← all repositories
mensfeld/coi

Give your AI agent root, but not your SSH keys

code-on-incus spins up full Linux system containers for AI coding tools so they can run systemd, Docker, and package managers without ever touching your host credentials or filesystem.

★732 stars Go Coding AssistantsAgents
coi
Velocity · 7d
+22
★ / day
Trend
↗accelerating
star history

What it does COI is a Go CLI that drives Incus to launch full system containers for AI coding agents like Claude Code and opencode. Each agent gets what looks like a real Linux machine—root, systemd, Docker, and cron—while your project files are mounted in with correct ownership via automatic UID shifting. The host keeps your SSH keys, environment variables, and Git tokens; the agent only sees what you explicitly mount.

The interesting bit Instead of hoping your AI behaves, COI monitors kernel-level nftables traffic in real time to detect reverse shells, C2 beacons, credential scanning, and DNS tunneling, then auto-pauses or kills the container. It even locks down .git/hooks and IDE configs with read-only mounts and host-side immutable attributes so a compromised agent cannot rewrite your supply chain.

Key highlights

  • Full system containers via Incus (not Docker), with native systemd and Docker-in-container support
  • Real-time threat detection and automated response: auto-pause on HIGH threats, auto-kill on CRITICAL
  • Credentials isolated by default; SSH keys and env vars are never exposed unless explicitly mounted
  • Session resume and persistent containers that survive reboots, plus parallel multi-slot isolation
  • Automatic UID/GID mapping means no chown hacks to fix file ownership after an agent touches your code

Caveats

  • Linux-only and requires Incus; the project is built for Linux from the ground up
  • Only Claude Code and opencode are supported today, with more tools listed as coming soon
  • Files created via sudo inside the workspace end up root-owned on the host

Verdict If you are already running Claude Code or opencode and want to stop worrying about leaked credentials or rogue curl | bash pipelines, this is worth the Incus dependency. If you are looking for a cross-platform Docker wrapper or a plug-and-play Windows tool, this is not for you yet.

Frequently asked

What is mensfeld/coi?
code-on-incus spins up full Linux system containers for AI coding tools so they can run systemd, Docker, and package managers without ever touching your host credentials or filesystem.
Is coi open source?
Yes — mensfeld/coi is open source, released under the MIT license.
What language is coi written in?
mensfeld/coi is primarily written in Go.
How popular is coi?
mensfeld/coi has 732 stars on GitHub and is currently accelerating.
Where can I find coi?
mensfeld/coi is on GitHub at https://github.com/mensfeld/coi.

heatdrop uses Google Analytics to see which pages get read — nothing else. Your call. How we handle data.