-
Notifications
You must be signed in to change notification settings - Fork 1
Comparing changes
Open a pull request
base repository: NodeOps-app/createos-cli
base: v0.0.22
head repository: NodeOps-app/createos-cli
compare: main
- 20 commits
- 76 files changed
- 5 contributors
Commits on Aug 19, 2026
-
chore(deps): bump golang.org/x/mod from 0.38.0 to 0.40.0 (#74)
Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.38.0 to 0.40.0. - [Commits](golang/mod@v0.38.0...v0.40.0) --- updated-dependencies: - dependency-name: golang.org/x/mod dependency-version: 0.40.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 89211c3 - Browse repository at this point
Copy the full SHA 89211c3View commit details -
chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#72)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.54.0 to 0.55.0. - [Commits](golang/crypto@v0.54.0...v0.55.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.55.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 2bed022 - Browse repository at this point
Copy the full SHA 2bed022View commit details -
* Add managed sandbox process sessions * Polish sandbox process UX and remove skills command
Configuration menu - View commit details
-
Copy full SHA for dff5f0b - Browse repository at this point
Copy the full SHA dff5f0bView commit details -
feat(sandbox): match sandbox refs by ID or name prefix (#73)
Passing a partial sandbox ID did nothing useful: resolveSandboxRef returned any `sb-` prefixed ref verbatim, so `sandbox rm sb-01243e` reached the API as a literal and came back "not found". Resolve refs the way Docker resolves container refs. Precedence runs most-specific first: exact ID, unique ID prefix, exact name (newest wins on duplicates, as before), then unique name prefix. A prefix matching several sandboxes is refused with the candidates listed rather than guessed at, which matters most for `rm`. All 17 sandbox subcommands already funnel through resolveSandboxRef, so no call sites change. The matching rules move into a pure matchSandboxRef so they can be unit-tested: SandboxClient wraps a live resty client and offers no mock seam. Two details worth keeping: Errors are *api.APIError, not fmt.Errorf. api.UserMessage rewrites every other error type into a generic "something went wrong", and rm.go prints resolve failures through it, so a plain error would have been swallowed on exactly the command that needs it most. The pre-existing not-found error had the same defect and is fixed too. An ID that matches nothing is still returned verbatim, and an ID-shaped ref survives a failed list call. The visible list is capped at 200 rows, so the API must stay the authority on whether an ID exists instead of the CLI inventing a not-found.
Configuration menu - View commit details
-
Copy full SHA for 9eb09af - Browse repository at this point
Copy the full SHA 9eb09afView commit details
Commits on Aug 21, 2026
-
fix(sandbox): pin ssh known_hosts to sandbox id (#76)
Tunnel mode writes `HostName 127.0.0.1` for every sandbox, so all sandboxes share one known_hosts identity. After the first box is recorded, the next one presents a different host key on the same `[127.0.0.1]:22` entry and ssh reports REMOTE HOST IDENTIFICATION HAS CHANGED. OpenSSH downgrades that to a warning when public-key auth is used, but stricter clients treat a changed host key as an attack and refuse the connection outright. Orca's SSH relay is one of them, which makes a second CreateOS sandbox unusable as a remote host. VPN mode has the same defect with a longer fuse: it keys on the overlay IP, and those are recycled between sandboxes. Add `HostKeyAlias <sandbox-id>` to both blocks. OpenSSH then keys known_hosts on the sandbox id, which is unique and stable across pause/resume, instead of on a shared address. Reproduced against sb-01m0hp7v5vtdnj2pwpj25drhwe while integrating CreateOS sandboxes as Orca remote hosts.
