Welcome to the TCecure CRC CyberLab documentation wiki. This wiki documents the architecture, configuration, and operational procedures for the CyberLab environment.
Status — September 5, 2026: all six CMMC Level 1 lab families (AC, IA, SI, SC, MP, PE — 57 labs) are live and seeded on all 20 pods. Automated verification and family auto-advance run every 30 minutes.
- Students get exactly one Guacamole connection,
PODXX-SRV— their own pod member server at10.50.XX.20. ThePODXX-GWfirewall tiles are hidden (guacd has nohttpprotocol) and the pod firewall is now reached from a browser inside that desktop athttp://10.51.XX.1. See Network & Firewall.- Three lab steps were credited on the shared DC — IA M2-L1, IA M3-L2 and MP M1-L1/M1-L2. On member servers the M2-L1 and MP steps become performable and their waivers are retired after the pilots; M3-L2 stays domain-wide. See Current Cohort Lab Notices.
- The hardened domain password policy is applied centrally (12 chars, all four character classes, lockout 10, history 24, max age 90).
- Lab health and per-pod progress now feed
https://my.digitalrcc.comread-only — see Lab Health Monitoring and Portal Integration.- Students now work on their own member server: all 20
PODXX-SRVare built, domain-joined, hardened and mapped one-to-one tostudentXX, seeding/verification targetcrc_pod_servers, and the portal issuesPODXX-SRV. DC01-P01 and DC02-P01 remain domain controllers and provide DNS, Kerberos, LDAP and SYSVOL/NETLOGON — students no longer sign in to them. See Pod Member Servers and Domain Controllers.- Remaining before student access: replacement Windows keys for POD07-SRV / POD11-SRV, the interactive Pod01/Pod03 pilots, and removal of student logon on DC01/DC02. The legacy
PODXX-DCtiles stay as rollback until then.- Retiring student sessions on DC01 also removes the RDS grace period exposure (Datacenter product keys are not RDS CALs).
| Audience | Page |
|---|---|
| Students | Student Quick Start — log in, find your pod, save evidence, check progress |
| Students | Lab Guides — completion guides for all six families |
| Students | Current Cohort Lab Notices — waivers, tool-launch rules, firewall access |
| Instructors | Lab Families — curriculum, module breakdown, lab counts |
| Instructors | AWX Automation — seed, verify, reset, auto-advance |
| Instructors | Training Tracker — per-pod progress dashboard |
| Instructors | Lab Health Monitoring — read-only Proxmox health on the DigitalRCC admin dashboard |
| Instructors | Portal Integration — how my.digitalrcc.com reads lab progress |
| Staff (owner-only) | DigitalRCC LabOps AI — support-triage assistant and Direct Chat in the LabOps console |
| Visitors | CyberLab Overview — high-level walkthrough for demos |
| Section | Description |
|---|---|
| Architecture Overview | Network topology, Proxmox hosts, VLANs |
| Domain Controllers | DC01-P01, DC02-P01, acs-p01.local domain |
| Pod Infrastructure | 20-pod student workspace architecture and per-pod networking |
| Pod Member Servers | Per-pod PODXX-SRV session hosts — build state and cutover plan |
| OU Structure | Active Directory OU hierarchy & delegation |
| User & Group Naming | PXX- prefix conventions for all objects |
| GPO & Logon Scripts | Per-pod desktop shortcut deployment |
| MMC Shortcuts | Scoped ADUC launchers per pod |
| VM Inventory | All VMs across PVE1 and PVE2 |
| Network & Firewall | Dreamwall, VLANs, routing, pod firewall access |
| Lab Health Monitoring | Read-only Proxmox poller feeding the portal |
| Portal Integration | my.digitalrcc.com progress + health integration |
| DigitalRCC LabOps AI | LabOps AI host, security model, Direct Chat, runbooks |
| Reverse Proxy Configuration | Public hostnames and routing |
| Backlog & Known Issues | Outstanding tasks and known issues |
| Section | Description |
|---|---|
| CDW Overview | Architecture, network, and purpose of the CDW environment |
| CDW VM Inventory | All 7 CDW VMs — specs, roles, IPs, snapshots |
| CDW Network & Access | VLAN 50, proxy routing, SSH jump paths, Guacamole connections |
| CDW Credentials | All usernames, passwords, and keys for CDW services |
| CDW Operations Guide | Engagement workflow, snapshot reset, troubleshooting |
| CDW VPN Configuration | WireGuard setup, client templates, NinjaOne deployment |
| Item | Value |
|---|---|
| Domain | acs-p01.local |
| DC01 (Primary, current student session host) | VM 200, 10.50.1.10, DC01-P01 — 12 vCPU / 32 GB, RD Session Host installed |
| DC02 (Replica, no student sessions) | VM 221, 10.50.1.11, DC02-P01 — 4 vCPU / 16 GB, Server 2022 Evaluation expiring Oct 2, 2026 |
| Proxmox Host 1 (PVE1) | 192.168.1.90 (SSH: 108.31.169.90:2225) |
| Proxmox Host 2 (PVE2) | 192.168.1.9 |
| Pod Count | 20 (Pod01 - Pod20), 1 student per pod |
| Pod Networks | 10.51.XX.0/24 per pod, pfSense gateway at 10.51.XX.1 (VMs 300–319); pod hosts on 10.50.XX.0/24 |
| Pod Member Servers | PODXX-SRV at 10.50.XX.20 (VM 400 + pod) — all 20 built, domain-joined and student-mapped; POD07/POD11 awaiting licences |
| Student Access | Guacamole — https://crc.guac.01.tcecure.com/#/ (single connection PODXX-SRV → 10.50.XX.20) |
| Progress Tracker | https://training.status.tcecure.com |
| Student / Staff Portal | https://my.digitalrcc.com |
| AWX | VM 103 (crc-awx-k8s-01), 192.168.1.103:30080, AWX 24.6.1 |
| Wiki.js | VM 106, 192.168.1.42:80 |
| CyberLab Portal / MCP | 192.168.1.61 |
| Lab Curriculum | 6 families, 57 labs (AC 12, IA 12, SI 12, SC 12, MP 3, PE 6) |
Last updated: August 22, 2026