IN PROGRESS
Technical summary
NEXUS Docker API connects the panel to multi-host Docker Engines over local socket, TCP+TLS or SSH to list, audit and control containers, networks and images. It ships Image Intelligence with Trivy (CVE, secrets, misconfig and CycloneDX SBOM) and turns events from tracked containers into NEXUS tasks.
Executed scope
- Plugin registration (
registerTab('docker-api','Docker API','container',tab.php,'DevOps & Infra')+registerDoc) anddocker_install()creating thedocker_audit_loganddocker_image_scanstables. - ~33
docker_*API actions: status/stats (per-host overview + per-container stats), containers (list/inspect/start/stop/restart/logs/remove), images (list/remove), networks, audit/history/alerts, hosts (list/save/delete/test), settings and scans (image_scan, scans_list, scan_get, scan_running) plus trivy_status/bootstrap and tracked/events (tracked_list/add/update/remove, events_poll) plus fastr and suggest. - Multi-host and transports:
hosts[]in Settings — local socket (DOCKER_DEFAULT_SOCKET), TCP with optional TLS and SSH with identity; PEM certs/keys instorage/docker-certs/<host_id>/(inside open_basedir);docker_host_testvalidates connection and version. - Security:
allow_control(false by default, global or per-host) enables start/stop/restart/remove (force) and image_remove;allow_logsgates logs; every control operation is written todocker_audit_log. - Image Intelligence (Trivy):
trivy_mode=autoresolves portable bootstrap atstorage/docker-scans/bin/trivy(no root) → customtrivy_bin→ system (/opt/trivy,/usr/local/bin,/usr/bin) →aquasec/trivyimage; vuln/secret/misconfig scanners; CycloneDX SBOM indocker_image_scans.sbom_json; cache instorage/docker-scans/trivy-cache/;docker_trivy_bootstrapinstalls the scanner from the UI (shared-hosting friendly). - Events → tasks (v1.3): containers tracked per host (
docker_tracked_*); event types die/oom/health_status/kill;docker_events_pollreads/events?since&untiland creates NEXUS tasks (configurable project/priority, 900 s dedupe). - Cronjobs/workers:
docker_scan_running(tick, 6 h throttle, max 4 images) anddocker_events_poll(tick, 2 min throttle) viacronjob.json;cli.phptriggers a 4-image running scan. - Fast Responses and enricher:
/dockerand/docker-scan(container/image select after the command; catalog in the comment when no choice),/ia docker//ia docker-scan;docker_fastr_suggestfeeds autocomplete;docker://nameordocker://host/nameenricher (priority 55). - UI (
tab.php, 1108 lines, AlpinedockerApp()): 9 tabs — Containers, Networks, Tracked, Inspect, Images, History, Alerts, Task and Config (hosts with socket/tcp/ssh picker) plus stat cards and the control gate.
Stack and tools
- PHP 8 backend (
strict_types, no framework) + MySQL 8 (docker_audit_log,docker_image_scans) - Docker Engine API: unix socket, TCP with optional TLS and SSH (multi-host)
- Trivy 0.72.0 (portable/system/Docker image) for vuln, secret, misconfig and CycloneDX SBOM
- Alpine.js + Tailwind CSS (
tab.php) - Internal Plugin API: PluginManager tabs/actions +
cronjob.json+fastr.json+ enricher
Operational tags
- Docker
- Multi-host
- Containers
- Networks
- Trivy
- Image Intelligence
- Events
- NEXUS Plugin
Operational result
- Unified multi-host: a single panel manages N Docker Engines (socket/TCP+TLS/SSH) with ping, version, stats and per-host auditing.
- Audited control with gates:
allow_controloff by default (global or per-host); destructive operations (remove/force) require the gate and are recorded indocker_audit_log. - Rootless Image Intelligence: portable Trivy under
storage/docker-scans/works on shared hosting (UI bootstrap), with vuln/secret/misconfig and SBOM. - Events → tasks: tracked containers become NEXUS tasks automatically (die, oom, health_status, kill) with dedupe and configurable project/priority.
- Fast Responses and enricher:
/dockerand/docker-scanrun via Fast Responses and thedocker://host/nameenricher attaches Docker context to tasks. - Integrated scheduling: running-image scans (6 h throttle) and event polling (2 min) run through the NEXUS Cronjobs soft-cron.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Connects the NEXUS panel to multi-host Docker Engines over local socket, TCP+TLS or SSH to list, audit and control containers, networks and images; ships Image Intelligence with Trivy and turns events from tracked containers into NEXUS tasks.
Architecture and organization
- PHP 8
- MySQL 8
- Docker Engine API
- Trivy
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.