-
Notifications
You must be signed in to change notification settings - Fork 8
Home

A visual canvas for red team infrastructure and cyber ranges. Compose a topology, export a complete, runnable working directory of Terraform and Ansible, and deploy it from your own machine. redStackPRO never holds your cloud credentials.
redStackPRO is a validation range for TTPs and tooling at production-operations level. Built for rehearsing operations, not teaching them from scratch. The shipped labs come with their solutions, because those are operator validation references.
Important
The export is the boundary. The canvas generates files; you run them under your own credentials. redStackPRO never deploys anything and never holds a secret.
| Step | Page | What you do |
|---|---|---|
| 1 | Getting Started | Run the canvas in Docker or from source, build your first topology |
| 2 | Concepts | The canvas, the topology, and the export-only model |
| 3 | Deploying a Range | The SSH key, the variables, and the deploy flow |
| 4 | Providers | The GCP, AWS, Azure, Proxmox and ESXi support matrix |
| 5 | Labs | The shipped ranges and what each one teaches |
| 6 | The lab's own walkthrough | Deployed a lab? Labs links each one's walkthrough (or says it has none yet) |
Tip
Driving it from code or your own choice of agent? See Automation and Agents.
Pre-release, and the topology schema is still moving. The pipeline works end to end: a topology compiles to Terraform and Ansible, and the export deploys.
- GCP and AWS are supported and tested end to end, for both target ranges and attack infrastructure.
- Azure, Proxmox, and ESXi are on the roadmap, not yet supported.
See Providers for the full matrix and the notes on each.
docker compose up # http://127.0.0.1:8000
Or from source with Python 3.11+ and Node 24. See Getting Started.
All wiki pages
| Page | What it covers |
|---|---|
| Getting Started | Install, run the canvas, first topology |
| Cloud Prerequisites | Cloud permissions and local tools, before you deploy |
| Concepts | Canvas, topology, export-only model |
| Deploying a Range | SSH key, variables, deploy flow |
| Providers | Support matrix and per-provider notes |
| Labs | The shipped ranges |
| Redirectors and Cover Stories | The attack side |
| Validation | The findings the canvas raises |
| Automation and Agents | Driving redStackPRO from code or an agent |
| FAQ | Common questions |
MIT. The GOAD range templates are derived from GOAD and carry GPLv3. A devZero Security LLC project.