Architecture

System diagram, microservices overview, data flow pipelines, network topology, and RabbitMQ exchanges.

System Diagram

                          Internet
                             |
                         [HAProxy]
                        /    |    \       \
                       /     |     \       \
                [NextJS]  [Inbound] [Corp] [Docs]
                   |         |
                   |    [RabbitMQ]
                   |    /    |    \
                [API]  /     |     \
                  |  [Store] |  [Alert]
                  |    |  [Scanner]
               [Valkey]|     |
                  |  [MySQL] |
                  |    |     |
               [Enricher]  [TacoDB]
                             |
                         [VulnDB CLI]

        [Fetcher] ---> [Inbound]       [Secrets] ---> [MySQL]
       (registries)                   (SBOM scanning)

Microservices

ServiceLanguageFrameworkPortRole
taco-apiGoEcho v48090REST API for frontend, manages users/subscriptions/projects/findings
taco-nextjsTypeScriptNext.js 163000Web frontend (portal.taco-sec.com)
taco-inboundGoEcho v48080SBOM ingestion gateway, publishes to RabbitMQ
taco-authGoEcho v48081Project token validation, Redis-cached lookups
taco-storeGostdlib8082RabbitMQ consumer, parses CycloneDX/SPDX SBOMs, stores components in MySQL
taco-alertGostdlib8083RabbitMQ consumer, dispatches alerts (Slack, email, webhook, PagerDuty)
taco-scannerGostdlib8084Vulnerability scanner, matches components against TacoDB
taco-fetcherGostdlib8085Fetches SBOMs from registries (Nexus, Artifactory, AWS, Azure, GCP)
taco-secretsGostdlib8086Scans SBOM content for leaked secrets/credentials
taco-enricherGostdlib8087Enriches findings with EPSS, NVD CVSS, CISA KEV, OSV.dev data
taco-vulndbGoCobra CLI--CLI tool to build/update/distribute vulnerability database
taco-libGolibrary--Shared library: vulndb engine, types, matching logic
taco-corpTypeScriptNext.js3000Corporate website (taco-sec.com)
taco-support-botTypeScriptNode.js3100Discord support bot

Infrastructure

ComponentImagePurpose
MySQL 8.0mysql:8.0Primary datastore for all services
RabbitMQ 3rabbitmq:3-management-alpineMessage broker for async SBOM/alert pipelines
Valkey 8valkey/valkey:8-alpineSession store (taco-api), token cache (taco-auth)
HAProxy 3.1haproxy:3.1-alpineTLS termination, subdomain routing
Nexus 3sonatype/nexus3:latestDevelopment artifact repository

Data Flow

SBOM Ingestion Pipeline

  1. Ingest -- An SBOM is submitted to taco-inbound via POST /api/v1/sbom with a project token in the Authorization header.
  2. Authenticate -- taco-inbound validates the token by calling taco-auth at GET /api/v1/token/validate.
  3. Publish -- The validated SBOM is published to RabbitMQ on the taco.sbom exchange with routing key sbom.ingest.
  4. Parse & Store -- taco-store consumes from the taco.sbom.store queue, parses the SBOM (CycloneDX or SPDX), extracts components, and inserts them into MySQL (sboms, components, sbom_components tables).
  5. Scan -- taco-scanner runs on a configurable interval (default 5m). It loads the TacoDB vulnerability database, queries all components from MySQL, and matches package URLs against known vulnerabilities. New findings are inserted into the findings table; resolved findings are marked with resolved_at.
  6. Alert -- When the scanner produces new findings, it publishes an event to RabbitMQ. taco-alert consumes these events, checks per-project alert configurations, filters by severity threshold, and dispatches notifications via configured channels (Slack, email, webhook, PagerDuty).
  7. Enrich -- taco-enricher runs a background worker that periodically queries findings with enrichment_status = 'pending'. For each CVE, it fetches EPSS scores from FIRST, CVSS vectors from NVD, checks CISA KEV status, and computes a composite risk score. Non-CVE IDs (GHSA, ALAS, etc.) are enriched via OSV.dev.
  8. Display -- taco-nextjs calls taco-api to fetch projects, SBOMs, components, findings, secrets, and dashboard data. The API serves all data from MySQL.

Secret Detection Pipeline

  1. taco-secrets polls MySQL for SBOMs that haven't been scanned for secrets (secrets_scan_state table).
  2. For each unscanned SBOM, it runs regex-based rules against the raw SBOM content (AWS keys, GitHub tokens, private keys, database URLs, etc.).
  3. Matches are masked before storage -- raw secrets are never persisted.
  4. Results are written to the secrets table with severity, category, confidence, and file location.

Automated Fetching Pipeline

  1. taco-fetcher runs on a configurable interval (default 10m).
  2. It connects to configured artifact sources: Nexus, JFrog Artifactory, AWS (ECR, Lambda, CodeArtifact), Azure (ACR, Functions, Artifacts), GCP (Artifact Registry, Cloud Functions, Cloud Run).
  3. For each source, it fetches component lists and submits them to taco-inbound as SBOMs, triggering the standard ingestion pipeline.

Vulnerability Database Update

  1. taco-vulndb CLI (or the scanner's built-in updater) fetches vulnerability data from 9 sources: NVD, OSV, GHSA, Alpine SecDB, Debian, Ubuntu, Red Hat, ALAS, CISA KEV.
  2. Data is merged with source-priority deduplication and compiled into a single compressed database file (taco.db.gz).
  3. taco-scanner loads this database file and uses it for component matching.
  4. The database can be distributed via OCI registries using taco-vulndb push/pull.

Network Topology

All services run on a single Docker Compose network (taco). External traffic enters through HAProxy, which terminates TLS and routes by subdomain:

SubdomainBackend
portal.taco-sec.comtaco-nextjs:3000
taco-inbound.taco-sec.comtaco-inbound:8080
docs.taco-sec.comtaco-documentation:3001
internaldocs.taco-sec.comtaco-internal-documentation:3001
taco-sec.comtaco-corp:3000

Internal services communicate via Docker DNS names (e.g., http://taco-api:8090, amqp://rabbitmq:5672).

RabbitMQ Exchanges and Queues

ExchangeTypeRouting KeyConsumer QueueProducerConsumer
taco.sbomtopicsbom.ingesttaco.sbom.storetaco-inboundtaco-store
taco.sbomtopicfindings.*taco.alert.queuetaco-scannertaco-alert
taco.sbom.dlxfanout----dead-letter--
taco.secretstopicsecrets.ingesttaco.secrets.storetaco-inboundtaco-store (secrets consumer)