Welcome to the Digital Resilience Community Clinic (DigitalRCC) lab documentation wiki — the architecture, configuration and operational procedures behind the CMMC Level 1 hands-on lab. The lab was previously branded TCecure CRC CyberLab; the infrastructure is unchanged, the public names are not.
Status — September 22, 2026: all six CMMC Level 1 lab families (AC, IA, SI, SC, MP, PE — 57 labs) run on per-student pod member servers, and the current cohort is seated through the portal.
- Public names moved to
digitalrcc.com. Guacamole, Moodle, AWX, the wiki, the tracker and LabOps all answer on*.digitalrcc.com; the old*.tcecure.comnames still serve as a rollback path. Map and certificate state on Reverse Proxy Configuration.- Students work on their own server. One Guacamole connection,
PODXX-SRVat10.50.XX.20, where the student is a local administrator.DC01-P01andDC02-P01remain domain controllers only — student logon on the DCs has been retired. See Pod Member Servers.- The three host-rights waivers are retired. IA M2-L1's stored-credential step, MP M1-L1/M1-L2 media mounting and IA M3-L2's password policy are now performed and graded for real in member-server mode (IA M3-L2 is graded against the session host's own local policy instead of the shared domain policy). See Current Cohort Lab Notices.
- The portal is the front door. Students are invited to
https://my.digitalrcc.com, where their pod, access window, digital lab guides and progress live; staff get the queue, student progress with frozen per-cohort standings, Live Operations and Impact. See Portal Integration.- Lab and portal email is authenticated DigitalRCC mail —
no-reply@digitalrcc.comover the Google Workspace relay, SPF/DKIM/DMARC in place. See Email Delivery.- The pod firewall is reached from a browser inside the pod server at
http://10.51.XX.1; thePODXX-GWtiles remain hidden. See Network & Firewall.- Open items: POD07-SRV / POD11-SRV are still unactivated (replacement Datacenter keys outstanding) and both pods are held back from auto-advance;
DC02-P01runs Datacenter Evaluation expiring October 2, 2026. See Backlog & Known Issues.
| Audience | Page |
|---|---|
| Students | Student Quick Start — portal, Guacamole, your pod, evidence, progress |
| Students | Lab Guides — completion guides for all six families |
| Students | Current Cohort Lab Notices — tool-launch rules, firewall access, known lab issues |
| Instructors | Lab Families — curriculum, module breakdown, lab counts |
| Instructors | AWX Automation — seed, verify, reset, auto-advance |
| Instructors | Training Tracker — per-pod progress dashboard |
| Instructors | Lab Health Monitoring — read-only Proxmox health on the DigitalRCC admin dashboard |
| Instructors | Portal Integration — cohorts, queue, progress, ratings, Live Operations |
| Staff | Email Delivery — sending domain, templates, what students receive |
| Staff (owner-only) | DigitalRCC LabOps AI — support-triage assistant and Direct Chat in the LabOps console |
| Visitors | CyberLab Overview — high-level walkthrough for demos |
| Section | Description |
|---|---|
| Architecture Overview | Network topology, Proxmox hosts, VLANs |
| Domain Controllers | DC01-P01, DC02-P01, acs-p01.local domain |
| Pod Infrastructure | 20-pod student workspace architecture and per-pod networking |
| Pod Member Servers | Per-pod PODXX-SRV session hosts |
| OU Structure | Active Directory OU hierarchy & delegation |
| User & Group Naming | PXX- prefix conventions for all objects |
| GPO & Logon Scripts | Per-pod desktop shortcut deployment |
| MMC Shortcuts | Scoped ADUC launchers per pod |
| VM Inventory | All VMs across PVE1 and PVE2 |
| Network & Firewall | Dreamwall, VLANs, routing, pod firewall access |
| Lab Health Monitoring | Read-only Proxmox poller feeding the portal |
| Portal Integration | my.digitalrcc.com cohorts, progress, Live Operations, Impact |
| Email Delivery | DigitalRCC sending domain, relay and templates |
| DigitalRCC LabOps AI | LabOps AI host, security model, Direct Chat, runbooks |
| Reverse Proxy Configuration | Public hostnames and routing |
| Backlog & Known Issues | Outstanding tasks and known issues |
| Section | Description |
|---|---|
| CDW Overview | Architecture, network, and purpose of the CDW environment |
| CDW VM Inventory | All 7 CDW VMs — specs, roles, IPs, snapshots |
| CDW Network & Access | VLAN 50, proxy routing, SSH jump paths, Guacamole connections |
| CDW Credentials | All usernames, passwords, and keys for CDW services |
| CDW Operations Guide | Engagement workflow, snapshot reset, troubleshooting |
| CDW VPN Configuration | WireGuard setup, client templates, NinjaOne deployment |
| Item | Value |
|---|---|
| Domain | acs-p01.local |
| DC01 (Primary, directory only) | VM 200, 10.50.1.10, DC01-P01 — 12 vCPU / 32 GB, no student logon |
| DC02 (Replica, no student sessions) | VM 221, 10.50.1.11, DC02-P01 — 4 vCPU / 16 GB, Server 2022 Evaluation expiring Oct 2, 2026 |
| Proxmox Host 1 (PVE1) | 192.168.1.90 (SSH: 108.31.169.90:2225) |
| Proxmox Host 2 (PVE2) | 192.168.1.9 |
| Pod Count | 20 (Pod01 - Pod20), 1 student per pod |
| Pod Networks | 10.51.XX.0/24 per pod, pfSense gateway at 10.51.XX.1 (VMs 300–319); pod hosts on 10.50.XX.0/24 |
| Pod Member Servers | PODXX-SRV at 10.50.XX.20 (VM 400 + pod) — all 20 built, domain-joined and student-mapped; POD07/POD11 awaiting licences |
| Student Access | Guacamole — https://guac.01.digitalrcc.com/#/ (single connection PODXX-SRV → 10.50.XX.20) |
| Student / Staff Portal | https://my.digitalrcc.com |
| Progress Tracker | https://training.digitalrcc.com |
| LMS (Moodle) | https://lms.digitalrcc.com |
| AWX | https://awx.digitalrcc.com — VM 103 (crc-awx-k8s-01), 192.168.1.103:30080, AWX 24.6.1 |
| LabOps console / LabOps AI | https://labops.digitalrcc.com — drcc-labops-01, 192.168.1.65 |
| Wiki.js | https://wiki.digitalrcc.com — VM 106, 192.168.1.42:80 |
| Tracker / MCP host | 192.168.1.61 |
| Sending domain | no-reply@digitalrcc.com (support: support@digitalrcc.com) |
| Lab Curriculum | 6 families, 57 labs (AC 12, IA 12, SI 12, SC 12, MP 3, PE 6) |
Last updated: September 22, 2026