Content Hub
Deploy ready environments from a card, built on your own appliance.
On this page
The Content Hub deploys complete environments from a card: a single appliance such as a threat-hunting stack, or a multi-device range such as an Active Directory attack range. Pick a card, answer a short wizard, and ONEP builds the environment and opens it on the canvas. Open the Content Hub from Content Hub in the sidebar.
A recipe, not a download#
Each card is a recipe. The first time you deploy an appliance card, ONEP builds it on your appliance from the project's own source and installer, then registers the finished image in Centrum. That first build needs internet access from the appliance and takes a while. A card that has not been built yet shows The first build takes a while. when you point at its size line.
Later deploys of the same card reuse the finished image. The card shows a Ready chip, and the wizard offers Already baked — registered in Centrum, deploys in seconds as the base. If the operating system image a recipe builds on is not in Centrum, the wizard fetches it from Discover first. That fetch does not use one of your monthly Discover downloads.
For content that comes from an upstream project, the wizard names the project under its step list (Built from) and again on the finish screen.
Find a card#
- Search blueprints in the page header matches a card's name, description and tags.
- The category buttons filter the list: All, Cybersecurity, OT/ICS, Telco and Cloud.
- The Tier buttons filter by the tier chip: All tiers, Official, Community and Premium.
- Cards are shown 16 to a page. When there is more than one page, Back and Next appear under the list with Page X of Y and the number of cards.
- If nothing matches, the list says No blueprints match. Clear filters clears the search and the category.
Reading a card#
- Title and description. The description is cut to three lines.
- Chips at the top right: the tier (Official, Community or Premium), Ready when the card has already been built on this appliance, and a chip on a card that is not available yet. A range built on Microsoft evaluation media also carries an Evaluation media chip; the finish screen repeats that the media is not for production use.
- Tags such as SIEM, Blue team, CVE or Range. Up to three are shown, then +N for the rest.
- Size line: the number of devices and approximate memory, with built added once the card has been built on this appliance. A collection of ranges shows its number of variants instead.
- One action: normally Deploy. Other actions and lines you may see in its place are described below.
| You see | What it means |
|---|---|
| Deploy | Opens the deploy wizard for the card. |
| Preview | On a card that is not available yet. Opens a dialog that reads the project's public repository. See Preview a card. |
| Take a look | On a range that is in development. Opens its description only. The range cannot be deployed in this release. |
| Runs on ONEP Pro / Runs on ONEP Lite | Your edition cannot run this card. See What your edition includes. |
| Needs N GB RAM | The appliance has too little memory for this card. See The size check. |
What your edition includes#
Every card stays visible on every edition. The edition decides what you can deploy:
- Cards with several devices and every range show Runs on ONEP Pro on Community and Lite.
- A single-appliance card larger than your edition's maximum device size shows Runs on followed by the smallest edition that can run it.
- Deploy allowance. On an edition that limits Content Hub deploys, a line under the page title shows what is left, for example 1 of 2 Content Hub deploys available · counted over 30 days. When it is used up the line reads No Content Hub deploys left and gives the date the next one is possible. A deploy is counted when the device is placed on the canvas. Editions without a limit show no line.
The numbers for each edition are on Limits per edition.
The size check#
Before a single-appliance card is offered, its declared size is compared with the appliance itself. The check uses the appliance's total memory and cores, not what is free at that moment.
- Memory refuses. If the card could never run on this appliance, the card shows Needs N GB RAM in place of Deploy. N is a memory size you can buy; it includes a reserve for ONEP itself. If a deploy is started another way, the server refuses it with a message of the form Needs a box with N GB RAM.
- Cores warn. If the appliance has fewer cores than the card recommends, a line under the card reads Runs slowly: N cores recommended. The deploy is still allowed.
If the check cannot read the appliance's memory it does not block the card.
Deploy a single appliance#
Choose Deploy on an appliance card. The wizard opens with its steps listed on the left. Use Back and Continue to move, or select a finished step on the left to return to it. Close the wizard with the close button or Esc; after the first step it asks Discard this deploy setup? first.
- Environment"Where does this environment live?" Choose New environment (a clean canvas, named <card> environment unless you change it) or Existing environment and pick one from the list. A line shows how many environments you have used. When you are at the limit, Continue is off and the wizard tells you to delete an environment or choose an existing one.
- Variant"Which <card> edition?" Most cards have one entry, Standard, already selected. Enterprise SIEM (HELK) offers four: Basic core, Core + ElastAlert, Core + Spark + Jupyter and Full suite. Each shows its memory.
