Skip to content

feat(integrations): add OCI Object Storage - #7413

Open
BillLeoutsakosvl346 wants to merge 2 commits into
stagingfrom
investigate/oci-object-storage-integration
Open

BillLeoutsakosvl346 wants to merge 2 commits into
stagingfrom
investigate/oci-object-storage-integration

Conversation

@BillLeoutsakosvl346

@BillLeoutsakosvl346 BillLeoutsakosvl346 commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Adds OCI Object Storage bucket/object listing, upload, download, metadata inspection, and deletion through Oracle's S3 Compatibility API. Users add and reconnect encrypted Customer Secret Keys through the shared credential modal, then select a regular saved credential in blocks and bucket/object selectors.

The client uses fixed commercial OCI endpoints, SigV4, bounded XML decoding, explicit timeouts, and bounded pagination. Transfers are capped at 100 MiB. Downloads use the shared file-result path, so files above the JSON response limit work without duplicate uploads. Uploads preserve trusted execution scope and authorize Sim file content before reading bytes. Terminal failures are logged without credentials or provider payloads.

No shared OAuth app, new Oracle-specific Secrets Manager entry, or database migration is required. Users supply their own Access Key, Secret Key, namespace, region, and appropriate OCI IAM permissions.

Validation:

  • Rebased onto staging after Oracle Database feat(oracledb): add Oracle Database integration #7378 merged. validate-integration, validate-selector, memory-load review, UI cleanup, and test audit completed against Oracle's published S3 Compatibility API specification.
  • Lint, all 26 workspace type checks, all 58 audits, docs manifest, and block-registry checks pass.
  • Both CI test shards pass. The complete local app suite with Oracle Database and Object Storage combined passes 36,806 tests (25 skipped) under Node 24 with four workers.
  • All 300 focused tests pass with Oracle Database and Object Storage combined on the latest staging base. Regressions were demonstrated before fixes for large downloads, cross-execution file scope, bounded XML responses, and terminal error logging. Deployment-availability tests pass.
  • All CI checks pass on the final rebased revision, including lint, both test shards, all eight database-integration shards, API end-to-end tests, the production build, and desktop smoke tests. There are no unresolved review threads.

Remaining release check: run credential verification and object CRUD against a real OCI tenancy. No signed-in tenancy or Customer Secret Key is currently available for this validation.

@vercel

vercel Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 8:12pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

Adds an OCI Object Storage integration backed by Oracle’s S3 Compatibility API, including customer-managed credentials and six workflow operations.

  • Registers the OCI block, tools, selectors, catalog metadata, generated API metadata, documentation, and icon mappings.
  • Adds credential creation and rotation with encrypted Customer Secret Key storage and provider validation.
  • Implements bounded bucket listing, uploads, preflighted downloads, metadata inspection, deletion, fixed public endpoints, and sanitized provider errors.
  • Adds focused tests for credential contracts, request serialization, authorization, transfer limits, selectors, and operation outputs.

Confidence Score: 5/5

The PR appears safe to merge based on the reviewed changes, with no concrete blocking or independently actionable non-blocking issue established.

The integration keeps credential resolution server-controlled, validates and encrypts provider-specific secrets, confines requests to fixed OCI endpoints, bounds transfer paths, and aligns its block, tools, selectors, contracts, and generated metadata.

Important Files Changed

Filename Overview
apps/sim/lib/internal/oci-object-storage/client.ts Adds the fixed-endpoint S3-compatible client, OCI response normalization, bounded bucket listings, retry configuration, and client cleanup.
apps/sim/lib/internal/oci-object-storage/operations.ts Implements the six provider operations with file authorization, transfer limits, download preflight, streaming bounds, and normalized outputs.
apps/sim/lib/credentials/oci-object-storage-service-account.ts Adds OCI credential normalization, live verification, encrypted-secret parsing, strict provider binding, and display identity handling.
apps/sim/lib/credentials/orchestration/index.ts Extends credential rotation orchestration to rebuild and atomically replace OCI service-account secrets.
apps/sim/blocks/blocks/oci_object_storage.ts Defines the OCI workflow block, six operations, selectors, parameter mapping, outputs, templates, and skills.
apps/sim/lib/selectors/server/providers/oci-object-storage.ts Adds authorized bucket and object selectors backed by the provider-local OCI client.
apps/sim/app/workspace/[workspaceId]/integrations/components/connect-service-account-modal/connect-service-account-modal.tsx Adds the OCI Customer Secret Key connection and reconnection form with required-field validation and secret-safe error handling.

