Lab Portal · santos.rwxorange.com
Cloudflare Lab Environment

One zone. Four labs. Every defense demonstrated live.

This portal fronts the santos.rwxorange.com lab environment: public application-security targets behind Cloudflare’s edge, and a Zero Trust application that only opens with a verified identity. Pick a lab below.

Choose a lab

Public · AppSec

Application Security Lab

Live origin behind WAF, managed rules and DDoS protection — the reference architecture of Cloudflare’s app security pipeline.

appsec-lab.santos.rwxorange.com
Public · Attack target

OWASP Juice Shop

Intentionally vulnerable web shop for WAF, bot management and DDoS demonstrations — attacks are inspected at the edge, not here.

juice-shop.santos.rwxorange.com
Public · API

API Lab & Playground

Interactive API with schema-validated endpoints, JWT auth and an echo diagnostic — built for API Shield and rate limiting demos.

api-lab.santos.rwxorange.com
Zero Trust · Identity required

ZTNA Lab

Private application reached only through Cloudflare Access — identity verified at the edge, origin never publicly exposed.

ztna-lab.santos.rwxorange.com
Portal status CHECKING
Host …
Local time …