IN PROGRESS
Technical summary
NEXUS AI Hub is the AI agent orchestrator running on Linux servers and multi-cloud environments (successor of oci-manager): central registry of satellite nodes with heartbeats, hardware metrics and latency, smart routing of tasks, comments and ideas to 8 specialists, LGPD/GDPR sanitization of secrets, smart truncate of huge logs and remote node management.
Executed scope
plugin.json: v1.0.0, slugnexus-ai-hub,legacy_slugs ["oci-manager","ai-hub"], "AI" category,is_core: false, public author_url and website (perciocastelo.com.br).- Registration: 2 tabs (
ai-hubandnexus-ai-hublegacy →tab.php), "AI Hub" doc (bot icon),oci-v2-assetsJS, 5 modals (oci-explorer,oci-preview,oci-logs,ia-chat-test,ai-hub-settings). - Central schema (legacy, consumed via
DB::fetchAll, no DDL in the plugin) —oci_nodes(id PK,name,ip,hostname,node_keyst-+ 24 bytes,provider,status,last_pulse,persona_name,persona_avatar) andoci_ai_endpoints(id PK,node_idFK,ip,urlon port/v1/chat/opencode,model,status,last_seen_at). - Personas — 18 agents with avatars (
assets/ia/people1|robo): automatic assignment without repetition (filters used ones, with fallback), re-assignment withforce, master detected bySERVER_ADDR,SITE_URLhostname, "Independent" provider or id 7. - AI panel routes —
ai_explain_task(explain task),ai_explain_comment(explain comment with context),ai_ask_ideas(ideas/refactors via Torvalds),ai_upload_report(PDF viapdftotextor plain text: LGPD sanitization + segmentation into 8,000-char chunks analyzed sequentially, "Part X of Y" header). - Multi-node routing — active
/v1/chat/opencodeendpoints deduplicated per node,nsx01priority, 90s global budget,node_lock_<id>locks (180s; 300s on failure),X-Proxy-Secret/X-Nexus-Proxy-Secretheaders +Host, rewrite tohttp://ip, 55s timeout (1.5s connect); local fallbackrun_local_opencode(35s,opencode-websetuid wrapper forwww-data, build-line filter). - 8 specialist subagents — JSON manifests with keywords (+1) and regex (+3), minimum 1: Torvalds (ideas), SecurityAI, HASHAI and CVEAI (
securitycategory preserves hashes — they are the forensic analysis target), NginxAI, ApacheAI (web servers), HestiaAI (sysadmin), PipelineAI (CI/CD devops). - Orchestrated delegation —
sleep(3)between typing presence and comments (Linus delegates → the specialist introduces itself) viapresence.php(working/idle, released infinally). - LGPD/GDPR —
lgpd_sanitize_contentmasks Google/OpenAI/AMZN keys, tokens, passwords, emails,.pem/.key/.cert/.crt/.pubfiles, private key blocks and hashes (except security forensics); privacy alert at the top of the reply when sanitized. - External references — Semgrep rule (
semgrep.dev/r), CVE via MITRE API (cveawg.mitre.org) and Wikipedia OpenSearch (3 terms with generic-word blacklist). - Smart truncate — description >7,000 chars → first 4,500 + last 2,000; last 15 comments capped at 1,500 (1,000+400); final 12,000 safety.
- Node management — registration preserves the existing
node_key; remote commands viam.php(purge,rebuild_llm,update_agent,logslines 1–500,reboot,shutdown; 8s/20s timeout;X-Nexus-Proxy-Secret;NEXUS-Dashboard/7.6User-Agent; "sudo requires password" live-log detection); synchronous latency ping via/health(3s). - Security — IP whitelist (
allowed_ips) enforced on all 4 AI routes; sync token rotation (st-+ 24 bytes withcreated_at) and optionalnode_keyrotation (kgn<ip>_+ 16 bytes). - API: 17 actions —
oci_rotate_tokens,oci_token_status,oci_nodes_list,oci_nodes_status(mapspersona_name/is_master),oci_endpoints_list,oci_node_delete,oci_node_register,oci_node_assign_avatar,oci_endpoint_register,oci_node_command,oci_node_ping,ai_explain_task,ai_explain_comment,ai_ask_ideas(session_write_closefor parallel processing),ai_upload_report($_POSTmerge),ai_hub_settings_get/set(allowed_ips+persona_categoryhumans|robots). - UI (
tab.php, 295 lines, slate + violet/blue theme) — Active AI Agents table (persona avatar, violet badge,last_pulse,LLAMA: UP/DOWN, IP/provider with ms latency, 12-point CPU/RAM sparklines,purge/rebuild_llm/update_agent/restart/logs/SSH/copy key/delete actions, "Master Shield Active" on the master) and IA Endpoints Active (model, provider, URL, chat test); top bar with settings (whitelist), masked sync token with countdown + rotation, Refresh (refreshOciAll()— renamed fromrefreshAll()to avoid the Alpine.js namespace clash with the core) and "Recruit Node". - Fastr —
/oci-nodes→oci_nodes_status(no argument). No cron (on demand). - Documented Safe Mode — persistent
opencode serve --port 8092daemon keeps the model in memory and a Python wrapper on port 8091 intercepts/v1/chat/opencodevia lightweight sockets (40s+ → ~2.8s on 1 Core ARM/1GB instances); telemetry/title bypass (agent.title.disable) with a whitelisted light model;MemoryMax=300Mremoved from systemd using native swap (2.5GB).
Stack and tools
- PHP 8 (no framework)
- MySQL 8 (
oci_nodes,oci_ai_endpoints,node_lock_*/oci_sync_token/ai_hub_settingsconfigs) - Alpine.js + Tailwind CSS (premium light, slate/violet/blue)
- cURL + REST (
/v1/chat/opencodeendpoints,m.php,health) - OpenCode (Safe Mode daemon v3.2 + local fallback)
- NEXUS plugin system (PluginManager: tabs, docs, API actions, modals, JS, Fastr)
Operational tags
- IA
- Agentes
- Orquestração
- Multi-cloud
- OCI
- Satélites
- OpenCode
- Subagentes
- LGPD
- DevOps
- Plugin NEXUS
Operational result
- Multi-cloud fleet: Oracle Cloud, OVH and independent nodes with heartbeat, CPU/RAM sparklines and ms latency — all in the panel.
- Automatic routing: tasks, comments and idea requests are forwarded to the active, least-loaded node (
nsx01priority), with anti-race locks and local fallback. - Visible specialists: 8 subagents delegate with typing messages and their own personas — the user sees who is analyzing what.
- Privacy by default: secrets and hashes are masked before leaving for the cloud; security forensics preserve the hashes (the analysis target).
- Huge logs become analyses: PDF/text upload segmented into sequential parts with per-part summaries.
- Operational security: IP whitelist, rotating sync token and one-click
node_keyrotation. - Manageable fleet: purge, LLM rebuild, agent update, live logs, SSH, restart and removal straight from the satellites table.
/oci-nodeschat command.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Multi-model artificial intelligence orchestration hub. Connects leading LLMs (OpenAI, Claude, Gemini, DeepSeek, and local Ollama models), manages specialized system prompts, and unifies virtual assistant workflows.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- cURL
- REST API
- OpenCode
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.