docs: update repo references mensfeld/coi -> coipond/coi (org transfer)
5ce53c4
docs: document reverse_shell_one_liners knob and one-liner detection change (#842/#846)
- Security-Monitoring: split reverse-shell threats into unambiguous vs
interpreter one-liner classes; add 'Interpreter one-liner policy' section
documenting reverse_shell_one_liners (critical|warn|off) and the network-
indicator gate; add the key to the full config block.
- Troubleshooting: note that benign interpreter one-liners no longer kill the
container, and how to downgrade the class instead of disabling auto-kill.
- Configuration: add reverse_shell_one_liners to the [monitoring] reference.
159d3f6
docs: align wiki to the Karafka writing style
Style-only pass across 39 pages: reduce decorative bold to scannable labels and
callouts, Title Case headings, expand contractions, present tense, US English,
cut filler and --- separators, tag code fences. Commands, code, config,
COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.
4475e49
docs: point URLs at mensfeld/coi + fix leftover code-on-incus branding
Repo renamed mensfeld/code-on-incus -> mensfeld/coi: update all wiki links
(install.sh raw URL, issues/releases/tree/wiki links) and one leftover
"code-on-incus" prose ref -> Coi.
00ec9c0
docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command)
COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)".
Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers
(they document the actual on-disk marker text). Lowercase coi commands unchanged.
451a6a0
docs: dedicated Updating COI page (binary + detection databases)
Promote update docs out of System-Health-Check into a standalone
Updating-COI page so it is discoverable on its own (prompted by #821).
- Document coi update / update core / update patterns, including the
GTFOBins + Sigma detection-database refresh the old docs omitted.
- Add troubleshooting for the Sigma/GTFOBins git pull --ff-only failure
(remove the clone dir and re-run) and the v0.11.0 doubled-version bug.
- Self-Update and System-Health-Check#updating-coi now point to the new
page; update Home, Sidebar, and Image-Management links.
e2e586b
docs(macos): add 'Claude auth on macOS (Keychain)' section (#818)
a66215a
docs(config): document per-mount `shift` field on [[mounts]] (#604)
305a090
docs(security): document unoverridable git identity lock + strict kernel-surface tier
- Security-Best-Practices: [git] readonly now enforces via three layers
(read-only mount + pinned GIT_* env + root-owned post-commit re-stamp);
document the -c/--author/env override paths it closes and the residual
gaps (repo-local core.hooksPath/husky, GIT_CONFIG_GLOBAL).
- Threat-Model: add the reduce_kernel_surface_strict tier (perf_event_open).
- Configuration: expand the readonly reference and add reduce_kernel_surface
+ reduce_kernel_surface_strict to [security].
6ad81d5
docs: [monitoring] forensics_on_kill — preserve a killed container for forensics (#792)
New 'Preserving a killed container for forensics' subsection under Automated
Response: what forensics_on_kill does (copy-before-kill to a stopped
*-forensics-* container), how to inspect/dispose of the copy, the 3-copy cap
and COW-reflink note, and why it is opt-in (default off). Config key added to
the [monitoring] block.
6126f38
docs: [git] strip_attribution — clean commit authorship (#788, PR #789)
- Configuration: the two new [git] keys in the sample block.
- Security best practices: new "Clean commit authorship" subsection under
Git Identity Guard — the global commit-msg hook (strip-don't-reject,
delegates to repo hooks), the Claude managed-settings layer, default
pattern coverage, trust scoping, and the documented limitations
(repo-local core.hooksPath / husky, git commit --no-verify).
a27e3ee
docs: reflect merged kernel-surface hardening PR (#787) final state
- Threat model: fail-closed guarantee for profile-pinned keys, new Kernel
mitigations health check, Incus recommended-floor now advisory (stays OK),
hardened profile's 4h session cap.
- Profiles: hardened preset table gains reduce_kernel_surface and
limits.runtime.max_duration rows; wording updated (the preset now carries
new enforcement, not only pre-existing controls).
- System health check: SYSTEM sample output + What's Checked cover kernel
build age, kernel mitigations, and distro support; Incus row notes the
6.7+ advisory.
a4d1ebd
Add 'Threat model: containment limits' page (kernel hardening flags + freshness guidance)
87e7d01
Document 0.12 tool-switching, headless prompt runs, and config/profile mount + env_command_timeout symmetry
- Container Lifecycle: new 'Running a different AI tool in the same container'
section (shared session_name across two per-tool profiles; first-switch
credential seeding) (#708)
- Headless Orchestration: new 'Fire-and-forget prompt runs' section covering
coi run --prompt / --prompt-file / --prompt-name and the [prompts] registry
(trusted-scope only) with a cron example (#701)
- Profiles/Configuration: correct the now-false 'profiles use [[mounts]], config
uses [[mounts.default]]' note — both shapes work in both scopes; document
env_command_timeout as profile-settable (#783)
- Configuration: [prompts] stub + capability rows; note coi build works in any
[incus] project (#777)
- Troubleshooting: kitty/xterm-* 'unsuitable terminal' is handled automatically (#772)
- Migration Guide + Supported Tools: surface tool-switching and headless prompts
e43f97f
Document interactive auto-mode behavior under permission_mode (#764)
620fab7
Document [limits.disk] size quota + clarify tmpfs_size is opt-in RAM /tmp (#728)
4d4590d
docs: document the universal --json output alias (#765)
Every command with --format text|json now also accepts --json (alias for
--format json; --json wins over --format text). Authoritative note + full
command list in Container Operations; inline shorthand on Image/Snapshot/
Health pages. Notes the coi container exec exception (--format json|raw).
