taco-auth

The token validation service. Validates project tokens for the SBOM ingestion pipeline.

The token validation service. Validates project tokens for the SBOM ingestion pipeline.

Overview

PropertyValue
LanguageGo
FrameworkEcho v4
Port8081
ExposedInternal only
DependenciesMySQL, Valkey
Repositorytacosec/taco-auth

Architecture

taco-auth is a focused service with a single responsibility: validating project tokens issued by taco-api. It uses a two-tier lookup strategy:

  1. Redis cache (Valkey) -- Fast path. Tokens are cached in Valkey with a configurable TTL (default 5 minutes).
  2. MySQL fallback -- If the token is not in cache, it queries the project_tokens table in MySQL.

This design allows taco-inbound to validate tokens at high throughput without putting load on MySQL for every SBOM submission.

Key Packages

PackagePurpose
handler/Token validation HTTP handler
token/Token store: Redis cache, MySQL backend, composite store
config/Environment variable loading
docs/Swagger/OpenAPI generated docs

Endpoints

GET /api/v1/token/validate

Validate a project token and return the associated project.

  • Query param: token -- The project token to validate
  • Response: 200 OK with project ID and project name if valid
  • Error: 401 Unauthorized if the token is invalid or expired

GET /healthz

Health check. Returns 200 when both Valkey and MySQL are reachable.

GET /swagger/*

Swagger UI for API documentation.

Token Store Architecture

Request --> RedisCache (TTL: 5m) --> Miss --> MySQLStore --> Cache result
                     |                                         |
                     v                                         v
                   Hit --> Return                         Return + Cache

The Store type composes RedisCache and MySQLStore:

  • On lookup: check Redis first, fall back to MySQL, cache the result on hit.
  • Token entries include: token hash, project_id, project_name, created_at, expires_at.

Tables Owned

  • project_tokens -- Stores hashed project tokens with project association and expiration

Environment Variables

VariableRequiredDefaultDescription
PORTNo8081HTTP listen port
REDIS_URLYes--Valkey/Redis URL (DB 0)
MYSQL_DSNYes--MySQL connection string
REDIS_TOKEN_TTLNo5mToken cache TTL in Valkey