Configuration menu - View commit details
-
Copy full SHA for b6f98bb - Browse repository at this point
Copy the full SHA b6f98bbView commit details
Commits on Aug 25, 2026
-
feat(sandbox): add Orca per-workspace environment (#78)
* feat(sandbox): add Orca per-workspace environment Add `createos setup orca`, which lets Orca run a workspace on a disposable sandbox instead of the user's laptop. The command has two halves: a human one that checks prerequisites and prints install instructions, and a hidden `--recipe` one that Orca calls for each lifecycle phase, selected by ORCA_VM_MODE. Create provisions a microVM, wires SSH through the gateway, waits for sshd, then packs and uploads the working tree and checks it out on a branch named after the workspace. The checkout is pushed rather than cloned, so no git token reaches the sandbox and private repositories need no extra setup; uncommitted edits travel with it. Suspend and resume are not declared. SSH does not reliably come back after a resume, and Orca requires the pair or neither. Coding agents are opt-in via --agents/CREATEOS_AGENTS. Orca passes no agent identity to a recipe, so this cannot be inferred. Installs run over SSH rather than the exec API: the two do not share a mount namespace outside /workspace, so anything the exec API installs is invisible to the session Orca launches the agent in. Each agent links into /usr/local/bin and is skipped when already present. Also pin ControlPath per sandbox in renderSSHBlock. Every tunnel-mode sandbox resolves to the same HostName/User, so a ControlPath built from %h/%r/%p -- including a common personal `Host *` default -- collides across sandboxes, and ssh reuses a stale multiplexed connection to a different, often destroyed, box. This affects `sandbox editor` today, independently of Orca. %n is the one token unique per sandbox. Same family as #76. probeSSH takes the wait as a parameter so the recipe can allow longer than the editor's default for a cold box. * fix(sandbox): satisfy repo lint rules in orca recipe errcheck runs with check-blank, so blank-assigned errors need an explicit nolint and a reason. Reuse the outer err instead of shadowing it, and drop the client argument orcaInstallAgents stopped using when agent installs moved from the exec API to SSH. No behaviour change. * refactor(sandbox): move setup under the sandbox group `createos setup orca` becomes `createos sandbox setup orca`. The command only ever configures sandboxes, so it belongs in the sandbox tree rather than as a second top-level group beside it. root.go is no longer touched by this feature: the group registers itself through NewSandboxCommand like every other sandbox subcommand, and NewSetupCommand becomes unexported. Document the shape in CLAUDE.md, since a harness integration is not like the other commands: it has a human half and a hidden machine half, the machine half owns stdout, and the command string is duplicated in a plugin that lives in another repo.
Configuration menu - View commit details
-
Copy full SHA for 713e82b - Browse repository at this point
Copy the full SHA 713e82bView commit details -
feat: make CLI tables responsive (#79)
* feat: make CLI tables responsive * fix: preallocate sandbox list table
Configuration menu - View commit details
-
Copy full SHA for 19e3451 - Browse repository at this point
Copy the full SHA 19e3451View commit details
Commits on Aug 26, 2026
-
feat(sandbox): add Herdr setup command (#80)
* feat(sandbox): add Herdr setup command * fix(sandbox): satisfy lint rules in Herdr setup
Configuration menu - View commit details
-
Copy full SHA for 9432293 - Browse repository at this point
Copy the full SHA 9432293View commit details -
fix(sandbox): honor --cwd/--env after the box name (#81)
urfave/cli stops parsing flags at the first positional argument, so every flag written after the sandbox name is discarded in silence: process run <box> --cwd /workspace -- pwd body: {"cmd":"pwd"} cwd lost process run --cwd /workspace <box> -- pwd body: {"cmd":"pwd","cwd":"/workspace"} cwd sent The process commands already carried raw-argv fallbacks for exactly this problem (processBoolFlag, processIntFlag, processStringFlag, rawProcessFlagValue). That is why --pty survived after the box name and --cwd did not: the cwd, cmd, and env reads never used them. Wire cwd and cmd to the existing processStringFlag. Add processStringSliceFlag and rawProcessFlagValues, because --env is repeatable and needs every occurrence, not just the first. Both raw readers stop at "--", so a sandbox command can never inject a flag. A test covers that. This is the same class of bug as #66, which hand-rolled parsing for the tunnel command. Two commands still carry it: sandbox sync reads --local/--remote/--mode with no fallback, and sandbox exec loses --stream. Left alone here, because the root fix is one argv reorder before parsing and it touches every command. Verified against a live sandbox: old, flag after box: "cwd": "/root" new, flag after box: "cwd": "/workspace" new, flag before box: "cwd": "/workspace" new, no flag: "cwd": "/root"Configuration menu - View commit details
