taco-inbound

The SBOM ingestion gateway. Receives SBOMs via HTTP and publishes them to RabbitMQ for processing.

The SBOM ingestion gateway. Receives SBOMs via HTTP and publishes them to RabbitMQ for processing.

Overview

PropertyValue
LanguageGo
FrameworkEcho v4
Port8080
ExposedVia HAProxy at taco-inbound.taco-sec.com
DependenciesRabbitMQ, taco-auth
Repositorytacosec/taco-inbound

Architecture

taco-inbound is a lightweight HTTP gateway that:

  1. Accepts SBOM submissions and secret reports via REST endpoints.
  2. Validates the project token by calling taco-auth.
  3. Publishes validated payloads to RabbitMQ exchanges for downstream consumers.

It has Swagger documentation available at /swagger/*.

Key Packages

PackagePurpose
handler/HTTP handlers for SBOM and secrets ingestion
authclient/HTTP client for taco-auth token validation
publisher/RabbitMQ publisher with connection management
config/Environment variable loading
docs/Swagger/OpenAPI generated docs

Endpoints

POST /api/v1/sbom

Submit an SBOM for processing.

  • Auth: Authorization: Bearer <project-token>
  • Body: Raw SBOM JSON (CycloneDX or SPDX)
  • Body limit: Configurable via MAX_BODY_SIZE (default varies)
  • Flow: Validates token via taco-auth, extracts project info, wraps in envelope, publishes to taco.sbom exchange with routing key sbom.ingest.

POST /api/v1/secrets

Submit secret scan results.

  • Auth: Authorization: Bearer <project-token>
  • Body: Secret findings JSON
  • Flow: Validates token via taco-auth, publishes to taco.secrets exchange with routing key secrets.ingest.

GET /healthz

Health check endpoint. Returns 200 when both RabbitMQ and taco-auth are reachable. Returns 503 if either is degraded.

GET /swagger/*

Swagger UI for API documentation.

Token Validation

Every request to the SBOM and secrets endpoints requires a valid project token. taco-inbound calls GET /api/v1/token/validate?token=<token> on taco-auth, which returns the associated project ID and project name.

Environment Variables

VariableRequiredDefaultDescription
PORTNo8080HTTP listen port
AUTH_SERVICE_URLYes--URL of taco-auth (e.g., http://taco-auth:8081)
RABBITMQ_URLYes--RabbitMQ AMQP URL
MAX_BODY_SIZENo--Maximum request body size