{"_id":"@claude-orchestrator/cco","_rev":"4-59324f0424d9d498ab7d191af8764fce","name":"@claude-orchestrator/cco","dist-tags":{"latest":"0.6.0"},"versions":{"0.5.0":{"name":"@claude-orchestrator/cco","version":"0.5.0","keywords":["claude","claude-code","orchestrator","docker","cco","ai","agents","developer-tools"],"author":{"name":"alergyonthestage"},"license":"MIT","_id":"@claude-orchestrator/cco@0.5.0","maintainers":[{"name":"alergy._","email":"alergy.official@gmail.com"}],"homepage":"https://github.com/alergyonthestage/claude-orchestrator#readme","bugs":{"url":"https://github.com/alergyonthestage/claude-orchestrator/issues"},"os":["darwin","linux"],"bin":{"cco":"bin/cco"},"dist":{"shasum":"fb2155de7e38aeaea08d8e1893519d6e06290718","tarball":"https://registry.npmjs.org/@claude-orchestrator/cco/-/cco-0.5.0.tgz","fileCount":183,"integrity":"sha512-h1GSQQQLW9OmDhW3uT4TDJobHAOUGQMFQxx7ysOTKRnC4itrIIsEFoWEzEd6CSLtFVku1ejjN/ghuTqjsQav9g==","signatures":[{"sig":"MEQCIDXxdCkFdj/NlyLStb5DejN/Y6s4kqg3tRXEFxEfj+tFAiAYruZJWwgLzod2Tko4zhQZTyh9FGYn34O69I4ta9bVMA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1401590},"engines":{"node":">=18"},"gitHead":"001d2fdb99f599b4078bc29b2d7ffd7afb3f5305","_npmUser":{"name":"alergy._","email":"alergy.official@gmail.com"},"repository":{"url":"git+https://github.com/alergyonthestage/claude-orchestrator.git","type":"git"},"_npmVersion":"11.5.2","description":"Isolated, preconfigured Claude Code sessions in Docker — multi-repo orchestration with a managed context hierarchy, knowledge packs, and agent teams.","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cco_0.5.0_1782823135123_0.3651449491016241","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@claude-orchestrator/cco","version":"0.5.1","keywords":["claude","claude-code","orchestrator","docker","cco","ai","agents","developer-tools"],"author":{"name":"alergyonthestage"},"license":"MIT","_id":"@claude-orchestrator/cco@0.5.1","maintainers":[{"name":"alergy._","email":"alergy.official@gmail.com"}],"homepage":"https://github.com/alergyonthestage/claude-orchestrator#readme","bugs":{"url":"https://github.com/alergyonthestage/claude-orchestrator/issues"},"os":["darwin","linux"],"bin":{"cco":"bin/cco"},"dist":{"shasum":"61b7772d5956bc2678141c2a6b1d5663eee14f3c","tarball":"https://registry.npmjs.org/@claude-orchestrator/cco/-/cco-0.5.1.tgz","fileCount":183,"integrity":"sha512-cN0w6fYQ8rYsnK2O9S0vdH2AmgNxnEfufDpV0CAIcKZI6Z4XiA4hIyDYLN7N6e6OqoZ9o5xUupmhrk5D6C6iqg==","signatures":[{"sig":"MEQCID9/mbP31ZFqKNGuU4QJhlS9dG26cwdqxvuqXubJQVnIAiAnTUKDbaruHsE86TXg9XoolMuXoPWqK9VaYCOeWx+1fg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@claude-orchestrator%2fcco@0.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1401590},"engines":{"node":">=18"},"gitHead":"f5f79b3b401fdf9997b7cea6f265d5ab559f9749","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:917f7f1d-95df-492e-b34f-9c6a4c93d9d6"}},"repository":{"url":"git+https://github.com/alergyonthestage/claude-orchestrator.git","type":"git"},"_npmVersion":"11.18.0","description":"Isolated, preconfigured Claude Code sessions in Docker — multi-repo orchestration with a managed context hierarchy, knowledge packs, and agent teams.","directories":{},"_nodeVersion":"24.17.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cco_0.5.1_1782842147496_0.47462973854689827","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"@claude-orchestrator/cco","version":"0.5.2","keywords":["claude","claude-code","orchestrator","docker","cco","ai","agents","developer-tools"],"author":{"name":"alergyonthestage"},"license":"MIT","_id":"@claude-orchestrator/cco@0.5.2","maintainers":[{"name":"alergy._","email":"alergy.official@gmail.com"}],"homepage":"https://github.com/alergyonthestage/claude-orchestrator#readme","bugs":{"url":"https://github.com/alergyonthestage/claude-orchestrator/issues"},"os":["darwin","linux"],"bin":{"cco":"bin/cco"},"dist":{"shasum":"90245b3f0ed0654b55dce8676d8121e61635d32f","tarball":"https://registry.npmjs.org/@claude-orchestrator/cco/-/cco-0.5.2.tgz","fileCount":183,"integrity":"sha512-CtBQqPSzwc33jqRntuXYnUVX7qEf1sUHJ+Zs/TJKWb79Vcm+X1Mkdxf/C7XB08owHHusOIZvXtwFphzKtlqARg==","signatures":[{"sig":"MEYCIQCO5ssYTvopi8t+/YavYXlI/PAgU9un/ZhiMVH/enUmzgIhAJyVXsKJgxyCM6joIRNMEx56VvFbE203KEsvKmS/8fiS","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@claude-orchestrator%2fcco@0.5.