Skip to content

History / Supported Tools

Revisions

  • docs: sync from coipond/coi-wiki (binary, pre_launch, protected branches, health --fix) Mirror of coi-wiki c8a4cd8 (docs/binary-pre-launch-guard-health), flattened: [tool] binary and pre_launch, [git] protected_branches, `coi health --fix`, visudo-validated sudoers instructions, current reverse-shell detection behavior, and the large-UID subuid/subgid fix. Also renames Updating-COI.md -> Updating-Coi.md, matching coi-wiki and the existing [Updating Coi](Updating-Coi) links, which pointed at a page that didn't exist under that name here.

    @mensfeld mensfeld committed Oct 2, 2026
  • docs: align wiki to the Karafka writing style Style-only pass across 39 pages: reduce decorative bold to scannable labels and callouts, Title Case headings, expand contractions, present tense, US English, cut filler and --- separators, tag code fences. Commands, code, config, COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command) COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)". Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers (they document the actual on-disk marker text). Lowercase coi commands unchanged.

    @mensfeld mensfeld committed Sep 29, 2026
  • Document 0.12 tool-switching, headless prompt runs, and config/profile mount + env_command_timeout symmetry - Container Lifecycle: new 'Running a different AI tool in the same container' section (shared session_name across two per-tool profiles; first-switch credential seeding) (#708) - Headless Orchestration: new 'Fire-and-forget prompt runs' section covering coi run --prompt / --prompt-file / --prompt-name and the [prompts] registry (trusted-scope only) with a cron example (#701) - Profiles/Configuration: correct the now-false 'profiles use [[mounts]], config uses [[mounts.default]]' note — both shapes work in both scopes; document env_command_timeout as profile-settable (#783) - Configuration: [prompts] stub + capability rows; note coi build works in any [incus] project (#777) - Troubleshooting: kitty/xterm-* 'unsuitable terminal' is handled automatically (#772) - Migration Guide + Supported Tools: surface tool-switching and headless prompts

    @mensfeld mensfeld committed Sep 8, 2026
  • Document interactive auto-mode behavior under permission_mode (#764)

    @mensfeld mensfeld committed Sep 3, 2026
  • docs: split Supported Tools — extract Sandbox Context + Adding New Tools Supported-Tools.md mixed three audiences. Keep all per-tool sections together (users compare tools at a glance) and extract the two genuinely independent, cross-cutting sections into their own pages (page now ~11.5 KB / 272 lines, down from ~15.6 KB / 379 lines): - New **Sandbox Context** — the `~/SANDBOX_CONTEXT.md` / `.json` environment description, auto-context injection per tool, disabling it, and custom/JSON context files. It's referenced from Architecture and Configuration and isn't really about *which* tool. - New **Adding New Tools** — contributor docs: the `Tool` interface and optional capability interfaces (incl. ToolWithPrompt / ToolWithContainerEnv for `coi tool spec`) with worked examples. Supported-Tools keeps pointer stubs to both. Re-pointed the Configuration cross-reference to the new Sandbox Context page; credentials/permission-mode links stay valid (those sections remain). Added both pages to Home + _Sidebar (nested under Supported Tools). All internal links verified.

    @mensfeld mensfeld committed Sep 1, 2026
  • docs: cover 0.12.0 capabilities (coi tool spec, coi top, omp, SANDBOX_CONTEXT.json) Bring the wiki up to date with capabilities added since the last update: - New page **Headless Orchestration (`coi tool spec`)** — the non-executing launch-spec API for external orchestrators, incl. --continue / --resume-id / --resume, the `prompt` field for non-embedding tools, and env/secrets model. - New page **Resource Usage (`coi top`)** — live per-container/per-process CPU, memory, disk and network usage; flags, examples, and how it reads cgroups. - **Supported Tools**: add the omp (Oh My Pi) tool section; document the ~/SANDBOX_CONTEXT.json companion (context_json / context_json_file, trusted scope only). - **Configuration**: add context_json / context_json_file to the [tool] reference. - Wire both new pages into Home + _Sidebar; cross-link Tmux Automation -> Headless Orchestration. (codex, tmpfs_size, per-host/per-destination ports, dns_servers, allowed_ports, and git readonly were already documented.)

