From 2e4f1ffe45771cb724a0ad47db7438d351040773 Mon Sep 17 00:00:00 2001 From: manuasir Date: Tue, 21 May 2019 19:13:15 +0200 Subject: [PATCH 1/6] Updating to 3.9.1-6.8.0 --- docker-compose.yml | 10 +++++----- elasticsearch/Dockerfile | 4 ++-- kibana/Dockerfile | 8 ++++---- logstash/Dockerfile | 2 +- wazuh/Dockerfile | 8 ++++---- 5 files changed, 16 insertions(+), 16 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index f45d2b1e..fa7df408 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -3,7 +3,7 @@ version: '2' services: wazuh: - image: wazuh/wazuh:3.9.0_6.7.2 + build: wazuh hostname: wazuh-manager restart: always ports: @@ -14,7 +14,7 @@ services: depends_on: - logstash logstash: - image: wazuh/wazuh-logstash:3.9.0_6.7.2 + build: logstash hostname: logstash restart: always links: @@ -26,7 +26,7 @@ services: environment: - LS_HEAP_SIZE=2048m elasticsearch: - image: wazuh/wazuh-elasticsearch:3.9.0_6.7.2 + build: elasticsearch hostname: elasticsearch restart: always ports: @@ -43,7 +43,7 @@ services: hard: -1 mem_limit: 2g kibana: - image: wazuh/wazuh-kibana:3.9.0_6.7.2 + build: kibana hostname: kibana restart: always depends_on: @@ -52,7 +52,7 @@ services: - elasticsearch:elasticsearch - wazuh:wazuh nginx: - image: wazuh/wazuh-nginx:3.9.0_6.7.2 + build: nginx hostname: nginx restart: always environment: diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index 25e6e30b..4c5d62ac 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -1,5 +1,5 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/elasticsearch/elasticsearch:6.7.2 +FROM docker.elastic.co/elasticsearch/elasticsearch:6.8.0 ENV ELASTICSEARCH_URL="http://elasticsearch:9200" @@ -39,7 +39,7 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./ RUN chmod +x ./load_settings.sh -RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.7.2.zip +RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.8.0.zip COPY config/configure_s3.sh ./config/configure_s3.sh RUN chmod 755 ./config/configure_s3.sh diff --git a/kibana/Dockerfile b/kibana/Dockerfile index e6eda42f..ab00f3a8 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -1,11 +1,11 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/kibana/kibana:6.7.2 -ARG WAZUH_APP_VERSION=3.9.0_6.7.2 +FROM docker.elastic.co/kibana/kibana:6.8.0 +ARG WAZUH_APP_VERSION=3.9.1_6.8.0 USER root -ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp +ADD https://packages-dev.wazuh.com/pre-release/app/kibana/wazuhapp-3.9.1_6.8.0.zip /tmp -RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip &&\ +RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-3.9.1_6.8.0.zip &&\ chown -R kibana:kibana /usr/share/kibana &&\ rm -rf /tmp/* diff --git a/logstash/Dockerfile b/logstash/Dockerfile index 1aa79f50..404b7b9d 100644 --- a/logstash/Dockerfile +++ b/logstash/Dockerfile @@ -1,5 +1,5 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/logstash/logstash:6.7.2 +FROM docker.elastic.co/logstash/logstash:6.8.0 COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index 454f8ea9..e5016dd1 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM phusion/baseimage:latest -ARG FILEBEAT_VERSION=6.7.2 -ARG WAZUH_VERSION=3.9.0-1 +ARG FILEBEAT_VERSION=6.8.0 +ARG WAZUH_VERSION=3.9.1-1 ENV API_USER="foo" \ API_PASS="bar" @@ -16,8 +16,8 @@ RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee / RUN add-apt-repository universe && apt-get update && apt-get upgrade -y -o Dpkg::Options::="--force-confold" && \ apt-get --no-install-recommends --no-install-suggests -y install openssl postfix bsd-mailx python-boto python-pip \ - apt-transport-https vim expect nodejs python-cryptography mailutils libsasl2-modules wazuh-manager=${WAZUH_VERSION} \ - wazuh-api=${WAZUH_VERSION} && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* && rm -f \ + apt-transport-https vim expect nodejs python-cryptography mailutils libsasl2-modules wazuh-manager \ + wazuh-api && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* && rm -f \ /var/ossec/logs/alerts/*/*/*.log && rm -f /var/ossec/logs/alerts/*/*/*.json && rm -f \ /var/ossec/logs/archives/*/*/*.log && rm -f /var/ossec/logs/archives/*/*/*.json && rm -f \ /var/ossec/logs/firewall/*/*/*.log && rm -f /var/ossec/logs/firewall/*/*/*.json From 8077b9b084802a06000b2906449a10fd16aa26a4 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Tue, 21 May 2019 23:45:55 +0200 Subject: [PATCH 2/6] Bump version --- CHANGELOG.md | 10 ++++++++++ README.md | 2 +- docker-compose.yml | 10 +++++----- elasticsearch/Dockerfile | 8 ++++---- elasticsearch/config/entrypoint.sh | 2 +- kibana/Dockerfile | 4 ++-- logstash/Dockerfile | 2 +- wazuh/Dockerfile | 4 ++-- 8 files changed, 26 insertions(+), 16 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b1351026..003c533b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,16 @@ # Change Log All notable changes to this project will be documented in this file. +## Wazuh Docker v3.9.1_6.8.0 + +### Added + +- Update to Wazuh version 3.9.1_6.8.0 ([#181](https://github.com/wazuh/wazuh-docker/pull/181)) + +### Fixed + +- Fixed `ELASTICSEARCH_KIBANA_IP` environment variable ([@manuasir](https://github.com/manuasir)) ([#181](https://github.com/wazuh/wazuh-docker/pull/181)) + ## Wazuh Docker v3.9.0_6.7.2 ### Changed diff --git a/README.md b/README.md index 1fec5721..030754ef 100644 --- a/README.md +++ b/README.md @@ -63,7 +63,7 @@ In addition, a docker-compose file is provided to launch the containers mentione * `stable` branch on correspond to the latest Wazuh-Docker stable version. * `master` branch contains the latest code, be aware of possible bugs on this branch. -* `Wazuh.Version_ElasticStack.Version` (for example 3.9.0_6.7.2) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch. +* `Wazuh.Version_ElasticStack.Version` (for example 3.9.1_6.8.2) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch. ## Credits and Thank you diff --git a/docker-compose.yml b/docker-compose.yml index f45d2b1e..8c43d7a7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -3,7 +3,7 @@ version: '2' services: wazuh: - image: wazuh/wazuh:3.9.0_6.7.2 + image: wazuh/wazuh:3.9.1_6.8.0 hostname: wazuh-manager restart: always ports: @@ -14,7 +14,7 @@ services: depends_on: - logstash logstash: - image: wazuh/wazuh-logstash:3.9.0_6.7.2 + image: wazuh/wazuh-logstash:3.9.1_6.8.0 hostname: logstash restart: always links: @@ -26,7 +26,7 @@ services: environment: - LS_HEAP_SIZE=2048m elasticsearch: - image: wazuh/wazuh-elasticsearch:3.9.0_6.7.2 + image: wazuh/wazuh-elasticsearch:3.9.1_6.8.0 hostname: elasticsearch restart: always ports: @@ -43,7 +43,7 @@ services: hard: -1 mem_limit: 2g kibana: - image: wazuh/wazuh-kibana:3.9.0_6.7.2 + image: wazuh/wazuh-kibana:3.9.1_6.8.0 hostname: kibana restart: always depends_on: @@ -52,7 +52,7 @@ services: - elasticsearch:elasticsearch - wazuh:wazuh nginx: - image: wazuh/wazuh-nginx:3.9.0_6.7.2 + image: wazuh/wazuh-nginx:3.9.1_6.8.0 hostname: nginx restart: always environment: diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index 25e6e30b..10ecaea3 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -1,5 +1,5 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/elasticsearch/elasticsearch:6.7.2 +FROM docker.elastic.co/elasticsearch/elasticsearch:6.8.0 ENV ELASTICSEARCH_URL="http://elasticsearch:9200" @@ -13,7 +13,7 @@ ENV XPACK_ML="true" ENV ENABLE_CONFIGURE_S3="false" -ENV TEMPLATE_VERSION=v3.9.0 +ENV TEMPLATE_VERSION=v3.9.1 # Elasticearch cluster configuration environment variables # If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration @@ -29,7 +29,7 @@ ENV ELASTIC_CLUSTER="false" \ CLUSTER_MAX_NODES="1" \ CLUSTER_DELAYED_TIMEOUT="1m" -ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/wazuh-elastic6-template-alerts.json /usr/share/elasticsearch/config +ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/6.x/wazuh-template.json /usr/share/elasticsearch/config COPY config/entrypoint.sh /entrypoint.sh @@ -39,7 +39,7 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./ RUN chmod +x ./load_settings.sh -RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.7.2.zip +RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.8.0.zip COPY config/configure_s3.sh ./config/configure_s3.sh RUN chmod 755 ./config/configure_s3.sh diff --git a/elasticsearch/config/entrypoint.sh b/elasticsearch/config/entrypoint.sh index c57703f1..9c799812 100644 --- a/elasticsearch/config/entrypoint.sh +++ b/elasticsearch/config/entrypoint.sh @@ -1,7 +1,7 @@ #!