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1407360},"engines":{"node":">=18"},"gitHead":"80bc101a9267642f34c4f9e878bdb3ffba365fe2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:917f7f1d-95df-492e-b34f-9c6a4c93d9d6"}},"repository":{"url":"git+https://github.com/alergyonthestage/claude-orchestrator.git","type":"git"},"_npmVersion":"11.18.0","description":"Isolated, preconfigured Claude Code sessions in Docker — multi-repo orchestration with a managed context hierarchy, knowledge packs, and agent teams.","directories":{},"_nodeVersion":"24.17.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cco_0.5.2_1782853386756_0.17821584861539685","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@claude-orchestrator/cco","version":"0.6.0","description":"Isolated, preconfigured Claude Code sessions in Docker — multi-repo orchestration with a managed context hierarchy, knowledge packs, and agent teams.","keywords":["claude","claude-code","orchestrator","docker","cco","ai","agents","developer-tools"],"bin":{"cco":"bin/cco"},"os":["darwin","linux"],"engines":{"node":">=18"},"license":"MIT","author":{"name":"alergyonthestage"},"homepage":"https://github.com/alergyonthestage/claude-orchestrator#readme","repository":{"type":"git","url":"git+https://github.com/alergyonthestage/claude-orchestrator.git"},"bugs":{"url":"https://github.com/alergyonthestage/claude-orchestrator/issues"},"gitHead":"71d00ff4ae30c9a367fc52718e1f0821a8f0a523","_id":"@claude-orchestrator/cco@0.6.0","_nodeVersion":"24.18.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-3Jzr0w7FQ1jmK60UtNfEOGyCI4QiBqAhkxk29B98fPb1HT1GEnzTZHGGfBJTkxbkMzA5tjBotkVnRpAEFxWBBw==","shasum":"72e1f781ab1e8d4b383660988df52eba6dcb96e1","tarball":"https://registry.npmjs.org/@claude-orchestrator/cco/-/cco-0.6.0.tgz","fileCount":193,"unpackedSize":2060780,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@claude-orchestrator%2fcco@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDpFDCvrZbgPYraUfUDGpCSdutAlH4cAaB17spvwqmivAiEA8hsHO/jUFFVKzCCuYZVXfljF2/NgGBwiyxzN8Wn9Zdk="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:917f7f1d-95df-492e-b34f-9c6a4c93d9d6"}},"directories":{},"maintainers":[{"name":"alergy._","email":"alergy.official@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cco_0.6.0_1785832913894_0.9811509858946439"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-30T12:38:54.884Z","modified":"2026-08-04T08:41:54.672Z","0.5.0":"2026-06-30T12:38:55.263Z","0.5.1":"2026-06-30T17:55:47.679Z","0.5.2":"2026-06-30T21:03:06.977Z","0.6.0":"2026-08-04T08:41:54.057Z"},"bugs":{"url":"https://github.com/alergyonthestage/claude-orchestrator/issues"},"author":{"name":"alergyonthestage"},"license":"MIT","homepage":"https://github.com/alergyonthestage/claude-orchestrator#readme","keywords":["claude","claude-code","orchestrator","docker","cco","ai","agents","developer-tools"],"repository":{"type":"git","url":"git+https://github.com/alergyonthestage/claude-orchestrator.git"},"description":"Isolated, preconfigured Claude Code sessions in Docker — multi-repo orchestration with a managed context hierarchy, knowledge packs, and agent teams.","maintainers":[{"name":"alergy._","email":"alergy.official@gmail.com"}],"readme":"# claude-orchestrator\n\n> Per-project, Docker-isolated Claude Code environments — multi-repo context, shareable team config, and safe autonomy, ready at startup.\n\n**The problem.