Codename:
THEATRE
Azazel-Deception is AZ-06 Azazel-Deception Host, the attacker-facing Engagement Environment Plane of the Azazel series.
It materializes bounded, coherent deception environments from versioned packages after approval by Azazel-Edge. It is a portable, capability-aware, container-first runtime: Raspberry Pi 5 is a minimum reference host, not a product constraint.
Engage expresses intent. Knowledge advises. Fabric describes. Edge decides and enforces. Deception Host materializes, transitions, records, and resets.
Phase 0 complete; Phase 1 in progress. The AZ-06 designation is ratified and the canonical Azazel-Fabric deception-environment contracts are landed and pinned to an exact release tag (see docs/fabric-pin.md). Live engagement remains disabled by default and stays that way until the Phase-1 live gates close — including physical/hardware-in-the-loop isolation gates that no CI run can satisfy. Per-item status is in docs/roadmap.md, docs/implementation-status.md and docs/live-gate-checklist.md.
Initial portability target:
- OCI containers
linux/arm64andlinux/amd64- Docker Compose reference adapter
- static Linux deception package
- deterministic package validation, lifecycle, evidence, and reset semantics
- no GPU, KVM, Kubernetes, or online LLM requirement
Implemented today: host capability discovery, fail-closed package validation with a normalize-first canonical content digest, deterministic non-executing placement planning, a synthetic Linux reference package on an immutable multi-architecture image digest, isolated Compose assets with a static isolation policy, a gated Compose lifecycle adapter (default-off), a tamper-evident evidence chain, authenticated one-shot Edge decision handling, an operator kill switch, an Edge shadow/replay boundary, native ARM64/AMD64 portability CI, tests, and safety/integration documentation. These are software properties; they are not field or HIL certification.
Azazel-Deception owns:
- host capability discovery
- validation and materialization of already-approved deception packages
- isolated decoy services, files, credentials, personas, and bounded activity runtime
- execution of approved finite-state transitions
- interaction evidence export
- deterministic reset and credential invalidation
Azazel-Deception does not own:
- final engagement decisions or route enforcement — Azazel-Edge owns those
- shared wire-contract authority — Azazel-Fabric owns those contracts
- effectiveness scoring or posture authority — Azazel-Knowledge remains advisory-only
- unrestricted autonomous planning
- hack-back, attacker-system compromise, arbitrary code delivery, or uncontrolled decoy egress
- runtime LLM authority
Azazel-Knowledge Advisor
| advisory-only context
v
Azazel-Edge Gateway
deterministic approval / routing / budgets / termination
| signed, versioned decision
v
Azazel-Deception Host
package validation / capability match / runtime adapter / evidence / reset
| measured outcomes
v
Azazel-Knowledge Advisor
Within AZ-06:
DeceptionPackage
|
v
Package Validator ---- Host Capabilities
| |
+----------+----------+
v
Placement Planner
|
v
Runtime Adapter
Docker Compose
|
v
Isolated Decoy Runtime
|
v
Evidence + Reset Result
| Tier | Reference host | Intended use |
|---|---|---|
lite |
Raspberry Pi 5 / ARM64 SBC | one small static Linux environment |
standard |
N100/N305-class x86 mini PC | multiple containers and richer deterministic environments |
heavy |
KVM-capable x86 host | later VM-capable and multi-segment environments |
cluster |
multiple nodes | future work; not part of the initial implementation |
Packages declare required capabilities and explicitly optional components. Missing required capabilities fail closed; AZ-06 never silently weakens isolation or required narrative components.
LLM use is optional and preparation-oriented. It may help draft narratives, synthetic documents, personas, or package content before deployment. Any AI-generated material must be validated, frozen, versioned, and signed before activation.
Approved packages remain fully executable with no LLM available at runtime. An LLM never selects an engagement, opens a port, changes routing, authorizes a transition, or mutates a live environment autonomously.
- no route from decoy workloads to protected production assets
- decoy egress denied by default
- no real credentials, personal data, secrets, or production artifacts in reference packages
- explicit duration, CPU, memory, storage, connection, and traffic budgets
- fail closed on unsupported schema, capability mismatch, invalid provenance, stale decision, or inconsistent narrative
- operator-visible lifecycle and manual termination
- evidence-preserving deterministic teardown and reset
- Docker socket, Edge control APIs, and host privileged interfaces are never exposed to attacker-facing workloads
See docs/safety-model.md.
