Skip to content

kastoria-proxy

An NGINX reverse proxy that serves as a public Kastoria ingress. The ingress routes browser and API traffic to the DICOMweb server, SMART Launch API, Admin Console API/UI, and OHIF viewer via port 8080.

The mTLS-enabled internal variant is a separate image, kastoria-proxy-mtls.

Runtime details

Property Value
Runtime base image nginxinc/nginx-unprivileged:1.31-alpine (pinned by digest)
Exposed port 8080
Container user nginx (non-root)
Entrypoint /entrypoint.sh (renders the config from its template, then execs NGINX)
Command CMD ["nginx", "-g", "daemon off;"]
Health check GET http://localhost:8080/healthz (every 30s, 5s timeout, 30s start period, 3 retries)
Stop signal SIGTERM

Both Azure proxy variants build from a common config template. The public build strips the mutual-TLS authorization blocks at build time, so the shipped public config provably carries no role gate and the entrypoint takes no mTLS path.

OCI labels

Label Value
org.opencontainers.image.title Kastoria Reverse Proxy
org.opencontainers.image.description NGINX reverse proxy for the Kastoria Health platform
org.opencontainers.image.licenses Proprietary
org.opencontainers.image.url https://github.com/merkalis-io/kastoria-health
org.opencontainers.image.documentation https://github.com/merkalis-io/kastoria-health
io.kastoria.health-endpoint /

The org.opencontainers.image.version, org.opencontainers.image.revision, org.opencontainers.image.created, org.opencontainers.image.source, io.kastoria.base-image, and io.kastoria.service labels are injected at build time by the CI/CD pipeline.

Pull and verify

Promoted images are published to the Distribution Registry under the customer namespace:

docker pull acrmerkalisdist0c66.azurecr.io/<customer>/kastoria-proxy:<release-tag>
notation verify acrmerkalisdist0c66.azurecr.io/<customer>/kastoria-proxy:<release-tag>

See the Distribution Registry guide for authentication and trust setup.

Environment variables

Variable Secret Required Default Description
KASTORIA_HEALTH_ADDRESS[1] No No kastoria-health:3000 Upstream DICOMweb server host and port.
KASTORIA_SMARTLAUNCH_ADDRESS[1] No No kastoria-smartlaunch:4000 Upstream SMART Launch API host and port.
KASTORIA_CONSOLEAPI_ADDRESS[1] No No kastoria-consoleapi:3005 Upstream Admin Console API host and port.
KASTORIA_CONSOLEUI_ADDRESS[1] No No kastoria-consoleui:8081 Upstream Admin Console UI host and port.
KASTORIA_REPORTVIEW_ADDRESS[1] No No kastoria-perfview:80 Upstream report viewer host and port.
KASTORIA_REPORTVIEW_ENABLED No No true Set to false to strip the /reportview/ route.
OHIF_VIEWER_ADDRESS[1] No No kastoria-ohif:8080 Upstream OHIF viewer host and port.
PORT[2] No No 8080 Used by the container HEALTHCHECK; NGINX listens on 8080.

Every variable above is substituted into the NGINX config at container start by /entrypoint.sh; disabled route blocks are removed before NGINX starts.

Note: The default values listed for the various *_ADDRESS are in place for using the proxy in a local docker compose environment. When deploying to Azure you must change these (see [1] below), or the container will fail to start.

Deploying to an Azure Container Apps Environment

[1] The various *_ADDRESS variables should be set to the environment's internal FQDN for the container app. The Azure configuration template automatically includes the correct (443) port.

[2] The selected value for PORT must match the environment's ingress Target port for the container app.

Available versions

  • v0.10.0
  • v0.9.1 — deprecated for security reasons (CVE-2026-93990); use v0.10.0