** Claude Code is powerful, but its context, memory, and\npermissions are tied to a single working directory on your local machine. Juggle\nseveral projects, clients, or multi-repo stacks and you end up re-explaining the\nsame context every session, leaking one project's memory into another, and\nchoosing between babysitting permission prompts or running\n`--dangerously-skip-permissions` unsandboxed on your host.\n\n**What cco does.** Every project gets its own isolated session with the right\nrepos mounted, the right instructions and docs loaded, its own memory, and a\n`project.yml` you can commit so your whole team gets the identical environment.\n`cco start client-a` and `cco start client-b` are completely separate contexts\nwith zero overlap.\n\ncco provides the mechanisms (Docker isolation, context hierarchy, knowledge\npacks, agent teams) and ships with **recommended defaults** tested through\nreal-world agentic development. Every rule, skill, agent, and default is fully\ncustomizable — adopt what works, change what doesn't.\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)\n\n<!-- TODO: add a short demo GIF here (cco start tutorial / a session launching) -->\n\n## Why not just native Claude Code + shell scripts?\n\ncco is **built on** Claude Code, not a replacement — it maps its configuration\ntiers directly onto Claude Code's native settings resolution\n(managed → user → project → nested) instead of reimplementing them. You *could*\nglue the rest together with shell scripts; cco is that glue, hardened and shared:\n\n- **Multi-repo, not single-dir.** A flat `/workspace` with every repo mounted\n  and one cross-repo `CLAUDE.md`, instead of one working directory at a time.\n- **Isolated memory per project.** Insights from one client never leak into\n  another — sessions are fully independent.\n- **Config you can commit.** `project.yml` and the project's `.cco/` tree ride\n  your normal git, so the environment is reproducible and shareable, not trapped\n  on your laptop.\n- **Safe autonomy.** Docker *is* the sandbox, so\n  `--dangerously-skip-permissions` is safe — no permission prompts, no risk to\n  your host.\n- **Lifecycle handled.** Socket GID fixes, secret detection, knowledge-pack\n  distribution, and versioned updates/migrations are done for you, not\n  re-discovered in every script.\n\n## Status\n\n**Alpha (v0.6.0)** — Under active development and already used daily by the\nauthor for real-world agentic development. It works well in practice, but APIs,\nconfiguration format, and defaults may change between releases. cco is\ndistributed on npm as [`@claude-orchestrator/cco`](https://www.npmjs.com/package/@claude-orchestrator/cco);\nit ships the decentralized in-repo config model (project config lives in each\nrepo's `.cco/`) and the native Claude Code installer (auto-updates in place).\n\n**Platform support:** macOS is the verified platform. Linux runs sessions but\ncco's own in-session commands do not work there yet — the detail is below, and\nthe [OS compatibility](#os-compatibility) table says the same thing.\n\n- **macOS** — the verified platform and primary development environment. OAuth login supported (via Keychain).\n- **Linux** — **partially supported.** Sessions start and Claude Code works on your repos, but the `cco` command *inside* a session cannot reach cco's own internal store. Every verb that reads the machine-local index (`cco list`, `cco path list`, `cco project show`, `cco project validate`…) and every config **write** refuses with an error. The store is created mode `0700` for an elevated identity (`cco-svc`, uid 900) that a session running as your own uid cannot search. The refusal is deliberate and names the limitation: until recently those verbs answered *\"the path index is empty — nothing is registered on this machine yet\"* at exit 0, which was a confident wrong answer. `cco` on your **host** is unaffected. Fixing this needs host-side setup and is scheduled for the next development cycle as a dedicated architecture decision, not a patch. Separately, OAuth login is not yet available on Linux; authentication requires an API key (`ANTHROPIC_API_KEY`, via `cco start --api-key`). Linux OAuth support with subscription-based login is planned — see the [roadmap](docs/maintainers/roadmap.md).