Every lab lives in its own public repository in the CyberCTF organization.
Anatomy of a lab
docker-compose.yml: the lab's services, including theevidenceservice that fetches the player's evidence at startup;lab.json: public metadata: title, category, difficulty, the evidence kind and its development value;tests/: automated tests proving the vulnerability is exploitable and the evidence reachable only through it.
Rules every lab follows
- Realism first: a plausible company, a plausible system, one vulnerability.
- Evidence, not magic strings: the proof is real business data, placed at runtime and reachable only by exploiting the lab.
- No spoilers: nothing in the UI, logs or README hints at the vulnerability or the evidence.
- Tested: CI runs the exploit path against the development evidence.
Publishing
When a lab is pushed to main, its workflow publishes the images and registers the lab with CyberCTF as a draft. It goes live once reviewed.