Skip to content

Deploying a Range

BaddKharma edited this page Sep 25, 2026 · 18 revisions

Deploying a Range

You deploy the export from your own machine, under your own credentials. redStackPRO is not in the loop once you press Download.

Fill in the variables

Open export/terraform/terraform.tfvars and set the values for your account (project or region, credentials profile, and any topology-specific inputs the briefing names).

Run deploy.sh

cd export && bash deploy.sh

deploy.sh applies the Terraform, then provisions from the range's own jumpbox. The managed hosts sit on a private subnet nothing else can reach, so provisioning runs from inside the range rather than from your laptop. Your cloud credentials stay on your machine throughout.

RANGE-BRIEFING.md in the export lists the credentials and what is planted where.

Redirectors need a real domain

A redirector is the one host that answers to the internet by name. A domain has to be registered and pointed at the box by a human, and nothing can invent one. Any shipped example that carries a redirector arrives one field short on purpose, and the validator says so with RDR001.

Supply a domain you control, either in the canvas inspector before you compile, or on the command line:

redstackpro compile <template> --hostname your-domain.example -o export

After apply, create the A record the briefing names, pointing your subdomain at the redirector's address. See Redirectors and Cover Stories.

Teardown

Teardown is a command in the export, not a button in the canvas. The briefing names it. Ranges are meant to be stood up, used, and torn down, so nothing keeps costing money after the work is done.

Providers

GCP and AWS are deployment-proven. See Providers for the full matrix and the notes on the preview providers.

Clone this wiki locally