Repository navigation
v0.9.0-drill — deployment candidate
Pre-release
Pre-release
·
153 commits
to main
since this release
Oct26 — v0.9.0-drill (deployment candidate)
Offline drill release for the Silent Ridge defensive-cybersecurity event. Status: drill-uncertified — the ten-team capacity gate (F03) and dress rehearsal (F06) are still open; certified_complete: false is recorded honestly in the bundle manifest.
What is in this release
asset-0000..0009.bin,distribution.json,fixtures.zip,source.zip— the source distribution (large tracked assets + fixtures + git source snapshot).bundle-*.json— offline bundle metadata (bundle-release-manifest.json,bundle-SHA256SUMS.json,bundle-source-image-checks.json).validated-images.tar.part-001..008— all 13 Docker images (custom + upstream mirrors), split into 800 MB parts.bundle-source.zip.part-001..008— the full bundle source archive (6 GB) in 800 MB parts.bundle-desktop / memory / autopsy / disk / evidence / guidespayloads are inside theasset-*.binandbundle-*files as mapped below.
Container images for the three custom services are also on GHCR as ghcr.io/judge-m/oct26-{integration,iris,ctfd}:v0.9.0-drill (package visibility may need to be flipped to public in Package settings).
Offline install (clean machine)
- Download all assets of this release into one empty folder.
- Assemble the bundle directory (mapping):
bundle-release-manifest.json→release-manifest.jsonbundle-SHA256SUMS.json→SHA256SUMS.jsonbundle-source-image-checks.json→source-image-checks.jsonvalidated-images.tar.part-001..008→ same names, bundle root- concatenate
bundle-source.zip.part-001..008(in order) →source.zip asset-0001.bin→autopsy/WS17-prepared-case-v2.tar.gzasset-0003.bin→desktop/silent-ridge-desktop-v1.qcow2.part001asset-0004.bin→desktop/silent-ridge-desktop-v1.qcow2.part002asset-0005.bin→desktop/silent-ridge-desktop-v1.qcow2.part003asset-0006.bin→desktop/silent-ridge-desktop-v1.qcow2.part004asset-0007.bin→desktop/silent-ridge-desktop-v1.qcow2.part005asset-0008.bin→desktop/silent-ridge-desktop-v1.qcow2.part006asset-0009.bin→memory/WS17-native-v1.tar.gzbundle-dependencies-case-and-wazuh-config.tar.gz→dependencies/case-and-wazuh-config.tar.gzbundle-disk-WS17-fat16.img→disk/WS17-fat16.imgbundle-evidence-public.tar.gz→evidence/evidence-public.tar.gzbundle-guides.tar.gz→guides/guides.tar.gz
- Verify + install (from a checkout of this tag, with Docker running):
python -m ridge.offline_install <bundle-dir> <install-dir>- The installer hashes every file against
SHA256SUMS.jsonbefore changing anything, then loads all images withdocker loadand writes an install receipt.
This exact flow was cold-tested from these release assets on 2026-09-21: all assets downloaded fresh, every hash verified, the desktop reassembled to its official full-image SHA-256, and docker load produced all 13 manifest image IDs.
Known gaps (tracked)
- The desktop qcow2 is the full official 6-part, 5.2 GB image (
assets/desktop-v1.json, sha2563cbe1ec5…); an earlier revision of these notes listed a truncated 2-part desktop — that was fixed and the reassembled image hash-verifies against the official manifest. - Bundle
source.zipis not attached as a single file (over the 2 GiB asset cap); use the 8 parts above.