XyDromatics VNA Repository

Archive Totals

DICOM C-STORE SCP

Host

Recent Studies

Patient IDAccessionStudy DateModality Study UIDSeriesInstances
Loading…

Study Search

Results

Patient IDAccessionStudy DateModality DescriptionStudy UID SeriesInstances
Enter a search criterion and click Search.

DICOM Peers

Remote modalities and PACS systems the Repository interacts with. Sources (inbound ◀) are peers allowed to send us studies via C-STORE. Destinations (outbound ▶) are peers we forward studies to when answering C-MOVE requests from a Query/Retrieve SCU. A single peer can be both.

NameAE TitleHostPort DirectionTLSEnabledActions
Loading…

Add Node

Advanced — presentation-context filters (optional)
Leave empty to accept whatever the peer proposes (the common case). Non-empty = allow-list: inbound (source role) only accepts PCs whose SOP/TS appear here; outbound (dest role) only proposes these to the peer. Values are raw DICOM UIDs, one per line or comma-separated.

Installed License

Loading…

Licensed Features

Upload License

Select a .lic file issued by the Synthology License Generator. The file is staged, decrypted, and — on successful parse — replaces the active license. Feature gating is re-evaluated on the next request; no restart is required.

Authentication & SCP

Buffers each outbound instance per destination so a transient destination failure retries with backoff instead of being dropped. Off by default. Takes effect after a service restart. Queue depth and reaper liveness appear under /health → checks.smart_routing_spool.

fo-dicom DicomServiceOptions.MaxPDULength. 256 KB reduces association round-trips for large pixel data (CT/MR/CR); pre-association negotiation will clamp if a peer doesn’t support it. 0 = use fo-dicom stock 16384. Restart the service to apply.

Operational Alerts & Monitoring

Archive Catalog Database

Current engine
Configured

Changing the archive catalog DB engine or connection string requires a service restart. The SCP will refuse to start until the catalog is reachable.

Object Storage Backend

Current backend
S3 secret
Azure conn string

The archive’s byte store. Local = filesystem under the data directory. S3 = an S3 or S3-compatible object store (AWS S3, Cloudflare R2, Backblaze B2, Wasabi, MinIO) — set an Endpoint for anything other than AWS S3. AzureBlob = Azure Blob Storage; prefer managed identity (no keys on disk) with the account URL, else a connection string. Changing the backend requires a service restart and does not migrate existing objects. Leave a Secret / Connection string blank to keep the stored (sealed) value. Note: on an object-store backend the local-filesystem maintenance passes (integrity bit-rot scan, on-disk OAS rewrite) are skipped — object durability is delegated to the store.

Import / Export Configuration

Export the host settings (DICOM listeners, archive catalog, authentication & LDAP) as a JSON file for backup or migration, or import a previously exported configuration. The catalog-DB connection string is redacted by default and re-applied from the running config on import; tick “Include credentials” to export it passphrase-encrypted for a full cross-host clone. Some changes (SCP / Q/R listeners, archive engine) take effect on the next service restart.

Health

SCP Status

Archive Counts

Study Browser

Loading totals…

No search executed yet — fill in any field (or none, to list everything) and click Search.

Document Store

Upload

Documents

Loading…

Batch Import

Queue a server-side folder for import. The background service walks the folder recursively, parses each .dcm file, and ingests through the same path C-STORE uses. License: batch_import. RBAC: manage_document_store.

Job IDFolderStatusScannedIngestedSkippedFailedCreated
No jobs yet.

Export

Export up to 10 studies as a single zip (synchronous streaming). For larger batches, use the future Phase 3 job-queue workflow. License: export. RBAC: manage_document_store.

Dedup Analysis

Content-based deduplication scan — scans up to N instances, computes SHA-256, identifies duplicates and reports potential savings. License: dedup. RBAC: view_storage_tiers.

Archive Analytics

Loading summary…

Modality Distribution

Loading…

Retention Policies

Configure how long archived studies are kept. Phase 3A ships preview-only mode: policies compute matching study counts but actual deletion is deferred to Phase 3A.2. License: retention. RBAC: view_retention / manage_retention.

NameFilterAge (d)EnabledLast PreviewMatch / BytesActions
No policies yet.

Storage Tiers

Hot / warm / cold storage tier assignment for archived studies. License: storage_tiers. RBAC: view_storage_tiers / manage_storage_tiers.

Label-only movement (v1): assigning a study to a tier records a real, queryable tier label; the physical byte relocation across storage back-ends is a documented follow-on (RI-2026-170) and is not performed yet — the Bytes relocated flag reports this honestly.

TierDescriptionAssignedEffectiveDefault
Loading…

Study Tier — Look Up / Move

Integrity

Walks the archive catalog + checks each instance's file is present + readable by fo-dicom. Records anomalies as findings. License: integrity. RBAC: view_storage_tiers. Hash-comparison verify is Phase 3B.2 follow-on.

FindingStudy UIDSOP UIDPathDetailsDetected
No findings.

Patient Merge

Merge configuration

Merge audit log

WhenSourceTargetStudiesByReason
No merges yet.

Consolidate patient records across MRN changes or source-system reconciliation. Merging re-keys every archived study from source to target patient_id in one transaction. Un-merge is not available — review carefully before executing. License: patient_merge. RBAC: view_patient_merge / manage_patient_merge.

