Repository navigation
Releases: Judge-M/Oct26
Release list
v0.10.0-rehearsal — deployment candidate
This release distributes the custom integration, IRIS and CTFd container images
through GitHub Packages. distribution.json records their immutable digests,
source commit and the checksums of source.zip and fixtures.zip.
source.zip includes tracked source. Materialized Git LFS exercise assets are
separate asset-*.bin files, mapped to repository paths by distribution.json.
Each distribution file is capped at 1 GiB; desktop disks use ordered parts.
fixtures.zip includes generated fictional training evidence and authored tickets.
It contains exercise answers and facilitator-only release evidence: distribute it
to organizers, not as the participant evidence share.
This is a deployment candidate, not an event-ready or complete offline bundle.
The source includes a prepared Autopsy case with completed ingest and a saved
keyword index; see assets/README.md for its evidence mount and validation.
The native Windows reconstruction, prepared case and desktop build are documented
with their provenance. Upstream dependency containers and the combined deployment
still need the compatibility and completeness checks documented
in docs/expanded-deployment.md. Application provisioning remains an operator
procedure. GitHub Packages may initially require authentication until package
visibility is configured.
v0.9.1-drill — deployment candidate
Oct26 — v0.9.1-drill (deployment candidate 2)
Offline drill release for the Operation Silent Ridge defensive-cybersecurity event. Status: drill-uncertified — the ten-team capacity gate (F03) and dress rehearsal (F06) remain open; certified_complete: false is recorded honestly in the bundle manifest.
What changed since v0.9.0-drill
- Desktop container rebuilt with a capped Autopsy heap (
-Xmx2500m, was upstream-Xmx4Gthat could exceed the container limit and get OOM-killed). Measured with the WS17 case open: loaded desktop 1.72 GiB (was 1.95), idle 145 MiB. - The VM desktop QCOW2 is no longer in the release (−5.2 GB download). It was never boot-validated and container desktops are the event path; it remains in the repo at
assets/vm-desktop/(Git LFS) for a future validated Hyper-V/AWS path. - The v0.9.0 bundle's truncated 2-part desktop metadata bug is fixed at the source (store assembly reads the full part list from
assets/desktop-v1.json). - Hosting requirements in the README are now measurement-based: 32 GB RAM min / 64 GB comfortable, 100 GB free NVMe for ten teams.
What is in this release (~13 GB total)
asset-0000..0003.bin,distribution.json,fixtures.zip,source.zip— the source distribution.bundle-*.json— offline bundle metadata (bundle-release-manifest.json,bundle-SHA256SUMS.json,bundle-source-image-checks.json).validated-images.tar.part-001..008— all 13 Docker images (custom + upstream mirrors), 800 MB parts.bundle-source.zip.part-001..008— the full bundle source archive (~6 GB), 800 MB parts.bundle-dependencies…,bundle-disk-…,bundle-evidence-…,bundle-guides…— the remaining bundle payloads.- Custom images also on GHCR:
ghcr.io/judge-m/oct26-{integration,iris,ctfd}:v0.9.1-drill(package visibility is managed under the owner's Packages settings).
Offline install (clean machine)
- Download all assets of this release into one empty folder.
- Assemble the bundle directory:
bundle-release-manifest.json→release-manifest.jsonbundle-SHA256SUMS.json→SHA256SUMS.jsonbundle-source-image-checks.json→source-image-checks.jsonvalidated-images.tar.part-001..008→ same names, bundle root- concatenate
bundle-source.zip.part-001..008(in order) →source.zip asset-0001.bin→autopsy/WS17-prepared-case-v2.tar.gzasset-0003.bin→memory/WS17-native-v1.tar.gzbundle-dependencies-case-and-wazuh-config.tar.gz→dependencies/case-and-wazuh-config.tar.gzbundle-disk-WS17-fat16.img→disk/WS17-fat16.imgbundle-evidence-public.tar.gz→evidence/evidence-public.tar.gzbundle-guides.tar.gz→guides/guides.tar.gz- (
asset-0000.binandasset-0002.binare prior-version/exercise inputs the bundle does not need; keep or skip.)
