Sign inSign up

tychoncorp/tac3

By tychoncorp

•Updated 1 day ago

TAC-3 tactical S3-compatible object storage node (FIPS 140-3, post-quantum, clustered).

Image
1

2.8K

tychoncorp/tac3 repository overview

⁠TAC-3 — Tactical Object Storage

TAC-3 is a self-contained, S3-compatible object storage node built for tactical and air-gapped environments. FIPS 140-3 validated cryptography, post-quantum (CNSA 2.0) protection, clustering with synchronous replication, and built-in data pipelines — in a single container.

Private image. Targeted for defense/tactical deployments. Not for general distribution.


⁠Highlights

  • S3-compatible API — AWS Signature V4; works with any S3 SDK/CLI. Buckets, multipart, versioning, tagging, object-lock.
  • FIPS 140-3 + CNSA 2.0 — AES-256-GCM at rest, ML-KEM-1024 (FIPS 203) + ML-DSA-87 (FIPS 204) for inter-node channels, HKDF/HMAC-SHA-384. Tamper-evident audit chain.
  • Clustering — multi-node fabric with automatic failover, deterministic primary election, and synchronous write-quorum replication (default: local + 1 replica before ack). Mirror and share replication groups.
  • Data pipelines — route bucket content to Kafka and Elasticsearch (bulk/ndjson, ingest pipelines, data streams, multi-cluster fan-out) as objects land.
  • Signing vault — in-node key custody with optional TPM 2.0 / PKCS#11 HSM, CSR→CA→import, and two-person dual-control signing.
  • Governance — Data Loss Prevention (content + hash rules), classification enforcement, RBAC (Admin / Operator / Signer / Viewer), OIDC + CAC/PIV, TOTP MFA.
  • Extras — WebDAV & syslog gateways, vector + semantic search with an on-node LLM, cross-site sync with bandwidth throttling.
  • Management — web console + generated OpenAPI docs at /api/v1/docs (/api/v1/openapi.json).

⁠Quick start (single node)

docker run -d --name tac3 \
  -p 9000:9000 -p 9001:9001 \
  -e TAC3_MASTER_KEY=$(openssl rand -hex 32) \
  -v tac3-data:/var/lib/tac3 \
  -v tac3-cfg:/etc/tac3 \
  tychoncorp/tac3:latest

A default /etc/tac3/node.toml is generated on first boot if none is mounted. The one-time admin password is printed to the container logs on first start and must be changed at first login:

docker logs tac3 | grep -A3 "FIRST BOOT"

Then open the console at https://localhost:9001⁠ (self-signed TLS by default; replace via Settings → Security → TLS).

⁠Ports

PortPurpose
9000S3 API (HTTPS, SigV4)
9001Management API + web console
9002Cluster / Raft RPC
9003/udpQUIC transport
9004WebDAV gateway (when enabled)

⁠Volumes

PathPurpose
/var/lib/tac3Object data, metadata, keys
/etc/tac3Node configuration (node.toml)

⁠Master key

Provide the 32-byte at-rest master key via one of (checked in order): HashiCorp Vault Transit, AWS KMS, a mounted key file, the TAC3_MASTER_KEY env var (64 hex chars), or a TPM/DMI hardware-sealed blob. A node generates and persists its own identity on first boot.

⁠Tags

  • latest — most recent build
  • YYYY-MM-DD — dated, immutable snapshot

⁠TPM support

The default image seals the master key to a TPM automatically when /dev/tpmrm0 and the tools are present, and falls back gracefully otherwise. Build with --build-arg WITH_TPM=true to bundle tpm2-tools, opensc, and softhsm2.

Tag summary

Content type

Image

Digest

sha256:3ae91bb33…

Size

98 MB

Last updated

1 day ago

docker pull tychoncorp/tac3