- Resolved plan"Here's what will land." Choose the Base operating system: the already built image (Already baked), a server image you have in Centrum, or Get Ubuntu server from Discover. If Centrum has no suitable image, the step says the operating system will be fetched from Discover first. Then set the appliance's IP, Subnet, and optionally Gateway and DNS; leave the last two empty to keep the appliance isolated. The plan lists the device with its vCPU, memory and disk and a badge: edition preset or your override. The pencil opens vCPU, RAM MB and Disk GB fields. The recipe's own minimums still apply.
- Companions"Complete the environment." Turn on Endpoint to add a workstation you work from, and choose its image from Centrum. Once an endpoint is on, a Switch option appears to connect the two; nothing is chosen for you, so pick a switch image or turn it off. Container access lets you inspect the appliance's containers without giving them a path out; it is on by default for appliance cards. Environments are isolated: if devices need the internet, add a Cloud on the canvas afterwards.
- Review"One last look." Shows the number of nodes, total memory, and the network (Air-gapped), then lists the environment, edition, base operating system, switch, endpoint and container access (shown as Container expose). Deploy environment starts the build.
- DeployThe build log and progress bar. See The build log.
The wizard checks your environment limit before it starts, and the deploy is also checked against your edition's device size and Content Hub allowance. A refusal comes back as a message in the wizard and no build starts.
Security Onion#
The Security Onion card works differently. Deploy looks in Centrum for a Security Onion image. If it finds one, it places a Security Onion device on a new canvas and opens that environment. If it does not, it starts the download from Discover and opens Centrum; deploy the card again when the download has finished.
Deploy a range#
Ranges are collections of environments, such as GOAD and the Malcolm NSM Range. A range card shows its number of variants and opens a shorter wizard with four steps: Environment (name the new environment), Variant (choose one scenario), Review and Deploy. A range always creates a new environment. Its machines, addressing and wiring come from the recipe, so there is no Companions step.
The Variant step lists each scenario with its device count, memory and a description. The description states how much free memory the appliance needs for that variant; check it against your hardware before you continue. Review shows the variant, devices, memory and the air-gapped network. The GOAD family builds its Windows machines from Microsoft 180-day evaluation media, and the wizard says so on Review and on the finish screen.
Switch choice#
A range whose recipe includes switches adds a Range switch choice on the Review step. One choice applies to every switch in the range. The default is the native switch built into ONEP, with nothing to license. You can instead pick a Layer 2 switch image from your library; those images are listed as customer-licensed and are yours to license.
Preview a card#
Preview on a card that is not available yet opens a dialog titled Deploy <card> that needs internet access. It scans the project's public repository, and then:
- Pick an environmentIf the repository defines more than one, choose one. A repository with nothing ONEP can deploy says why and what you can do instead.
- Check the imagesEach device appears with a green or amber dot. Green means a matching image is in Centrum. For an amber device you can use Get <image> to start a Discover download, Register your own to open Centrum, or Skip. Re-check library matches again.
- Deploy environmentStays off until every amber device has an image or has been skipped.
The build log#
After you choose Deploy environment, the wizard shows Building your environment: one line per step and a progress bar. A line turns green when the step has been confirmed, and amber when a step did not land. While a card is being built, the bar follows the real build; a deploy that reuses a finished image still shows this screen for about two minutes. Short notes about the project and about how ONEP builds appear underneath while you wait. You cannot close the wizard while it is building.
When it ends you see one of two screens:
- Your environment is ready when every step landed.
- Deployed with gaps with a list of what did not land. Everything else is up. If a feature that depends on a missing step does not behave, check it from the device's console.
How to get in lists the logins for the deployed machines. A password is hidden until you press the eye icon (Reveal password); the copy icon (Copy password) puts it on the clipboard without showing it. Enter environment opens the canvas. Close returns to the Content Hub.
After the deploy#
- The environment is on your canvas like any other. Start, stop and open consoles as usual; see Environments.
- All machines of a range share one Layer 2 segment. For a routed, multi-segment design, build it on the canvas.
- Only one build runs at a time. If you start a card while another card is being built, the deploy is refused with a message naming the one in progress; try again when it finishes. A range deploy and a card build on the same appliance also compete for processor time.
Delete a deployed environment#
A deployed environment is deleted from the Environments page like any other. An image cannot be removed from Centrum while an environment uses it, so delete the environment first.