\n- **Windows** — use via WSL2 + Docker Desktop (see [Requirements](#requirements)). WSL2 runs as Linux, so the Linux caveats above apply.\n\n**Planned before stable release:** network hardening (internet access control per project), E2E integration tests, Linux internal-store reachability, Linux OAuth support. See the [roadmap](docs/maintainers/roadmap.md) for the full plan.\n\nFeedback, bug reports, and contributions are welcome! See [CONTRIBUTING.md](CONTRIBUTING.md).\n\n## Quick Start\n\nEach step earns its place — here's what you get from it:\n\n```bash\n# 1. Install the CLI from npm — this is the `cco` command and its defaults\nnpm install -g @claude-orchestrator/cco\n\n# 2. Initialize — run this INSIDE the repo you want Claude to work in.\n#    It scaffolds that repo's committed .cco/ config and registers it on this\n#    machine; on your very first run it also seeds your personal ~/.cco store\n#    from the defaults and builds the Docker image.\ncd ~/projects/my-repo\ncco init\n\n# 3. Learn by doing — the interactive tutorial walks you through everything\ncco start tutorial\n```\n\n> `cco init` is the **project** entry verb and works on the current directory — it is\n> not a global setup step to run from wherever you happen to be. The global store is\n> seeded as a first-run side effect, not as the point of the command.\n\n> **Prefer to install from source?** Clone the repo and put `bin/` on your PATH\n> instead of installing from npm — see the [maintainer setup](CONTRIBUTING.md#local-development)\n> in CONTRIBUTING.md.\n\n### Keeping cco up to date\n\ncco has **three independent update tracks** — don't confuse them, and don't stop\nafter the first:\n\n```bash\n# Upgrade the engine, migrate your config, then rebuild the image:\nnpm update -g @claude-orchestrator/cco && cco update && cco build\n```\n\n- `npm update -g @claude-orchestrator/cco` upgrades the **engine** (the `cco`\n  command on your host and its shipped defaults).\n- `cco update` runs **migrations + config discovery** for your existing\n  projects; it does *not* upgrade the engine. After an engine upgrade it tells\n  you the exact command to run for your install method (npm / source).\n- `cco build` rebuilds the **Docker image**, and nothing else does it for you —\n  neither of the other two commands touches it. The image carries the copy of\n  cco that runs *inside* a session, the socket proxy, and the privilege boundary\n  around cco's internal store. Skip it and your sessions keep running the\n  previous release while your host runs the new one, with no warning that the\n  two disagree.\n- Claude Code itself is upgraded separately — the native installer auto-updates\n  it in place (see [Always-current Claude Code](#feature-highlights)).\n\n### The tutorial is your starting point\n\nThe built-in **tutorial project** is the recommended way to learn cco. It walks\nyou through creating and configuring your first project, setting up knowledge\npacks for your stack, customizing rules/skills/workflow, and understanding the\ncontext hierarchy — referencing the [user guides](docs/users/README.md) along the\nway so you finish with a config that reflects how you actually work.\n\n### Prefer to skip the tutorial?\n\n```bash\ncd ~/projects/my-repo         # a repo you want Claude to work in\ncco init                      # scaffold <repo>/.cco/ and ensure ~/.cco\ncco start my-repo\n```\n\nTo work on a project a teammate shared, clone its repo and run `cco start\n<project>` from inside it — cwd-first resolution registers it automatically.\nOther entry points: `cco join <project>` to add the current repo to an existing\nproject as a member, and `cco init --migrate <project>` to migrate a legacy\nproject into the in-repo layout.