Back to the README.
No cache, no shared state: the vault is per request and ephemeral, policy is a JSON file, the audit log is a local file. One container, no Redis or database.
docker compose up -d --build # from a clone: cordon on 127.0.0.1:8080, audit log on a volume
./deploy.sh # idempotent clone/pull/build/healthcheck to a remote boxEvery tagged release publishes a multi-arch image (linux/amd64, linux/arm64) to GHCR with keyless Sigstore provenance and an SBOM. Verify it came from this repository's release workflow:
gh attestation verify oci://ghcr.io/askalf/cordon:v0.3.0 --repo askalf/cordonSharing one Claude or ChatGPT subscription through dario without leaking PII: dario's cordon integration guide.