Deploy reference
verify the current repository scripts before executionFull provision (USB, first time / hardware change)
Operator reference for update-phones.sh. Confirm the current script, Android tooling and handset authorisation in the GhostWire repository before running it.
export COCKPIT_PASSWORD='…' # enables fleet auto-enroll
bash update-phones.sh
Treat the command as a runbook pointer, not evidence that provisioning or enrolment has completed.
Publish an update candidate
Operator reference for publish-ghostwire-update.sh. A successful manifest read confirms only the published metadata; it does not prove a handset downloaded or installed the APK.
bash publish-ghostwire-update.sh path/to/signed.apk "release notes"
Live OTA manifest
ghostwire-updates.craig-45c.workers.dev/manifest.json …Target build profile
verification checklist · not a current device inventoryLayer 1 — GrapheneOS controls to verify
Anti-seizure
- Verify duress-PIN behaviour
- Set and verify auto-reboot policy
- Verify USB policy while locked
- Verify bootloader and signing-key state
- Verify per-profile storage policy
Built-in firewall
- Verify per-app network policy
- Verify per-app sensor policy
- Verify storage and contact scopes
- Record the tested OS build
Bundled apps
- Verify the approved browser
- Verify camera and PDF apps
- Verify the attestation route
- Record optional app-store policy
Layer 2 — candidate application profile to verify
GhostWireours
- Verify messaging on the target build
- Verify voice and video on-device
- Verify message-lifecycle and media handling
- Verify vault, screen and QR controls
Mullvad VPN3rd-party
- Verify connection and leak tests
- Verify the approved account policy
- Verify DNS policy on-device
Pharoah Mobile Shieldours
- Verify supported detections
- Verify audit and travel modes
- Verify any fleet reporting separately
Aegis3rd-party
- Verify storage and offline operation
KeePassDX3rd-party
- Verify vault policy on-device
Orbot / Tor3rd-party
- Verify routing for the approved apps
- Record the tested configuration
Distribution candidate
Aurora Store3rd-party
Evaluate this route for approved third-party apps and record the tested account and update behaviour. GhostWire release metadata is checked separately through the live OTA manifest above.
Per-phone hardening profile
saves to this browser · do on the reference device, then cloneThese are GrapheneOS Settings toggles (not all adb-settable). Nail them on one reference phone, photograph the settings, then replicate identically across the fleet.
Fleet management source
open the authenticated cockpit to verify current stateOpen the GhostWire Fleet cockpit to verify devices, enrolment, billing and version state. This portal page does not fetch, copy or infer fleet records.
Gap register boundary
no cached operational statusNo current GhostWire gap register is connected to this route. The previous static owner/status table has been removed so old assignments and device figures cannot be mistaken for live work. Use the owning repository and authenticated fleet cockpit as the current sources.