- Verify + install (from a checkout of this tag, with Docker running):
python -m ridge.offline_install <bundle-dir> <install-dir>- The installer hashes every file against
SHA256SUMS.jsonbefore changing anything, then loads all images withdocker loadand writes an install receipt.
Known gaps (tracked)
- Drill-uncertified: ten-team capacity rehearsal (F03) and dress rehearsal (F06) still open.
- The parked VM QCOW2 (
assets/vm-desktop/) retains the old-Xmx4GAutopsy config and is unvalidated (hyperv_boot_validated: false,aws_import_validated: false) — it is not part of the event path. - The bundle was install-verified at build time (hashes, staging,
docker load→ all 13 image IDs). A full cold-download re-verification from this page follows the v0.9.0 procedure.
v0.9.0-drill — deployment candidate
Oct26 — v0.9.0-drill (deployment candidate)
Offline drill release for the Silent Ridge defensive-cybersecurity event. Status: drill-uncertified — the ten-team capacity gate (F03) and dress rehearsal (F06) are still open; certified_complete: false is recorded honestly in the bundle manifest.
What is in this release
asset-0000..0009.bin,distribution.json,fixtures.zip,source.zip— the source distribution (large tracked assets + fixtures + git source snapshot).bundle-*.json— offline bundle metadata (bundle-release-manifest.json,bundle-SHA256SUMS.json,bundle-source-image-checks.json).validated-images.tar.part-001..008— all 13 Docker images (custom + upstream mirrors), split into 800 MB parts.bundle-source.zip.part-001..008— the full bundle source archive (6 GB) in 800 MB parts.bundle-desktop / memory / autopsy / disk / evidence / guidespayloads are inside theasset-*.binandbundle-*files as mapped below.
Container images for the three custom services are also on GHCR as ghcr.io/judge-m/oct26-{integration,iris,ctfd}:v0.9.0-drill (package visibility may need to be flipped to public in Package settings).
Offline install (clean machine)
- Download all assets of this release into one empty folder.
- Assemble the bundle directory (mapping):
bundle-release-manifest.json→release-manifest.jsonbundle-SHA256SUMS.json→SHA256SUMS.jsonbundle-source-image-checks.json→source-image-checks.jsonvalidated-images.tar.part-001..008→ same names, bundle root- concatenate
bundle-source.zip.part-001..008(in order) →source.zip asset-0001.bin→autopsy/WS17-prepared-case-v2.tar.gzasset-0003.bin→desktop/silent-ridge-desktop-v1.qcow2.part001asset-0004.bin→desktop/silent-ridge-desktop-v1.qcow2.part002asset-0005.bin→desktop/silent-ridge-desktop-v1.qcow2.part003asset-0006.bin→desktop/silent-ridge-desktop-v1.qcow2.part004asset-0007.bin→desktop/silent-ridge-desktop-v1.qcow2.part005asset-0008.bin→desktop/silent-ridge-desktop-v1.qcow2.part006asset-0009.bin→memory/WS17-native-v1.tar.gzbundle-dependencies-case-and-wazuh-config.tar.gz→dependencies/case-and-wazuh-config.tar.gzbundle-disk-WS17-fat16.img→disk/WS17-fat16.imgbundle-evidence-public.tar.gz→evidence/evidence-public.tar.gzbundle-guides.tar.gz→guides/guides.tar.gz
- Verify + install (from a checkout of this tag, with Docker running):
python -m ridge.offline_install <bundle-dir> <install-dir>- The installer hashes every file against
SHA256SUMS.jsonbefore changing anything, then loads all images withdocker loadand writes an install receipt.
This exact flow was cold-tested from these release assets on 2026-09-21: all assets downloaded fresh, every hash verified, the desktop reassembled to its official full-image SHA-256, and docker load produced all 13 manifest image IDs.
Known gaps (tracked)
- The desktop qcow2 is the full official 6-part, 5.2 GB image (
assets/desktop-v1.json, sha2563cbe1ec5…); an earlier revision of these notes listed a truncated 2-part desktop — that was fixed and the reassembled image hash-verifies against the official manifest. - Bundle
source.zipis not attached as a single file (over the 2 GiB asset cap); use the 8 parts above.