IN PROGRESS
Technical summary
Native NEXUS plugin that centralizes CI runs, checks, gates, audited exceptions and regressions. Webhooks feed a data-driven gate policy with SLA and regression detection; the worker comments on breaches and creates tasks, while the Intelligence Hub and /pipeline command expose each RUN.
Executed scope
plugin.json— v1.0.0,is_core: true, NEXUS category, lucidegit-branchicon withicon_bg #f0fdf4,settings_route "plugin=pipeline-control".- Registrations:
registerTab("pipeline-control", "Pipeline", "git-branch", tab.php, "NEXUS")andregisterDoc(...). - 8 API actions (
plugin.php, viaPluginManager::registerApiAction) —pipeline_list_runs(gate_status/repo/branch/q/failed_only filters, LIMIT 200 + stats),pipeline_get_run(id/code/q with details),pipeline_ingest_webhook(CI ingestion with external_id dedupe),pipeline_update_exception(grant/revoke waiver),pipeline_lookup(slash/fastr),pipeline_stats(counters),pipeline_sla_breaches(LIMIT 100),pipeline_cron_tick(manual worker run). - Database:
pipeline_install()on load — 3 tables (pipeline_runs,pipeline_checks,pipeline_exceptions) with search indexes (status, gate_status, repo+branch, commit, task, sla_due_at, external_id). - Gate:
pipeline_evaluate_gate()— policy-as-data: fail onlint|test|sast|sca|policy|buildwith statusfailor sast/sca withseverity_critical > 0; active exception →waived(does not rewrite checks); no checks →open. - Regression:
pipeline_detect_regression()— previous run of the same repo+branch withpassed/waivedgate and current runfailed→regression_flag=1. - CI webhook:
pipeline_ingest_webhook()— payload through authenticated API (session + CSRF or Bearer Master API Key; actions mapped in theapi.phpACL, lines 312-315), dedupe byexternal_id, default SLA 48h, raw_json preserved, gate re-evaluated on ingest. - Audited exception:
pipeline_update_exception()— required reason +approved_by+valid_until/valid_hours; deactivates previous active ones;revoke=1reverts and re-evaluates the gate. - Worker:
pipeline_cron_check()— comments on linked tasks with SLA breach (daily marker in notes, once/day) and creates a NEXUS task (Pipeline project, priority 3) for regressions withouttask_id;pipelinecronjob incronjob.json(tick, check/run) +cli.phpCLI +pipeline_cron_tickaction. - Intelligence Hub:
pipeline_intel_enrich()—\bRUN-\d{1,6}\b, severity 3 (SLA breach/gate failed), 2 (regression), 1 (waived), 0 (otherwise);pipeline_run/pipeline_refartifacts. - Fast Responses:
fastr.json—/pipeline <RUN-0001>viapipeline_lookup(requiredcodearg,pass_task_id: false); markdown reply with code, repo@branch, commit, gate, SLA and checks. - Alpine.js UI (
tab.php, 382 lines): metric cards (Total/Gate fail/SLA breach/Regressions), runs list with filters and gate chips + REG flag, detail drawer with checks and exceptions (grant with 72h/revoke), Ingest tab simulating a CI webhook, Compliance Hub link. - Seed:
pipeline_seed_demo_if_empty()— 2 demo runs (build ok; SAST critical with regression) when the table is empty.
Stack and tools
- PHP 8 (no framework,
strict_types) - MySQL 8 (
pipeline_runs/pipeline_checks/pipeline_exceptions— DDL on load) - Alpine.js + Tailwind CSS
- NEXUS plugin system (
PluginManager::registerTab/registerDoc/registerApiAction) - NEXUS cronjobs (
cronjob.json—pipelinejob with tick) + CLI (cli.php) - Intelligence Hub (
nx_intel_register_enricher) + Fast Responses (fastr.json)
Operational tags
- Pipeline
- CI
- QA
- Gates
- Exceptions
- SLA
- Regression
- NEXUS Plugin
Operational result
- CI quality/compliance source of truth: runs persisted with
RUN-####codes, checks with severities and a gate evaluated by declarative policy — exceptions stay audited (reason, approver, validity) and never rewrite the checks. - Regressions detected automatically by comparing with the previous run of the same repo+branch (gate ok → failed) and flagged with
regression_flag, becoming a NEXUS task via the worker. - Authenticated CI webhook (Bearer Master API Key or session) with
external_iddedupe, configurable SLA (default 48h) and gate re-evaluation on ingest. - SLA worker comments once/day on tasks linked to runs with breached SLA (notes marker avoids spam) and auto-creates tasks for orphan regressions.
RUN-####codes cited in tasks/comments get enriched in the Intelligence Hub with gate status, SLA and regression info.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Quality gate and governance control center for continuous integration pipelines (CI/CD). Tracks pipeline runs, consolidates linting, testing, SAST, and SCA results, evaluates automated quality gates, and manages audited waivers with SLA monitoring and regression tracking.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
- Cronjobs
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.