taco-fetcher

The automated SBOM fetcher. Periodically pulls component data from artifact registries and cloud services.

The automated SBOM fetcher. Periodically pulls component data from artifact registries and cloud services, then submits it to taco-inbound.

Overview

PropertyValue
LanguageGo
FrameworkStandard library HTTP
Port8085 (health check)
ExposedInternal only
Dependenciestaco-inbound
Repositorytacosec/taco-fetcher

Architecture

taco-fetcher is a periodic fetcher that connects to configured artifact sources, retrieves component/image lists, and submits them to taco-inbound as SBOMs. This automates SBOM generation for organizations that store artifacts in registries.

Supported Sources

Nexus (Sonatype Nexus Repository)

  • Fetches components from Docker and other repository types
  • Configured with URL, credentials, and comma-separated repository names
  • Extracts: name, version, purl

JFrog Artifactory

  • Fetches components from Artifactory repositories
  • Same configuration pattern as Nexus

AWS

SourceDescription
ECR (Elastic Container Registry)Fetches container images and their metadata
LambdaFetches Lambda function deployments and their dependencies
CodeArtifactFetches packages from CodeArtifact repositories

Azure

SourceDescription
ACR (Azure Container Registry)Fetches container images
FunctionsFetches Azure Function deployments
ArtifactsFetches packages from Azure DevOps Artifacts

GCP

SourceDescription
Artifact RegistryFetches container images and packages
Cloud FunctionsFetches function deployments
Cloud RunFetches Cloud Run service images

Key Packages

PackagePurpose
nexus/Nexus Repository client
artifactory/JFrog Artifactory client
aws/AWS client (ECR, Lambda, CodeArtifact)
azure/Azure client (ACR, Functions, Artifacts)
gcp/GCP client (Artifact Registry, Cloud Functions, Cloud Run)
ingest/HTTP client for submitting to taco-inbound
config/Environment variable loading

Fetch Flow

  1. On startup and every FETCH_INTERVAL (default 10m):
  2. For each configured source, fetch the component list.
  3. Convert to a standardized component format (name, version, purl, type).
  4. Submit to taco-inbound via POST /api/v1/sbom with the INBOUND_TOKEN.
  5. taco-inbound publishes to RabbitMQ, which triggers taco-store and the rest of the pipeline.

Environment Variables

VariableRequiredDefaultDescription
INBOUND_URLYes--URL of taco-inbound
INBOUND_TOKENYes--Project token for taco-inbound authentication
FETCH_INTERVALNo10mTime between fetch cycles
HEALTH_PORTNo8085Health check HTTP port
Nexus
NEXUS_URLNo--Nexus base URL
NEXUS_USERNAMENo--Nexus username
NEXUS_PASSWORDNo--Nexus password
NEXUS_REPOSNo--Comma-separated repository names
Artifactory
ARTIFACTORY_URLNo--Artifactory base URL
ARTIFACTORY_USERNAMENo--Artifactory username
ARTIFACTORY_PASSWORDNo--Artifactory password
ARTIFACTORY_REPOSNo--Comma-separated repository names
AWS
AWS_REGIONNous-east-1AWS region
AWS_ACCESS_KEY_IDNo--AWS access key
AWS_SECRET_ACCESS_KEYNo--AWS secret key
AWS_SESSION_TOKENNo--AWS session token
AWS_ECR_REGISTRY_IDNo--ECR registry ID
AWS_LAMBDA_ENABLEDNofalseEnable Lambda fetching (true/false)
AWS_CODEARTIFACT_DOMAINNo--CodeArtifact domain
AWS_CODEARTIFACT_REPONo--CodeArtifact repository
Azure
AZURE_TENANT_IDNo--Azure AD tenant ID
AZURE_CLIENT_IDNo--Azure AD client ID
AZURE_CLIENT_SECRETNo--Azure AD client secret
AZURE_TOKENNo--Azure bearer token (alternative to client credentials)
AZURE_ACR_REGISTRYNo--ACR registry name
AZURE_SUBSCRIPTION_IDNo--Azure subscription ID (for Functions)
AZURE_DEVOPS_ORGNo--Azure DevOps organization (for Artifacts)
AZURE_DEVOPS_PROJECTNo--Azure DevOps project (for Artifacts)
GCP
GCP_PROJECT_IDNo--GCP project ID
GCP_TOKENNo--GCP bearer token
GCP_LOCATIONNous-central1GCP region/location

At least one source must be configured for the service to start.

Health Check

GET /healthz -- Always returns 200 OK (no external dependencies to check at health time).