Skip to content

Concepts

BaddKharma edited this page Sep 25, 2026 · 13 revisions

Concepts

Canvas and topology

The canvas is the surface you work on. The topology is what you build on it: the infrastructure as nodes and edges. The topology is the product; the canvas is a view onto it, and the compiler is a backend that renders it.

Provider vocabulary never appears in the topology. You describe what a thing is and how it connects, not AWS resource types or Proxmox bridges.

Node kinds

A node's kind is what it is: network, segment, teamserver, redirector, collector, jumpbox, operator box. Containers are node kinds too, so every edge endpoint is a bare node id.

Edges

Edges connect nodes and carry meaning. A fronts edge puts a redirector in front of a teamserver. A logs_to edge sends a host's telemetry to a collector. The compiler derives firewall rules, play ordering, and references from the edges, so a rule exists because an edge does.

Overlays

Overlays are per-node parameters: which C2 on this teamserver, which gating rules on this redirector, which services on this jumpbox. Every overlay field is either user-supplied or derived. User-supplied fields become form inputs on the canvas and tfvars entries in the export. Derived fields become references you never see.

Two modes

A topology has a mode, either ops or range.

  • ops builds attack infrastructure (redirectors, teamservers, operators).
  • range builds a target environment (an Active Directory range and its hosts).

Mode gates the canvas palette and chrome. The compiler treats both the same: one model, one validator, one export shape.

Blueprints

Blueprints are saved topologies you clone and modify. The shipped labs are blueprints. Cloning one gives you a private copy to edit; the baseline stays put.

The export-only model

redStackPRO generates code and hands it to you. It does not apply Terraform, run Ansible, or reach your cloud. Your credentials stay on your machine.

That boundary has consequences the tool accepts on purpose:

  • No deployment status tracking in the canvas
  • No destroy button (teardown is a command in the export)
  • No drift detection

See Deploying a Range for what you do with the export.

Clone this wiki locally