Repository navigation
v0.9.1-drill — deployment candidate
Pre-release
Pre-release
·
143 commits
to main
since this release
Oct26 — v0.9.1-drill (deployment candidate 2)
Offline drill release for the Operation Silent Ridge defensive-cybersecurity event. Status: drill-uncertified — the ten-team capacity gate (F03) and dress rehearsal (F06) remain open; certified_complete: false is recorded honestly in the bundle manifest.
What changed since v0.9.0-drill
- Desktop container rebuilt with a capped Autopsy heap (
-Xmx2500m, was upstream-Xmx4Gthat could exceed the container limit and get OOM-killed). Measured with the WS17 case open: loaded desktop 1.72 GiB (was 1.95), idle 145 MiB. - The VM desktop QCOW2 is no longer in the release (−5.2 GB download). It was never boot-validated and container desktops are the event path; it remains in the repo at
assets/vm-desktop/(Git LFS) for a future validated Hyper-V/AWS path. - The v0.9.0 bundle's truncated 2-part desktop metadata bug is fixed at the source (store assembly reads the full part list from
assets/desktop-v1.json). - Hosting requirements in the README are now measurement-based: 32 GB RAM min / 64 GB comfortable, 100 GB free NVMe for ten teams.
What is in this release (~13 GB total)
asset-0000..0003.bin,distribution.json,fixtures.zip,source.zip— the source distribution.bundle-*.json— offline bundle metadata (bundle-release-manifest.json,bundle-SHA256SUMS.json,bundle-source-image-checks.json).validated-images.tar.part-001..008— all 13 Docker images (custom + upstream mirrors), 800 MB parts.bundle-source.zip.part-001..008— the full bundle source archive (~6 GB), 800 MB parts.bundle-dependencies…,bundle-disk-…,bundle-evidence-…,bundle-guides…— the remaining bundle payloads.- Custom images also on GHCR:
ghcr.io/judge-m/oct26-{integration,iris,ctfd}:v0.9.1-drill(package visibility is managed under the owner's Packages settings).
Offline install (clean machine)
- Download all assets of this release into one empty folder.
- Assemble the bundle directory:
bundle-release-manifest.json→release-manifest.jsonbundle-SHA256SUMS.json→SHA256SUMS.jsonbundle-source-image-checks.json→source-image-checks.jsonvalidated-images.tar.part-001..008→ same names, bundle root- concatenate
bundle-source.zip.part-001..008(in order) →source.zip asset-0001.bin→autopsy/WS17-prepared-case-v2.tar.gzasset-0003.bin→memory/WS17-native-v1.tar.gzbundle-dependencies-case-and-wazuh-config.tar.gz→dependencies/case-and-wazuh-config.tar.gzbundle-disk-WS17-fat16.img→disk/WS17-fat16.imgbundle-evidence-public.tar.gz→evidence/evidence-public.tar.gzbundle-guides.tar.gz→guides/guides.tar.gz- (
asset-0000.binandasset-0002.binare prior-version/exercise inputs the bundle does not need; keep or skip.)
- Verify + install (from a checkout of this tag, with Docker running):
python -m ridge.offline_install <bundle-dir> <install-dir>- The installer hashes every file against
SHA256SUMS.jsonbefore changing anything, then loads all images withdocker loadand writes an install receipt.
Known gaps (tracked)
- Drill-uncertified: ten-team capacity rehearsal (F03) and dress rehearsal (F06) still open.
- The parked VM QCOW2 (
assets/vm-desktop/) retains the old-Xmx4GAutopsy config and is unvalidated (hyperv_boot_validated: false,aws_import_validated: false) — it is not part of the event path. - The bundle was install-verified at build time (hashes, staging,
docker load→ all 13 image IDs). A full cold-download re-verification from this page follows the v0.9.0 procedure.