/bin/bash # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# For more information https://github.com/elastic/elasticsearch-docker/blob/6.5.4/build/elasticsearch/bin/docker-entrypoint.sh +# For more information https://github.com/elastic/elasticsearch-docker/blob/6.8.0/build/elasticsearch/bin/docker-entrypoint.sh set -e diff --git a/kibana/Dockerfile b/kibana/Dockerfile index e6eda42f..cd0c14ab 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -1,6 +1,6 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/kibana/kibana:6.7.2 -ARG WAZUH_APP_VERSION=3.9.0_6.7.2 +FROM docker.elastic.co/kibana/kibana:6.8.0 +ARG WAZUH_APP_VERSION=3.9.1_6.8.0 USER root ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp diff --git a/logstash/Dockerfile b/logstash/Dockerfile index 1aa79f50..404b7b9d 100644 --- a/logstash/Dockerfile +++ b/logstash/Dockerfile @@ -1,5 +1,5 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/logstash/logstash:6.7.2 +FROM docker.elastic.co/logstash/logstash:6.8.0 COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index 454f8ea9..44610dd6 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM phusion/baseimage:latest -ARG FILEBEAT_VERSION=6.7.2 -ARG WAZUH_VERSION=3.9.0-1 +ARG FILEBEAT_VERSION=6.8.0 +ARG WAZUH_VERSION=3.9.1-1 ENV API_USER="foo" \ API_PASS="bar" From d96e94f4fa29878ebfdd13a15176a046fac9bc60 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Tue, 21 May 2019 23:18:35 +0200 Subject: [PATCH 3/6] Changed entrypoint copy location --- kibana/Dockerfile | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/kibana/Dockerfile b/kibana/Dockerfile index cd0c14ab..7cfe18b2 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -9,8 +9,8 @@ RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin chown -R kibana:kibana /usr/share/kibana &&\ rm -rf /tmp/* -COPY config/entrypoint.sh /entrypoint.sh -RUN chmod 755 /entrypoint.sh +COPY config/entrypoint.sh ./entrypoint.sh +RUN chmod 755 ./entrypoint.sh USER kibana @@ -73,4 +73,4 @@ RUN ./welcome_wazuh.sh RUN /usr/local/bin/kibana-docker --optimize -ENTRYPOINT /entrypoint.sh +ENTRYPOINT ./entrypoint.sh From 948aaf289c138b6b89cc94a050b7d60b22ceddf3 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Tue, 21 May 2019 23:18:51 +0200 Subject: [PATCH 4/6] Fixed sed command in kibana_settings --- kibana/config/kibana_settings.sh | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/kibana/config/kibana_settings.sh b/kibana/config/kibana_settings.sh index 3255338b..96e5f35b 100644 --- a/kibana/config/kibana_settings.sh +++ b/kibana/config/kibana_settings.sh @@ -19,7 +19,8 @@ WAZUH_MAJOR=3 # Customize elasticsearch ip ############################################################################## if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then - sed -i "s/elasticsearch:9200/$ELASTICSEARCH_KIBANA_IP/" /usr/share/kibana/config/kibana.yml + sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_KIBANA_IP'|g' /usr/share/kibana/config/kibana.yml + fi if [ "$KIBANA_IP" != "" ]; then From 09164c4285a6dfdbc54cbd8bf43abab776579f75 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Tue, 21 May 2019 23:47:05 +0200 Subject: [PATCH 5/6] Bump version --- VERSION | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/VERSION b/VERSION index 649829d1..3e8fc28f 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="3.9.0_6.7.2" -REVISION="3900" \ No newline at end of file +WAZUH-DOCKER_VERSION="3.9.1_6.8.0" +REVISION="3901" \ No newline at end of file From 7944897a0d233f16c047b514e5026a7df4c6203b Mon Sep 17 00:00:00 2001 From: manuasir Date: Wed, 22 May 2019 12:21:55 +0200 Subject: [PATCH 6/6] Fixed template URL --- elasticsearch/config/load_settings.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/elasticsearch/config/load_settings.sh b/elasticsearch/config/load_settings.sh index 2a69b36f..23fabd6c 100644 --- a/elasticsearch/config/load_settings.sh +++ b/elasticsearch/config/load_settings.sh @@ -45,9 +45,9 @@ fi #Insert default templates -sed -i 's| "index.refresh_interval": "5s"| "index.refresh_interval": "5s", "number_of_shards" : '"${ALERTS_SHARDS}"', "number_of_replicas" : '"${ALERTS_REPLICAS}"'|' /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json +sed -i 's| "index.refresh_interval": "5s"| "index.refresh_interval": "5s", "number_of_shards" : '"${ALERTS_SHARDS}"', "number_of_replicas" : '"${ALERTS_REPLICAS}"'|' /usr/share/elasticsearch/config/wazuh-template.json -cat /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json | curl -XPUT "$el_url/_template/wazuh" ${auth} -H 'Content-Type: application/json' -d @- +cat /usr/share/elasticsearch/config/wazuh-template.json | curl -XPUT "$el_url/_template/wazuh" ${auth} -H 'Content-Type: application/json' -d @- sleep 5