Skip to content

v0.9.1-drill — deployment candidate

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 22 Sep 04:07
· 143 commits to main since this release
f310f39

Oct26 — v0.9.1-drill (deployment candidate 2)

Offline drill release for the Operation Silent Ridge defensive-cybersecurity event. Status: drill-uncertified — the ten-team capacity gate (F03) and dress rehearsal (F06) remain open; certified_complete: false is recorded honestly in the bundle manifest.

What changed since v0.9.0-drill

  • Desktop container rebuilt with a capped Autopsy heap (-Xmx2500m, was upstream -Xmx4G that could exceed the container limit and get OOM-killed). Measured with the WS17 case open: loaded desktop 1.72 GiB (was 1.95), idle 145 MiB.
  • The VM desktop QCOW2 is no longer in the release (−5.2 GB download). It was never boot-validated and container desktops are the event path; it remains in the repo at assets/vm-desktop/ (Git LFS) for a future validated Hyper-V/AWS path.
  • The v0.9.0 bundle's truncated 2-part desktop metadata bug is fixed at the source (store assembly reads the full part list from assets/desktop-v1.json).
  • Hosting requirements in the README are now measurement-based: 32 GB RAM min / 64 GB comfortable, 100 GB free NVMe for ten teams.

What is in this release (~13 GB total)

  • asset-0000..0003.bin, distribution.json, fixtures.zip, source.zip — the source distribution.
  • bundle-*.json — offline bundle metadata (bundle-release-manifest.json, bundle-SHA256SUMS.json, bundle-source-image-checks.json).
  • validated-images.tar.part-001..008 — all 13 Docker images (custom + upstream mirrors), 800 MB parts.
  • bundle-source.zip.part-001..008 — the full bundle source archive (~6 GB), 800 MB parts.
  • bundle-dependencies…, bundle-disk-…, bundle-evidence-…, bundle-guides… — the remaining bundle payloads.
  • Custom images also on GHCR: ghcr.io/judge-m/oct26-{integration,iris,ctfd}:v0.9.1-drill (package visibility is managed under the owner's Packages settings).

Offline install (clean machine)

  1. Download all assets of this release into one empty folder.
  2. Assemble the bundle directory:
    • bundle-release-manifest.json → release-manifest.json
    • bundle-SHA256SUMS.json → SHA256SUMS.json
    • bundle-source-image-checks.json → source-image-checks.json
    • validated-images.tar.part-001..008 → same names, bundle root
    • concatenate bundle-source.zip.part-001..008 (in order) → source.zip
    • asset-0001.bin → autopsy/WS17-prepared-case-v2.tar.gz
    • asset-0003.bin → memory/WS17-native-v1.tar.gz
    • bundle-dependencies-case-and-wazuh-config.tar.gz → dependencies/case-and-wazuh-config.tar.gz
    • bundle-disk-WS17-fat16.img → disk/WS17-fat16.img
    • bundle-evidence-public.tar.gz → evidence/evidence-public.tar.gz
    • bundle-guides.tar.gz → guides/guides.tar.gz
    • (asset-0000.bin and asset-0002.bin are prior-version/exercise inputs the bundle does not need; keep or skip.)
  3. Verify + install (from a checkout of this tag, with Docker running):
    • python -m ridge.offline_install <bundle-dir> <install-dir>
    • The installer hashes every file against SHA256SUMS.json before changing anything, then loads all images with docker load and writes an install receipt.

Known gaps (tracked)

  • Drill-uncertified: ten-team capacity rehearsal (F03) and dress rehearsal (F06) still open.
  • The parked VM QCOW2 (assets/vm-desktop/) retains the old -Xmx4G Autopsy config and is unvalidated (hyperv_boot_validated: false, aws_import_validated: false) — it is not part of the event path.
  • The bundle was install-verified at build time (hashes, staging, docker load → all 13 image IDs). A full cold-download re-verification from this page follows the v0.9.0 procedure.