 Patient IDNameBirthSexStudiesInstancesSize
Click Search to load patients.

IOCM Rejections

IHE PCC §4.1 Object Change Management. Mark a study, series, or instance as REJECTED with a reason code. Downstream consumers honor active rejections to hide affected objects from clinical workflows. License: iocm. RBAC: view_iocm / manage_iocm.

KindTarget UIDReasonDetailsStatusCreatedActions
No rejections.

Site-to-Site Replication

Replicate archive instances to one or more peer VNAs via DICOMweb STOW-RS. The replication service polls every 30 seconds, scans for new instances, and POSTs them to each enabled peer. License: replication. RBAC: view_replication / manage_replication.

Phase 4B accepts auth_type=none or bearer. mTLS is not yet accepted — the server-side auth-type whitelist + client-certificate STOW handshake are a Phase 4B.2 follow-on in the shared replication service; the form intentionally does not offer an mTLS option until that lands (submitting it would be rejected). No mTLS field is shown to avoid a broken control.

Add / edit peer

Configured peers

NameURLAuthModalityEnabledReplicatedLast successLast errorActions
No peers configured.

Recent jobs

StatusPeerSOP UIDAttemptsQueuedCompletedLast error
No replication jobs yet.

FHIR R4 Gateway

Read-only FHIR R4 endpoints projecting the archive catalog into ImagingStudy + DiagnosticReport resources. Standard FHIR JSON Bundle responses. License: fhir. RBAC: view_dicomweb.

Endpoint base
/fhir/
  • GET /fhir/metadata — CapabilityStatement
  • GET /fhir/ImagingStudy?patient=...&accession=...&modality=...&started=...
  • GET /fhir/ImagingStudy/{StudyInstanceUID}
  • GET /fhir/DiagnosticReport?patient=...&identifier=...
  • GET /fhir/DiagnosticReport/{AccessionNumber}

          

Storage Commitment Journal

DICOM Storage Commitment (PS3.4 Annex J) journal — records every N-ACTION-RQ + N-EVENT-REPORT-RQ pair. Status tracks whether the SCP confirmed each requested SOP UID. License: storage_commitments. RBAC: view_storage_commit / manage_storage_commit.

SCP-side wiring to actually post records is Phase 4A.2 follow-on; this pane ships the storage + REST today.
Transaction UIDCalling AESOP CountStatusRequestedResponded
No commitment requests recorded. SCP-side wire-up ships in Phase 4A.2.

AI Pipeline

AI-vendor-driven ingestion of SR, SC, and SEG DICOM objects. Each vendor authenticates with an opaque API key (X-Ai-Vendor-Key header). The ingest endpoint enforces a per-vendor allowed-SOP-class list. License: ai_pipeline. RBAC: view_study_browser.

Ingest endpoint
POST /api/ai_pipeline/ingest
Header: X-Ai-Vendor-Key: <vendor's API key>
Body: multipart/form-data with one file (DICOM bytes).
Response: 201 on accept; 401 on auth; 415 on disallowed SOP class.

Register vendor

NameAPI KeyEnabledSOP ClassesTotal IngestLast IngestActions
No vendors registered.

Ingest audit log

WhenVendorStatusSOP ClassStudy UIDSource IPReason
No ingest events yet.

Diagnostic Viewer

⚠ NOT FOR CLINICAL DIAGNOSIS OR DECISION MAKING
This viewer is display-only. It is non-device software under FD&C Act §520(o)(1)(D) and is not cleared, certified, or intended for diagnostic interpretation. Use a clinically-validated viewer (e.g., a diagnostic workstation intended for primary interpretation) for any reading that informs patient care.

Read-only image preview. Pick a study, browse instances, adjust window/level. This is a basic viewer — advanced viewing (MPR, 3D, GSPS, comparison, mammography, measurements) is a clinical capability provided by XyDromatics VNA Clinical, not the Repository. License: diagnostic_viewer. RBAC: view_study_browser.

Load a study first.
Pick a study + instance to display.

IHE Profiles

Per-profile config for the 5 IHE profiles allowed in Repository mode. Each profile has its own license feature. Status badge: green = licensed + enabled, amber = licensed not enabled, gray = not licensed. RBAC: view_dicomweb (read) / edit_dicomweb (save).

Runtime honesty: only ARI has live runtime today — it is served by the existing DICOMweb QIDO/WADO surface. The other four profiles (Dose Monitoring, SR Viewer, PDQm, SMART) persist config now; their protocol runtime (Dose-SR receive/auto-forward, SR rendering, PDQm proxy, SMART OAuth2 enforcement) is a per-profile follow-on and is not yet active. See the per-row note under each profile.

Migration

One-shot bulk move of studies to a peer destination over DICOM C-STORE (MigrationDispatchService + OutboundScuService — start jobs run, returning 200). License: migration. RBAC: view_destinations / edit_destinations.

Scheduled Send

Cron-scheduled outbound rules. Phase 7 stores rules + cron expressions opaquely; the scheduler runtime ships in Phase 7.A.2. License: scheduled_send. RBAC: edit_destinations.

Smart Routing

Rule-based routing — match predicates (modality, source AE, age) to a destination. Phase 7 stores rules; the new-arrival match hook ships in Phase 7.A.3. License: smart_routing. RBAC: edit_destinations.