taco-auth
The token validation service. Validates project tokens for the SBOM ingestion pipeline.
The token validation service. Validates project tokens for the SBOM ingestion pipeline.
Overview
| Property | Value |
|---|---|
| Language | Go |
| Framework | Echo v4 |
| Port | 8081 |
| Exposed | Internal only |
| Dependencies | MySQL, Valkey |
| Repository | tacosec/taco-auth |
Architecture
taco-auth is a focused service with a single responsibility: validating project tokens issued by taco-api. It uses a two-tier lookup strategy:
- Redis cache (Valkey) -- Fast path. Tokens are cached in Valkey with a configurable TTL (default 5 minutes).
- MySQL fallback -- If the token is not in cache, it queries the
project_tokenstable in MySQL.
This design allows taco-inbound to validate tokens at high throughput without putting load on MySQL for every SBOM submission.
Key Packages
| Package | Purpose |
|---|---|
handler/ | Token validation HTTP handler |
token/ | Token store: Redis cache, MySQL backend, composite store |
config/ | Environment variable loading |
docs/ | Swagger/OpenAPI generated docs |
Endpoints
GET /api/v1/token/validate
Validate a project token and return the associated project.
- Query param:
token-- The project token to validate - Response:
200 OKwith project ID and project name if valid - Error:
401 Unauthorizedif the token is invalid or expired
GET /healthz
Health check. Returns 200 when both Valkey and MySQL are reachable.
GET /swagger/*
Swagger UI for API documentation.
Token Store Architecture
Request --> RedisCache (TTL: 5m) --> Miss --> MySQLStore --> Cache result
| |
v v
Hit --> Return Return + Cache
The Store type composes RedisCache and MySQLStore:
- On lookup: check Redis first, fall back to MySQL, cache the result on hit.
- Token entries include: token hash, project_id, project_name, created_at, expires_at.
Tables Owned
project_tokens-- Stores hashed project tokens with project association and expiration
Environment Variables
| Variable | Required | Default | Description |
|---|---|---|---|
PORT | No | 8081 | HTTP listen port |
REDIS_URL | Yes | -- | Valkey/Redis URL (DB 0) |
MYSQL_DSN | Yes | -- | MySQL connection string |
REDIS_TOKEN_TTL | No | 5m | Token cache TTL in Valkey |