qARX Core — zero-knowledge secrets manager backend (Go REST API). Your Digital Fortress
717
Backend API for qARX — a self-hosted, zero-knowledge, end-to-end encrypted Secret Manager with attribute-based access control and integrated remote-session launching (SSH/RDP/VNC). Your Digital Fortress.
Go REST API handling authentication (OPAQUE, passkeys, TOTP), ABAC authorization, encrypted vaults, audit logging, notifications and licensing. Secrets are encrypted client-side — the server never sees plaintext.
This image also ships qarx-cli, which generates your compose.yml and .env.
Everything needed for a deployment lives in this image — no repository checkout.
mkdir -p /opt/qarx && cd /opt/qarx
# 1. Pull the image (compose.yml and .env are generated from it)
docker pull wearequantico/qarx-core:latest
# 2. Generate compose.yml (static, no secrets)
docker run --rm wearequantico/qarx-core:latest qarx-cli compose > compose.yml
# 3. Generate .env (random secrets + your two values, pinned to this release)
docker run --rm wearequantico/qarx-core:latest qarx-cli env init -n \
--public-url https://yourdomain.com \
--admin-email [email protected] > .env
chmod 600 .env
# 4. Start the stack
docker compose up -d
# 5. Retrieve the admin activation link
docker compose logs qarx-core | grep -A8 "ADMIN ACTIVATION LINK"
Full installation & deployment guide (Docker Compose / Kubernetes, reverse proxy, backups, hardening): https://quanticoarx.com
| Setting | Notes |
|---|---|
| Listen port | 8080 (container-internal; not published by default — Portal reaches Core over the Docker network) |
| Health probes | /livez, /readyz |
| Database | PostgreSQL 18+ (DB_HOST, DB_NAME, DB_USER, DB_PASSWORD, DB_SSLMODE) |
| Cache | Redis 8+ (REDIS_HOST, REDIS_PORT, REDIS_PASSWORD) |
| Required secrets | CORE_JWT_ED25519_PRIVATE_KEY, CORE_TEMP_TOKEN_KEY, CORE_ENCRYPTION_KEY, CORE_INTERNAL_AUTH_TOKEN |
| Public URL | QARX_PUBLIC_URL (used for links in emails and callbacks) |
qarx-cli env init generates every secret above for you.
:X.Y.Z — specific release (recommended; pin by digest in production):latest — most recent releaseCore, Portal and Drop are released in lockstep — always deploy the same tag for all three. Database migrations run automatically at startup; read the release notes before upgrading across a minor version.
This image is one component of a full qARX deployment:
wearequantico/qarx-core — backend API (this image)wearequantico/qarx-portal — web UIwearequantico/qarx-drop — zero-knowledge one-time secret sharing for external recipientsOptional client-side components (distributed outside Docker Hub): qARX.Bridge (browser extension), qARX.Executor (native messaging host for SSH/RDP/VNC), qARX.Desk (native desktop connection manager).
Zero-knowledge architecture: encryption and decryption happen on the client. The server stores only ciphertext and never has access to your secrets. Authentication uses OPAQUE — the password never leaves the client, not even during login.
Report vulnerabilities to [email protected].
Proprietary © Quantico S.r.l. The image is free to deploy; Business and Enterprise features are unlocked by a license key. See https://quanticoarx.com
Support: [email protected]
Content type
Image
Digest
sha256:d9344f391…
Size
32.5 MB
Last updated
8 days ago
docker pull wearequantico/qarx-core