CyberForge portal

Select a hardened base image, then initialize a lease-bound ephemeral instance.

Demonstration mode — provisioner not armed.

Initializing an instance runs the provision server action in demo mode. Connection strings use the reserved .invalid domain and resolve to nothing — no live endpoint is exposed from this front door.

Demo
PillarCybersecurity
IdentityDwayne Randle
VPN gatewayNo injection · net3

Network segment

Select an isolated segment to restrict the image catalog and target new instances to that profile.

VPN gateway injection — net3

No third-party pipeline connection is authorized on net3. Toggle to patch one into this isolated profile.

Hardened image catalog

All segments · 5 images
Red Hat Enterprise Linux 8+

rhel8-hardened-base:v2.1

x86_64 · DISA STIG

net 1 / 2 / 3

Hardened RHEL base for security analyst tooling and CLI workloads.

SLSA: Unattested
Selected
Red Hat Enterprise Linux 9

rhel9-hardened-base:v1.3

x86_64 · DISA STIG

net 1 / 2 / 3 / 4 / 5

Current-generation RHEL base with FIPS mode available.

SLSA: Unattested
Select this template
Windows 11 Enterprise (Secure VDI)

win11-stig-vdi-client:v1.4

x86_64 · STIG VDI

net 3 / 4

Hardened Windows 11 virtual desktop client for secure analyst sessions.

SLSA: Unattested
Select this template
Windows Server 2025

win2025-stig-base:v1.0

x86_64 · STIG

net 4 / 5

Hardened Windows Server base for application and service hosting.

SLSA: Unattested
Select this template
Ubuntu 22.04 LTS (Hardened)

ubuntu2204-cis-base:v2.0

x86_64 · CIS Level 2

net 1 / 2

CIS-benchmarked Ubuntu base for container and dev workloads.

SLSA: Unattested
Select this template

Instance deployment actions

Runtime lease allotment4h
1h8h max

Target: Red Hat Enterprise Linux 8+ on net3 · no VPN injection