-
Notifications
You must be signed in to change notification settings - Fork 8.2k
gordon: revise gordon docs for gordon v2/ga #24074
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
✅ Deploy Preview for docsdocker ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Signed-off-by: David Karlsson <35727626+dvdksn@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Documentation Review
This is a comprehensive revision for Gordon v2/GA. The documentation is well-structured and clear overall. I found a few issues in the newly added content that could improve clarity.
Summary
- CONFIRMED: 1 medium-severity issue (undefined term)
- LIKELY: 3 medium-severity issues (consistency, clarity)
All issues are in newly added content.
|
|
||
|  | ||
|
|
||
| Gordon still requests approval before running allow-listed tools, unless YOLO |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Undefined term
The phrase "YOLO mode" is used here without explanation. While it's defined later in permissions.md ("bypass permission checking altogether"), readers of this page may not understand what it means.
Consider:
- Defining it on first use: "YOLO mode (auto-approve mode that bypasses permission checks)"
- Linking to the permissions page where it's explained
- Using the more descriptive "auto-approve mode" consistently
| - Data is anonymized and cannot be traced back to you or your account. | ||
| - Docker does not use this data to train AI models or share it with third | ||
| parties. | ||
|  |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inconsistent image formatting
This image reference lacks the ?border=true parameter that's used for the terminal screenshot at line 72. The permissions image at line 84 also lacks it.
For consistency, consider either:
- Adding
?border=trueto all screenshots - Removing it from all screenshots
- Documenting when borders should/shouldn't be used
| | Business | 6x | Six times Personal tier usage | | ||
|
|
||
| > [!NOTE] | ||
| > Limits are per user, not per organization for Team and Business |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Potentially unclear tier distinction
The note mentions "Limits are per user, not per organization for Team and Business" but the table shows Pro and Team both have 3x multipliers. While the distinction is about scope (per-user vs per-organization) rather than the multiplier value, this could confuse readers.
Consider clarifying: "Team provides the same multiplier as Pro (3x), but limits apply per individual user rather than being shared across the organization."
|
|
||
| Command execution: | ||
| Commands run with your user permissions. Gordon has no elevated privileges | ||
| unless you explicitly grant them. Avoid granting `sudo` access without careful |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Vague security guidance
The warning "Avoid granting sudo access without careful review" doesn't specify what constitutes careful review. While the "Verify before approving" checklist below provides general guidance, it doesn't specifically address sudo concerns.
Consider making this more actionable: "Avoid granting sudo access. If necessary, verify the command is essential, understand its full scope, and confirm there's no alternative without elevated privileges."
Signed-off-by: David Karlsson 35727626+dvdksn@users.noreply.github.com