kastoria-proxy
An NGINX reverse proxy that serves as a public Kastoria ingress. The ingress
routes browser and API traffic to the DICOMweb server, SMART Launch API, Admin
Console API/UI, and OHIF viewer via port 8080.
The mTLS-enabled internal variant is a separate image, kastoria-proxy-mtls.
Runtime details
| Property | Value |
|---|---|
| Runtime base image | nginxinc/nginx-unprivileged:1.31-alpine (pinned by digest) |
| Exposed port | 8080 |
| Container user | nginx (non-root) |
| Entrypoint | /entrypoint.sh (renders the config from its template, then execs NGINX) |
| Command | CMD ["nginx", "-g", "daemon off;"] |
| Health check | GET http://localhost:8080/healthz (every 30s, 5s timeout, 30s start period, 3 retries) |
| Stop signal | SIGTERM |
Both Azure proxy variants build from a common config template. The public build strips the mutual-TLS authorization blocks at build time, so the shipped public config provably carries no role gate and the entrypoint takes no mTLS path.
OCI labels
| Label | Value |
|---|---|
org.opencontainers.image.title |
Kastoria Reverse Proxy |
org.opencontainers.image.description |
NGINX reverse proxy for the Kastoria Health platform |
org.opencontainers.image.licenses |
Proprietary |
org.opencontainers.image.url |
https://github.com/merkalis-io/kastoria-health |
org.opencontainers.image.documentation |
https://github.com/merkalis-io/kastoria-health |
io.kastoria.health-endpoint |
/ |
The org.opencontainers.image.version, org.opencontainers.image.revision,
org.opencontainers.image.created, org.opencontainers.image.source,
io.kastoria.base-image, and io.kastoria.service labels are injected at
build time by the CI/CD pipeline.
Pull and verify
Promoted images are published to the Distribution Registry under the customer namespace:
docker pull acrmerkalisdist0c66.azurecr.io/<customer>/kastoria-proxy:<release-tag>
notation verify acrmerkalisdist0c66.azurecr.io/<customer>/kastoria-proxy:<release-tag>
See the Distribution Registry guide for authentication and trust setup.
Environment variables
| Variable | Secret | Required | Default | Description |
|---|---|---|---|---|
KASTORIA_HEALTH_ADDRESS[1] |
No | No | kastoria-health:3000 |
Upstream DICOMweb server host and port. |
KASTORIA_SMARTLAUNCH_ADDRESS[1] |
No | No | kastoria-smartlaunch:4000 |
Upstream SMART Launch API host and port. |
KASTORIA_CONSOLEAPI_ADDRESS[1] |
No | No | kastoria-consoleapi:3005 |
Upstream Admin Console API host and port. |
KASTORIA_CONSOLEUI_ADDRESS[1] |
No | No | kastoria-consoleui:8081 |
Upstream Admin Console UI host and port. |
KASTORIA_REPORTVIEW_ADDRESS[1] |
No | No | kastoria-perfview:80 |
Upstream report viewer host and port. |
KASTORIA_REPORTVIEW_ENABLED |
No | No | true |
Set to false to strip the /reportview/ route. |
OHIF_VIEWER_ADDRESS[1] |
No | No | kastoria-ohif:8080 |
Upstream OHIF viewer host and port. |
PORT[2] |
No | No | 8080 |
Used by the container HEALTHCHECK; NGINX listens on 8080. |
Every variable above is substituted into the NGINX config at container start by
/entrypoint.sh; disabled route blocks are removed before NGINX starts.
Note: The default values listed for the various *_ADDRESS are in place for using the
proxy in a local docker compose environment. When deploying to Azure you must change these (see [1] below), or the container will fail to start.
Deploying to an Azure Container Apps Environment
[1] The various *_ADDRESS variables should be set to the environment's internal FQDN for the container app. The Azure configuration template automatically includes the correct (443) port.
[2] The selected value for PORT must match the environment's ingress Target port for the container app.
Available versions
v0.10.0v0.9.1— deprecated for security reasons (CVE-2026-93990); usev0.10.0