Cover image for project: NEXUS AI Hub IN PROGRESS

Technical summary

NEXUS AI Hub is the AI agent orchestrator running on Linux servers and multi-cloud environments (successor of oci-manager): central registry of satellite nodes with heartbeats, hardware metrics and latency, smart routing of tasks, comments and ideas to 8 specialists, LGPD/GDPR sanitization of secrets, smart truncate of huge logs and remote node management.

Executed scope

  • plugin.json: v1.0.0, slug nexus-ai-hub, legacy_slugs ["oci-manager","ai-hub"], "AI" category, is_core: false, public author_url and website (perciocastelo.com.br).
  • Registration: 2 tabs (ai-hub and nexus-ai-hub legacy → tab.php), "AI Hub" doc (bot icon), oci-v2-assets JS, 5 modals (oci-explorer, oci-preview, oci-logs, ia-chat-test, ai-hub-settings).
  • Central schema (legacy, consumed via DB::fetchAll, no DDL in the plugin) — oci_nodes (id PK, name, ip, hostname, node_key st- + 24 bytes, provider, status, last_pulse, persona_name, persona_avatar) and oci_ai_endpoints (id PK, node_id FK, ip, url on port /v1/chat/opencode, model, status, last_seen_at).
  • Personas — 18 agents with avatars (assets/ia/people1|robo): automatic assignment without repetition (filters used ones, with fallback), re-assignment with force, master detected by SERVER_ADDR, SITE_URL hostname, "Independent" provider or id 7.
  • AI panel routes — ai_explain_task (explain task), ai_explain_comment (explain comment with context), ai_ask_ideas (ideas/refactors via Torvalds), ai_upload_report (PDF via pdftotext or plain text: LGPD sanitization + segmentation into 8,000-char chunks analyzed sequentially, "Part X of Y" header).
  • Multi-node routing — active /v1/chat/opencode endpoints deduplicated per node, nsx01 priority, 90s global budget, node_lock_<id> locks (180s; 300s on failure), X-Proxy-Secret/X-Nexus-Proxy-Secret headers + Host, rewrite to http://ip, 55s timeout (1.5s connect); local fallback run_local_opencode (35s, opencode-web setuid wrapper for www-data, build-line filter).
  • 8 specialist subagents — JSON manifests with keywords (+1) and regex (+3), minimum 1: Torvalds (ideas), SecurityAI, HASHAI and CVEAI (security category preserves hashes — they are the forensic analysis target), NginxAI, ApacheAI (web servers), HestiaAI (sysadmin), PipelineAI (CI/CD devops).
  • Orchestrated delegation — sleep(3) between typing presence and comments (Linus delegates → the specialist introduces itself) via presence.php (working/idle, released in finally).
  • LGPD/GDPR — lgpd_sanitize_content masks Google/OpenAI/AMZN keys, tokens, passwords, emails, .pem/.key/.cert/.crt/.pub files, private key blocks and hashes (except security forensics); privacy alert at the top of the reply when sanitized.
  • External references — Semgrep rule (semgrep.dev/r), CVE via MITRE API (cveawg.mitre.org) and Wikipedia OpenSearch (3 terms with generic-word blacklist).
  • Smart truncate — description >7,000 chars → first 4,500 + last 2,000; last 15 comments capped at 1,500 (1,000+400); final 12,000 safety.
  • Node management — registration preserves the existing node_key; remote commands via m.php (purge, rebuild_llm, update_agent, logs lines 1–500, reboot, shutdown; 8s/20s timeout; X-Nexus-Proxy-Secret; NEXUS-Dashboard/7.6 User-Agent; "sudo requires password" live-log detection); synchronous latency ping via /health (3s).
  • Security — IP whitelist (allowed_ips) enforced on all 4 AI routes; sync token rotation (st- + 24 bytes with created_at) and optional node_key rotation (kgn<ip>_ + 16 bytes).
  • API: 17 actions — oci_rotate_tokens, oci_token_status, oci_nodes_list, oci_nodes_status (maps persona_name/is_master), oci_endpoints_list, oci_node_delete, oci_node_register, oci_node_assign_avatar, oci_endpoint_register, oci_node_command, oci_node_ping, ai_explain_task, ai_explain_comment, ai_ask_ideas (session_write_close for parallel processing), ai_upload_report ($_POST merge), ai_hub_settings_get/set (allowed_ips + persona_category humans|robots).
  • UI (tab.php, 295 lines, slate + violet/blue theme) — Active AI Agents table (persona avatar, violet badge, last_pulse, LLAMA: UP/DOWN, IP/provider with ms latency, 12-point CPU/RAM sparklines, purge/rebuild_llm/update_agent/restart/logs/SSH/copy key/delete actions, "Master Shield Active" on the master) and IA Endpoints Active (model, provider, URL, chat test); top bar with settings (whitelist), masked sync token with countdown + rotation, Refresh (refreshOciAll() — renamed from refreshAll() to avoid the Alpine.js namespace clash with the core) and "Recruit Node".
  • Fastr — /oci-nodes → oci_nodes_status (no argument). No cron (on demand).
  • Documented Safe Mode — persistent opencode serve --port 8092 daemon keeps the model in memory and a Python wrapper on port 8091 intercepts /v1/chat/opencode via lightweight sockets (40s+ → ~2.8s on 1 Core ARM/1GB instances); telemetry/title bypass (agent.title.disable) with a whitelisted light model; MemoryMax=300M removed from systemd using native swap (2.5GB).

Stack and tools

  • PHP 8 (no framework)
  • MySQL 8 (oci_nodes, oci_ai_endpoints, node_lock_*/oci_sync_token/ai_hub_settings configs)
  • Alpine.js + Tailwind CSS (premium light, slate/violet/blue)
  • cURL + REST (/v1/chat/opencode endpoints, m.php, health)
  • OpenCode (Safe Mode daemon v3.2 + local fallback)
  • NEXUS plugin system (PluginManager: tabs, docs, API actions, modals, JS, Fastr)

Operational tags

  • IA
  • Agentes
  • Orquestração
  • Multi-cloud
  • OCI
  • Satélites
  • OpenCode
  • Subagentes
  • LGPD
  • DevOps
  • Plugin NEXUS

Operational result

  • Multi-cloud fleet: Oracle Cloud, OVH and independent nodes with heartbeat, CPU/RAM sparklines and ms latency — all in the panel.
  • Automatic routing: tasks, comments and idea requests are forwarded to the active, least-loaded node (nsx01 priority), with anti-race locks and local fallback.
  • Visible specialists: 8 subagents delegate with typing messages and their own personas — the user sees who is analyzing what.
  • Privacy by default: secrets and hashes are masked before leaving for the cloud; security forensics preserve the hashes (the analysis target).
  • Huge logs become analyses: PDF/text upload segmented into sequential parts with per-part summaries.
  • Operational security: IP whitelist, rotating sync token and one-click node_key rotation.
  • Manageable fleet: purge, LLM rebuild, agent update, live logs, SSH, restart and removal straight from the satellites table.
  • /oci-nodes chat command.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Multi-model artificial intelligence orchestration hub. Connects leading LLMs (OpenAI, Claude, Gemini, DeepSeek, and local Ollama models), manages specialized system prompts, and unifies virtual assistant workflows.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.