    @mensfeld mensfeld committed Sep 1, 2026
  • Document 0.12.0: egress hardening, per-host ports, Codex CLI, [git] readonly

    @mensfeld mensfeld committed Aug 19, 2026
  • Align wiki with 0.11.1: OrbStack guide, filesystem-first UID mapping, dir-pool health warning, idempotent context injection, version-fix note - macOS Setup Guide: OrbStack is now a first-class documented option (setup steps, how COI handles the FUSE-backed macOS share via raw.idmap, the OrbStack >=2.2.2 silent-breakage background, storage notes); 'How It Works' rewritten around the v0.11.1 filesystem check with the reactive fallback; Manual Override reframed as rarely needed; Colima instructions now install Incus from Zabbly (Ubuntu's 6.0 is below the required 6.1). - Configuration/Architecture/File-Transfer/FAQ pages: UID-mapping mechanism descriptions updated (auto-selected shift vs raw.idmap), disable_shift comment rewritten, Colima-only framing widened to Colima/Lima/OrbStack. - System Health Check/Troubleshooting/Best Practices/Getting Started/ Linux Setup Guide: dir-pool driver warning documented (detection, cost, fix), example output shows the new 'pool (driver)' label, manual-setup example no longer recommends a dir pool, Zabbly note reframed around the automatic raw.idmap recovery, #673 version/update known-issue note added. - Troubleshooting/Supported-Tools/Profiles: idempotent marker-delimited sandbox-context injection documented incl. auto-healing of bloated files; tool interface snippets synced (AlwaysSetupConfig, full effort level list). - nftables internals: NFT monitoring is disabled by default. - Nav (Home/Sidebar/Footer): 0.10.1->0.11.0 migration links; FAQ count fix; IPv6 host-side blocking wording.

    @mensfeld mensfeld committed Aug 10, 2026
  • Post-release audit: fix ~50 inaccuracies vs v0.10.0 behavior Triple-check audit of every page against the released binary and code. Systemic: firewalld -> nftables (stale since the v0.9 #405 migration) across Network-Isolation, Linux-Setup-Guide, Architecture-and-Security-Model, Getting-Started, Home, FAQ*, Best-Practices, Troubleshooting, System-Health-Check — including the whole 'Firewalld Setup' section that told users to create the wrong sudoers file (/etc/sudoers.d/coi-firewalld); now documents nftables + /etc/sudoers.d/coi-nft (matching install.sh), the real error string, use_sudo=false, and the real orphan classes and health check names. Distro-default-firewall tips (Fedora/openSUSE) kept but decoupled from COI's own mechanism. Audit-Log: JSONL examples and field reference rewritten to the real ThreatEvent shape (id/timestamp/level/category/title/description/evidence/ action — the old examples used fields that never existed); COI_AUDIT_* tuning corrected (host env is not forwarded; use incus config set). Security-Best-Practices: default protected-paths table matches the 0.10 set; protection-weakening keys documented as trusted-scope only (untrusted project configs are sanitized); #533 linked-worktree support and #556 git identity seeding documented. Command usage: coi update core --check (not coi update --check), coi info <session-id>, coi persist <container>, coi run's interactive build prompt, stop-before-publish in the image workflow, --slot pinning. Config accuracy: memory enforce default is soft; effort_level accepts low/medium/high/xhigh/max/auto (default unset); [limits.disk] values are I/O rates not storage caps (Best-Practices example fixed); protected_paths default list completed; threat levels are INFO/WARNING/HIGH/CRITICAL. Navigation: 0.9->0.10 migration section linked from Home, sidebar, and footer; broken FAQ prompt-injection anchor retargeted.

