Docker Images
General Information
This section is provided in good faith as an informal guide and summary. It is not an official compliance document and does not modify, supersede, or override the official Merkalis Docker image compliance policies or security standards. Users are responsible for verifying requirements against official source documentation prior to deployment.
- Unless otherwise noted the images will run as a non-privileged user. (There are no current exceptions to this.)
- By default at least one trivy security scan has been performed on all Kastoria images as part of the build pipeline. (There are no current exceptions to this.)
- By default no image can be promoted with a known
CriticalorHighCVE finding. (There are no current exceptions to this.) - All images are signed using notation and the resulting notary v2 signature is attached to the image.
- All images will have their SLSA provenance and software attestation attached.
- All images will have their Software Bill of Materials (SBOM) attached in the SPDX format.
Image Description Layout
Each image page documents a published image with a consistent structure:
- What the image is and what it is for
- Runtime details (base image, exposed port, health check)
- OCI labels
- How to pull and verify the image
- Container-specific environment variables
- Job configuration information (for images intended to be run as a batch job)
- Available versions
Configuration
The images that read or write stored data share one configuration document, supplied through
KASTORIA_CONFIG_JSON or KASTORIA_CONFIG_FILE. See Configuration.
Images Available
| Image | Description |
|---|---|
| kastoria-proxy | Public NGINX reverse proxy: single ingress that routes traffic to every Kastoria service |
| kastoria-proxy-mtls | Mutual-TLS variant of the reverse proxy for internal traffic inside the Azure VNet |
| kastoria-health | DICOMweb server: STOW-RS ingestion, QIDO-RS queries, and WADO-RS retrieval |
| kastoria-studyprocessor | One-shot DICOM study processor that projects committed studies into the query surfaces and FHIR |
| kastoria-eventnotification | One-shot publisher that sends a Notification Event to a queue for each processed study version |
| kastoria-smart-launch-api | SMART on FHIR EHR Launch API that brokers launches from an EHR into the viewer |
| kastoria-consoleapi | Admin Console REST API for inspecting stored content and managing SMART launch configurations |
| kastoria-consoleui | Admin Console web UI: React SPA served by unprivileged NGINX |
| kastoria-ohif | OHIF DICOM viewer served by unprivileged NGINX |
| kastoria-testcontainer | Static test container used to exercise the Kastoria Health CI/CD image pipeline |
Note: The images available in the distribution registry will be prefixed with your customer name.
So, for example, kastoria-testcontainer will be available as <customer>/kastoria-testcontainer.