Deployment
Server setup, Docker Compose configuration, HAProxy routing, environment variables, and health checks.
The TACO platform runs on a single server using Docker Compose.
Server
| Property | Value |
|---|---|
| IP | 129.212.221.136 |
| User | root |
| OS | Linux |
| Runtime | Docker + Docker Compose |
| Deploy dir | /opt/taco/ (or wherever docker-compose.yml lives) |
Docker Compose Setup
All services are defined in a single docker-compose.yml. Infrastructure services (MySQL, RabbitMQ, Valkey, Nexus) run alongside application services.
Service Categories
Infrastructure (run locally, persistent volumes):
mysql-- Port 3306, volume:mysql-datarabbitmq-- Ports 5672 (AMQP) + 15672 (management UI)valkey-- Port 6379nexus-- Port 8443 (mapped from 8081), volume:nexus-data
Application services (pulled from GHCR):
taco-auth(8081),taco-inbound(8080),taco-store(8082),taco-alert(8083),taco-scanner(8084),taco-fetcher(8085),taco-secrets(8086),taco-enricher(no exposed port),taco-api(8090),taco-nextjs(3000),taco-corp(3000),taco-documentation(3001),taco-internal-documentation(3001),taco-support-bot(3100)
Runners (4 GitHub Actions self-hosted runners):
github-runner,github-runner-2,github-runner-3,github-runner-4
Reverse proxy:
haproxy-- Ports 80, 443, 8404 (stats)
Network
All services run on a single Docker bridge network called taco. Services communicate via Docker DNS names (e.g., mysql, rabbitmq, taco-api).
Deploy Commands
Pull latest images and restart
bashdocker compose pull
docker compose up -d
Restart a specific service
bashdocker compose pull taco-api
docker compose up -d taco-api
View logs
bashdocker compose logs -f taco-api
docker compose logs --tail 100 taco-scanner
Check service status
bashdocker compose ps
Force recreate a service
bashdocker compose up -d --force-recreate taco-api
HAProxy Configuration
HAProxy handles TLS termination and routes traffic by subdomain. Configuration file: haproxy.cfg.
Subdomain Routing
| Subdomain | Backend | Port |
|---|---|---|
portal.taco-sec.com | taco-nextjs | 3000 |
taco-inbound.taco-sec.com | taco-inbound | 8080 |
docs.taco-sec.com | taco-documentation | 3001 |
internaldocs.taco-sec.com | taco-internal-documentation | 3001 |
taco-sec.com | taco-corp | 3000 |
TLS
- TLS certificates are stored in
./certs/and mounted read-only into the HAProxy container. - ACME challenges are handled via a dedicated backend on port 80.
- HSTS headers are set with
max-age=63072000; includeSubDomains; preload. - HTTP to HTTPS redirect is enforced for all external traffic.
Local Access
Requests from private IP ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are allowed on plain HTTP for internal/development use.
Stats
HAProxy stats UI is available at http://localhost:8404/ (bound to 127.0.0.1).
TacoDB Volume
The vulnerability database file is stored at /opt/taco/data/taco.db.gz on the host and mounted into the taco-scanner container at /data/taco.db.gz.
Environment Variables
Sensitive configuration is stored in a .env file alongside docker-compose.yml. Key variables:
MYSQL_ROOT_PASSWORD,MYSQL_USER,MYSQL_PASSWORDRABBITMQ_USER,RABBITMQ_PASSJWT_SECRETGITHUB_CLIENT_ID,GITHUB_CLIENT_SECRETGOOGLE_CLIENT_ID,GOOGLE_CLIENT_SECRETMAILGUN_DOMAIN,MAILGUN_API_KEY,MAILGUN_FROMSTRIPE_SECRET_KEY,STRIPE_WEBHOOK_SECRETSTRIPE_PRICE_PRO_MONTHLY,STRIPE_PRICE_ENTERPRISE_MONTHLYFETCHER_INBOUND_TOKENTACO_NVD_API_KEYGITHUB_RUNNER_PATDISCORD_BOT_TOKEN,DISCORD_APP_ID,DISCORD_SUPPORT_CHANNEL_IDSUPPORT_WEBHOOK_SECRET,DISCORD_SUPPORT_WEBHOOK_URL
Self-Hosted Runners
Four GitHub Actions runners are deployed as Docker containers:
- Scoped to the
tacosecorganization - Labels:
self-hosted,linux,taco-platform - Ephemeral mode (fresh environment per job)
- Docker socket mounted for Docker-in-Docker builds
- Work directories on separate volumes (
runner-work,runner-work-2,runner-work-3,runner-work-4)
Health Checks
Every service exposes a GET /healthz endpoint. Docker Compose health checks use these to determine service readiness and manage startup dependencies.
Dependency chain:
mysql (healthy) + rabbitmq (healthy) + valkey (healthy)
|
|-- taco-auth (healthy)
| |-- taco-inbound (healthy)
| |-- taco-store
| |-- taco-fetcher
| |-- taco-scanner
|
|-- taco-alert
|-- taco-secrets
|-- taco-enricher
|-- taco-api --> taco-nextjs