Self-hosted control room for collaborating on authorized CTFd events with isolated Codex and Claude workers.
- Copy
.env.exampleto.envand replace all placeholder secrets. Generate the encryption key withopenssl rand -hex 32. - Build the worker image:
docker build -f worker.Dockerfile -t ctf-command-worker:local . - Start the platform:
docker compose up --build. - Sign in at
http://localhost:3000withBOOTSTRAP_EMAILandBOOTSTRAP_PASSWORD.
The first compose start applies migrations/001_initial.sql. The app container needs Docker socket access solely to create resource-limited worker containers; deploy it only on a trusted, dedicated host.
- Owners add CTFd instances with an admin API token stored using AES-256-GCM encryption, invite existing platform users, sync challenges, and activate full-auto orchestration.
- Activation queues three isolated workers for each unsolved challenge. Members can create extra Codex or Claude runs, review the event stream, send shared guidance, stop jobs, and run commands in workers they own.
- Candidate flags are persisted with evidence. Unlimited-attempt challenges can be submitted to CTFd; limited or unknown attempt limits are deliberately blocked pending a human confirmation workflow.
- The worker image contains the native Codex and Claude CLIs. Authenticate them only through their native login flows on a trusted deployment. Provider credential volumes and structured provider-runner adapters are the next hardening/integration step before production use.
Use only against CTFs you are authorized to test. Workers intentionally have outbound internet access and therefore must run on a dedicated, non-sensitive host. Do not publish this deployment as a public credential-hosting service.