IN PROGRESS
Technical summary
NEXUS plugin that integrates Oracle Cloud Infrastructure Object Storage via RSA-SHA256 signed REST API: browse buckets and objects, stream upload/download, generate PAR links (Pre-Authenticated Requests), global search and bulk zip — all from the panel, without relying on the OCI CLI.
Executed scope
- Native REST, no shell:
oci_rest_call()implements the OCI signature (RFC 2617 / draft-cavage-http-signatures) —host,date,(request-target),x-content-sha256,content-type,content-lengthheaders, RSA-SHA256 via OpenSSL andAuthorization: Signature version="1",keyId=tenancy/user/fingerprint— for theobjectstorage,computeandmonitoringservices. - OCI profiles:
get_oci_profiles()mergessettings('oci.profiles')with the real tenancies read from the physical~/.oci/configfile (configurable config_path);oci_parse_config_profiles()parses the INI; tenancy from config > compartment_id from settings; profiles without tenancy are ignored. - Buckets:
oci_cloud_buckets_list()fetches the namespace per profile (GET /n/), lists buckets by compartment and enriches withapproximateSize/approximateCount(fieldsparam) — per-bucket stats right in the panel. - Objects:
oci_cloud_bucket_objects()lists objects withprefix/delimiter(limit 1000, fieldsname,size,etag,timeCreated,md5);oci_encode_path()encodes names preserving/for subfolders. - Download:
oci_cloud_object_stream()proxies the OCI direct stream (CURLOPT_WRITEFUNCTION) with Content-Type/Content-Length/Range (video and partial download support), MIME fallback by extension and inline/attachment Content-Disposition. - Upload:
oci_cloud_object_save_contents()(text PUT),oci_cloud_object_put()(binary PUT with SHA256 computed in 64KB chunks, streaming via CURLOPT_INFILE, 600s timeout) and chunked upload (oci_cloud_chunk_save/oci_cloud_chunks_assemble/oci_cloud_chunks_cleanup) — parts stored inuploads/tmp/oci_chunksand merged before the final PUT. - PAR links:
oci_cloud_par_create()generates Pre-Authenticated Requests (ObjectRead/ObjectWrite, configurable expiry; the action uses ObjectRead +2h) — the API returns the full URLhttps://objectstorage.{region}.oraclecloud.com{access-uri}. - Object/folder management:
oci_cloud_object_rename()(POSTactions/renameObject),oci_cloud_object_delete(),oci_cloud_folder_create()(PUT of an empty object ending in/),oci_cloud_folder_delete()(lists and deletes by prefix) andoci_cloud_bucket_stats(). - Search and zip:
oci_cloud_global_search()(case-insensitive LIKE on the name, limit 1000) andoci_cloud_bulk_zip()(ZipArchive + streaming — downloads objects, builds the ZIP inuploads/tmpand sends it with Content-Disposition). - Compute/monitoring (satellites):
oci_cloud_instances_list()(instances + VNIC public IP),oci_cloud_instance_action()(START/STOP/RESET/SOFTRESET/SOFTSTOP) andoci_cloud_instance_metrics()(CpuUtilization/MemoryUtilization via monitoring, 5min cache in /tmp) — feed the "Active Satellites" column of the tab. - UI: "OCI Infrastructure" tab (
tab.php) — Satellites (cards with status/IP/CPU-RAM sparklines and SOFTRESET/STOP/SSH/logs/purge/test AI/delete actions) + Bucket Management (cards with namespace, count and size, "Open Explorer"); "Configure OCI Storage" modal (profiles + masked private_key), explorer (breadcrumbs, grid/list, multi-select, upload/download/rename/delete/PAR/search/zip and pagination) and preview modal (inline text editing, fullscreen, download). - Frontend:
assets/oci-v2.js(1384 lines, AlpineociModule()) — refresh, explorer, chunked upload, PAR, preview, search and zip;oci_cloud_profiles_statusaction registered viaPluginManager::registerApiAction(profile id/label/region) + Fastr/oci-cloudcommand. - Core config:
settings.php—oci.config_path,user_ocid,fingerprint,private_key(masked on save),profiles[]; auto-generation of~/.oci/configand the PEM key (chmod 0600) when credentials are saved; automatic single-profile → multi-profile migration. - No
install.sql/update.sql(config in admin_configs/system_settings);cronjob.jsonwith no jobs ("on-demand plugin");cors.phpregisters the OCI proxy (POST/GET/OPTIONS methods, Content-Type/Authorization headers). - Non-core plugin (
is_core: false), Cloud category, version 1.0.0, author Percio Andrade.
Stack and tooling
- PHP 8 (no framework) + OpenSSL (RSA-SHA256 signing)
- OCI REST API — objectstorage, compute and monitoring (no shell)
- MySQL 8 (config in admin_configs/system_settings)
- Alpine.js + Tailwind CSS (premium light, blue)
- ZipArchive (PHP) for bulk zip
Operational tags
- OCI
- Oracle Cloud
- Object Storage
- PAR
- Cloud Storage
- Plugin NEXUS
Operational outcome
- Single panel for multi-profile/multi-region Object Storage (e.g.: SP sa-saopaulo-1, CA ca-montreal-1) without the OCI CLI: buckets with stats, navigation, upload/download and expiring PAR links.
- Native REST signing (Signature v1 RSA-SHA256) replaces runtime CLI execution — the legacy
oci_cloud.phpusedoci_cli_exec(). - Direct download with Range support (videos/partials), correct MIME and Content-Disposition; chunked upload for large files with a 10-minute limit.
- Security: credentials never exposed in the UI (private_key masked on save), PEM key with 0600 permissions, profiles without tenancy ignored and power-action whitelist on compute.
- Built-in compute/monitoring gives satellite visibility (public IP, CPU/RAM sparklines) and power actions with satellite fallback when IAM blocks.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that integrates Oracle Cloud Infrastructure Object Storage via RSA-SHA256 signed REST API: browse buckets and objects, stream upload/download, generate PAR links, global search and bulk zip — without relying on the OCI CLI.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- OCI REST API
- ZipArchive
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.