2026-03-10T21:25:20Z - 2026-09-10T21:25:20Z

Overview

89 active pull requests
66 active issues
Excluding merges, 2 authors have pushed 6 commits to main and 224 commits to all branches. On main, 4 files have changed and there have been 58 additions and 30 deletions.

4 releases published by 1 user

Published 0.9.0 0.9.0 2026-07-21 18:06:38 +00:00

Published 0.8.0 0.8.0 2026-07-19 23:04:02 +00:00

Published 0.7.0 0.7.0 2026-07-19 14:24:18 +00:00

Published 0.6.0 0.6.0 2026-07-18 13:39:45 +00:00

89 pull requests merged by 1 user

Merged #148 release: 0.9.0 2026-07-21 18:06:38 +00:00

Merged #151 refactor: one drill record per version, in drills/ 2026-07-21 17:41:42 +00:00

Merged #149 feat: CI refuses a release PR with no drill record 2026-07-21 16:17:40 +00:00

Merged #147 docs(changelog): one line per entry, and a pass over the whole file 2026-07-21 14:43:50 +00:00

Merged #146 fix: the release suite accepts the ceremony's own tree 2026-07-21 14:43:35 +00:00

Merged #132 feat: mark 'bootstrapped' after a rig hook box watched succeed 2026-07-21 12:21:32 +00:00

Merged #133 feat: box import records the trip, without rewriting who the box was 2026-07-21 12:09:30 +00:00

Merged #128 feat: snapshot 'pristine' at mint, before the rig bootstrap hook 2026-07-21 11:49:22 +00:00

Merged #127 fix: the racing-reader sweep guards the class, and revoke-user captures the trust store 2026-07-21 11:25:04 +00:00

Merged #129 feat: a minted box records how it was minted, and box info reads it back 2026-07-21 11:24:40 +00:00

Merged #120 fix: drill/wipe.sh reads ufw into a capture, not into an early-exit reader 2026-07-21 10:55:33 +00:00

Merged #119 fix: teardown-host refuses a terminal-less run instead of aborting mute 2026-07-20 23:38:14 +00:00

Merged #144 fix(changelog-monotonic): check uniqueness before anything base-side 2026-07-20 23:37:43 +00:00

Merged #142 fix(labels): sweep on labeled so the handoff is immediate 2026-07-20 20:32:20 +00:00

Merged #139 docs(contributing): document the blocker axis and merge-next ownership 2026-07-20 19:07:21 +00:00

Merged #138 refactor(labels): split PR labels into state (whose ball) and blocker (what is in the way) 2026-07-20 18:30:04 +00:00

Merged #137 fix(labels): state:needs-human means a human could merge it right now 2026-07-20 17:02:52 +00:00

Merged #121 fix: run setup-host over a migrated flat tree, and name what the migration left 2026-07-20 14:43:12 +00:00

Merged #126 fix: refuse a PR that deletes a shipped changelog heading 2026-07-20 14:15:57 +00:00

Merged #118 fix: lint the release path — globstar does not descend into dot-directories 2026-07-20 13:53:47 +00:00

Merged #125 refactor(templates): the tenant seeds carry rig's -box family suffix 2026-07-20 13:09:30 +00:00

Merged #114 release: 0.8.0 2026-07-19 23:04:02 +00:00

Merged #112 fix: Ctrl-D at a confirm prompt aborts out loud, not in silence (#111) 2026-07-19 21:27:57 +00:00

Merged #110 fix: the release ceremony re-arms CHANGELOG.md, and CI keeps main armed (#108) 2026-07-19 21:07:11 +00:00

Merged #109 fix: box restore asks before it destroys, in its own words (#105) 2026-07-19 20:26:00 +00:00

Merged #106 fix: the fresh-UFW test block no longer flakes on a missing log 2026-07-19 18:54:47 +00:00

Merged #101 fix: box grant provisions incus-admin members instead of refusing them 2026-07-19 18:05:34 +00:00

