Give your AI agent root, but not your SSH keys
code-on-incus spins up full Linux system containers for AI coding tools so they can run systemd, Docker, and package managers without ever touching your host credentials or filesystem.

What it does COI is a Go CLI that drives Incus to launch full system containers for AI coding agents like Claude Code and opencode. Each agent gets what looks like a real Linux machine—root, systemd, Docker, and cron—while your project files are mounted in with correct ownership via automatic UID shifting. The host keeps your SSH keys, environment variables, and Git tokens; the agent only sees what you explicitly mount.
The interesting bit
Instead of hoping your AI behaves, COI monitors kernel-level nftables traffic in real time to detect reverse shells, C2 beacons, credential scanning, and DNS tunneling, then auto-pauses or kills the container. It even locks down .git/hooks and IDE configs with read-only mounts and host-side immutable attributes so a compromised agent cannot rewrite your supply chain.
Key highlights
- Full system containers via Incus (not Docker), with native systemd and Docker-in-container support
- Real-time threat detection and automated response: auto-pause on HIGH threats, auto-kill on CRITICAL
- Credentials isolated by default; SSH keys and env vars are never exposed unless explicitly mounted
- Session resume and persistent containers that survive reboots, plus parallel multi-slot isolation
- Automatic UID/GID mapping means no
chownhacks to fix file ownership after an agent touches your code
Caveats
- Linux-only and requires Incus; the project is built for Linux from the ground up
- Only Claude Code and opencode are supported today, with more tools listed as coming soon
- Files created via
sudoinside the workspace end up root-owned on the host
Verdict
If you are already running Claude Code or opencode and want to stop worrying about leaked credentials or rogue curl | bash pipelines, this is worth the Incus dependency. If you are looking for a cross-platform Docker wrapper or a plug-and-play Windows tool, this is not for you yet.
Frequently asked
- What is mensfeld/coi?
- code-on-incus spins up full Linux system containers for AI coding tools so they can run systemd, Docker, and package managers without ever touching your host credentials or filesystem.
- Is coi open source?
- Yes — mensfeld/coi is open source, released under the MIT license.
- What language is coi written in?
- mensfeld/coi is primarily written in Go.
- How popular is coi?
- mensfeld/coi has 732 stars on GitHub and is currently accelerating.
- Where can I find coi?
- mensfeld/coi is on GitHub at https://github.com/mensfeld/coi.