    @mensfeld mensfeld committed Jul 10, 2026
  • 0.10.0 release sweep: convert removed flags/env-vars to config-key docs, add 0.9->0.10 migration section PUSH TO MASTER ONLY WHEN v0.10.0 IS TAGGED — this describes 0.10 behavior. - Migration-Guide: full 'Upgrading from 0.9 to 0.10' section (removed-flags table, deleted env-var layers, claude-on-incus retirement, resume persistence conversion, profile-beats-project-config, new opt-in features incl. [[credentials]], hardened profile, use_sudo, ready_timeout, coi run script, list filters) - Configuration: hierarchy table drops the env-var and config-flag layers; env-var section becomes a removed->replacement table; CLI flags section rewritten around operational-only flags with a removed-flags table; [shell] use_tmux added to the reference - Getting-Started, Best-Practices, Architecture, Container-Lifecycle, Container-Operations, Tmux-Automation: --persistent examples converted to [container] persistent = true config; shutdown --timeout -> shutdown_timeout - Image-Management: --image/--persistent/--compression workflows converted to config/profile equivalents (image publish keeps --compression) - Supported-Tools: --tool selection converted to [tool] name / per-tool profiles; new 'Tool Credentials and Third-Party Providers' section covering the credential catalog and [[credentials]] - Profiles: profile create flag list matches 0.10 (--inherits/--user/ --project only); profile-vs-project-config precedence note

    @mensfeld mensfeld committed Jul 10, 2026
  • docs: 0.9 updates — upgrade guide (0.8→0.9), sockets, env_commands, pi - Migration-Guide: add 'Upgrading from 0.8 to 0.9' (trust gate, network sanitize, read-only .coi, protected git paths, allowlist/IPv6 tightening; new features: sockets, env_commands, coi trust/audit, pi) - Configuration: document [[sockets]] and [defaults.env_commands]; fix default protected_paths list; add pi to tool name - Supported-Tools: add pi section - Home: link the 0.8→0.9 upgrade guide

    Maciej Mensfeld committed Jun 17, 2026
  • fix: correct --resume/--continue description for opencode (both are aliases)

    Maciej Mensfeld committed May 28, 2026
  • docs: fix macOS apt assumption and add sandbox context cross-link - macOS-Setup-Guide: add Warning callout before Setup Instructions noting that apt commands assume the Ubuntu Colima template; recommend Ubuntu for best compatibility with COI's base image - Supported-Tools: link Sandbox Context File section to Architecture-and-Security-Model; add Architecture to See Also

    @mensfeld mensfeld committed May 26, 2026
  • docs: quick-win formatting pass across all wiki pages - Add H1 title to all 16 pages that were missing one - Add FAQ question index with 22 anchor-linked entries grouped by category - Add See Also section to all 19 pages with curated cross-links - Upgrade three high-risk inline warnings to blockquote callouts: allow_local_network_access, mount parent dir, disable_protection

    @mensfeld mensfeld committed May 26, 2026
  • docs: replace em dashes with hyphens across all wiki pages

    @mensfeld mensfeld committed May 26, 2026
  • Update wiki for 0.8.0 release - Rename default image coi → coi-default - Move config path ~/.config/coi/config.toml → ~/.coi/config.toml - Drop /etc/coi/ and ~/.config/coi/ from config hierarchy - Replace coi build custom with profile-based build workflow - Rename coi profile show → coi profile info - Document profile inheritance (inherits field) - Document coi profile create/edit/delete commands - Remove non-existent coi config --init reference

    @mensfeld mensfeld committed Apr 9, 2026
  • Update wiki for CLI flag removal and readonly mount support Remove references to 21 CLI flags that are now config/profile-only. Replace --network, --monitor, --ssh-agent, --forward-env, --timezone, --mount, --env, --limit-*, --writable-git-hooks examples with config TOML equivalents. Add readonly = true mount documentation and Claude skills/commands/plugins mounting guide (ref #260). Still-valid flags (--format, --capture, --tty, --env on container exec, --timeout, --compression on build) are unchanged.