Merged #97 feat: merging a release-labeled PR is the release 2026-07-19 17:12:29 +00:00

Merged #98 chore: bump main to 0.7.1-dev 2026-07-19 16:03:25 +00:00

Merged #95 release: 0.7.0 2026-07-19 14:24:18 +00:00

Merged #94 fix: narrate and time-box the incus launch — a wedge fails loudly, not forever (#93) 2026-07-19 13:13:02 +00:00

Merged #90 feat: release flow — install-from-tag, release.yml, and -dev versions (#83) 2026-07-18 22:24:34 +00:00

Merged #91 feat(setup-host): auto-pick a free subnet — nested box-in-box with zero flags (#80) 2026-07-18 22:15:22 +00:00

Merged #89 box-firewall: converge the UFW carve-out off the live bridge; fail closed at boot (#86 follow-up) 2026-07-18 21:14:18 +00:00

Merged #88 feat: thin templates — box mints, rig converges (#81) 2026-07-18 21:08:44 +00:00

Merged #86 setup-host: refuse a claimed subnet (#80); BOX_SUBNET end-to-end; doctor learns the gateway-squat signature 2026-07-18 20:34:09 +00:00

Merged #87 fix: base the human auto-request on this handoff, not review history 2026-07-18 20:33:29 +00:00

Merged #85 feat: label automation — state reconciler, path-scoped labeler, and CONTRIBUTING 2026-07-18 20:14:26 +00:00

Merged #82 feat: BOX_REQUIRE_VM / BOX_AUTOSTART template keys + dynamic template test suite 2026-07-18 19:08:42 +00:00

Merged #78 feat: box export / import — state that survives the box and the host (#70) 2026-07-18 19:01:57 +00:00

Merged #79 feat: versioned installs, and a real uninstall 2026-07-18 18:52:48 +00:00

Merged #84 docs: LABELS.md — the label taxonomy (states, stale/blocked, scopes) 2026-07-18 18:19:54 +00:00

Merged #75 Restricted incus tier: per-user projects converged onto hardened boxnet (#74) 2026-07-18 13:21:16 +00:00

Merged #66 Make host setup complete in one run, and let the installer run it 2026-07-18 00:24:39 +00:00

Merged #73 feat: global install (#71), tmux (#65), CI + tests; folds #66 2026-07-18 00:24:38 +00:00

Merged #62 fix(doctor): a fresh host is not a dirty one 2026-07-15 00:57:48 +00:00

Merged #61 fix(install): the rename broke every install — stop guessing the tarball's top dir 2026-07-15 00:39:39 +00:00

Merged #60 docs(readme): how to run the drill against the latest version 2026-07-15 00:29:13 +00:00

Merged #58 docs: make the box narrative agent-agnostic, not Claude-specific 2026-07-15 00:24:44 +00:00

Merged #59 feat(new): inline resource overrides — --cpu, --memory, --disk 2026-07-15 00:22:57 +00:00

Merged #56 release: box 0.5.0 — codex+grok templates, migrate-host, box expose 2026-07-15 00:04:54 +00:00

Merged #52 feat!: claudebox becomes box — the Claude box is one template among several 2026-07-14 15:44:10 +00:00

Merged #51 fix: create the storage pool deliberately — btrfs, because cloning is the whole point 2026-07-14 13:24:32 +00:00

Merged #50 feat: 'claudebox doctor' — the host-health checks as a first-class verb 2026-07-14 13:24:17 +00:00

Merged #49 feat: 'claudebox tmux <box> [session]' — a shell that survives you 2026-07-14 13:23:58 +00:00

Merged #48 docs(drill): record runs 11–13 — the contract measured at zero, from a bare host 2026-07-14 13:01:42 +00:00

Merged #47 docs(readme): the isolation contract as it ships — and measured, not claimed 2026-07-14 13:01:29 +00:00

Merged #45 fix: pin claudenet's resolver — a box's DNS is not a function of the host's VPN 2026-07-14 12:22:47 +00:00

