From e00cd1081a82e5cd190415925be217745e4b29cb Mon Sep 17 00:00:00 2001 From: Jose M Date: Fri, 5 Jul 2019 12:18:37 +0200 Subject: [PATCH 1/8] Fix Bash syntax error with multiple conditions on ES and Kibana --- kibana/config/entrypoint.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kibana/config/entrypoint.sh b/kibana/config/entrypoint.sh index 80cf73cd..87bbef39 100644 --- a/kibana/config/entrypoint.sh +++ b/kibana/config/entrypoint.sh @@ -13,7 +13,7 @@ else el_url="${ELASTICSEARCH_URL}" fi -if [ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]; then +if [[ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]]; then auth="" else auth="--user ${ELASTICSEARCH_USERNAME}:${ELASTICSEARCH_PASSWORD}" From 5db7509b52ca35dac1a075ed9daaf32c30756e04 Mon Sep 17 00:00:00 2001 From: manuasir Date: Fri, 19 Jul 2019 18:06:27 +0200 Subject: [PATCH 2/8] Fixed cluster configuration --- elasticsearch/config/config_cluster.sh | 55 ++++++++++++-------------- 1 file changed, 26 insertions(+), 29 deletions(-) diff --git a/elasticsearch/config/config_cluster.sh b/elasticsearch/config/config_cluster.sh index 2222099e..406cdf30 100644 --- a/elasticsearch/config/config_cluster.sh +++ b/elasticsearch/config/config_cluster.sh @@ -3,39 +3,36 @@ elastic_config_file="/usr/share/elasticsearch/config/elasticsearch.yml" +remove_single_node_conf(){ + if grep -Fq "discovery.type" $1; then + sed -i '/discovery.type\: /d' $1 + fi +} -# If Elasticsearch cluster is enable -if [[ $ELASTIC_CLUSTER == "true" ]] -then - - # Set the cluster.name and discovery.zen.minimun_master_nodes variables - sed -i 's:cluster.name\: "docker-cluster":cluster.name\: "'$CLUSTER_NAME'":g' $elastic_config_file - #sed -i 's:discovery.zen.minimum_master_nodes\: 1:discovery.zen.minimum_master_nodes\: '$CLUSTER_NUMBER_OF_MASTERS':g' $elastic_config_file +# If Elasticsearch cluster is enable, then set up the elasticsearch.yml +if [[ $ELASTIC_CLUSTER == "true" && $CLUSTER_NODE_MASTER != "" && $CLUSTER_NODE_DATA != "" && $CLUSTER_NODE_INGEST != "" ]];then - # Add the cluster configuration - echo " -#cluster node -node: - master: ${CLUSTER_NODE_MASTER} - data: ${CLUSTER_NODE_DATA} - ingest: ${CLUSTER_NODE_INGEST} - name: ${CLUSTER_NODE_NAME} - max_local_storage_nodes: ${CLUSTER_MAX_NODES} + remove_single_node_conf $elastic_config_file -bootstrap: - memory_lock: ${CLUSTER_MEMORY_LOCK} + # Remove the old configuration + sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file -cluster.initial_master_nodes: - - '${CLUSTER_INITIAL_MASTER_NODES}' + # Add the current cluster configuration +cat > $elastic_config_file << EOF +# cluster node +network.host: 0.0.0.0 +node.name: $CLUSTER_NODE_NAME +node.master: $CLUSTER_NODE_MASTER -" >> $elastic_config_file -else - -cat >> $elastic_config_file <<'EOF' -cluster.initial_master_nodes: - - 'elasticsearch' +cluster.initial_master_nodes: + - $CLUSTER_INITIAL_MASTER_NODES +# end cluster config" EOF -# echo 'discovery.type: single-node' - -fi +# If the cluster is disabled, then set a single-node configuration +else + sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file + # If it's not already configured + remove_single_node_conf $elastic_config_file + echo "discovery.type: single-node" >> $elastic_config_file +fi \ No newline at end of file From 9740ddcf3ee5b4f0451ba3848af8c4ff9c99a381 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Fri, 19 Jul 2019 23:03:11 +0200 Subject: [PATCH 3/8] Added more fixes to configuration files --- docker-compose.yml | 21 +++++++++++++----- elasticsearch/Dockerfile | 5 ++--- elasticsearch/config/config_cluster.sh | 30 ++++++++++++++++++++------ 3 files changed, 41 insertions(+), 15 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 31ca6356..6face8e8 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -12,22 +12,33 @@ services: - "514:514/udp" - "55000:55000" elasticsearch: - image: wazuh/wazuh-elasticsearch:3.9.2_7.1.1 + build: elasticsearch hostname: elasticsearch restart: always ports: - "9200:9200" environment: - - node.name=node-1 - - cluster.name=wazuh - - network.host=0.0.0.0 - - bootstrap.memory_lock=true - "ES_JAVA_OPTS=-Xms1g -Xmx1g" + - ELASTIC_CLUSTER=true + - CLUSTER_NODE_MASTER=true + - CLUSTER_MASTER_NODE_NAME=es01 + + es02: + build: elasticsearch + hostname: es02 + restart: always + environment: + - "ES_JAVA_OPTS=-Xms1g -Xmx1g" + - ELASTIC_CLUSTER=true + - CLUSTER_MASTER_NODE_NAME=elasticsearch + - CLUSTER_NODE_NAME=es02 ulimits: memlock: soft: -1 hard: -1 mem_limit: 2g + + kibana: image: wazuh/wazuh-kibana:3.9.2_7.1.1 hostname: kibana diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index 05ad928a..a2764d01 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -22,10 +22,11 @@ ARG TEMPLATE_VERSION=v3.9.2 # CLUSTER_INITIAL_MASTER_NODES set to own node by default. ENV ELASTIC_CLUSTER="false" \ CLUSTER_NAME="wazuh" \ - CLUSTER_NODE_MASTER="true" \ + CLUSTER_NODE_MASTER="false" \ CLUSTER_NODE_DATA="true" \ CLUSTER_NODE_INGEST="true" \ CLUSTER_NODE_NAME="wazuh-elasticsearch" \ + CLUSTER_MASTER_NODE_NAME="master-node" \ CLUSTER_MEMORY_LOCK="true" \ CLUSTER_DISCOVERY_SERVICE="wazuh-elasticsearch" \ CLUSTER_NUMBER_OF_MASTERS="2" \ @@ -33,8 +34,6 @@ ENV ELASTIC_CLUSTER="false" \ CLUSTER_DELAYED_TIMEOUT="1m" \ CLUSTER_INITIAL_MASTER_NODES="wazuh-elasticsearch" -ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /usr/share/elasticsearch/config - COPY config/entrypoint.sh /entrypoint.sh RUN chmod 755 /entrypoint.sh diff --git a/elasticsearch/config/config_cluster.sh b/elasticsearch/config/config_cluster.sh index 406cdf30..2a851286 100644 --- a/elasticsearch/config/config_cluster.sh +++ b/elasticsearch/config/config_cluster.sh @@ -10,25 +10,41 @@ remove_single_node_conf(){ } # If Elasticsearch cluster is enable, then set up the elasticsearch.yml -if [[ $ELASTIC_CLUSTER == "true" && $CLUSTER_NODE_MASTER != "" && $CLUSTER_NODE_DATA != "" && $CLUSTER_NODE_INGEST != "" ]];then +if [[ $ELASTIC_CLUSTER == "true" && $CLUSTER_NODE_MASTER != "" && $CLUSTER_NODE_DATA != "" && $CLUSTER_NODE_INGEST != "" && $CLUSTER_MASTER_NODE_NAME != "" ]]; then remove_single_node_conf $elastic_config_file # Remove the old configuration sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file - # Add the current cluster configuration +if [[ $CLUSTER_NODE_MASTER == "true" ]]; then +# Add the master configuration +# cluster.initial_master_nodes for bootstrap the cluster +cat > $elastic_config_file << EOF +# cluster node +network.host: 0.0.0.0 +node.name: $CLUSTER_MASTER_NODE_NAME +node.master: $CLUSTER_NODE_MASTER +cluster.initial_master_nodes: + - $CLUSTER_MASTER_NODE_NAME +# end cluster config" +EOF + +elif [[ $CLUSTER_NODE_NAME != "" ]];then + +sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file + cat > $elastic_config_file << EOF # cluster node network.host: 0.0.0.0 node.name: $CLUSTER_NODE_NAME -node.master: $CLUSTER_NODE_MASTER - -cluster.initial_master_nodes: - - $CLUSTER_INITIAL_MASTER_NODES +node.master: false +discovery.seed_hosts: + - $CLUSTER_MASTER_NODE_NAME + - $CLUSTER_NODE_NAME # end cluster config" EOF - +fi # If the cluster is disabled, then set a single-node configuration else sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file From 60b32d0d21f8a87e7c53d586233b73d29df0d054 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Sat, 20 Jul 2019 18:23:33 +0200 Subject: [PATCH 4/8] Improve cluster configuration --- elasticsearch/config/config_cluster.sh | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/elasticsearch/config/config_cluster.sh b/elasticsearch/config/config_cluster.sh index 2a851286..d1d0e532 100644 --- a/elasticsearch/config/config_cluster.sh +++ b/elasticsearch/config/config_cluster.sh @@ -9,13 +9,15 @@ remove_single_node_conf(){ fi } +remove_cluster_config(){ + sed -i '/# cluster node/,/# end cluster config/d' $1 +} + # If Elasticsearch cluster is enable, then set up the elasticsearch.yml if [[ $ELASTIC_CLUSTER == "true" && $CLUSTER_NODE_MASTER != "" && $CLUSTER_NODE_DATA != "" && $CLUSTER_NODE_INGEST != "" && $CLUSTER_MASTER_NODE_NAME != "" ]]; then - - remove_single_node_conf $elastic_config_file - # Remove the old configuration - sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file + remove_single_node_conf $elastic_config_file + remove_cluster_config $elastic_config_file if [[ $CLUSTER_NODE_MASTER == "true" ]]; then # Add the master configuration @@ -31,8 +33,9 @@ cluster.initial_master_nodes: EOF elif [[ $CLUSTER_NODE_NAME != "" ]];then - -sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file +# Remove the old configuration +remove_single_node_conf $elastic_config_file +remove_cluster_config $elastic_config_file cat > $elastic_config_file << EOF # cluster node @@ -47,8 +50,8 @@ EOF fi # If the cluster is disabled, then set a single-node configuration else - sed -i '/# cluster node/,/# end cluster config/d' $elastic_config_file - # If it's not already configured + # Remove the old configuration remove_single_node_conf $elastic_config_file + remove_cluster_config $elastic_config_file echo "discovery.type: single-node" >> $elastic_config_file fi \ No newline at end of file From 881a0abfa57973edeaa2de333ac87cec0a0996a2 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Sat, 20 Jul 2019 18:32:33 +0200 Subject: [PATCH 5/8] Bump version --- CHANGELOG.md | 5 +++++ README.md | 2 +- VERSION | 4 ++-- docker-compose.yml | 20 +++++--------------- elasticsearch/Dockerfile | 4 ++-- kibana/Dockerfile | 6 +++--- wazuh/Dockerfile | 6 +++--- 7 files changed, 21 insertions(+), 26 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index fd19f395..ee5aca1b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,11 @@ # Change Log All notable changes to this project will be documented in this file. +## Wazuh Docker v3.9.3_7.2.0 + +### Fixed +- Wazuh-docker reinserts cluster settings after resuming containers ([@manuasir](https://github.com/manuasir)) [#213](https://github.com/wazuh/wazuh-docker/pull/213) + ## Wazuh Docker v3.9.2_7.1.1 ### Added diff --git a/README.md b/README.md index 173b7eb5..7eae4b5a 100644 --- a/README.md +++ b/README.md @@ -57,7 +57,7 @@ In addition, a docker-compose file is provided to launch the containers mentione * `stable` branch on correspond to the latest Wazuh-Docker stable version. * `master` branch contains the latest code, be aware of possible bugs on this branch. -* `Wazuh.Version_ElasticStack.Version` (for example 3.9.1_6.8.2) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch. +* `Wazuh.Version_ElasticStack.Version` (for example 3.9.3_7.2.0) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch. ## Credits and Thank you diff --git a/VERSION b/VERSION index 84433ac9..585e30a6 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="3.9.2_7.1.1" -REVISION="3920" \ No newline at end of file +WAZUH-DOCKER_VERSION="3.9.3_7.2.0" +REVISION="3930" \ No newline at end of file diff --git a/docker-compose.yml b/docker-compose.yml index 6face8e8..fb28f66e 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -3,7 +3,7 @@ version: '2' services: wazuh: - image: wazuh/wazuh:3.9.2_7.1.1 + image: wazuh/wazuh:3.9.3_7.2.0 hostname: wazuh-manager restart: always ports: @@ -11,8 +11,9 @@ services: - "1515:1515" - "514:514/udp" - "55000:55000" + elasticsearch: - build: elasticsearch + image: wazuh/wazuh-kibana:3.9.3_7.2.0 hostname: elasticsearch restart: always ports: @@ -22,25 +23,14 @@ services: - ELASTIC_CLUSTER=true - CLUSTER_NODE_MASTER=true - CLUSTER_MASTER_NODE_NAME=es01 - - es02: - build: elasticsearch - hostname: es02 - restart: always - environment: - - "ES_JAVA_OPTS=-Xms1g -Xmx1g" - - ELASTIC_CLUSTER=true - - CLUSTER_MASTER_NODE_NAME=elasticsearch - - CLUSTER_NODE_NAME=es02 ulimits: memlock: soft: -1 hard: -1 mem_limit: 2g - kibana: - image: wazuh/wazuh-kibana:3.9.2_7.1.1 + image: wazuh/wazuh-kibana:3.9.3_7.2.0 hostname: kibana restart: always depends_on: @@ -49,7 +39,7 @@ services: - elasticsearch:elasticsearch - wazuh:wazuh nginx: - image: wazuh/wazuh-nginx:3.9.2_7.1.1 + image: wazuh/wazuh-nginx:3.9.3_7.2.0 hostname: nginx restart: always environment: diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index a2764d01..83023c08 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -1,5 +1,5 @@ # Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -ARG ELASTIC_VERSION=7.1.1 +ARG ELASTIC_VERSION=7.2.0 FROM docker.elastic.co/elasticsearch/elasticsearch:${ELASTIC_VERSION} ARG S3_PLUGIN_URL="https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-${ELASTIC_VERSION}.zip" @@ -15,7 +15,7 @@ ENV XPACK_ML="true" ENV ENABLE_CONFIGURE_S3="false" -ARG TEMPLATE_VERSION=v3.9.2 +ARG TEMPLATE_VERSION=v3.9.3 # Elasticearch cluster configuration environment variables # If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration diff --git a/kibana/Dockerfile b/kibana/Dockerfile index e521eb43..dafeb622 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -1,7 +1,7 @@ # Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/kibana/kibana:7.1.1 -ARG ELASTIC_VERSION=7.1.1 -ARG WAZUH_VERSION=3.9.2 +FROM docker.elastic.co/kibana/kibana:7.2.0 +ARG ELASTIC_VERSION=7.2.0 +ARG WAZUH_VERSION=3.9.3 ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}" USER root diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index e4a2814c..da842789 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -1,14 +1,14 @@ # Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM phusion/baseimage:latest -ARG FILEBEAT_VERSION=7.1.1 +ARG FILEBEAT_VERSION=7.2.0 -ARG WAZUH_VERSION=3.9.2-1 +ARG WAZUH_VERSION=3.9.3-1 ENV API_USER="foo" \ API_PASS="bar" -ARG TEMPLATE_VERSION="v3.9.2" +ARG TEMPLATE_VERSION="v3.9.3" # Set repositories. RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \ From 61b1f45bc48e27d6839d4b9f09da65f88750208a Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Sat, 20 Jul 2019 18:33:04 +0200 Subject: [PATCH 6/8] Updated docker-compose --- docker-compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docker-compose.yml b/docker-compose.yml index fb28f66e..b69f350b 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -13,7 +13,7 @@ services: - "55000:55000" elasticsearch: - image: wazuh/wazuh-kibana:3.9.3_7.2.0 + image: wazuh/wazuh-elasticsearch:3.9.3_7.2.0 hostname: elasticsearch restart: always ports: From 40bb6350361325184c756056d4aacc6cd85ec0d9 Mon Sep 17 00:00:00 2001 From: manuasir Date: Mon, 22 Jul 2019 16:19:41 +0200 Subject: [PATCH 7/8] Allowing install Wazuh plugin as root --- kibana/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kibana/Dockerfile b/kibana/Dockerfile index dafeb622..d8830750 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -8,7 +8,7 @@ USER root ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp -RUN /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip +RUN /usr/share/kibana/bin/kibana-plugin install --allow-root file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip RUN rm -rf /tmp/wazuhapp-${WAZUH_APP_VERSION}.zip COPY config/entrypoint.sh ./entrypoint.sh From 507d27a44837854f3608b85195e5d856a0e81de7 Mon Sep 17 00:00:00 2001 From: manuasir Date: Mon, 22 Jul 2019 16:30:26 +0200 Subject: [PATCH 8/8] Updated Kibana RESTful API version to v2 --- kibana/config/kibana_settings.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kibana/config/kibana_settings.sh b/kibana/config/kibana_settings.sh index 1982e352..cb4151fa 100644 --- a/kibana/config/kibana_settings.sh +++ b/kibana/config/kibana_settings.sh @@ -74,6 +74,6 @@ curl -POST "http://$kibana_ip:5601/api/kibana/settings" -H "Content-Type: applic sleep 5 # Do not ask user to help providing usage statistics to Elastic -curl -POST "http://$kibana_ip:5601/api/telemetry/v1/optIn" -H "Content-Type: application/json" -H "kbn-xsrf: true" -d '{"enabled":false}' +curl -POST "http://$kibana_ip:5601/api/telemetry/v2/optIn" -H "Content-Type: application/json" -H "kbn-xsrf: true" -d '{"enabled":false}' echo "End settings"