Sign inSign up

wearequantico/qarx-core

By wearequantico

•Updated 8 days ago

qARX Core — zero-knowledge secrets manager backend (Go REST API). Your Digital Fortress

Image
Security
0

717

wearequantico/qarx-core repository overview

⁠qARX Core

Backend API for qARX — a self-hosted, zero-knowledge, end-to-end encrypted Secret Manager with attribute-based access control and integrated remote-session launching (SSH/RDP/VNC). Your Digital Fortress.

Go REST API handling authentication (OPAQUE, passkeys, TOTP), ABAC authorization, encrypted vaults, audit logging, notifications and licensing. Secrets are encrypted client-side — the server never sees plaintext.

This image also ships qarx-cli, which generates your compose.yml and .env.

⁠Quick start

Everything needed for a deployment lives in this image — no repository checkout.

mkdir -p /opt/qarx && cd /opt/qarx

# 1. Pull the image (compose.yml and .env are generated from it)
docker pull wearequantico/qarx-core:latest

# 2. Generate compose.yml (static, no secrets)
docker run --rm wearequantico/qarx-core:latest qarx-cli compose > compose.yml

# 3. Generate .env (random secrets + your two values, pinned to this release)
docker run --rm wearequantico/qarx-core:latest qarx-cli env init -n \
    --public-url https://yourdomain.com \
    --admin-email [email protected] > .env
chmod 600 .env

# 4. Start the stack
docker compose up -d

# 5. Retrieve the admin activation link
docker compose logs qarx-core | grep -A8 "ADMIN ACTIVATION LINK"

Full installation & deployment guide (Docker Compose / Kubernetes, reverse proxy, backups, hardening): https://quanticoarx.com⁠

⁠Configuration

SettingNotes
Listen port8080 (container-internal; not published by default — Portal reaches Core over the Docker network)
Health probes/livez, /readyz
DatabasePostgreSQL 18+ (DB_HOST, DB_NAME, DB_USER, DB_PASSWORD, DB_SSLMODE)
CacheRedis 8+ (REDIS_HOST, REDIS_PORT, REDIS_PASSWORD)
Required secretsCORE_JWT_ED25519_PRIVATE_KEY, CORE_TEMP_TOKEN_KEY, CORE_ENCRYPTION_KEY, CORE_INTERNAL_AUTH_TOKEN
Public URLQARX_PUBLIC_URL (used for links in emails and callbacks)

qarx-cli env init generates every secret above for you.

⁠Tags

  • :X.Y.Z — specific release (recommended; pin by digest in production)
  • :latest — most recent release

Core, Portal and Drop are released in lockstep — always deploy the same tag for all three. Database migrations run automatically at startup; read the release notes before upgrading across a minor version.

⁠Architecture

This image is one component of a full qARX deployment:

  • wearequantico/qarx-core — backend API (this image)
  • wearequantico/qarx-portal — web UI
  • wearequantico/qarx-drop — zero-knowledge one-time secret sharing for external recipients
  • plus PostgreSQL 18+ and Redis 8+

Optional client-side components (distributed outside Docker Hub): qARX.Bridge (browser extension), qARX.Executor (native messaging host for SSH/RDP/VNC), qARX.Desk (native desktop connection manager).

⁠Security

Zero-knowledge architecture: encryption and decryption happen on the client. The server stores only ciphertext and never has access to your secrets. Authentication uses OPAQUE — the password never leaves the client, not even during login.

Report vulnerabilities to [email protected]⁠.

⁠License

Proprietary © Quantico S.r.l. The image is free to deploy; Business and Enterprise features are unlocked by a license key. See https://quanticoarx.com⁠

Support: [email protected]⁠

Tag summary

Content type

Image

Digest

sha256:d9344f391…

Size

32.5 MB

Last updated

8 days ago

docker pull wearequantico/qarx-core