Cover image for project: Nexus DAST Deploy IN PROGRESS

Technical summary

NEXUS plugin (DevOps & Infra category) that orchestrates post-deploy DAST for Kagin and Evolya: Coolify/CI calls dast_deploy_hook (or the UI//dast slash triggers it), NEXUS runs Nuclei (projectdiscovery/nuclei:latest) and/or OWASP ZAP baseline (ghcr.io/zaproxy/zaproxy:stable) via Docker with --network host, imports the reports into the Nexus Security Scanner with compliance (source: nexus-dast-deploy), persists the run in dast_runs and creates an optional [DAST] task in NEXUS — closing the SDLC loop where the workflow/CI triggers and the plugin is the source of truth.

Executed scope

  • backend.php backend (972 lines): dast_default_config() in DB::getConfig('plugin.dast-deploy') with kagin (https://kagin.com.br) and evolya (https://evolya.com.br) targets per production/staging environment, default scanners ['nuclei','zap'], nuclei_severity critical,high,medium, configurable Docker images, webhook_secret, create_run_task, timeout_sec (60–3600 clamp), allow_manual and notify_inngest.
  • dast_runs table created by dast_install() (InnoDB, utf8mb4, indexes on app/status/created_at) with per-severity counts nuclei_critical/high/medium/low and zap_high/medium/low, task_id, summary_json, duration_ms and timestamps.
  • dast_deploy_hook: post-deploy webhook that validates secret with hash_equals (required when configured), accepts app/application/service, env (prod/stage aliases), URL override and scanners, with an async option.
  • dast_run: validates allow_manual, resolves the target (dast_resolve_target — app+env or URL override), checks Docker (dast_docker_ok via nx_secure_exec_status), creates the [DAST] {app}/{env} — scan pós-deploy task (NEXUS project, priority 2, in_progress), inserts the running run and emits the Inngest nexus/dast.deploy event (when the Inngest plugin is active).
  • Nuclei (dast_run_nuclei): docker run --rm --network host -v <reports>:/out -u <url> -severity <sev> -je <report> -silent -nc -timeout 10; counts by severity (non-zero exit with findings is still OK) and normalizes NDJSON.
  • ZAP (dast_run_zap): zap-baseline.py -t <url> -J <report> -I; counts alerts by riskdesc/riskcode (High/Medium/Low/Informational).
  • Compliance-aware import (dast_import_report): security_import_with_compliance with nuclei → security_process_nuclei_scan and zap → security_process_zap_scan, repo: deploy/{app}, project: NEXUS, source: nexus-dast-deploy; loads the Security Scanner backend on demand if absent.
  • Final status ok/partial/error depending on scanner success; DAST finalizado (...) comment on the task and task_update to done (no findings) or pending with priority 4 (critical/high present).
  • dast_normalize_url: only http/https; blocks localhost, 127.0.0.1, 0.0.0.0, ::1, 169.254.* and *.local.
  • API: 9 actions via PluginManager::registerApiAction — dast_dashboard, dast_settings_get, dast_settings_save, dast_deploy_hook, dast_run, dast_runs_list, dast_run_get, dast_fastr, dast_fastr_suggest (session/Bearer authenticated with CSRF).
  • Alpine.js UI (tab.php 219 lines): Docker OK badge (pulsing green dot), stat cards (Runs · OK · Partial/Err · Crit/High), Run tab (app/env/scanners/URL override + Coolify/CI webhook box), History tab (runs with colored status and N c/h · Z h · duration counts) and Config tab (4 target URLs + masked webhook secret abcd•••wxyz, timeout and booleans).
  • fastr /dast command (dast_fastr + dast_fastr_suggest): summary, kagin, evolya/staging (triggers a Nuclei run) or dast_<id>; dast_intel_enrich enricher (priority 56) recognizes dast://kagin, dast://evolya/staging and configured host URLs. No cronjob.json (event-driven plugin).

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (settings in admin_configs + dast_runs table)
  • Docker Engine (Nuclei and OWASP ZAP in containers, nx_secure_exec)
  • Alpine.js + Tailwind CSS
  • NEXUS plugin system (PluginManager)

Operational tags

  • DAST
  • Nuclei
  • OWASP ZAP
  • DevSecOps
  • Plugin NEXUS

Operational outcome

  • Closes the post-deploy DAST loop: every Coolify/CI deploy can automatically trigger the scan via dast_deploy_hook, with no manual action.
  • Two complementary containerized scanners: Nuclei (templates, configurable severities) + OWASP ZAP baseline (passive/active), with JSON reports persisted in storage/dast-deploy/reports.
  • Direct import into the Nexus Security Scanner with compliance (source: nexus-dast-deploy) — findings flow into the same security pipeline, with repo deploy/{app}.
  • Full traceability: run in dast_runs with per-severity counts, duration and error; [DAST] task in NEXUS with a result comment and raised priority when critical/high findings exist.
  • Trigger security: secret validated with hash_equals and normalized URL that blocks local/link-local targets (localhost, 169.254.*, *.local).

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that orchestrates post-deploy DAST scans with Nuclei and OWASP ZAP via Docker, triggered by Coolify/CI webhook, panel tab or /dast slash — with report import into the Nexus Security Scanner, runs persisted in dast_runs and a [DAST] task in NEXUS.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.