IN PROGRESS
Technical summary
NEXUS plugin (DevOps & Infra category) that orchestrates post-deploy DAST for Kagin and Evolya: Coolify/CI calls dast_deploy_hook (or the UI//dast slash triggers it), NEXUS runs Nuclei (projectdiscovery/nuclei:latest) and/or OWASP ZAP baseline (ghcr.io/zaproxy/zaproxy:stable) via Docker with --network host, imports the reports into the Nexus Security Scanner with compliance (source: nexus-dast-deploy), persists the run in dast_runs and creates an optional [DAST] task in NEXUS — closing the SDLC loop where the workflow/CI triggers and the plugin is the source of truth.
Executed scope
backend.phpbackend (972 lines):dast_default_config()inDB::getConfig('plugin.dast-deploy')withkagin(https://kagin.com.br) andevolya(https://evolya.com.br) targets per production/staging environment, defaultscanners['nuclei','zap'],nuclei_severitycritical,high,medium, configurable Docker images,webhook_secret,create_run_task,timeout_sec(60–3600 clamp),allow_manualandnotify_inngest.dast_runstable created bydast_install()(InnoDB, utf8mb4, indexes onapp/status/created_at) with per-severity countsnuclei_critical/high/medium/lowandzap_high/medium/low,task_id,summary_json,duration_msand timestamps.dast_deploy_hook: post-deploy webhook that validatessecretwithhash_equals(required when configured), acceptsapp/application/service,env(prod/stagealiases), URL override andscanners, with anasyncoption.dast_run: validatesallow_manual, resolves the target (dast_resolve_target— app+env or URL override), checks Docker (dast_docker_okvianx_secure_exec_status), creates the[DAST] {app}/{env} — scan pós-deploytask (NEXUS project, priority 2,in_progress), inserts therunningrun and emits the Inngestnexus/dast.deployevent (when the Inngest plugin is active).- Nuclei (
dast_run_nuclei):docker run --rm --network host -v <reports>:/out -u <url> -severity <sev> -je <report> -silent -nc -timeout 10; counts by severity (non-zero exit with findings is still OK) and normalizes NDJSON. - ZAP (
dast_run_zap):zap-baseline.py -t <url> -J <report> -I; counts alerts byriskdesc/riskcode(High/Medium/Low/Informational). - Compliance-aware import (
dast_import_report):security_import_with_compliancewithnuclei→security_process_nuclei_scanandzap→security_process_zap_scan,repo: deploy/{app},project: NEXUS,source: nexus-dast-deploy; loads the Security Scanner backend on demand if absent. - Final status
ok/partial/errordepending on scanner success;DAST finalizado (...)comment on the task andtask_updatetodone(no findings) orpendingwith priority 4 (critical/high present). dast_normalize_url: onlyhttp/https; blockslocalhost,127.0.0.1,0.0.0.0,::1,169.254.*and*.local.- API: 9 actions via
PluginManager::registerApiAction—dast_dashboard,dast_settings_get,dast_settings_save,dast_deploy_hook,dast_run,dast_runs_list,dast_run_get,dast_fastr,dast_fastr_suggest(session/Bearer authenticated with CSRF). - Alpine.js UI (
tab.php219 lines): Docker OK badge (pulsing green dot), stat cards (Runs · OK · Partial/Err · Crit/High), Run tab (app/env/scanners/URL override + Coolify/CI webhook box), History tab (runs with colored status andN c/h · Z h · durationcounts) and Config tab (4 target URLs + masked webhook secretabcd•••wxyz, timeout and booleans). - fastr
/dastcommand (dast_fastr+dast_fastr_suggest): summary,kagin,evolya/staging(triggers a Nuclei run) ordast_<id>;dast_intel_enrichenricher (priority 56) recognizesdast://kagin,dast://evolya/stagingand configured host URLs. Nocronjob.json(event-driven plugin).
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (settings in
admin_configs+dast_runstable) - Docker Engine (Nuclei and OWASP ZAP in containers,
nx_secure_exec) - Alpine.js + Tailwind CSS
- NEXUS plugin system (
PluginManager)
Operational tags
- DAST
- Nuclei
- OWASP ZAP
- DevSecOps
- Plugin NEXUS
Operational outcome
- Closes the post-deploy DAST loop: every Coolify/CI deploy can automatically trigger the scan via
dast_deploy_hook, with no manual action. - Two complementary containerized scanners: Nuclei (templates, configurable severities) + OWASP ZAP baseline (passive/active), with JSON reports persisted in
storage/dast-deploy/reports. - Direct import into the Nexus Security Scanner with compliance (
source: nexus-dast-deploy) — findings flow into the same security pipeline, withrepo deploy/{app}. - Full traceability: run in
dast_runswith per-severity counts, duration and error;[DAST]task in NEXUS with a result comment and raised priority when critical/high findings exist. - Trigger security: secret validated with
hash_equalsand normalized URL that blocks local/link-local targets (localhost,169.254.*,*.local).
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that orchestrates post-deploy DAST scans with Nuclei and OWASP ZAP via Docker, triggered by Coolify/CI webhook, panel tab or /dast slash — with report import into the Nexus Security Scanner, runs persisted in dast_runs and a [DAST] task in NEXUS.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Docker
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.