The initial CLI is intentionally non-executing. It reports host capabilities, validates the bootstrap reference package, and produces a deterministic placement plan while the Fabric and Edge activation contracts stabilize.
python -m azazel_deception capabilities
python -m azazel_deception validate examples/packages/municipal-linux-v1/package.yaml
python -m azazel_deception plan examples/packages/municipal-linux-v1/package.yaml
# Canonical package integrity (representation-invariant, normalize-first):
python -m azazel_deception digest examples/packages/municipal-linux-v1/package.yaml
python -m azazel_deception canonical-payload examples/packages/municipal-linux-v1/package.yaml
python -m azazel_deception seal examples/packages/municipal-linux-v1/package.yaml # emits sealed package to stdoutThe plan command produces a descriptive placement plan only. It does not start containers and carries no activation authority.
package_digest is a deterministic semantic content digest computed from the normalized Fabric model (never the raw YAML), so the same meaning hashes identically across raw dict, model, YAML reload, and JSON round-trip. seal stamps that digest at authoring time and never rewrites the source in place; validate verifies it fail-closed. The detached signature_ref locator is excluded from the digest so an attestation reference can be rotated after signing.
src/azazel_deception/ bootstrap control-plane code
runtime/compose/ reference Docker Compose adapter assets
examples/packages/ deterministic reference deception packages
scripts/dev/ developer/verification tooling (preflight, compose smoke, virtual lab)
docs/ architecture, safety, contracts, integration, roadmap, traceability
tests/ deterministic bootstrap tests
Notable changes are recorded in CHANGELOG.md.
The requirements inherited from the Azazel-series issues are mapped in docs/source-traceability.md. This records which doctrine, Fabric, Edge, Knowledge, and Gadget issues produced each AZ-06 responsibility and safety invariant.
Primary cross-repository dependencies:
- Doctrine / parent:
01rabbit/Azazel#61 - Engage system model:
01rabbit/Azazel#60 - Shared contracts:
01rabbit/Azazel-Fabric#9and#8 - Edge authority / activation:
01rabbit/Azazel-Edge#325and#319 - Effectiveness analysis:
01rabbit/Azazel-Knowledge#58and#52 - Gadget fixed-profile compatibility boundary:
01rabbit/Azazel-Gadget#17and#16
Issue states below were read from GitHub on 2026-09-19. Route work only to the open trackers.
| Open issue | Purpose |
|---|---|
| #3 | Prove one signed reference package on ARM64 and AMD64 — reviewed SBOM-content policy and equivalent end-to-end lifecycle on both architectures remain open |
| #28 | Separate Deception lifecycle state from Edge/Gadget Defensive State |
| #30 | Research: Deception as a Presented Terrain engine with transition, fingerprint, and outcome-evidence discipline |
| #31 | Static Presented Terrain vertical slice — the v0 slice is delivered and CI-green; the issue tracks the adaptive/fingerprint/benchmark follow-ons its body excludes |
| #35 | Reconcile AZ-06 assurance evidence and define bounded Nexus/Boot Lite profiles |
| #6 | Phase 2 coherent narrative, honey artifacts, credentials, personas, and finite-state transitions — gated, not started |
Closed, kept only as history: #1 (canonical Fabric contracts), #2 (feature-disabled Compose lifecycle adapter), #4 (isolation/evidence/termination/reset harness), #5 (Edge shadow/replay integration). Closing them did not close the hardware-in-the-loop gates; those remain open in docs/live-gate-checklist.md.
The remaining order is #3 → live Phase 1 gate → #6, with #28/#30/#31 running alongside. Live exposure must not be enabled merely because a runtime adapter can start containers, and Phase 2 must not begin merely because CI is green.
- Phase 0 — canonical contracts, threat model, isolation, provenance, golden fixtures, dry-run only.
- Phase 1 — one static coherent Linux environment on ARM64 and AMD64, behind explicit Edge authorization and feature gates.
- Phase 2 — coherent honey artifacts, decoy-only credentials, deterministic personas, and Edge-approved finite-state transitions.
- Phase 3 — Knowledge effectiveness loop, advisory-only.
- Phase 4 — additional Linux/Windows/OT/IoT environment classes after isolation and reset are proven.
Use MITRE Engage-aligned or Engage-informed. This project does not claim MITRE certification or guaranteed attacker belief. Measure and report observed interaction, observed reaction, and measured outcomes.
MIT. See LICENSE.