    @mensfeld mensfeld committed Apr 3, 2026
  • 0.8.0 release updates

    @mensfeld mensfeld committed Apr 2, 2026
  • Document auto_context feature for sandbox context injection (#243) - Configuration.md: Add auto_context option to [tool] config reference, add Auto-Context Injection subsection explaining Claude/OpenCode behavior - Supported-Tools.md: Add ToolWithAutoContextFile and ToolWithAutoContextPath interfaces to Adding New Tools section, add Auto-Context Injection subsection with per-tool details and opt-out instructions

    @mensfeld mensfeld committed Mar 30, 2026
  • docs: add Configuration page and document 0.8.0 features across wiki - Create Configuration.md with full config reference (was linked but missing) - Add SSH agent forwarding and env var forwarding to Container-Lifecycle-and-Sessions - Update Network-Isolation with TTL-aware DNS refresh behavior - Add sandbox context file docs to Supported-Tools - Add SSH/env forwarding security considerations to Security-Best-Practices - Fix stale mount_claude_config reference in FAQ - Update env var isolation statement in FAQ for forward_env - Add Configuration link to Home page

    @mensfeld mensfeld committed Mar 15, 2026
  • docs: add permission_mode documentation (#165)

    @mensfeld mensfeld committed Mar 2, 2026
  • docs: update wiki with recent fixes and improvements Security Monitoring: - Add large file write detection, gateway IP RFC1918 exclusion - Document dropped event tracking and orphan NFT rule cleanup - Add alert deduplication and NFT error routing details Troubleshooting (6 new entries): - Docker Compose fails in session containers - Permission denied / UID/GID mismatch - Security settings silently disabled (config merge bug) - Firewall rules accumulating - Settings.json overwritten - Cross-device link session save errors Supported Tools: - Add Claude effort level configuration - Fix opencode config path to XDG-compliant location - Update Go interfaces (ToolWithConfigDirFiles, ToolWithEffortLevel) Network Isolation: - Clarify gateway IP auto-exclusion from RFC1918 checks - Document cleanup on all termination paths including nftables - Remove duplicated container access section Container Lifecycle: - Add coi persist and coi resume commands - Document Docker/Compose support in sessions - Note sync.Once cleanup protection Container Operations: - Document three-step launch sequence for Docker support - Add UID/GID remapping and extra mount documentation FAQ: Add Docker Compose and preserve_workspace_path entries Resource Limits: Add tmpfs_size to disk limits config

    @mensfeld mensfeld committed Mar 2, 2026
  • docs: add Claude effort level configuration Document the new [tool.claude] effort_level setting that controls response thoroughness and prevents interactive prompts in autonomous shell sessions.

    @mensfeld mensfeld committed Feb 25, 2026
  • docs: update wiki for recent security monitoring features Security-Monitoring.md: - Add large write detection for data exfiltration - Add disk space monitoring (/tmp > 80% warning) - Add coi resume command documentation - Add threat deduplication (30-second window) - Add complete configuration options - Add threat level table with severities - Add example for detecting data exfiltration - Add NFT cleanup troubleshooting Supported-Tools.md: - Update opencode resume behavior (--continue flag) - Add permission bypass row to comparison table System-Health-Check.md: - Clarify Incus storage pool thresholds Troubleshooting.md: - Add section for container paused by monitoring - Add section for container killed by monitoring - Document coi resume workflow FAQ.md: - Add real-time threat detection to protection list - Add monitoring best practices

    @mensfeld mensfeld committed Feb 24, 2026
  • docs: add Security Monitoring and Supported Tools pages, update health checks - Add Security-Monitoring.md: real-time threat detection, nftables monitoring, automated response, audit logging - Add Supported-Tools.md: Claude Code vs opencode comparison, tool selection, API key configuration, adding new tools - Update System-Health-Check.md: add Incus storage pool, monitoring checks, container networking checks - Update Security-Best-Practices.md: reference new Security Monitoring page - Update Home.md: add links to new pages

    @mensfeld mensfeld committed Feb 19, 2026