Skip to content

History / nftables Setup

Revisions

  • docs: sync from coipond/coi-wiki (binary, pre_launch, protected branches, health --fix) Mirror of coi-wiki c8a4cd8 (docs/binary-pre-launch-guard-health), flattened: [tool] binary and pre_launch, [git] protected_branches, `coi health --fix`, visudo-validated sudoers instructions, current reverse-shell detection behavior, and the large-UID subuid/subgid fix. Also renames Updating-COI.md -> Updating-Coi.md, matching coi-wiki and the existing [Updating Coi](Updating-Coi) links, which pointed at a page that didn't exist under that name here.

    @mensfeld mensfeld committed Oct 2, 2026
  • docs: align wiki to the Karafka writing style Style-only pass across 39 pages: reduce decorative bold to scannable labels and callouts, Title Case headings, expand contractions, present tense, US English, cut filler and --- separators, tag code fences. Commands, code, config, COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command) COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)". Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers (they document the actual on-disk marker text). Lowercase coi commands unchanged.

    @mensfeld mensfeld committed Sep 29, 2026
  • docs: split Network Isolation into focused pages Network-Isolation.md had grown to ~20 KB / 365 lines covering four distinct topics. Extract the two self-contained ones into their own pages, leaving the core page focused on egress modes + hardening (now ~13.7 KB / 244 lines): - New **Static Host Entries** — `[[network.hosts]]` config, per-host `ports`, the per-mode reachability table, trusted-scope rules, and runtime `coi hosts`. - New **nftables Setup** — the open-mode workaround, install + sudoers steps, how the FORWARD-chain rules work, and orphaned-rule cleanup. Network-Isolation keeps short pointer stubs to both; the "(see below)" per-host ports reference now links the new page. Host Access to Container Services stays on the core page (it's `allow_local_network_access` firewall content, not port-publishing). Re-pointed the Container-Operations and Configuration cross-references to Static Host Entries, and added both pages to Home + _Sidebar (nested under Network Isolation). All internal links verified.

    @mensfeld mensfeld committed Sep 1, 2026