\n\n## Feature highlights\n\n| Feature | What it gives you | Learn more |\n|---|---|---|\n| **Multi-repo workspaces** | Group frontend, backend, infra, and docs into one project with a cross-repo `CLAUDE.md`. | [Project setup](docs/users/configuration/guides/project-setup.md) · [project.yml reference](docs/users/configuration/reference/project-yaml.md) |\n| **Four-tier context hierarchy** | Managed → Global → Project → Repo, mapped natively onto Claude Code's settings resolution. | [Context hierarchy](docs/users/foundation/reference/context-hierarchy.md) |\n| **Knowledge packs** | Reusable docs, rules, agents, and skills — define once, activate per project, share via a sharing repo. | [Knowledge packs](docs/users/packs/guides/knowledge-packs.md) |\n| **Shareable, versioned config** | Commit `project.yml` and `<repo>/.cco/` with your repo; version your personal `~/.cco` store with `cco config save/push/pull` and built-in secret detection. | [Configuration management](docs/users/configuration/guides/configuration-management.md) · [Configuring rules](docs/users/configuration/guides/configuring-rules.md) |\n| **Isolated memory** | Each project has its own memory and transcripts — no cross-project leakage. | [Concepts](docs/users/foundation/guides/concepts.md) |\n| **Agent teams** | tmux sessions with a lead plus teammates; optional iTerm2 on macOS. | [Agent teams](docs/users/integration/guides/agent-teams.md) · [Subagents](docs/users/integration/guides/subagents.md) |\n| **Docker-from-Docker** | The Docker socket is mounted, so Claude can run `docker compose` to spin up sibling services (databases, queues). | [Docker & networking](docs/users/environment/guides/docker-and-networking.md) · [Socket security](docs/users/security/guides/socket-security.md) |\n| **Flexible authentication** | OAuth (macOS Keychain), API key via env var, GitHub token for `gh`. | [Authentication](docs/users/integration/guides/authentication.md) |\n| **Extensible environment** | Per-project setup scripts, extra packages, and custom images. | [Custom environment](docs/users/environment/guides/custom-environment.md) |\n| **Always-current Claude Code** | Installed by the official native installer at first start into a persistent cache — it auto-updates in place, so you never rebuild to get a new version. Pin or switch channels via `~/.cco/claude-version`. | [CLI reference](docs/users/reference/cli.md) |\n| **Browser automation** | Drive Chrome via the DevTools Protocol from inside a session. | [Browser automation](docs/users/integration/guides/browser-automation.md) |\n| **Monolithic CLI** | A single Bash script (`bin/cco`) — no dependencies beyond Bash 3.2+, Docker, and standard Unix tools. | [CLI reference](docs/users/reference/cli.md) |\n\n## Use cases\n\n**Multi-project developer** — You work on 5+ projects with different stacks and\nconventions. Each has its own `project.yml`: repos mounted, rules loaded, ports\nmapped. `cco start client-a` vs `cco start client-b` — completely separate\ncontexts, zero overlap.\n\n**Team of developers** — Commit the project's `.cco/` to your shared repo. Every\nteammate runs `cco start` and gets the same environment: same repos, same\n`CLAUDE.md`, same rules and agents. No \"works on my machine\" for AI context.\n\n**Agency / consultant work** — Each client is a project. Client documentation\nlives in a knowledge pack. Claude knows the client's codebase, conventions, and\narchitecture from session one. Switch clients by switching projects.\n\n## How it works\n\n```mermaid\ngraph LR\n    subgraph Host\n        CLI[\"cco CLI\"]\n        GLOBAL[\"~/.cco<br/>(personal store)\"]\n        REPOS[\"Your repos<br/>(each with .cco/)\"]\n    end\n\n    subgraph DC[\"Docker Container\"]\n        CC[\"Claude Code<br/>with full context\"]\n        TMUX[\"tmux<br/>(agent team)\"]\n        DOCK[\"Docker CLI<br/>(infrastructure)\"]\n    end\n\n    CLI -->|generate & start| DC\n    GLOBAL -->|mount| CC\n    REPOS -->|mount read-write| DC\n    CC --- TMUX\n    CC --- DOCK\n```\n\n`cco start` reads the project's `project.yml`, validates repo paths, generates a\n`docker-compose.yml`, and launches a container. The entrypoint fixes the Docker\nsocket permissions and starts tmux, then runs\n`claude --dangerously-skip-permissions` — safe, because Docker is the sandbox.