-
Copy full SHA for 8c1f7ac - Browse repository at this point
Copy the full SHA 8c1f7acView commit details
Commits on Aug 27, 2026
-
feat: image run using - sandbox
run(#83)* feat(sandbox): add docker-style run command * fix(sandbox): clarify network attach order * fix(sandbox): limit network detach picker to members * fix(sandbox): show device counts in network picker * fix(sandbox): address run command lint * docs: add sandbox run usage
Configuration menu - View commit details
-
Copy full SHA for d7ac16f - Browse repository at this point
Copy the full SHA d7ac16fView commit details
Commits on Sep 2, 2026
-
Configuration menu - View commit details
-
Copy full SHA for e678271 - Browse repository at this point
Copy the full SHA e678271View commit details
Commits on Sep 6, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 167cfed - Browse repository at this point
Copy the full SHA 167cfedView commit details -
Add isolation-primitives blog diagrams for public CDN (#87)
createos-content is private, so raw GitHub URLs 404 for site visitors. Host these PNGs on public createos-cli for createos.sh blog figures. Co-authored-by: Roma from Marketing <roma@nodeops.xyz>
Configuration menu - View commit details
-
Copy full SHA for 5015abb - Browse repository at this point
Copy the full SHA 5015abbView commit details -
Add Blog B diagrams for when-coding-agents-need-firecracker (#88)
Public CDN assets for createos.sh (createos-content is private). Co-authored-by: Roma from Marketing <roma@nodeops.xyz>
Configuration menu - View commit details
-
Copy full SHA for c871a21 - Browse repository at this point
Copy the full SHA c871a21View commit details
Commits on Sep 7, 2026
-
Remove temporary blog-diagrams from createos-cli (#89)
Blog figures move to createos-v2-landing public/blog-diagrams (served at createos.sh). CLI is not an asset CDN. Co-authored-by: Roma from Marketing <roma@nodeops.xyz>
Configuration menu - View commit details
-
Copy full SHA for bb38864 - Browse repository at this point
Copy the full SHA bb38864View commit details
Commits on Sep 8, 2026
-
chore(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 (#90)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.55.0 to 0.56.0. - [Commits](golang/crypto@v0.55.0...v0.56.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.56.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0bab9b3 - Browse repository at this point
Copy the full SHA 0bab9b3View commit details
Commits on Sep 11, 2026
-
docs: add cross-repo mesh block
This repo had no mesh section, so an agent working here had no signal that a change can ripple into the SDKs, the CLI, the docs or the integrations. Adds a block generated from fc/mesh.json carrying the repo graph, what counts as a shared surface, the ripple order and the read-and-report protocol.
Configuration menu - View commit details
-
Copy full SHA for 9148db8 - Browse repository at this point
Copy the full SHA 9148db8View commit details
Commits on Sep 12, 2026
-
docs: stop restating internal tooling names in public repos
The leak-guard protocol step listed what to strip when copying out of the private control plane — internal tooling names, host paths, mTLS/CA internals. That list is only actionable with control-plane access, and restating it in a public repo publishes the very names the rule exists to keep out. Make the step audience-aware: the private repo keeps the strip-list, public repos get a step that tells a contributor without access to hand the change to someone who has it. Also skip rather than fail on repos that are not checked out, so a partial checkout can still regenerate.
Configuration menu - View commit details
-
Copy full SHA for bfa0c71 - Browse repository at this point
Copy the full SHA bfa0c71View commit details -
docs: regenerate mesh block with the shared CLI driver
packages/shared/sandbox-engine.ts is the shared driver the plugin packages build on and the most CLI-coupled code in the mesh, so a command or flag rename lands there first. Add it to the integrations table.
Configuration menu - View commit details
-
Copy full SHA for 8e8d1b1 - Browse repository at this point
Copy the full SHA 8e8d1b1View commit details
Commits on Sep 19, 2026
-
chore(deps): bump golang.org/x/crypto from 0.56.0 to 0.57.0 (#93)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.56.0 to 0.57.0. - [Commits](golang/crypto@v0.56.0...v0.57.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.57.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 202b2cb - Browse repository at this point
Copy the full SHA 202b2cbView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v0.0.22...main