Net assumes the participants are the threat. Every segment is isolated by default, egress is deny-all except an explicit allowlist, and the range control plane is unreachable from the participant VLAN. The allowlist's source of truth is Wargames' required network access document — Net implements exactly that and nothing more.
VLAN ladder
Six segments, isolated by default, routed only where a documented need exists.
Participants can reach the range on VLAN 20 but never each other — no lateral movement, no cross-team snooping on the participant segment.
Resolver answers only for hosts the wargames require. Everything else is NXDOMAIN — no arbitrary outbound name resolution.
Default-deny egress on VLAN 50. The allowlist mirrors Wargames' required-network-access document exactly.
Bandwidth is shaped per client so a single aggressive scan can't starve the range for everyone else.
The order Net comes online before doors open.
Checkpoint order is the design intent; the live status of each is tracked in Event.
A modular, multi-tenant cyber range on bare-metal K3s.
MODULE 02 — COURSE OF FIREWargames59 challenges, three tracks, one fail-closed deploy.
MODULE 04 — THE OPERATIONEventA full-scale, self-hosted CTF experience — 80 operators, 59 challenges.
MODULE 05 — LOADOUTAgentA friendly CTF coaching AI that runs on your own laptop.