
Crucible
github.com/cmu-sei/crucible- Category
- Cybersecurity
- Rank
- No. 1051Tools index
- Pricing
- Open Source
- Type
- TOOL
- Use case
- Research & Education · Security & Identity
- Interfaces
- Web · Desktop · API
- Builder
- cmu-sei
- GitHub
- 55 stars
- Latest release
- 09.16.2026-1
- Date
About
Crucible is an open-source framework built on Angular and .NET Core for designing, deploying, and managing virtual environments used in cybersecurity training, exercises, and competitions. It provides modular applications for building lab topologies, running scenario-based events, scoring games, and reviewing incident data, and has powered large-scale US DoD cyber exercises since 2018.
What it does
Carnegie Mellon's Software Engineering Institute ships Crucible as a family of separate apps, each with its own API and web front end, that together run a cyber range. TopoMojo builds small labs from forms. Caster deploys larger networks as code onto VMware, Proxmox, Azure or AWS. Player is the browser window participants work in. Steamfitter runs scripted tasks inside the virtual machines through StackStorm, and Gameboard scores competitions. This repository holds the documentation site and the index of those apps, not their code.
Why it's ranked here
The case rests on provenance and scope. The docs say Crucible has run large US Defense Department exercises and the President's Cybersecurity Challenge since 2018. The license is MIT, and the install guide covers the whole stack: Kubernetes operators for Keycloak and PostgreSQL, one umbrella Helm chart for every app, and an optional Grafana monitoring stack. Few open source ranges cover lab building, scenario scripting, scoring and incident review in one family. That breadth is the verdict; it says nothing about code quality, because none of the application code lives here.
What's good
The documentation is organised by role, with separate paths for infrastructure administrators, range builders, instructors and participants, which matters when four different people touch one exercise. Mechanisms are stated plainly: Steamfitter sends commands to guest machines through the hypervisor rather than over the network, and TopoMojo appends a unique isolation tag to every machine and network name so player copies never collide. Player and Steamfitter ship default roles with named permissions. The install order is explicit, including a warning to remove custom resources before the operators so an uninstall does not wipe them cluster-wide.
Tradeoffs
This is a heavy platform. The stated baseline is Kubernetes, Helm, a VMware vCenter or Proxmox host and an OAuth provider, with minimal nodes at 100 to 250 GB of storage, 8 GB of RAM and 2 cores. The code is spread across more than twenty other repositories, so this one tells you nothing about tests or code health. The docs also disagree with themselves: the front page describes an appliance built on a single-node Docker swarm on Ubuntu 20.04, while the install guide assumes Kubernetes, and Caster is described as wrapping OpenTofu in one place and Terraform in another.
How to use it well
The fit is a team that runs recurring hands-on security training or competitions and already operates Kubernetes plus a VMware or Proxmox cluster. Start with TopoMojo for single labs and Gameboard for scoring, which the docs pitch at individual training. Add Player, Caster, Steamfitter and Alloy only when you need team exercises with scripted events, and deploy through the umbrella chart rather than app by app. It is not a lightweight host for a weekend capture the flag, and it does not replace a learning management system; it plugs into Moodle instead.
Technical notes+
The repository is an MkDocs Material site: requirements.txt lists only mkdocs-material, Pygments, pillow and cairosvg, and mkdocs.yml defines the nav across nine core app guides, four role guides and three tutorials. docs/install/index.md orders deployment as four Helm charts (crucible-operators, crucible-infra, crucible-apps, crucible-monitoring) and pins Keycloak Operator 26.5.6 and the CloudNative-PG chart 0.25.0. docs/topomojo/index.md documents shared networks through the PodVlanReservations environment keys. docs/steamfitter/index.md admits the view-based task page fails when two scenarios share one Player view and recommends the scenario-based URL. docs/player/index.md describes webhook Subscriptions (ViewCreated, ViewDeleted) that the VM API uses for on-demand events. LICENSE is MIT (SEI) with a 2021 copyright while README.md says 2026.
Observed
- License
- MIT (SEI variant), DoD-funded, Distribution Statement A
- Repository contents
- MkDocs documentation site only; application code lives in separate per-app API and UI repositories
- Application stack
- Angular front ends and .NET Core services, per docs/index.md
- Deployment
- Kubernetes with per-app Helm charts plus an umbrella chart
- Hypervisors
- VMware vSphere and Proxmox; Caster also targets Azure and AWS
- Authentication
- OpenID Connect, with Keycloak as the recommended provider
- Interfaces
- Browser UIs, per-app APIs, a Terraform provider, Moodle and osTicket plugins
- Minimum node size
- 100 to 250 GB storage, 8 GB RAM, 2 cores
Read from README.md, LICENSE, requirements.txt, mkdocs.yml, docs/index.md, docs/getting-started/index.md, docs/install/index.md, docs/roles/administrator/deployment/index.md, docs/topomojo/index.md, docs/gameboard/index.md, docs/player/index.md, docs/steamfitter/index.md.
What it can do
Run scenario-based training events and exercises
Exercise scenario → Running training event
Score cybersecurity competitions and games
Competition activity data → Scores
Review incident data from exercises
Incident data → Incident review
Tags
Tech Stack
Media
Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.