Sequence Diagram

sequenceDiagram
  participant User as Workflow user
  participant Exec as Tool execution boundary
  participant Cred as Credential service
  participant OCI as OCI S3-compatible endpoint
  participant Files as Sim file storage

  User->>Exec: Invoke OCI operation with credential reference
  Exec->>Cred: Resolve authorized encrypted credential
  Cred-->>Exec: Access key, secret, namespace, region
  Exec->>OCI: Signed S3-compatible request
  alt Upload from Sim file
    Exec->>Files: Authorize and read bounded file
    Files-->>Exec: File bytes and content type
    Exec->>OCI: PutObject
  else Download object
    Exec->>OCI: HeadObject preflight
    OCI-->>Exec: Size and metadata
    Exec->>OCI: GetObject
    OCI-->>Exec: Bounded object stream
    Exec-->>User: Canonical file output and metadata
  else List, inspect, or delete
    OCI-->>Exec: Normalized operation result
  end
Loading

Reviews (1): Last reviewed commit: "feat(integrations): add OCI Object Stora..." | Re-trigger Greptile

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

@cubic

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 64 files

Re-trigger cubic

Comment thread apps/sim/lib/internal/oci-object-storage/operations.test.ts Outdated
Comment thread apps/sim/lib/credentials/orchestration/index.test.ts
Comment thread apps/sim/lib/internal/oci-object-storage/errors.ts Outdated
Comment thread apps/sim/lib/credentials/oci-object-storage-service-account.test.ts
Comment thread apps/sim/lib/internal/oci-object-storage/execute-tool.ts Outdated
Comment thread apps/sim/lib/internal/oci-object-storage/execute-tool.ts Outdated
Comment thread apps/sim/lib/internal/oci-object-storage/schema.ts Outdated
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

Addressed the Cubic review in dc1ab88756:

  1. Headless inline uploads: inline-content uploads now work without a user ID. Referenced-file uploads still require an authorized actor, prefer the delegated subject user when present, return 401 without one, and do not read the file first.
  2. Null-safe provider errors: null and undefined rejections now normalize to sanitized 500 responses instead of throwing during error normalization.
  3. Cleared reconnect descriptions: reconnect sends description: null when the field is cleared; create continues to use undefined when the description is omitted.
  4. Blank maxKeys: null, empty, and whitespace-only values normalize to the documented default of 100 before coercion.
  5. Retry assertions: operation tests now verify three attempts for representative reads and one attempt for uploads and deletes.
  6. Custom-label rotation coverage: the test now asserts a successful result, encrypted-secret persistence, and that no display-name update occurs.
  7. Connection validation coverage: the provider test now asserts validation sends a ListBucketsCommand.
  8. Logging severity: normalized upstream/5xx failures log at error; expected 4xx authentication, permission, validation, size, and not-found failures remain at warn. This keeps actionable server failures prominent without treating normal user-caused responses as application errors.

Validation after the changes:

  • All 14 changed Vitest files: 195 tests passed
  • App type-check passed
  • Formatting and lint checks passed
  • All 45 repository audits passed
  • git diff --check passed for this fix commit

Live OCI smoke testing remains unavailable because no disposable OCI tenant, bucket, or Customer Secret Key is available; the PR does not claim live verification.

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic please re-review the latest commit.

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

@cubic please re-review the latest commit.

@BillLeoutsakosvl346 Incremental reviews are turned off for this repository. Comment @cubic review to run a full review.

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic review

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

@cubic review

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

Final head is now dc11784a05, including the latest origin/staging reconciliation. The only conflict was generated tool metadata; it was resolved by running the repository generator. The 195 tests, type-check, format, lint, all 45 audits, and diff checks were rerun successfully on the reconciled tree.

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic review

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

@cubic review

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 64 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

This branch was successfully deployed

1 active deployment
Preview — b536a23f Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants