Deployment

Server setup, Docker Compose configuration, HAProxy routing, environment variables, and health checks.

The TACO platform runs on a single server using Docker Compose.

Server

PropertyValue
IP129.212.221.136
Userroot
OSLinux
RuntimeDocker + Docker Compose
Deploy dir/opt/taco/ (or wherever docker-compose.yml lives)

Docker Compose Setup

All services are defined in a single docker-compose.yml. Infrastructure services (MySQL, RabbitMQ, Valkey, Nexus) run alongside application services.

Service Categories

Infrastructure (run locally, persistent volumes):

  • mysql -- Port 3306, volume: mysql-data
  • rabbitmq -- Ports 5672 (AMQP) + 15672 (management UI)
  • valkey -- Port 6379
  • nexus -- Port 8443 (mapped from 8081), volume: nexus-data

Application services (pulled from GHCR):

  • taco-auth (8081), taco-inbound (8080), taco-store (8082), taco-alert (8083), taco-scanner (8084), taco-fetcher (8085), taco-secrets (8086), taco-enricher (no exposed port), taco-api (8090), taco-nextjs (3000), taco-corp (3000), taco-documentation (3001), taco-internal-documentation (3001), taco-support-bot (3100)

Runners (4 GitHub Actions self-hosted runners):

  • github-runner, github-runner-2, github-runner-3, github-runner-4

Reverse proxy:

  • haproxy -- Ports 80, 443, 8404 (stats)

Network

All services run on a single Docker bridge network called taco. Services communicate via Docker DNS names (e.g., mysql, rabbitmq, taco-api).

Deploy Commands

Pull latest images and restart

bashdocker compose pull
docker compose up -d

Restart a specific service

bashdocker compose pull taco-api
docker compose up -d taco-api

View logs

bashdocker compose logs -f taco-api
docker compose logs --tail 100 taco-scanner

Check service status

bashdocker compose ps

Force recreate a service

bashdocker compose up -d --force-recreate taco-api

HAProxy Configuration

HAProxy handles TLS termination and routes traffic by subdomain. Configuration file: haproxy.cfg.

Subdomain Routing

SubdomainBackendPort
portal.taco-sec.comtaco-nextjs3000
taco-inbound.taco-sec.comtaco-inbound8080
docs.taco-sec.comtaco-documentation3001
internaldocs.taco-sec.comtaco-internal-documentation3001
taco-sec.comtaco-corp3000

TLS

  • TLS certificates are stored in ./certs/ and mounted read-only into the HAProxy container.
  • ACME challenges are handled via a dedicated backend on port 80.
  • HSTS headers are set with max-age=63072000; includeSubDomains; preload.
  • HTTP to HTTPS redirect is enforced for all external traffic.

Local Access

Requests from private IP ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are allowed on plain HTTP for internal/development use.

Stats

HAProxy stats UI is available at http://localhost:8404/ (bound to 127.0.0.1).

TacoDB Volume

The vulnerability database file is stored at /opt/taco/data/taco.db.gz on the host and mounted into the taco-scanner container at /data/taco.db.gz.

Environment Variables

Sensitive configuration is stored in a .env file alongside docker-compose.yml. Key variables:

  • MYSQL_ROOT_PASSWORD, MYSQL_USER, MYSQL_PASSWORD
  • RABBITMQ_USER, RABBITMQ_PASS
  • JWT_SECRET
  • GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET
  • GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET
  • MAILGUN_DOMAIN, MAILGUN_API_KEY, MAILGUN_FROM
  • STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET
  • STRIPE_PRICE_PRO_MONTHLY, STRIPE_PRICE_ENTERPRISE_MONTHLY
  • FETCHER_INBOUND_TOKEN
  • TACO_NVD_API_KEY
  • GITHUB_RUNNER_PAT
  • DISCORD_BOT_TOKEN, DISCORD_APP_ID, DISCORD_SUPPORT_CHANNEL_ID
  • SUPPORT_WEBHOOK_SECRET, DISCORD_SUPPORT_WEBHOOK_URL

Self-Hosted Runners

Four GitHub Actions runners are deployed as Docker containers:

  • Scoped to the tacosec organization
  • Labels: self-hosted, linux, taco-platform
  • Ephemeral mode (fresh environment per job)
  • Docker socket mounted for Docker-in-Docker builds
  • Work directories on separate volumes (runner-work, runner-work-2, runner-work-3, runner-work-4)

Health Checks

Every service exposes a GET /healthz endpoint. Docker Compose health checks use these to determine service readiness and manage startup dependencies.

Dependency chain:

mysql (healthy) + rabbitmq (healthy) + valkey (healthy)
    |
    |-- taco-auth (healthy)
    |       |-- taco-inbound (healthy)
    |               |-- taco-store
    |               |-- taco-fetcher
    |               |-- taco-scanner
    |
    |-- taco-alert
    |-- taco-secrets
    |-- taco-enricher
    |-- taco-api --> taco-nextjs