Skip to content

CTFd ContainersOne Docker container per team

A CTFd plugin that starts an isolated container for every team on demand, issues a unique flag, expires it automatically, and keeps a full audit trail.

What this plugin does ​

A CTFd plugin that gives every team (or every user, depending on the CTF mode) its own Docker container for a challenge. Containers expire on their own, and the plugin keeps an audit trail of everything that happens.

Containers console

Start here ​

DocumentWhat it covers
InstallationRequirements, Docker setup, dependencies, first run
ConfigurationEvery setting and what it changes
Creating challengesImages, ports, flags, scoring, limits
Player guideWhat a player sees and can do
Admin consoleThe console, tab by tab
Anti-cheatFlag reuse detection, the two outcomes, auto-ban
Subdomain routingServing web challenges through Traefik
ImportCSV and Excel bulk import
OperationsBackground jobs, expiry, retention, recovery
SecurityIsolation model and its limits
TroubleshootingCommon errors and fixes
Compared with other projectswhale, CTFd-owl, rCTF, kCTF, redpwn/jail
ChangelogWhat changed and why

Security warning ​

Browsers send cookies to every port on a hostname. If challenge containers are published on the same hostname as CTFd, a challenge with a remote code execution bug can steal player session cookies. Use a separate hostname or IP for challenges. See Security for the full picture.

Released under the MIT License.