taco-inbound
The SBOM ingestion gateway. Receives SBOMs via HTTP and publishes them to RabbitMQ for processing.
The SBOM ingestion gateway. Receives SBOMs via HTTP and publishes them to RabbitMQ for processing.
Overview
| Property | Value |
|---|---|
| Language | Go |
| Framework | Echo v4 |
| Port | 8080 |
| Exposed | Via HAProxy at taco-inbound.taco-sec.com |
| Dependencies | RabbitMQ, taco-auth |
| Repository | tacosec/taco-inbound |
Architecture
taco-inbound is a lightweight HTTP gateway that:
- Accepts SBOM submissions and secret reports via REST endpoints.
- Validates the project token by calling taco-auth.
- Publishes validated payloads to RabbitMQ exchanges for downstream consumers.
It has Swagger documentation available at /swagger/*.
Key Packages
| Package | Purpose |
|---|---|
handler/ | HTTP handlers for SBOM and secrets ingestion |
authclient/ | HTTP client for taco-auth token validation |
publisher/ | RabbitMQ publisher with connection management |
config/ | Environment variable loading |
docs/ | Swagger/OpenAPI generated docs |
Endpoints
POST /api/v1/sbom
Submit an SBOM for processing.
- Auth:
Authorization: Bearer <project-token> - Body: Raw SBOM JSON (CycloneDX or SPDX)
- Body limit: Configurable via
MAX_BODY_SIZE(default varies) - Flow: Validates token via taco-auth, extracts project info, wraps in envelope, publishes to
taco.sbomexchange with routing keysbom.ingest.
POST /api/v1/secrets
Submit secret scan results.
- Auth:
Authorization: Bearer <project-token> - Body: Secret findings JSON
- Flow: Validates token via taco-auth, publishes to
taco.secretsexchange with routing keysecrets.ingest.
GET /healthz
Health check endpoint. Returns 200 when both RabbitMQ and taco-auth are reachable. Returns 503 if either is degraded.
GET /swagger/*
Swagger UI for API documentation.
Token Validation
Every request to the SBOM and secrets endpoints requires a valid project token. taco-inbound calls GET /api/v1/token/validate?token=<token> on taco-auth, which returns the associated project ID and project name.
Environment Variables
| Variable | Required | Default | Description |
|---|---|---|---|
PORT | No | 8080 | HTTP listen port |
AUTH_SERVICE_URL | Yes | -- | URL of taco-auth (e.g., http://taco-auth:8081) |
RABBITMQ_URL | Yes | -- | RabbitMQ AMQP URL |
MAX_BODY_SIZE | No | -- | Maximum request body size |