Cover image for project: NEXUS OCI Cloud Storage IN PROGRESS

Technical summary

NEXUS plugin that integrates Oracle Cloud Infrastructure Object Storage via RSA-SHA256 signed REST API: browse buckets and objects, stream upload/download, generate PAR links (Pre-Authenticated Requests), global search and bulk zip — all from the panel, without relying on the OCI CLI.

Executed scope

  • Native REST, no shell: oci_rest_call() implements the OCI signature (RFC 2617 / draft-cavage-http-signatures) — host, date, (request-target), x-content-sha256, content-type, content-length headers, RSA-SHA256 via OpenSSL and Authorization: Signature version="1",keyId=tenancy/user/fingerprint — for the objectstorage, compute and monitoring services.
  • OCI profiles: get_oci_profiles() merges settings('oci.profiles') with the real tenancies read from the physical ~/.oci/config file (configurable config_path); oci_parse_config_profiles() parses the INI; tenancy from config > compartment_id from settings; profiles without tenancy are ignored.
  • Buckets: oci_cloud_buckets_list() fetches the namespace per profile (GET /n/), lists buckets by compartment and enriches with approximateSize/approximateCount (fields param) — per-bucket stats right in the panel.
  • Objects: oci_cloud_bucket_objects() lists objects with prefix/delimiter (limit 1000, fields name,size,etag,timeCreated,md5); oci_encode_path() encodes names preserving / for subfolders.
  • Download: oci_cloud_object_stream() proxies the OCI direct stream (CURLOPT_WRITEFUNCTION) with Content-Type/Content-Length/Range (video and partial download support), MIME fallback by extension and inline/attachment Content-Disposition.
  • Upload: oci_cloud_object_save_contents() (text PUT), oci_cloud_object_put() (binary PUT with SHA256 computed in 64KB chunks, streaming via CURLOPT_INFILE, 600s timeout) and chunked upload (oci_cloud_chunk_save/oci_cloud_chunks_assemble/oci_cloud_chunks_cleanup) — parts stored in uploads/tmp/oci_chunks and merged before the final PUT.
  • PAR links: oci_cloud_par_create() generates Pre-Authenticated Requests (ObjectRead/ObjectWrite, configurable expiry; the action uses ObjectRead +2h) — the API returns the full URL https://objectstorage.{region}.oraclecloud.com{access-uri}.
  • Object/folder management: oci_cloud_object_rename() (POST actions/renameObject), oci_cloud_object_delete(), oci_cloud_folder_create() (PUT of an empty object ending in /), oci_cloud_folder_delete() (lists and deletes by prefix) and oci_cloud_bucket_stats().
  • Search and zip: oci_cloud_global_search() (case-insensitive LIKE on the name, limit 1000) and oci_cloud_bulk_zip() (ZipArchive + streaming — downloads objects, builds the ZIP in uploads/tmp and sends it with Content-Disposition).
  • Compute/monitoring (satellites): oci_cloud_instances_list() (instances + VNIC public IP), oci_cloud_instance_action() (START/STOP/RESET/SOFTRESET/SOFTSTOP) and oci_cloud_instance_metrics() (CpuUtilization/MemoryUtilization via monitoring, 5min cache in /tmp) — feed the "Active Satellites" column of the tab.
  • UI: "OCI Infrastructure" tab (tab.php) — Satellites (cards with status/IP/CPU-RAM sparklines and SOFTRESET/STOP/SSH/logs/purge/test AI/delete actions) + Bucket Management (cards with namespace, count and size, "Open Explorer"); "Configure OCI Storage" modal (profiles + masked private_key), explorer (breadcrumbs, grid/list, multi-select, upload/download/rename/delete/PAR/search/zip and pagination) and preview modal (inline text editing, fullscreen, download).
  • Frontend: assets/oci-v2.js (1384 lines, Alpine ociModule()) — refresh, explorer, chunked upload, PAR, preview, search and zip; oci_cloud_profiles_status action registered via PluginManager::registerApiAction (profile id/label/region) + Fastr /oci-cloud command.
  • Core config: settings.php — oci.config_path, user_ocid, fingerprint, private_key (masked on save), profiles[]; auto-generation of ~/.oci/config and the PEM key (chmod 0600) when credentials are saved; automatic single-profile → multi-profile migration.
  • No install.sql/update.sql (config in admin_configs/system_settings); cronjob.json with no jobs ("on-demand plugin"); cors.php registers the OCI proxy (POST/GET/OPTIONS methods, Content-Type/Authorization headers).
  • Non-core plugin (is_core: false), Cloud category, version 1.0.0, author Percio Andrade.

Stack and tooling

  • PHP 8 (no framework) + OpenSSL (RSA-SHA256 signing)
  • OCI REST API — objectstorage, compute and monitoring (no shell)
  • MySQL 8 (config in admin_configs/system_settings)
  • Alpine.js + Tailwind CSS (premium light, blue)
  • ZipArchive (PHP) for bulk zip

Operational tags

  • OCI
  • Oracle Cloud
  • Object Storage
  • PAR
  • Cloud Storage
  • Plugin NEXUS

Operational outcome

  • Single panel for multi-profile/multi-region Object Storage (e.g.: SP sa-saopaulo-1, CA ca-montreal-1) without the OCI CLI: buckets with stats, navigation, upload/download and expiring PAR links.
  • Native REST signing (Signature v1 RSA-SHA256) replaces runtime CLI execution — the legacy oci_cloud.php used oci_cli_exec().
  • Direct download with Range support (videos/partials), correct MIME and Content-Disposition; chunked upload for large files with a 10-minute limit.
  • Security: credentials never exposed in the UI (private_key masked on save), PEM key with 0600 permissions, profiles without tenancy ignored and power-action whitelist on compute.
  • Built-in compute/monitoring gives satellite visibility (public IP, CPU/RAM sparklines) and power actions with satellite fallback when IAM blocks.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that integrates Oracle Cloud Infrastructure Object Storage via RSA-SHA256 signed REST API: browse buckets and objects, stream upload/download, generate PAR links, global search and bulk zip — without relying on the OCI CLI.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.