Merged #44 fix(drill): stop demanding an empty host — assert OUR boxes, not NO boxes 2026-07-14 12:12:06 +00:00

Merged #43 fix(doctor): the gateway does not answer ping — by design, so stop asking 2026-07-14 11:59:27 +00:00

Merged #42 fix(doctor): pin the probes' stdin — an interactive exec cannot be timed out 2026-07-14 11:54:37 +00:00

Merged #41 fix(drill): read curl's message — the exit code cannot tell you what happened 2026-07-14 11:28:37 +00:00

Merged #40 fix(doctor): four checks that lied, and none of them about a real fault 2026-07-14 11:28:24 +00:00

Merged #36 docs(drill): the audit is complete — boxes are not isolated from each other 2026-07-14 11:28:10 +00:00

Merged #39 fix(doctor): read the isolation off the bridge, not off the config 2026-07-14 02:18:30 +00:00

Merged #38 fix: isolate boxes with the bridge's port-isolation flag 2026-07-14 01:42:35 +00:00

Merged #37 fix: boxes could reach each other — isolate them at the bridge 2026-07-14 01:30:29 +00:00

Merged #35 fix(doctor): check that something is actually serving the network 2026-07-14 01:23:51 +00:00

Merged #34 fix: a failed cold mint must say why; doctor gains DNS diagnosis and --pin-dns 2026-07-14 01:01:35 +00:00

Merged #32 fix(drill): stop poisoning the host, and add a doctor to prove it 2026-07-14 00:33:31 +00:00

Merged #31 fix(drill): refuse to judge #16 on a broken baseline 2026-07-14 00:06:02 +00:00

Merged #30 fix: the clone identity reset could never reboot, so it never took effect 2026-07-14 00:05:48 +00:00

Merged #28 fix(drill): the NIC inside a VM is enp5s0, not eth0 — read the address by subnet 2026-07-13 23:33:40 +00:00

Merged #27 fix: a clone must not inherit its source's identity (two boxes, one IP) 2026-07-13 23:33:28 +00:00

Merged #25 fix(drill): clean the host before setup-host, and bound it 2026-07-13 23:10:19 +00:00

Merged #24 fix(drill): stop going silent through host setup, and keep the run log in the repo 2026-07-13 23:07:46 +00:00

Merged #23 fix(drill): delete every listener — refused-vs-dropped already answers it 2026-07-13 23:03:15 +00:00

Merged #22 fix(drill): no in-box probe can hang the run again 2026-07-13 22:57:17 +00:00

Merged #21 fix(drill): read eth0 from inside the box; settle the flaky dns.mode verdict 2026-07-13 22:41:57 +00:00

Merged #20 fix: run-2 cascade (per-name cleanup), and claude on exec's PATH 2026-07-13 22:30:17 +00:00

Merged #19 fix: first-run drill defects — pipefail false FAILs, exec-pty hang, DHCP race 2026-07-13 22:07:32 +00:00

Merged #18 test: add an end-to-end drill against a real Incus 2026-07-13 21:34:44 +00:00

Merged #13 feat: make the command surface a table, add rename and an escape hatch 2026-07-13 20:56:46 +00:00

Merged #10 fix: standard help, honest flags, and an rm that asks first 2026-07-13 20:43:14 +00:00

Merged #9 feat: add claudebox list, with snapshot labels 2026-07-13 20:43:00 +00:00

Merged #5 fix: preinstall the GitHub CLI in boxes 2026-07-11 11:25:40 +00:00

Merged #4 feat: drop the claude- instance-name prefix 2026-07-10 17:11:30 +00:00

Merged #2 fix: install from the public canonical repo 2026-07-10 16:00:21 +00:00

Merged #1 Import claudebox: creds-free, trust-less Claude Code VMs 2026-07-10 15:01:39 +00:00

