Vibeleaderboard
Index / tool
Visit cmu-sei.github.io
Category
Cybersecurity
Rank
No. 1051Tools index
Pricing
Open Source
Type
TOOL
Use case
Research & Education · Security & Identity
Interfaces
Web · Desktop · API
Builder
cmu-sei
GitHub
55 stars
Latest release
09.16.2026-1
Date

About

Crucible is an open-source framework built on Angular and .NET Core for designing, deploying, and managing virtual environments used in cybersecurity training, exercises, and competitions. It provides modular applications for building lab topologies, running scenario-based events, scoring games, and reviewing incident data, and has powered large-scale US DoD cyber exercises since 2018.

What it does

Carnegie Mellon's Software Engineering Institute ships Crucible as a family of separate apps, each with its own API and web front end, that together run a cyber range. TopoMojo builds small labs from forms. Caster deploys larger networks as code onto VMware, Proxmox, Azure or AWS. Player is the browser window participants work in. Steamfitter runs scripted tasks inside the virtual machines through StackStorm, and Gameboard scores competitions. This repository holds the documentation site and the index of those apps, not their code.

Why it's ranked here

The case rests on provenance and scope. The docs say Crucible has run large US Defense Department exercises and the President's Cybersecurity Challenge since 2018. The license is MIT, and the install guide covers the whole stack: Kubernetes operators for Keycloak and PostgreSQL, one umbrella Helm chart for every app, and an optional Grafana monitoring stack. Few open source ranges cover lab building, scenario scripting, scoring and incident review in one family. That breadth is the verdict; it says nothing about code quality, because none of the application code lives here.

What's good

The documentation is organised by role, with separate paths for infrastructure administrators, range builders, instructors and participants, which matters when four different people touch one exercise. Mechanisms are stated plainly: Steamfitter sends commands to guest machines through the hypervisor rather than over the network, and TopoMojo appends a unique isolation tag to every machine and network name so player copies never collide. Player and Steamfitter ship default roles with named permissions. The install order is explicit, including a warning to remove custom resources before the operators so an uninstall does not wipe them cluster-wide.

Tradeoffs

This is a heavy platform. The stated baseline is Kubernetes, Helm, a VMware vCenter or Proxmox host and an OAuth provider, with minimal nodes at 100 to 250 GB of storage, 8 GB of RAM and 2 cores. The code is spread across more than twenty other repositories, so this one tells you nothing about tests or code health. The docs also disagree with themselves: the front page describes an appliance built on a single-node Docker swarm on Ubuntu 20.04, while the install guide assumes Kubernetes, and Caster is described as wrapping OpenTofu in one place and Terraform in another.

How to use it well

The fit is a team that runs recurring hands-on security training or competitions and already operates Kubernetes plus a VMware or Proxmox cluster. Start with TopoMojo for single labs and Gameboard for scoring, which the docs pitch at individual training. Add Player, Caster, Steamfitter and Alloy only when you need team exercises with scripted events, and deploy through the umbrella chart rather than app by app. It is not a lightweight host for a weekend capture the flag, and it does not replace a learning management system; it plugs into Moodle instead.

Technical notes+

The repository is an MkDocs Material site: requirements.txt lists only mkdocs-material, Pygments, pillow and cairosvg, and mkdocs.yml defines the nav across nine core app guides, four role guides and three tutorials. docs/install/index.md orders deployment as four Helm charts (crucible-operators, crucible-infra, crucible-apps, crucible-monitoring) and pins Keycloak Operator 26.5.6 and the CloudNative-PG chart 0.25.0. docs/topomojo/index.md documents shared networks through the PodVlanReservations environment keys. docs/steamfitter/index.md admits the view-based task page fails when two scenarios share one Player view and recommends the scenario-based URL. docs/player/index.md describes webhook Subscriptions (ViewCreated, ViewDeleted) that the VM API uses for on-demand events. LICENSE is MIT (SEI) with a 2021 copyright while README.md says 2026.

Observed

License
MIT (SEI variant), DoD-funded, Distribution Statement A
Repository contents
MkDocs documentation site only; application code lives in separate per-app API and UI repositories
Application stack
Angular front ends and .NET Core services, per docs/index.md
Deployment
Kubernetes with per-app Helm charts plus an umbrella chart
Hypervisors
VMware vSphere and Proxmox; Caster also targets Azure and AWS
Authentication
OpenID Connect, with Keycloak as the recommended provider
Interfaces
Browser UIs, per-app APIs, a Terraform provider, Moodle and osTicket plugins
Minimum node size
100 to 250 GB storage, 8 GB RAM, 2 cores

Read from README.md, LICENSE, requirements.txt, mkdocs.yml, docs/index.md, docs/getting-started/index.md, docs/install/index.md, docs/roles/administrator/deployment/index.md, docs/topomojo/index.md, docs/gameboard/index.md, docs/player/index.md, docs/steamfitter/index.md.

What it can do

  • Run scenario-based training events and exercises

    Exercise scenario → Running training event

  • Score cybersecurity competitions and games

    Competition activity data → Scores

  • Review incident data from exercises

    Incident data → Incident review

Tags

cybersecuritycyber-rangetrainingopen-sourcesimulationdodvirtual-environmentsgamification

Tech Stack

Python

Media

Crucible

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.