Sign inSign up

wearequantico/qarx-drop

By wearequantico

•Updated 8 days ago

qARX Drop — secure, ephemeral one-time secret sharing service for qARX

Image
Security
0

661

wearequantico/qarx-drop repository overview

⁠qARX Drop

qARX.Drop — zero-knowledge, one-time secret sharing for recipients who do not have a qARX account. Part of qARX, the self-hosted, end-to-end encrypted Secret Manager. Your Digital Fortress.

Go service (Echo) with an embedded SQLite store. The Portal encrypts the payload client-side with a random one-time key; that key travels only in the URL fragment (#), which browsers never send to a server. Drop stores an opaque ciphertext it cannot decrypt, enforces view limits and TTL, and deletes the blob when it expires or is burned.

Security airgap by design: Drop is the internet-facing component and keeps its own SQLite database. It has no access to the vault database, and compromising it exposes zero plaintext.

⁠Quick start

Drop is deployed as part of the qARX stack. Generate the full compose.yml from the Core image:

docker run --rm wearequantico/qarx-core:latest qarx-cli compose > compose.yml

Full installation & deployment guide: https://quanticoarx.com⁠

⁠Configuration

SettingNotes
Listen port8081 (published on 127.0.0.1:8081 by the generated compose file)
Health probe/livez
PersistenceSQLite at DROP_DB_PATH (/data/qarx-drop.db) — mount a volume
Public URLDROP_PUBLIC_URL — must be reachable by external recipients over HTTPS
Shared secretsDROP_CORE_TO_DROP_KEY, DROP_DROP_TO_CORE_KEY (HMAC, generated by qarx-cli env init)
LimitsDROP_DEFAULT_TTL (24h), DROP_MAX_TTL (720h), DROP_MAX_VIEWS_MAX, DROP_MAX_BLOB_SIZE, per-IP rate limits
EgressDROP_GEOIP_ENABLED (default true) geolocates access-log IPs via a third-party service; set false for zero outbound traffic

Drop is deliberately kept off the internal network: it never reaches PostgreSQL or Redis.

⁠Tags

  • :X.Y.Z — specific release (recommended; pin by digest in production)
  • :latest — most recent release

Core, Portal and Drop are released in lockstep — always deploy the same tag for all three.

⁠Architecture

  • wearequantico/qarx-core — backend API
  • wearequantico/qarx-portal — web UI
  • wearequantico/qarx-drop — one-time secret sharing (this image)
  • plus PostgreSQL 18+ and Redis 8+

⁠Security

Zero-knowledge architecture: the decryption key lives only in the URL fragment held by the sender and the recipient. Drop stores ciphertext exclusively and can never read what it distributes.

Report vulnerabilities to [email protected]⁠.

⁠License

Proprietary © Quantico S.r.l. Sharing via qARX.Drop is a license-gated feature. See https://quanticoarx.com⁠ Support: [email protected]⁠

Tag summary

Content type

Image

Digest

sha256:08b993dad…

Size

10.9 MB

Last updated

8 days ago

docker pull wearequantico/qarx-drop