57 issues closed from 1 user

Closed #135 changelog: seed ## Unreleased with all three section headings, and let the -dev bump write them 2026-08-18 00:28:43 +00:00

Closed #145 labels: state:needs-human is sticky again — the reconciler cannot tell its own human-request from a maintainer's 2026-08-17 22:31:17 +00:00

Closed #156 Box import command not working 2026-08-17 22:29:03 +00:00

Closed #130 box: mark bootstrapped after a successful rig hook 2026-07-21 12:21:33 +00:00

Closed #131 box import records nothing about the import event — and origin=import is the wrong fix 2026-07-21 12:09:31 +00:00

Closed #104 Snapshot 'pristine' at mint, before the rig bootstrap hook 2026-07-21 11:49:24 +00:00

Closed #124 The racing-reader sweep pins '| grep' only, and the same shape exists outside ufw (revoke-user.sh:206) 2026-07-21 11:25:06 +00:00

Closed #103 A minted box records nothing about how it was minted 2026-07-21 11:24:41 +00:00

Closed #107 drill/wipe.sh carries the #102 SIGPIPE shape — safe only because it lacks pipefail 2026-07-21 10:55:35 +00:00

Closed #113 teardown-host.sh has no [ -t 0 ] gate: a non-interactive run without --yes dies mute 2026-07-20 23:38:15 +00:00

Closed #143 changelog-monotonic: the uniqueness half is gated behind base-side conditions it does not need 2026-07-20 23:37:44 +00:00

Closed #141 labels: sweep on labeled so the handoff is immediate, and let the author set state:needs-human 2026-07-20 20:32:21 +00:00

Closed #136 labels: state:needs-human is sticky and blind to mergeability, and nothing says which PR to merge next 2026-07-20 17:02:54 +00:00

Closed #115 An upgrade over a pre-0.7.0 flat /opt/box skips setup-host: box --version says 0.8.0 while box-firewall stays pre-#102 2026-07-20 14:43:13 +00:00

Closed #117 The pre-0.7.0 migration manufactures a version entry nobody installed, and never mentions it 2026-07-20 14:43:13 +00:00

Closed #122 changelog-armed.sh does not notice a deleted release heading — a PR can erase a shipped section and CI stays green 2026-07-20 14:15:58 +00:00

Closed #116 CI's shellcheck sweep never lints .github/scripts/*.sh — globstar does not descend into dot-directories 2026-07-20 13:53:48 +00:00

Closed #123 templates: suffix the seeds -box, and follow rig's tenant role rename 2026-07-20 13:09:31 +00:00

Closed #111 confirm() swallows Ctrl-D: an interactive abort exits 1 in silence, never reaching 'aborted.' 2026-07-19 21:27:59 +00:00

Closed #108 The ceremony disarms CHANGELOG.md: a PR predating a release lands its Unreleased entry inside the shipped section, silently 2026-07-19 21:07:12 +00:00

Closed #105 box restore destroys without asking 2026-07-19 20:26:01 +00:00

Closed #102 box-firewall takes the no-UFW branch on a UFW host (SIGPIPE under pipefail); surfaced as a test flake 2026-07-19 18:54:48 +00:00

Closed #99 box grant refuses incus-admin members, leaving them with no project 2026-07-19 18:05:35 +00:00

Closed #100 Box manifest 2026-07-19 17:58:08 +00:00

Closed #96 Merging a release-labeled PR should BE the release — auto-tag + publish on merge, version transition as the interlock 2026-07-19 17:12:30 +00:00

Closed #92 0.6.0 setup-host leaves a stale ACL gateway carve-out when boxnet's subnet moved — fixed on main, evidence for cutting 0.6.1 2026-07-19 15:48:07 +00:00

Closed #93 Intermittent: 'box new' hangs before the instance exists — incus launch client wedges with no server-side operation 2026-07-19 13:13:03 +00:00

Closed #83 release flow: install-from-tag, release automation, and a -dev version convention 2026-07-18 22:32:55 +00:00