86208ba
docs(headless): rename tool-spec --resume to --resume-latest; note the rejected bare --resume
bd42107
docs(home): name the current tool set in the intro (Codex, pi, omp)
bf201b4
docs: add 0.11 → 0.12 Migration Guide entry
The Migration Guide stopped at 0.10.1 → 0.11.0; add the 0.11 → 0.12 section for
the upcoming release. 0.12.0 is additive (no breaking changes, no config
migration), so it follows the "New in X (opt-in, no action needed)" pattern:
lists the new capabilities (coi tool spec, coi top, codex, omp,
SANDBOX_CONTEXT.json, egress hardening, git readonly) with links to their pages,
plus Notes on the three fixes with upgrade-relevant behavior (#744 tool env on
exec/reused containers, #733 tmpfs_size, #726 shell storage_pool).
Surfaced the new entry in Home + _Sidebar migration sub-links. All links verified.
b825b6c
docs: split Supported Tools — extract Sandbox Context + Adding New Tools
Supported-Tools.md mixed three audiences. Keep all per-tool sections together
(users compare tools at a glance) and extract the two genuinely independent,
cross-cutting sections into their own pages (page now ~11.5 KB / 272 lines,
down from ~15.6 KB / 379 lines):
- New **Sandbox Context** — the `~/SANDBOX_CONTEXT.md` / `.json` environment
description, auto-context injection per tool, disabling it, and custom/JSON
context files. It's referenced from Architecture and Configuration and isn't
really about *which* tool.
- New **Adding New Tools** — contributor docs: the `Tool` interface and optional
capability interfaces (incl. ToolWithPrompt / ToolWithContainerEnv for
`coi tool spec`) with worked examples.
Supported-Tools keeps pointer stubs to both. Re-pointed the Configuration
cross-reference to the new Sandbox Context page; credentials/permission-mode
links stay valid (those sections remain). Added both pages to Home + _Sidebar
(nested under Supported Tools). All internal links verified.
6449f2a
docs: split Network Isolation into focused pages
Network-Isolation.md had grown to ~20 KB / 365 lines covering four distinct
topics. Extract the two self-contained ones into their own pages, leaving the
core page focused on egress modes + hardening (now ~13.7 KB / 244 lines):
- New **Static Host Entries** — `[[network.hosts]]` config, per-host `ports`,
the per-mode reachability table, trusted-scope rules, and runtime `coi hosts`.
- New **nftables Setup** — the open-mode workaround, install + sudoers steps,
how the FORWARD-chain rules work, and orphaned-rule cleanup.
Network-Isolation keeps short pointer stubs to both; the "(see below)" per-host
ports reference now links the new page. Host Access to Container Services stays
on the core page (it's `allow_local_network_access` firewall content, not
port-publishing). Re-pointed the Container-Operations and Configuration
cross-references to Static Host Entries, and added both pages to Home + _Sidebar
(nested under Network Isolation). All internal links verified.
202bfe6
docs: cover 0.12.0 capabilities (coi tool spec, coi top, omp, SANDBOX_CONTEXT.json)
Bring the wiki up to date with capabilities added since the last update:
- New page **Headless Orchestration (`coi tool spec`)** — the non-executing
launch-spec API for external orchestrators, incl. --continue / --resume-id /
--resume, the `prompt` field for non-embedding tools, and env/secrets model.
- New page **Resource Usage (`coi top`)** — live per-container/per-process CPU,
memory, disk and network usage; flags, examples, and how it reads cgroups.
- **Supported Tools**: add the omp (Oh My Pi) tool section; document the
~/SANDBOX_CONTEXT.json companion (context_json / context_json_file, trusted
scope only).
- **Configuration**: add context_json / context_json_file to the [tool] reference.
- Wire both new pages into Home + _Sidebar; cross-link Tmux Automation ->
Headless Orchestration.
(codex, tmpfs_size, per-host/per-destination ports, dns_servers, allowed_ports,
and git readonly were already documented.)
53c52c4
Troubleshooting: host won't suspend with a container running (udisks2, #706)
94944e4
Document 0.12.0: egress hardening, per-host ports, Codex CLI, [git] readonly
3b50e9f
0.11.2: firewalld veth-bloat check in the health table; --orphans hint
1f7a100
firewalld veth exclusion: use unmanaged-devices+= (plain = replaces a user's own exclusion list under NM last-file-wins semantics)
ec911e9
Document firewalld veth zone bloat (#695): Troubleshooting diagnosis/fix, manual NM exclusion in Linux Setup Guide
0b433c2
Release-readiness pass for 0.11.1: session_name cross-references, --resume scoping correction, --container as-is note, named-session limitations
b5c2c59
Document [container] session_name: named sessions that survive workspace moves (0.11.1)
ba3206b