diff --git a/.github/workflows/4_build_and_push_images.yml b/.github/workflows/4_build_and_push_images.yml new file mode 100644 index 00000000..afef0da3 --- /dev/null +++ b/.github/workflows/4_build_and_push_images.yml @@ -0,0 +1,309 @@ +run-name: Build and push images 4.x - ${{ inputs.dev && 'dev' || 'release' }} - ${{ inputs.id }} +name: Build and push images 4.x + +on: + workflow_dispatch: + inputs: + image_tag: + description: 'Docker image tag' + default: '4.14.7' + required: true + docker_reference: + description: 'wazuh-docker reference' + required: true + filebeat_module_version: + description: 'Filebeat module version' + default: '0.5' + required: true + type: string + products: + description: 'Comma-separated list of the image names to build and push' + default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' + required: false + type: string + revision: + description: 'Package revision' + default: '1' + required: true + id: + description: "ID used to identify the workflow uniquely." + type: string + required: false + dev: + description: "Add tag suffix '-dev' to the image tag ?" + type: boolean + default: true + required: false + workflow_call: + inputs: + image_tag: + description: 'Docker image tag' + default: '4.14.7' + required: true + type: string + docker_reference: + description: 'wazuh-docker reference' + required: false + type: string + filebeat_module_version: + description: 'Filebeat module version' + default: '0.5' + required: true + type: string + products: + description: 'Comma-separated list of the image names to build and push' + default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' + required: false + type: string + revision: + description: 'Package revision' + default: '1' + required: true + type: string + id: + description: "ID used to identify the workflow uniquely." + type: string + required: false + dev: + description: "Add tag suffix '-dev' to the image tag ?" + type: boolean + default: false + required: false + +jobs: + setup: + runs-on: ubuntu-22.04 + + permissions: + id-token: write + contents: read + + env: + IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }} + IMAGE_TAG: ${{ inputs.image_tag }} + FILEBEAT_MODULE_VERSION: ${{ inputs.filebeat_module_version }} + REVISION: ${{ inputs.revision }} + + outputs: + WAZUH_COMPONENTS: ${{ steps.compute-outputs.outputs.WAZUH_COMPONENTS }} + ALL_PRODUCTS_SELECTED: ${{ steps.compute-outputs.outputs.ALL_PRODUCTS_SELECTED }} + + steps: + - name: Print inputs + run: | + echo "---------------------------------------------" + echo "Running 4_build_and_push_images workflow" + echo "---------------------------------------------" + echo "* BRANCH: ${{ github.ref }}" + echo "* COMMIT: ${{ github.sha }}" + echo "---------------------------------------------" + echo "Inputs provided:" + echo "---------------------------------------------" + echo "* id: ${{ inputs.id }}" + echo "* image_tag: ${{ inputs.image_tag }}" + echo "* docker_reference: ${{ inputs.docker_reference }}" + echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}" + echo "* products: ${{ inputs.products }}" + echo "* revision: ${{ inputs.revision }}" + echo "* dev: ${{ inputs.dev }}" + echo "---------------------------------------------" + + - name: Set up variables + id: compute-outputs + run: | + # Use the default list if products is empty + PRODUCTS="${{ inputs.products }}" + if [[ -z "$PRODUCTS" || "$PRODUCTS" == "null" ]]; then + PRODUCTS="wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent" + fi + + # Check if all 4 core components are present in the string + if [[ "$PRODUCTS" == *"wazuh-manager"* && "$PRODUCTS" == *"wazuh-dashboard"* && "$PRODUCTS" == *"wazuh-indexer"* && "$PRODUCTS" == *"wazuh-agent"* ]]; then + echo "ALL_PRODUCTS_SELECTED=true" >> $GITHUB_OUTPUT + else + echo "ALL_PRODUCTS_SELECTED=false" >> $GITHUB_OUTPUT + fi + + # Convert to JSON for the matrix (Your existing logic) + IFS=',' read -ra COMPONENTS <<< "$PRODUCTS" + JSON_ARRAY=$(printf '%s\n' "${COMPONENTS[@]}" | jq -R . | jq -s -c .) + echo "WAZUH_COMPONENTS=$JSON_ARRAY" >> $GITHUB_OUTPUT + + build-and-push: + runs-on: ubuntu-22.04 + + permissions: + id-token: write + contents: read + + needs: + - setup + + strategy: + fail-fast: false # all jobs will run even if one fails + matrix: + wazuh_component: ${{ fromJson(needs.setup.outputs.WAZUH_COMPONENTS) }} + + env: + IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }} + IMAGE_TAG: ${{ inputs.image_tag }} + REVISION: ${{ inputs.revision }} + + steps: + - name: Checkout repository + uses: actions/checkout@v6 + with: + ref: ${{ inputs.docker_reference }} + + - name: free disk space + uses: ./.github/free-disk-space + + - name: Set up QEMU + uses: docker/setup-qemu-action@v4 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v4 + + - name: Configure aws credentials + if: ${{ inputs.dev == true }} + uses: aws-actions/configure-aws-credentials@v6 + with: + role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }} + aws-region: "${{ secrets.AWS_REGION }}" + + - name: Log in to Amazon ECR + if: ${{ inputs.dev == true }} + uses: aws-actions/amazon-ecr-login@v2 + + - name: Log in to Docker Hub + if: ${{ inputs.dev == false }} + uses: docker/login-action@v4 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_PASSWORD }} + + - name: Build Wazuh images + run: | + IMAGE_TAG="${{ inputs.image_tag }}" + FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }} + REVISION=${{ inputs.revision }} + + if [[ "$IMAGE_TAG" == *"-"* ]]; then + IFS='-' read -r -a tokens <<< "$IMAGE_TAG" + if [ -z "${tokens[1]}" ]; then + echo "Invalid image tag: $IMAGE_TAG" + exit 1 + fi + DEV_STAGE=${tokens[1]} + WAZUH_VER=${tokens[0]} + ./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m -c ${{ matrix.wazuh_component }} + else + ./build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m -c ${{ matrix.wazuh_component }} + fi + + # Save .env file (generated by build-images.sh) contents to $GITHUB_ENV + ENV_FILE_PATH="../.env" + + if [ -f $ENV_FILE_PATH ]; then + while IFS= read -r line || [ -n "$line" ]; do + echo "$line" >> $GITHUB_ENV + done < $ENV_FILE_PATH + else + echo "The environment file $ENV_FILE_PATH does not exist!" + exit 1 + fi + working-directory: ./build-docker-images + + + notify: + runs-on: ubuntu-22.04 + needs: [setup, build-and-push] + # Only run if NOT dev AND all products were selected + if: ${{ inputs.dev == false && needs.setup.outputs.ALL_PRODUCTS_SELECTED == 'true' }} + + steps: + - name: Image exists validation + id: validation + run: | + IMAGE_TAG=${{ inputs.image_tag }} + IMAGE_REGISTRY="${{ vars.IMAGE_REGISTRY_PROD }}" + PURPOSE="" + + if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then + if docker manifest inspect $IMAGE_REGISTRY/wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then + PURPOSE="regeneration" + echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'" + else + PURPOSE="new release" + echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'" + fi + echo "✅ Release tag: '$IMAGE_TAG'" + elif [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+-(alpha|beta|rc)[0-9]+$ ]]; then + PURPOSE="new stage" + echo "✅ Stage tag: '$IMAGE_TAG'. Setting PURPOSE to 'new stage'" + else + echo "❌ No release or stage tag ('$IMAGE_TAG'), the GH issue will not be created" + fi + + echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT + + - name: GH issue notification + if: ${{ steps.validation.outputs.purpose != '' }} + env: + GH_TOKEN: ${{ secrets.NOTIFICATION_GH_ARTIFACT_TOKEN }} + run: | + IMAGE_TAG=${{ inputs.image_tag }} + PURPOSE="${{ steps.validation.outputs.purpose }}" + + GH_TITLE="" + GH_MESSAGE="" + + ## Setting GH issue title + GH_TITLE="Artifactory vulnerabilities update \`v$IMAGE_TAG\`" + + ## Setting GH issue body + GH_MESSAGE=$(cat <<- EOF | tr -d '\r' | sed 's/^[[:space:]]*//' + ### Description + - [ ] Update the [Artifactory vulnerabilities](${{ secrets.NOTIFICATION_SHEET_URL }}) sheet with the \`v$IMAGE_TAG\` vulnerabilities. + + **Purpose**: $PURPOSE + >[!NOTE] + >To update the \`Tentative Release\` column, follow these steps: + https://github.com/wazuh/${{ secrets.NOTIFICATION_REPO }}/issues/2049#issuecomment-2671590268 + EOF + ) + + # Print the GH Variables content + echo "--- Variable Content ---" + echo "$GH_TITLE" + echo "------------------------" + + echo "--- Variable Content ---" + echo "$GH_MESSAGE" + echo "------------------------" + + ## GH issue creation + ISSUE_URL=$(gh issue create \ + -R wazuh/${{ secrets.NOTIFICATION_REPO }} \ + --title "$GH_TITLE" \ + --body "$GH_MESSAGE" \ + --label "level/task" \ + --label "type/maintenance" \ + --label "request/operational") + + ## Adding the issue to the team project + PROJECT_ITEM_ID=$(gh project item-add \ + ${{ secrets.NOTIFICATION_PROJECT_NUMBER }} \ + --url $ISSUE_URL \ + --owner wazuh \ + --format json \ + | jq -r '.id') + + ## Setting Objective + gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_OBJECTIVE_ID }} --text "Security scans" + ## Setting Priority + gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_OPTION_ID }} + ## Setting Size + gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_OPTION_ID }} + ## Setting Subteam + gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_OPTION_ID }} diff --git a/.github/workflows/4_pr_check.yml b/.github/workflows/4_pr_check.yml new file mode 100644 index 