Prepare the workstation and account

Run these commands from a local checkout of the repository. You need Go compatible with the repository module, Make, Terraform 1.6 or newer, the AWS CLI and an SSH public key. Install kubectl and Helm 3 if you will stage the Kubernetes runtime. The referenced module declares Go 1.22; check the version in the checkout you are studying.

Use a dedicated AWS lab account with billing alerts, temporary SSO credentials and MFA. An easy range still creates paid resources, including EKS, a NAT Gateway, an application load balancer and compute. Select a region with sufficient account quotas before you apply the plan.

You also need your current public IPv4 address as a single /32 and the stable IAM role ARN intended for EKS administration. The initial workflow does not require a domain, DNS zone or attacker jumpbox.

Establish the intended AWS identity

Create or use an IAM Identity Center profile. The commands below use vulnvm as the local profile name.

aws configure sso
aws sso login --profile vulnvm
aws sts get-caller-identity --profile vulnvm

Check that the returned account is your lab account. The identity command usually prints a temporary STS session ARN. EKS configuration needs the underlying stable IAM role ARN instead, including any Identity Center role path. Your account administrator can provide that value. Read the identity separation guidance before choosing permanent permissions.

Build and initialize locally

Replace the public IP, account number and role name below with your own values. The SSH argument must point to a public key, never a private key.

make build
bin/vulnvm init aws -p vulnvm -r eu-central-1 \
  -c YOUR_PUBLIC_IP/32 -k ~/.ssh/id_ed25519.pub \
  --eks-operator-arn arn:aws:iam::123456789012:role/YOUR_OPERATOR_ROLE
bin/vulnvm doctor

Initialization creates .vulnvm/config.json. It does not deploy resources. Doctor checks the local tools, configuration, key, EKS principal and AWS identity. Resolve failed checks before proceeding. Missing Helm or kubectl can appear as optional checks because basic infrastructure operations and workload installation have different prerequisites.

Inspect the scenario before planning

bin/vulnvm catalog
bin/vulnvm inspect telecom-provider
bin/vulnvm plan telco -t easy -n telco-easy-1

The catalog lists available scenarios and tiers. Inspect explains public and private services, expected AWS resources and outputs. telco is an alias for telecom-provider.

Planning produces a compact Terraform resource summary without applying it. Review the scenario, tier, region, account, operator address and resources. Planning can initialize Terraform and query AWS, so valid credentials and provider dependencies still matter. Keep telco-easy-1 as the name for the rest of this guide.

Create and inspect the named environment

The next command creates paid AWS resources after confirmation.

bin/vulnvm up telco -t easy -n telco-easy-1
bin/vulnvm status -n telco-easy-1
bin/vulnvm outputs -n telco-easy-1

Open a public route printed by outputs from the allowed operator address. The generated scenario application is served through the AWS ALB DNS name. Outputs can use cached values when Terraform output retrieval is unavailable; use status to inspect live infrastructure health.

For progress or a failure, use bin/vulnvm logs -n telco-easy-1 -f. These are Terraform logs. They are different from application request logs or behavior evidence.

Optionally stage the Kubernetes workload

The Kubernetes slice documented by this legacy guide is telecom-provider/easy. It requires a published, anonymously pullable GHCR image pinned by its release digest. Follow runtime installation to deploy the portal, provisioning, inventory and behavior workloads.

The install waits for a healthy EKS target but leaves its listener weight at zero. Public ALB traffic continues to use EC2. This staged runtime is useful for verifying the service chain and deterministic activity without implying that a public traffic cutover has occurred.

Finish by removing the same run

bin/vulnvm destroy -n telco-easy-1 --plan-only
bin/vulnvm destroy -n telco-easy-1
bin/vulnvm ls

Review the destroy plan, then confirm teardown. If installed, the application is removed before the load balancer controller and Terraform infrastructure. Keep the local run state until cleanup has finished.

The CLI requires an empty managed Terraform inventory and no root outputs before recording destruction. Independently inspect the AWS account for leftovers. TTL tags and reminders do not perform this teardown for you.