-
Notifications
You must be signed in to change notification settings - Fork 8
Home

A visual canvas for red team infrastructure and cyber ranges. Compose a topology, export a complete, runnable working directory of Terraform and Ansible, and deploy it from your own machine. redStackPRO never holds your cloud credentials.
Important
redStackPRO is in prerelease (beta). The schema and features are still moving. GCP and AWS are tested end to end; Azure, Proxmox, and ESXi are on the roadmap. Expect rough edges, and pin to a released version if you need stability.
Hit a rough edge, or have feedback? Open an issue at
Issues. If it was a
deploy, attach the scrubbed logs/deploy-*.log the run wrote (it records versions,
provider, and where it stopped, with secrets removed) so it can be analyzed fast. Your
reports shape the release.
redStackPRO is a validation range for TTPs and tooling at production-operations level. Built for rehearsing operations, not teaching them from scratch. The shipped labs come with their solutions, because those are operator validation references.
Important
The export is the boundary. The canvas generates files; you run them under your own credentials. redStackPRO never deploys anything and never holds a secret.
| Step | Page | What you do |
|---|---|---|
| 1 | Getting Started | Run the canvas in Docker or from source, build your first topology |
| 2 | Cloud Prerequisites | Cloud permissions, local tools, and auth, before you deploy |
| 3 | Concepts | The canvas, the topology, and the export-only model |
| 4 | Deploying a Range | The SSH key, the variables, and the deploy flow |
| 5 | Providers | The GCP, AWS, Azure, Proxmox, and ESXi support matrix |
| 6 | Labs | The shipped ranges, what each one teaches, and a link to each one's walkthrough (or a note that it has none yet) |
Tip
Driving it from code or your own choice of agent? See Automation and Agents.
Prerelease, and the topology schema is still moving. The pipeline works end to end: a topology compiles to Terraform and Ansible, and the export deploys.
- GCP and AWS are supported and tested end to end, for both target ranges and attack infrastructure.
- Azure, Proxmox, and ESXi are on the roadmap, not yet supported.
See Providers for the full matrix and the notes on each.
docker compose up # http://127.0.0.1:8000
Or from source with Python 3.11+ and Node 24. See Getting Started.
All wiki pages
| Page | What it covers |
|---|---|
| Getting Started | Install, run the canvas, first topology |
| Cloud Prerequisites | Cloud permissions and local tools, before you deploy |
| Concepts | Canvas, topology, export-only model |
| Library and Blueprints | Blueprints, saving, publishing, and cloning |
| Deploying a Range | SSH key, variables, deploy flow |
| Providers | Support matrix and per-provider notes |
| Labs | The shipped ranges |
| Redirectors and Cover Stories | The attack side |
| Validation | The findings the canvas raises |
| Automation and Agents | Driving redStackPRO from code or an agent |
| FAQ | Common questions |
MIT. The GOAD range blueprints are derived from GOAD and carry GPLv3. A devZero Security LLC project.