00000000..a7b7f344 --- /dev/null +++ b/.github/workflows/4_pr_check.yml @@ -0,0 +1,376 @@ +name: Wazuh Docker pipeline 4.x + +on: + pull_request: + paths: + - 'build-docker-images/**' + - 'multi-node/**' + - 'single-node/**' + - 'wazuh-agent/**' + - '.github/**' + +jobs: + build-docker-images: + runs-on: ubuntu-22.04 + steps: + + - name: Check out code + uses: actions/checkout@v6 + + - name: Build Wazuh images + run: ./build-images.sh + working-directory: ./build-docker-images + + - name: Create enviroment variables + run: cat .env > $GITHUB_ENV + + - name: Create backup Docker images + run: | + mkdir -p /home/runner/work/wazuh-docker/wazuh-docker/docker-images/ + docker save wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-manager.tar + docker save wazuh/wazuh-indexer:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-indexer.tar + docker save wazuh/wazuh-dashboard:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar + docker save wazuh/wazuh-agent:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-agent.tar + + - name: Temporarily save Wazuh manager Docker image + uses: actions/upload-artifact@v7 + with: + name: docker-artifact-manager + path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-manager.tar + retention-days: 1 + + - name: Temporarily save Wazuh indexer Docker image + uses: actions/upload-artifact@v7 + with: + name: docker-artifact-indexer + path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-indexer.tar + retention-days: 1 + + - name: Temporarily save Wazuh dashboard Docker image + uses: actions/upload-artifact@v7 + with: + name: docker-artifact-dashboard + path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar + retention-days: 1 + + - name: Temporarily save Wazuh agent Docker image + uses: actions/upload-artifact@v7 + with: + name: docker-artifact-agent + path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-agent.tar + retention-days: 1 + + - name: Install Goss + uses: e1himself/goss-installation-action@v1.0.3 + with: + version: v0.3.16 + + - name: Execute Goss tests (wazuh-manager) + run: dgoss run wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}} + env: + GOSS_SLEEP: 30 + GOSS_FILE: .github/.goss.yaml + + check-single-node: + runs-on: ubuntu-22.04 + needs: build-docker-images + steps: + + - name: Check out code + uses: actions/checkout@v6 + + - name: Create enviroment variables + run: cat .env > $GITHUB_ENV + + - name: Retrieve saved Wazuh indexer Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-indexer + + - name: Retrieve saved Wazuh manager Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-manager + + - name: Retrieve saved Wazuh dashboard Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-dashboard + + - name: Retrieve saved Wazuh agent Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-agent + + - name: Docker load + run: | + docker load --input ./wazuh-indexer.tar + docker load --input ./wazuh-dashboard.tar + docker load --input ./wazuh-manager.tar + docker load --input ./wazuh-agent.tar + + - name: Create single node certficates + run: docker compose -f single-node/generate-indexer-certs.yml run --rm generator + + - name: Start single node stack + run: docker compose -f single-node/docker-compose.yml up -d + + - name: Check Wazuh indexer start + run: | + sleep 60 + status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`" + if [[ $status_green -eq 1 ]]; then + curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s + else + curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s + exit 1 + fi + status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`" + status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep "green" | wc -l`" + if [[ $status_index_green -eq $status_index ]]; then + curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s + else + curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s + exit 1 + fi + + + - name: Check Wazuh indexer nodes + run: | + nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`" + if [[ $nodes -eq 1 ]]; then + echo "Wazuh indexer nodes: ${nodes}" + else + echo "Wazuh indexer nodes: ${nodes}" + exit 1 + fi + + - name: Check documents into wazuh-alerts index + run: | + sleep 120 + docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`" + if [[ $docs -gt 0 ]]; then + echo "wazuh-alerts index documents: ${docs}" + else + echo "wazuh-alerts index documents: ${docs}" + exit 1 + fi + + - name: Check Wazuh templates + run: | + qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics" | wc -l`" + templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics"`" + if [[ $qty_templates -gt 3 ]]; then + echo "wazuh templates:" + echo "${templates}" + else + echo "wazuh templates:" + echo "${templates}" + exit 1 + fi + + - name: Check Wazuh manager start + run: | + services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`" + if [[ $services -gt 9 ]]; then + echo "Wazuh Manager Services: ${services}" + echo "OK" + else + echo "Wazuh indexer nodes: ${nodes}" + curl -k -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items + exit 1 + fi + env: + TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") + + - name: Check filebeat output + run: ./.github/single-node-filebeat-check.sh + + - name: Check Wazuh dashboard service URL + run: | + status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I -s | grep -E "^HTTP" | awk '{print $2}') + if [[ $status -eq 200 ]]; then + echo "Wazuh dashboard status: ${status}" + else + echo "Wazuh dashboard status: ${status}" + exit 1 + fi + + - name: Modify Docker endpoint into Wazuh agent docker-compose.yml file + run: sed -i "s//$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml + + - name: Start Wazuh agent + run: docker compose -f wazuh-agent/docker-compose.yml up -d + + - name: Check Wazuh agent enrollment + run: | + sleep 20 + curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" + env: + TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") + + - name: Check errors in ossec.log for Wazuh manager + run: ./.github/single-node-log-check.sh + + check-multi-node: + runs-on: ubuntu-22.04 + needs: build-docker-images + steps: + + - name: Check out code + uses: actions/checkout@v6 + + - name: Create enviroment variables + run: cat .env > $GITHUB_ENV + + - name: free disk space + uses: ./.github/free-disk-space + + - name: Retrieve saved Wazuh dashboard Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-dashboard + + - name: Retrieve saved Wazuh manager Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-manager + + - name: Retrieve saved Wazuh indexer Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-indexer + + - name: Retrieve saved Wazuh agent Docker image + uses: actions/download-artifact@v8 + with: + name: docker-artifact-agent + + - name: Docker load + run: | + docker load --input ./wazuh-manager.tar + docker load --input ./wazuh-indexer.tar + docker load --input ./wazuh-dashboard.tar + docker load --input ./wazuh-agent.tar + rm -rf wazuh-manager.tar wazuh-indexer.tar wazuh-dashboard.tar wazuh-agent.tar + + - name: Create multi node certficates + run: docker compose -f multi-node/generate-indexer-certs.yml run --rm generator + + - name: Start multi node stack + run: docker compose -f multi-node/docker-compose.yml up -d + + - name: Check Wazuh indexer start + run: | + until [[ `curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l` -eq 1 ]] + do + echo 'Waiting for Wazuh indexer start' + free -m + df -h + sleep 120 + done + status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`" + if [[ $status_green -eq 1 ]]; then + curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s + else + curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s + exit 1 + fi + status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`" + status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep -E "green" | wc -l`" + if [[ $status_index_green -eq $status_index ]]; then + curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s + else + curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s + exit 1 + fi + + - name: Check Wazuh indexer nodes + run: | + nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`" + if [[ $nodes -eq 3 ]]; then + echo "Wazuh indexer nodes: ${nodes}" + else + echo "Wazuh indexer nodes: ${nodes}" + exit 1 + fi + + - name: Check documents into wazuh-alerts index + run: | + until [[ $(``curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"``) -gt 0 ]] + do + echo 'Waiting for Wazuh indexer events' + free -m + df -h + sleep 10 + done + docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`" + if [[ $docs -gt 0 ]]; then + echo "wazuh-alerts index documents: ${docs}" + else + echo "wazuh-alerts index documents: ${docs}" + exit 1 + fi + + - name: Check Wazuh templates + run: | + qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh" | wc -l`" + templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh"`" + if [[ $qty_templates -gt 3 ]]; then + echo "wazuh templates:" + echo "${templates}" + else + echo "wazuh templates:" + echo "${templates}" + exit 1 + fi + + - name: Check Wazuh manager start + run: | + services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`" + if [[ $services -gt 10 ]]; then + echo "Wazuh Manager Services: ${services}" + echo "OK" + else + echo "Wazuh indexer nodes: ${nodes}" + curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items + exit 1 + fi + nodes=$(curl -k -s -X GET "https://0.0.0.0:55000/cluster/nodes" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r ".data.affected_items[].name" | wc -l) + if [[ $nodes -eq 2 ]]; then + echo "Wazuh manager nodes: ${nodes}" + else + echo "Wazuh manager nodes: ${nodes}" + exit 1 + fi + env: + TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") + + - name: Check filebeat output + run: ./.github/multi-node-filebeat-check.sh + + - name: Check Wazuh dashboard service URL + run: | + status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I | grep -E "^HTTP" | awk '{print $2}') + if [[ $status -eq 200 ]]; then + echo "Wazuh dashboard status: ${status}" + else + echo "Wazuh dashboard status: ${status}" + exit 1 + fi + + - name: Modify Docker endpoint into Wazuh agent docker-compose.yml file + run: sed -i "s//$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml + + - name: Start Wazuh agent + run: docker compose -f wazuh-agent/docker-compose.yml up -d + + - name: Check Wazuh agent enrollment + run: | + sleep 20 + curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" + env: + TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") + + - name: Check errors in ossec.log for Wazuh manager + run: ./.github/multi-node-log-check.sh diff --git a/.github/workflows/Procedure_push_docker_images.yml b/.github/workflows/5_build_and_push_images.yml similarity index 99% rename from .github/workflows/Procedure_push_docker_images.yml rename to .github/workflows/5_build_and_push_images.yml index c0294cdc..bd630f01 100644 --- a/.github/workflows/Procedure_push_docker_images.yml +++ b/.github/workflows/5_build_and_push_images.yml @@ -1,5 +1,5 @@ -run-name: Launch Push Docker Images - ${{ inputs.id }} -name: Push Docker Images +run-name: Build and push images 5.x - ${{ inputs.dev && 'dev' || 'release' }} - ${{ inputs.id }} +name: Build and push images 5.x on: workflow_dispatch: @@ -96,7 +96,7 @@ jobs: - name: Print inputs run: | echo "---------------------------------------------" - echo "Running Procedure_push_docker_images workflow" + echo "Running 5_build_and_push_images workflow" echo "---------------------------------------------" echo "* BRANCH: ${{ github.ref }}" echo "* COMMIT: ${{ github.sha }}" diff --git a/.github/workflows/check_integration_tools.yaml b/.github/workflows/5_check_integration_tools.yml similarity index 99% rename from .github/workflows/check_integration_tools.yaml rename to .github/workflows/5_check_integration_tools.yml index 048c56ea..d78c9850 100644 --- a/.github/workflows/check_integration_tools.yaml +++ b/.github/workflows/5_check_integration_tools.yml @@ -2,7 +2,7 @@ run-name: >- ${{ github.event_name == 'workflow_dispatch' && format('Docker Integration Test - Manual {0} on {1}', inputs.deployment_type, inputs.pr_head_ref) || format('Docker Integration Test - #{0} {1}', github.event.issue.number, github.event.issue.title) }} -name: PR Check - Docker Integration Tests +name: PR Check - Docker Integration Tests 5.x on: issue_comment: @@ -291,7 +291,7 @@ jobs: # ------------------------------------------------------------------------- # Job 3: Build Docker images (only for ECR, when no explicit version/stage provided). - # Calls Procedure_push_docker_images.yml and pushes to the dev registry. + # Calls 5_build_and_push_images.yml and pushes to the dev registry. # ------------------------------------------------------------------------- build_images: name: Build Docker images @@ -302,7 +302,7 @@ jobs: inputs.version == '' && inputs.stage == '' && (inputs.registry == 'ECR' || github.event_name == 'issue_comment') - uses: ./.github/workflows/Procedure_push_docker_images.yml + uses: ./.github/workflows/5_build_and_push_images.yml with: image_tag: "${{ needs.prepare.outputs.wazuh_version }}-${{ needs.prepare.outputs.wazuh_stage }}" docker_reference: ${{ needs.prepare.outputs.pr_head_ref }} diff --git a/.github/workflows/5_pr_check.yml b/.github/workflows/5_pr_check.yml index b47934c3..f3fc69fa 100644 --- a/.github/workflows/5_pr_check.yml +++ b/.github/workflows/5_pr_check.yml @@ -1,10 +1,16 @@ -name: Wazuh Docker pipeline +name: Wazuh Docker pipeline 5.x permissions: contents: read id-token: write on: pull_request: types: [opened, synchronize, reopened, ready_for_review] + paths: + - 'build-docker-images/**' + - 'multi-node/**' + - 'single-node/**' + - 'wazuh-agent/**' + - '.github/**' workflow_dispatch: inputs: docker_reference: @@ -41,7 +47,7 @@ jobs: build-images: needs: prepare-variables - uses: ./.github/workflows/Procedure_push_docker_images.yml + uses: ./.github/workflows/5_build_and_push_images.yml secrets: inherit with: image_tag: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }}