/GID mismatch
- Security settings silently disabled (config merge bug)
- Firewall rules accumulating
- Settings.json overwritten
- Cross-device link session save errors
Supported Tools:
- Add Claude effort level configuration
- Fix opencode config path to XDG-compliant location
- Update Go interfaces (ToolWithConfigDirFiles, ToolWithEffortLevel)
Network Isolation:
- Clarify gateway IP auto-exclusion from RFC1918 checks
- Document cleanup on all termination paths including nftables
- Remove duplicated container access section
Container Lifecycle:
- Add coi persist and coi resume commands
- Document Docker/Compose support in sessions
- Note sync.Once cleanup protection
Container Operations:
- Document three-step launch sequence for Docker support
- Add UID/GID remapping and extra mount documentation
FAQ: Add Docker Compose and preserve_workspace_path entries
Resource Limits: Add tmpfs_size to disk limits config
docs: update wiki for recent security monitoring features
Security-Monitoring.md:
- Add large write detection for data exfiltration
- Add disk space monitoring (/tmp > 80% warning)
- Add coi resume command documentation
- Add threat deduplication (30-second window)
- Add complete configuration options
- Add threat level table with severities
- Add example for detecting data exfiltration
- Add NFT cleanup troubleshooting
Supported-Tools.md:
- Update opencode resume behavior (--continue flag)
- Add permission bypass row to comparison table
System-Health-Check.md:
- Clarify Incus storage pool thresholds
Troubleshooting.md:
- Add section for container paused by monitoring
- Add section for container killed by monitoring
- Document coi resume workflow
FAQ.md:
- Add real-time threat detection to protection list
- Add monitoring best practices
docs: add Security Monitoring and Supported Tools pages, update health checks
- Add Security-Monitoring.md: real-time threat detection, nftables monitoring,
automated response, audit logging
- Add Supported-Tools.md: Claude Code vs opencode comparison, tool selection,
API key configuration, adding new tools
- Update System-Health-Check.md: add Incus storage pool, monitoring checks,
container networking checks
- Update Security-Best-Practices.md: reference new Security Monitoring page
- Update Home.md: add links to new pages