Skip to content
BaddKharma edited this page Sep 25, 2026 · 14 revisions

redStackPRO: red team infrastructure and cyber ranges

MIT license version 0.9.0 providers GCP and AWS status pre-release Terraform and Ansible

redStackPRO Wiki

A visual canvas for red team infrastructure and cyber ranges. Compose a topology, export a complete, runnable working directory of Terraform and Ansible, and deploy it from your own machine. redStackPRO never holds your cloud credentials.

redStackPRO is a validation range for TTPs and tooling at production-operations level. It is a place to practice for real operations, not a course to learn them. The shipped labs come with their solutions, because those are operator validation references.

Important

The export is the boundary. The canvas generates files; you run them under your own credentials. redStackPRO never deploys anything and never holds a secret.


🚀 Start here

Step Page What you do
1 Getting Started Run the canvas in Docker or from source, build your first topology
2 Concepts The canvas, the topology, and the export-only model
3 Deploying a Range The SSH key, the variables, and the deploy flow
4 Providers The GCP, AWS, Azure, Proxmox and ESXi support matrix
5 Labs The shipped ranges and what each one teaches

Tip

Driving it from code or your own choice of agent? See Automation and Agents.


🧭 Status

Pre-release, and the topology schema is still moving. The pipeline works end to end: a topology compiles to Terraform and Ansible, and the export deploys.

  • GCP and AWS are supported and tested end to end, for both target ranges and attack infrastructure.
  • Azure, Proxmox and ESXi are on the roadmap. See Providers.

⚡ Two ways to run

docker compose up                    # http://127.0.0.1:8000

Or from source with Python 3.11+ and Node 24. See Getting Started.


📚 Reference

All wiki pages
Page What it covers
Getting Started Install, run the canvas, first topology
Concepts Canvas, topology, export-only model
Deploying a Range SSH key, variables, deploy flow
Providers Support matrix and per-provider notes
Labs The shipped ranges
Redirectors and Cover Stories The attack side
Validation The findings the canvas raises
Automation and Agents Driving redStackPRO from code or an agent
FAQ Common questions

License

MIT. The GOAD range templates are derived from GOAD and carry GPLv3. A devZero Security LLC project.

Clone this wiki locally