-
Notifications
You must be signed in to change notification settings - Fork 14
Concepts
The canvas is the surface you work on. The topology is what you build on it: the infrastructure as nodes and edges. The topology is the product; the canvas is a view onto it, and the compiler turns it into deployable code.
Provider vocabulary never appears in the topology. You describe what a thing is and how it connects, not AWS resource types or Proxmox bridges.
A node's kind is what it is: network, segment, teamserver, redirector, collector, jumpbox, operator box. Containers are node kinds too, so every edge endpoint is a bare node id.
Edges connect nodes and carry meaning. A fronts edge puts a redirector in front of
a teamserver. A logs_to edge sends a host's telemetry to a collector. The compiler
derives firewall rules, play ordering, and references from the edges, so a rule
exists because an edge does.
Overlays are per-node parameters: which C2 on this teamserver, which gating rules on this redirector, which services on this jumpbox. Every overlay field is either user-supplied or derived. User-supplied fields become form inputs on the canvas and tfvars entries in the export. Derived fields become references you never see.
A topology has a mode, either ops or range.
-
opsbuilds attack infrastructure (redirectors, teamservers, operators). -
rangebuilds a target environment (an Active Directory range and its hosts).
Mode gates the canvas palette and chrome. The compiler treats both the same: one model, one validator, one export shape.
Blueprints are saved topologies you clone and modify. The shipped labs are blueprints. Cloning one gives you a private copy to edit; the baseline stays put.
A few cloud terms come up across this wiki without being defined where they appear. Plain definitions, not exhaustive ones:
- VPC (Virtual Private Cloud): an isolated network inside a cloud account. Every redStackPRO network compiles to one of these.
- Subnet: a slice of a VPC's address range that hosts actually sit in.
- NAT gateway: a managed device that lets hosts with no public address reach the internet outbound (updates, package installs) without being reachable from it.
- Elastic IP (AWS's term; GCP calls it a static external address): a public IPv4 address that stays the same across a stop and restart, rather than changing every time.
- VPC peering: a private network path between two VPCs, so hosts in one can reach hosts in the other without going over the public internet.
-
Apply: the Terraform step that actually creates or changes cloud resources to
match a plan.
terraform applyis what your money starts paying for. - On-Demand: the cloud's default, pay-as-you-go pricing for a running instance, as opposed to a reserved or spot instance.
The topology schema (currently 0.4.0) and the product version (0.9.0, this
release) are two different numbers. The schema is what a topology document is
validated against; the product version is the release of redStackPRO itself. A
schema bump does not necessarily mean a new product release, and vice versa, so
check which one an example or a bug report is pinned to before assuming it is
current.
redStackPRO generates code and hands it to you. It does not apply Terraform, run Ansible, or reach your cloud. Your credentials stay on your machine.
That boundary has consequences the tool accepts on purpose:
- No deployment status tracking in the canvas
- No destroy button (teardown is a command in the export)
- No drift detection
See Deploying a Range for what you do with the export.