Skip to content

v0.9.0-drill — deployment candidate

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 21 Sep 09:48
· 153 commits to main since this release
b95094d

Oct26 — v0.9.0-drill (deployment candidate)

Offline drill release for the Silent Ridge defensive-cybersecurity event. Status: drill-uncertified — the ten-team capacity gate (F03) and dress rehearsal (F06) are still open; certified_complete: false is recorded honestly in the bundle manifest.

What is in this release

  • asset-0000..0009.bin, distribution.json, fixtures.zip, source.zip — the source distribution (large tracked assets + fixtures + git source snapshot).
  • bundle-*.json — offline bundle metadata (bundle-release-manifest.json, bundle-SHA256SUMS.json, bundle-source-image-checks.json).
  • validated-images.tar.part-001..008 — all 13 Docker images (custom + upstream mirrors), split into 800 MB parts.
  • bundle-source.zip.part-001..008 — the full bundle source archive (6 GB) in 800 MB parts.
  • bundle-desktop / memory / autopsy / disk / evidence / guides payloads are inside the asset-*.bin and bundle-* files as mapped below.

Container images for the three custom services are also on GHCR as ghcr.io/judge-m/oct26-{integration,iris,ctfd}:v0.9.0-drill (package visibility may need to be flipped to public in Package settings).

Offline install (clean machine)

  1. Download all assets of this release into one empty folder.
  2. Assemble the bundle directory (mapping):
    • bundle-release-manifest.json → release-manifest.json
    • bundle-SHA256SUMS.json → SHA256SUMS.json
    • bundle-source-image-checks.json → source-image-checks.json
    • validated-images.tar.part-001..008 → same names, bundle root
    • concatenate bundle-source.zip.part-001..008 (in order) → source.zip
    • asset-0001.bin → autopsy/WS17-prepared-case-v2.tar.gz
    • asset-0003.bin → desktop/silent-ridge-desktop-v1.qcow2.part001
    • asset-0004.bin → desktop/silent-ridge-desktop-v1.qcow2.part002
    • asset-0005.bin → desktop/silent-ridge-desktop-v1.qcow2.part003
    • asset-0006.bin → desktop/silent-ridge-desktop-v1.qcow2.part004
    • asset-0007.bin → desktop/silent-ridge-desktop-v1.qcow2.part005
    • asset-0008.bin → desktop/silent-ridge-desktop-v1.qcow2.part006
    • asset-0009.bin → memory/WS17-native-v1.tar.gz
    • bundle-dependencies-case-and-wazuh-config.tar.gz → dependencies/case-and-wazuh-config.tar.gz
    • bundle-disk-WS17-fat16.img → disk/WS17-fat16.img
    • bundle-evidence-public.tar.gz → evidence/evidence-public.tar.gz
    • bundle-guides.tar.gz → guides/guides.tar.gz
  3. Verify + install (from a checkout of this tag, with Docker running):
    • python -m ridge.offline_install <bundle-dir> <install-dir>
    • The installer hashes every file against SHA256SUMS.json before changing anything, then loads all images with docker load and writes an install receipt.

This exact flow was cold-tested from these release assets on 2026-09-21: all assets downloaded fresh, every hash verified, the desktop reassembled to its official full-image SHA-256, and docker load produced all 13 manifest image IDs.

Known gaps (tracked)

  • The desktop qcow2 is the full official 6-part, 5.2 GB image (assets/desktop-v1.json, sha256 3cbe1ec5…); an earlier revision of these notes listed a truncated 2-part desktop — that was fixed and the reassembled image hash-verifies against the official manifest.
  • Bundle source.zip is not attached as a single file (over the 2 GiB asset cap); use the 8 parts above.