Repository navigation
feat(integrations): add OCI Object Storage - #7413
BillLeoutsakosvl346 wants to merge 2 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummaryAdds an OCI Object Storage integration backed by Oracle’s S3 Compatibility API, including customer-managed credentials and six workflow operations.
Confidence Score: 5/5The PR appears safe to merge based on the reviewed changes, with no concrete blocking or independently actionable non-blocking issue established. The integration keeps credential resolution server-controlled, validates and encrypts provider-specific secrets, confines requests to fixed OCI endpoints, bounds transfer paths, and aligns its block, tools, selectors, contracts, and generated metadata.
|
| Filename | Overview |
|---|---|
| apps/sim/lib/internal/oci-object-storage/client.ts | Adds the fixed-endpoint S3-compatible client, OCI response normalization, bounded bucket listings, retry configuration, and client cleanup. |
| apps/sim/lib/internal/oci-object-storage/operations.ts | Implements the six provider operations with file authorization, transfer limits, download preflight, streaming bounds, and normalized outputs. |
| apps/sim/lib/credentials/oci-object-storage-service-account.ts | Adds OCI credential normalization, live verification, encrypted-secret parsing, strict provider binding, and display identity handling. |
| apps/sim/lib/credentials/orchestration/index.ts | Extends credential rotation orchestration to rebuild and atomically replace OCI service-account secrets. |
| apps/sim/blocks/blocks/oci_object_storage.ts | Defines the OCI workflow block, six operations, selectors, parameter mapping, outputs, templates, and skills. |
| apps/sim/lib/selectors/server/providers/oci-object-storage.ts | Adds authorized bucket and object selectors backed by the provider-local OCI client. |
| apps/sim/app/workspace/[workspaceId]/integrations/components/connect-service-account-modal/connect-service-account-modal.tsx | Adds the OCI Customer Secret Key connection and reconnection form with required-field validation and secret-safe error handling. |
Sequence Diagram
sequenceDiagram
participant User as Workflow user
participant Exec as Tool execution boundary
participant Cred as Credential service
participant OCI as OCI S3-compatible endpoint
participant Files as Sim file storage
User->>Exec: Invoke OCI operation with credential reference
Exec->>Cred: Resolve authorized encrypted credential
Cred-->>Exec: Access key, secret, namespace, region
Exec->>OCI: Signed S3-compatible request
alt Upload from Sim file
Exec->>Files: Authorize and read bounded file
Files-->>Exec: File bytes and content type
Exec->>OCI: PutObject
else Download object
Exec->>OCI: HeadObject preflight
OCI-->>Exec: Size and metadata
Exec->>OCI: GetObject
OCI-->>Exec: Bounded object stream
Exec-->>User: Canonical file output and metadata
else List, inspect, or delete
OCI-->>Exec: Normalized operation result
end
Reviews (1): Last reviewed commit: "feat(integrations): add OCI Object Stora..." | Re-trigger Greptile
|
@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete. |
|
Addressed the Cubic review in
Validation after the changes:
Live OCI smoke testing remains unavailable because no disposable OCI tenant, bucket, or Customer Secret Key is available; the PR does not claim live verification. |
|
@cubic please re-review the latest commit. |
@BillLeoutsakosvl346 Incremental reviews are turned off for this repository. Comment |
|
@cubic review |
@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete. |
|
Final head is now |
|
@cubic review |
@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete. |
8bcb2bf to
a2d685f
Compare
a2d685f to
b536a23
Compare
Adds OCI Object Storage bucket/object listing, upload, download, metadata inspection, and deletion through Oracle's S3 Compatibility API. Users add and reconnect encrypted Customer Secret Keys through the shared credential modal, then select a regular saved credential in blocks and bucket/object selectors.
The client uses fixed commercial OCI endpoints, SigV4, bounded XML decoding, explicit timeouts, and bounded pagination. Transfers are capped at 100 MiB. Downloads use the shared file-result path, so files above the JSON response limit work without duplicate uploads. Uploads preserve trusted execution scope and authorize Sim file content before reading bytes. Terminal failures are logged without credentials or provider payloads.
No shared OAuth app, new Oracle-specific Secrets Manager entry, or database migration is required. Users supply their own Access Key, Secret Key, namespace, region, and appropriate OCI IAM permissions.
Validation:
Remaining release check: run credential verification and object CRUD against a real OCI tenancy. No signed-in tenancy or Customer Secret Key is currently available for this validation.