\nConfig is resolved across four tiers that map onto Claude Code's native\nsettings:\n\n| Orchestrator Layer | Host Source | Container Path | Claude Code Scope | Overridable? |\n|---|---|---|---|---|\n| `defaults/managed/` | baked in image | `/etc/claude-code/` | Managed (highest priority) | No — baked in image |\n| Global `.claude/` | `~/.cco/.claude/` | `~/.claude/` | User-level (always loaded) | Yes — user-owned |\n| Project `.claude/` | `<repo>/.cco/claude/` | `/workspace/.claude/` | Project-level (always loaded) | Yes — per-project |\n| Repo's own `.claude/` | `<repo>/.claude/` | `/workspace/<repo>/.claude/` | Nested (on-demand) | Yes — from repo |\n\nManaged settings (hooks, env vars, deny rules) have the highest priority and\ncannot be overridden; user and project settings are fully customizable. For the\nfull model see the [context hierarchy reference](docs/users/foundation/reference/context-hierarchy.md).\n\n## Documentation\n\n| You are a… | Start here |\n|---|---|\n| **User** — running cco, configuring projects | [docs/users/README.md](docs/users/README.md) — learning path + per-domain guides and references |\n| **Maintainer** — developing/contributing to cco | [docs/maintainers/README.md](docs/maintainers/README.md) — architecture, ADRs, design docs, roadmap |\n| **Contributor** — local dev setup & publishing | [CONTRIBUTING.md](CONTRIBUTING.md) — install from source, run the tests, cut a release |\n\nFull index: [docs/README.md](docs/README.md)\n\n## Requirements\n\n- **OS**: macOS 12+ or Linux — see [compatibility notes](#os-compatibility) below\n- **Node.js**: 18+ (only to install the CLI via `npm install -g`; `cco` itself is Bash and shells out to Docker)\n- **Docker**: Docker Desktop (macOS) or Docker Engine (Linux)\n- **Bash**: 3.2+ (the CLI is compatible with macOS default `/bin/bash`)\n- **Claude Code**: Pro, Team, Enterprise account, or API key\n\n## OS compatibility\n\n| OS | Status | Notes |\n|---|---|---|\n| **macOS 12+** | Fully supported — the verified platform | Keychain integration for OAuth, iTerm2 agent teams |\n| **Linux** | Partially supported | Sessions run and Claude Code works on your repos. `cco` **inside** a session cannot reach the internal store, so index-reading verbs and config writes refuse — the store is mode `0700` for the elevated identity `cco-svc` (uid 900), unsearchable by a session running as your uid. `cco` on the host is unaffected. No Keychain OAuth (`ANTHROPIC_API_KEY` required), no iTerm2 agent teams. See [Platform support](#status) |\n| **Windows (WSL2)** | Partially supported, not officially tested | Runs as Linux inside WSL2, so the Linux row applies; Docker Desktop with WSL2 backend required |\n| **Windows (native)** | Not supported | Would require a PowerShell rewrite; not planned |\n\n> **Windows users:** Install WSL2 + Docker Desktop with the WSL2 backend, then use cco from inside the WSL2 terminal. No changes to the tool are needed.\n\n## Security\n\nThe Docker socket is mounted into the container by default so Claude can manage\ninfrastructure (databases, services) via `docker compose`. This grants full\nDocker API access — equivalent to root on the host. If your workflow doesn't need\nDocker-from-Docker, disable it in `project.yml`:\n\n```yaml\ndocker:\n  mount_socket: false\n```\n\nOr per-session: `cco start my-project --no-docker`\n\nSecrets (API keys, tokens) should go in `secrets.env` files (gitignored,\n`chmod 600`), never in `setup.sh` (which is baked into the Docker image and\nvisible via `docker history`).\n\nFor the user-facing socket guidance see\n[socket security](docs/users/security/guides/socket-security.md); for the full\nthreat model and proxy design see the\n[security design](docs/maintainers/security/design/design-security-model.md).\n","readmeFilename":"README.md"}