Closed #81 thin templates — tenant content moves to rig bootstrap roles; templates shrink to creds-free seeds 2026-07-18 21:08:45 +00:00

Closed #80 Running box setup-host inside a box creates a nested boxnet on the same hardcoded 10.88.0.0/24 as the guest's own uplink, causing intermittent egress blackouts 2026-07-18 20:34:10 +00:00

Closed #68 Server-class boxes: staging template for control-plane-managed staging VMs 2026-07-18 19:11:04 +00:00

Closed #70 box export: a box's state that survives the box (and the host) 2026-07-18 19:01:58 +00:00

Closed #67 Version-aware install: migrate boxes across an upgrade instead of refusing 2026-07-18 14:31:29 +00:00

Closed #77 Oh my zsh is nnot being properly configured in the claude template 2026-07-18 14:30:13 +00:00

Closed #65 Fix: Box should come with tmux installed to support the box tmux command 2026-07-18 14:22:17 +00:00

Closed #71 Global install: root branch in install.sh for multi-user hosts 2026-07-18 14:20:56 +00:00

Closed #76 Surface the box version 2026-07-18 14:20:44 +00:00

Closed #72 Multi-user hosts: make box work in per-user Incus projects (restricted incus tier) 2026-07-18 13:27:54 +00:00

Closed #74 Restricted incus tier: redesign around incus-user's per-user bridge (Task-0 findings) 2026-07-18 13:21:17 +00:00

Closed #64 Andres: The install.sh file should run the box setup-host itself (avoid user interaction) 2026-07-18 00:24:40 +00:00

Closed #63 Andres: Fix the doblue box setup-host command 2026-07-18 00:24:39 +00:00

Closed #57 box new: inline resource overrides (--cpu / --memory / --disk) 2026-07-15 00:22:58 +00:00

Closed #55 'box expose <box> <port>' — a deliberate, loopback-only door to a box's dev server 2026-07-15 00:04:56 +00:00

Closed #53 host/migrate-host.sh — re-home legacy boxes onto the new stack, then retire the old one 2026-07-15 00:04:55 +00:00

Closed #54 Two new templates: codex (OpenAI Codex CLI) and grok (xAI's CLI) 2026-07-15 00:04:55 +00:00

Closed #17 Reframe claudebox as box: the Claude box is one template among several 2026-07-14 15:44:11 +00:00

Closed #29 setup-host takes 'dir' storage — every clone is a full disk copy, and cloning is the whole point 2026-07-14 13:24:33 +00:00

Closed #46 claudebox needs a 'doctor' verb — every fault the drill's doctor catches is a user's fault too 2026-07-14 13:24:18 +00:00

Closed #6 Add 'claudebox tmux <box> [session]' — attach-or-create a named tmux session in the box 2026-07-14 13:23:59 +00:00

Closed #33 On a Tailscale host, boxes inherit the tailnet's DNS — flaky resolution, and tailnet names resolve from inside a box 2026-07-14 12:22:48 +00:00

Closed #26 Incus daemon wedged on the drill host — forensics before reprovisioning 2026-07-14 12:10:28 +00:00

Closed #16 🔴 Boxes are NOT isolated from each other — sibling isolation does not hold (confirmed live) 2026-07-14 12:10:26 +00:00

Closed #15 Audit the isolation stack: verify the box boundary behaves as designed 2026-07-13 23:03:16 +00:00

Closed #12 Reframe claudebox as box: the Claude box is one template, and sibling isolation should be deliberate 2026-07-13 21:17:50 +00:00

Closed #11 Stop proxying incus one verb at a time: a rule for what claudebox owns, a table to add it, and a door out 2026-07-13 20:56:47 +00:00

Closed #8 claudebox help is a sed of its own header, and the flags it advertises are not real 2026-07-13 20:43:15 +00:00

Closed #7 Add claudebox list — no way to see your boxes, and none at all to see their snapshots 2026-07-13 20:43:01 +00:00

9 issues created by 2 users