Cover image for project: Nexus Pipeline Control IN PROGRESS

Technical summary

Native NEXUS plugin that centralizes CI runs, checks, gates, audited exceptions and regressions. Webhooks feed a data-driven gate policy with SLA and regression detection; the worker comments on breaches and creates tasks, while the Intelligence Hub and /pipeline command expose each RUN.

Executed scope

  • plugin.json — v1.0.0, is_core: true, NEXUS category, lucide git-branch icon with icon_bg #f0fdf4, settings_route "plugin=pipeline-control".
  • Registrations: registerTab("pipeline-control", "Pipeline", "git-branch", tab.php, "NEXUS") and registerDoc(...).
  • 8 API actions (plugin.php, via PluginManager::registerApiAction) — pipeline_list_runs (gate_status/repo/branch/q/failed_only filters, LIMIT 200 + stats), pipeline_get_run (id/code/q with details), pipeline_ingest_webhook (CI ingestion with external_id dedupe), pipeline_update_exception (grant/revoke waiver), pipeline_lookup (slash/fastr), pipeline_stats (counters), pipeline_sla_breaches (LIMIT 100), pipeline_cron_tick (manual worker run).
  • Database: pipeline_install() on load — 3 tables (pipeline_runs, pipeline_checks, pipeline_exceptions) with search indexes (status, gate_status, repo+branch, commit, task, sla_due_at, external_id).
  • Gate: pipeline_evaluate_gate() — policy-as-data: fail on lint|test|sast|sca|policy|build with status fail or sast/sca with severity_critical > 0; active exception → waived (does not rewrite checks); no checks → open.
  • Regression: pipeline_detect_regression() — previous run of the same repo+branch with passed/waived gate and current run failed → regression_flag=1.
  • CI webhook: pipeline_ingest_webhook() — payload through authenticated API (session + CSRF or Bearer Master API Key; actions mapped in the api.php ACL, lines 312-315), dedupe by external_id, default SLA 48h, raw_json preserved, gate re-evaluated on ingest.
  • Audited exception: pipeline_update_exception() — required reason + approved_by + valid_until/valid_hours; deactivates previous active ones; revoke=1 reverts and re-evaluates the gate.
  • Worker: pipeline_cron_check() — comments on linked tasks with SLA breach (daily marker in notes, once/day) and creates a NEXUS task (Pipeline project, priority 3) for regressions without task_id; pipeline cronjob in cronjob.json (tick, check/run) + cli.php CLI + pipeline_cron_tick action.
  • Intelligence Hub: pipeline_intel_enrich() — \bRUN-\d{1,6}\b, severity 3 (SLA breach/gate failed), 2 (regression), 1 (waived), 0 (otherwise); pipeline_run/pipeline_ref artifacts.
  • Fast Responses: fastr.json — /pipeline <RUN-0001> via pipeline_lookup (required code arg, pass_task_id: false); markdown reply with code, repo@branch, commit, gate, SLA and checks.
  • Alpine.js UI (tab.php, 382 lines): metric cards (Total/Gate fail/SLA breach/Regressions), runs list with filters and gate chips + REG flag, detail drawer with checks and exceptions (grant with 72h/revoke), Ingest tab simulating a CI webhook, Compliance Hub link.
  • Seed: pipeline_seed_demo_if_empty() — 2 demo runs (build ok; SAST critical with regression) when the table is empty.

Stack and tools

  • PHP 8 (no framework, strict_types)
  • MySQL 8 (pipeline_runs/pipeline_checks/pipeline_exceptions — DDL on load)
  • Alpine.js + Tailwind CSS
  • NEXUS plugin system (PluginManager::registerTab/registerDoc/registerApiAction)
  • NEXUS cronjobs (cronjob.json — pipeline job with tick) + CLI (cli.php)
  • Intelligence Hub (nx_intel_register_enricher) + Fast Responses (fastr.json)

Operational tags

  • Pipeline
  • CI
  • QA
  • Gates
  • Exceptions
  • SLA
  • Regression
  • NEXUS Plugin

Operational result

  • CI quality/compliance source of truth: runs persisted with RUN-#### codes, checks with severities and a gate evaluated by declarative policy — exceptions stay audited (reason, approver, validity) and never rewrite the checks.
  • Regressions detected automatically by comparing with the previous run of the same repo+branch (gate ok → failed) and flagged with regression_flag, becoming a NEXUS task via the worker.
  • Authenticated CI webhook (Bearer Master API Key or session) with external_id dedupe, configurable SLA (default 48h) and gate re-evaluation on ingest.
  • SLA worker comments once/day on tasks linked to runs with breached SLA (notes marker avoids spam) and auto-creates tasks for orphan regressions.
  • RUN-#### codes cited in tasks/comments get enriched in the Intelligence Hub with gate status, SLA and regression info.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Quality gate and governance control center for continuous integration pipelines (CI/CD). Tracks pipeline runs, consolidates linting, testing, SAST, and SCA results, evaluates automated quality gates, and manages audited waivers with SLA monitoring and regression tracking.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.