The automated SBOM fetcher. Periodically pulls component data from artifact registries and cloud services.
The automated SBOM fetcher. Periodically pulls component data from artifact registries and cloud services, then submits it to taco-inbound.
Overview
| Property | Value |
|---|
| Language | Go |
| Framework | Standard library HTTP |
| Port | 8085 (health check) |
| Exposed | Internal only |
| Dependencies | taco-inbound |
| Repository | tacosec/taco-fetcher |
Architecture
taco-fetcher is a periodic fetcher that connects to configured artifact sources, retrieves component/image lists, and submits them to taco-inbound as SBOMs. This automates SBOM generation for organizations that store artifacts in registries.
Supported Sources
Nexus (Sonatype Nexus Repository)
- Fetches components from Docker and other repository types
- Configured with URL, credentials, and comma-separated repository names
- Extracts: name, version, purl
JFrog Artifactory
- Fetches components from Artifactory repositories
- Same configuration pattern as Nexus
AWS
| Source | Description |
|---|
| ECR (Elastic Container Registry) | Fetches container images and their metadata |
| Lambda | Fetches Lambda function deployments and their dependencies |
| CodeArtifact | Fetches packages from CodeArtifact repositories |
Azure
| Source | Description |
|---|
| ACR (Azure Container Registry) | Fetches container images |
| Functions | Fetches Azure Function deployments |
| Artifacts | Fetches packages from Azure DevOps Artifacts |
GCP
| Source | Description |
|---|
| Artifact Registry | Fetches container images and packages |
| Cloud Functions | Fetches function deployments |
| Cloud Run | Fetches Cloud Run service images |
Key Packages
| Package | Purpose |
|---|
nexus/ | Nexus Repository client |
artifactory/ | JFrog Artifactory client |
aws/ | AWS client (ECR, Lambda, CodeArtifact) |
azure/ | Azure client (ACR, Functions, Artifacts) |
gcp/ | GCP client (Artifact Registry, Cloud Functions, Cloud Run) |
ingest/ | HTTP client for submitting to taco-inbound |
config/ | Environment variable loading |
Fetch Flow
- On startup and every
FETCH_INTERVAL (default 10m):
- For each configured source, fetch the component list.
- Convert to a standardized component format (name, version, purl, type).
- Submit to taco-inbound via
POST /api/v1/sbom with the INBOUND_TOKEN.
- taco-inbound publishes to RabbitMQ, which triggers taco-store and the rest of the pipeline.
Environment Variables
| Variable | Required | Default | Description |
|---|
INBOUND_URL | Yes | -- | URL of taco-inbound |
INBOUND_TOKEN | Yes | -- | Project token for taco-inbound authentication |
FETCH_INTERVAL | No | 10m | Time between fetch cycles |
HEALTH_PORT | No | 8085 | Health check HTTP port |
| Nexus | | | |
NEXUS_URL | No | -- | Nexus base URL |
NEXUS_USERNAME | No | -- | Nexus username |
NEXUS_PASSWORD | No | -- | Nexus password |
NEXUS_REPOS | No | -- | Comma-separated repository names |
| Artifactory | | | |
ARTIFACTORY_URL | No | -- | Artifactory base URL |
ARTIFACTORY_USERNAME | No | -- | Artifactory username |
ARTIFACTORY_PASSWORD | No | -- | Artifactory password |
ARTIFACTORY_REPOS | No | -- | Comma-separated repository names |
| AWS | | | |
AWS_REGION | No | us-east-1 | AWS region |
AWS_ACCESS_KEY_ID | No | -- | AWS access key |
AWS_SECRET_ACCESS_KEY | No | -- | AWS secret key |
AWS_SESSION_TOKEN | No | -- | AWS session token |
AWS_ECR_REGISTRY_ID | No | -- | ECR registry ID |
AWS_LAMBDA_ENABLED | No | false | Enable Lambda fetching (true/false) |
AWS_CODEARTIFACT_DOMAIN | No | -- | CodeArtifact domain |
AWS_CODEARTIFACT_REPO | No | -- | CodeArtifact repository |
| Azure | | | |
AZURE_TENANT_ID | No | -- | Azure AD tenant ID |
AZURE_CLIENT_ID | No | -- | Azure AD client ID |
AZURE_CLIENT_SECRET | No | -- | Azure AD client secret |
AZURE_TOKEN | No | -- | Azure bearer token (alternative to client credentials) |
AZURE_ACR_REGISTRY | No | -- | ACR registry name |
AZURE_SUBSCRIPTION_ID | No | -- | Azure subscription ID (for Functions) |
AZURE_DEVOPS_ORG | No | -- | Azure DevOps organization (for Artifacts) |
AZURE_DEVOPS_PROJECT | No | -- | Azure DevOps project (for Artifacts) |
| GCP | | | |
GCP_PROJECT_ID | No | -- | GCP project ID |
GCP_TOKEN | No | -- | GCP bearer token |
GCP_LOCATION | No | us-central1 | GCP region/location |
At least one source must be configured for the service to start.
Health Check
GET /healthz -- Always returns 200 OK (no external dependencies to check at health time).