Skip to content

Docker Images

General Information

This section is provided in good faith as an informal guide and summary. It is not an official compliance document and does not modify, supersede, or override the official Merkalis Docker image compliance policies or security standards. Users are responsible for verifying requirements against official source documentation prior to deployment.

  • Unless otherwise noted the images will run as a non-privileged user. (There are no current exceptions to this.)
  • By default at least one trivy security scan has been performed on all Kastoria images as part of the build pipeline. (There are no current exceptions to this.)
  • By default no image can be promoted with a known Critical or High CVE finding. (There are no current exceptions to this.)
  • All images are signed using notation and the resulting notary v2 signature is attached to the image.
  • All images will have their SLSA provenance and software attestation attached.
  • All images will have their Software Bill of Materials (SBOM) attached in the SPDX format.

Image Description Layout

Each image page documents a published image with a consistent structure:

  • What the image is and what it is for
  • Runtime details (base image, exposed port, health check)
  • OCI labels
  • How to pull and verify the image
  • Container-specific environment variables
  • Job configuration information (for images intended to be run as a batch job)
  • Available versions

Configuration

The images that read or write stored data share one configuration document, supplied through KASTORIA_CONFIG_JSON or KASTORIA_CONFIG_FILE. See Configuration.

Images Available

Image Description
kastoria-proxy Public NGINX reverse proxy: single ingress that routes traffic to every Kastoria service
kastoria-proxy-mtls Mutual-TLS variant of the reverse proxy for internal traffic inside the Azure VNet
kastoria-health DICOMweb server: STOW-RS ingestion, QIDO-RS queries, and WADO-RS retrieval
kastoria-studyprocessor One-shot DICOM study processor that projects committed studies into the query surfaces and FHIR
kastoria-eventnotification One-shot publisher that sends a Notification Event to a queue for each processed study version
kastoria-smart-launch-api SMART on FHIR EHR Launch API that brokers launches from an EHR into the viewer
kastoria-consoleapi Admin Console REST API for inspecting stored content and managing SMART launch configurations
kastoria-consoleui Admin Console web UI: React SPA served by unprivileged NGINX
kastoria-ohif OHIF DICOM viewer served by unprivileged NGINX
kastoria-testcontainer Static test container used to exercise the Kastoria Health CI/CD image pipeline

Note: The images available in the distribution registry will be prefixed with your customer name. So, for example, kastoria-testcontainer will be available as <customer>/kastoria-testcontainer.