Cover image for project: NEXUS Docker API IN PROGRESS

Technical summary

NEXUS Docker API connects the panel to multi-host Docker Engines over local socket, TCP+TLS or SSH to list, audit and control containers, networks and images. It ships Image Intelligence with Trivy (CVE, secrets, misconfig and CycloneDX SBOM) and turns events from tracked containers into NEXUS tasks.

Executed scope

  • Plugin registration (registerTab('docker-api','Docker API','container',tab.php,'DevOps & Infra') + registerDoc) and docker_install() creating the docker_audit_log and docker_image_scans tables.
  • ~33 docker_* API actions: status/stats (per-host overview + per-container stats), containers (list/inspect/start/stop/restart/logs/remove), images (list/remove), networks, audit/history/alerts, hosts (list/save/delete/test), settings and scans (image_scan, scans_list, scan_get, scan_running) plus trivy_status/bootstrap and tracked/events (tracked_list/add/update/remove, events_poll) plus fastr and suggest.
  • Multi-host and transports: hosts[] in Settings — local socket (DOCKER_DEFAULT_SOCKET), TCP with optional TLS and SSH with identity; PEM certs/keys in storage/docker-certs/<host_id>/ (inside open_basedir); docker_host_test validates connection and version.
  • Security: allow_control (false by default, global or per-host) enables start/stop/restart/remove (force) and image_remove; allow_logs gates logs; every control operation is written to docker_audit_log.
  • Image Intelligence (Trivy): trivy_mode=auto resolves portable bootstrap at storage/docker-scans/bin/trivy (no root) → custom trivy_bin → system (/opt/trivy, /usr/local/bin, /usr/bin) → aquasec/trivy image; vuln/secret/misconfig scanners; CycloneDX SBOM in docker_image_scans.sbom_json; cache in storage/docker-scans/trivy-cache/; docker_trivy_bootstrap installs the scanner from the UI (shared-hosting friendly).
  • Events → tasks (v1.3): containers tracked per host (docker_tracked_*); event types die/oom/health_status/kill; docker_events_poll reads /events?since&until and creates NEXUS tasks (configurable project/priority, 900 s dedupe).
  • Cronjobs/workers: docker_scan_running (tick, 6 h throttle, max 4 images) and docker_events_poll (tick, 2 min throttle) via cronjob.json; cli.php triggers a 4-image running scan.
  • Fast Responses and enricher: /docker and /docker-scan (container/image select after the command; catalog in the comment when no choice), /ia docker//ia docker-scan; docker_fastr_suggest feeds autocomplete; docker://name or docker://host/name enricher (priority 55).
  • UI (tab.php, 1108 lines, Alpine dockerApp()): 9 tabs — Containers, Networks, Tracked, Inspect, Images, History, Alerts, Task and Config (hosts with socket/tcp/ssh picker) plus stat cards and the control gate.

Stack and tools

  • PHP 8 backend (strict_types, no framework) + MySQL 8 (docker_audit_log, docker_image_scans)
  • Docker Engine API: unix socket, TCP with optional TLS and SSH (multi-host)
  • Trivy 0.72.0 (portable/system/Docker image) for vuln, secret, misconfig and CycloneDX SBOM
  • Alpine.js + Tailwind CSS (tab.php)
  • Internal Plugin API: PluginManager tabs/actions + cronjob.json + fastr.json + enricher

Operational tags

  • Docker
  • Multi-host
  • Containers
  • Networks
  • Trivy
  • Image Intelligence
  • Events
  • NEXUS Plugin

Operational result

  • Unified multi-host: a single panel manages N Docker Engines (socket/TCP+TLS/SSH) with ping, version, stats and per-host auditing.
  • Audited control with gates: allow_control off by default (global or per-host); destructive operations (remove/force) require the gate and are recorded in docker_audit_log.
  • Rootless Image Intelligence: portable Trivy under storage/docker-scans/ works on shared hosting (UI bootstrap), with vuln/secret/misconfig and SBOM.
  • Events → tasks: tracked containers become NEXUS tasks automatically (die, oom, health_status, kill) with dedupe and configurable project/priority.
  • Fast Responses and enricher: /docker and /docker-scan run via Fast Responses and the docker://host/name enricher attaches Docker context to tasks.
  • Integrated scheduling: running-image scans (6 h throttle) and event polling (2 min) run through the NEXUS Cronjobs soft-cron.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Connects the NEXUS panel to multi-host Docker Engines over local socket, TCP+TLS or SSH to list, audit and control containers, networks and images; ships Image Intelligence with Trivy and turns events from tracked containers into NEXUS tasks.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.