diff --git a/.github/.goss.yaml b/.github/.goss.yaml index 4e083406..a5a1c9c7 100644 --- a/.github/.goss.yaml +++ b/.github/.goss.yaml @@ -13,64 +13,20 @@ file: group: wazuh filetype: file contains: [] - /var/ossec/etc/rules/local_rules.xml: - exists: true - mode: "0660" - owner: wazuh - group: wazuh - filetype: file - contains: [] /var/ossec/etc/sslmanager.cert: exists: true - mode: "0640" + mode: "0644" owner: root group: root filetype: file contains: [] /var/ossec/etc/sslmanager.key: exists: true - mode: "0640" + mode: "0600" owner: root group: root filetype: file contains: [] -package: - wazuh-manager: - installed: true - versions: - - 5.0.0 -port: - tcp:1514: - listening: true - ip: - - 0.0.0.0 - tcp:1515: - listening: true - ip: - - 0.0.0.0 - tcp:55000: - listening: true - ip: - - 0.0.0.0 -process: - wazuh-analysisd: - running: true - wazuh-authd: - running: true - wazuh-execd: - running: true - wazuh-monitord: - running: true - wazuh-remoted: - running: true - wazuh-syscheckd: - running: true - s6-supervise: - running: true - wazuh-db: - running: true - wazuh-modulesd: - running: true user: wazuh: exists: true diff --git a/.github/workflows/5_pr_check.yml b/.github/workflows/5_pr_check.yml new file mode 100644 index 00000000..f54a8164 --- /dev/null +++ b/.github/workflows/5_pr_check.yml @@ -0,0 +1,562 @@ +name: Wazuh Docker pipeline +permissions: + contents: read + id-token: write +on: [pull_request] + +jobs: + + prepare-variables: + runs-on: ubuntu-latest + outputs: + WAZUH_VERSION: ${{ steps.dotenv.outputs.WAZUH_VERSION }} + WAZUH_IMAGE_VERSION: ${{ steps.dotenv.outputs.WAZUH_IMAGE_VERSION }} + WAZUH_TAG_REVISION: ${{ steps.dotenv.outputs.WAZUH_TAG_REVISION }} + WAZUH_UI_REVISION: ${{ steps.dotenv.outputs.WAZUH_UI_REVISION }} + WAZUH_REGISTRY: ${{ vars.IMAGE_REGISTRY_DEV }} + IMAGE_TAG: ${{ steps.dotenv.outputs.IMAGE_TAG }} + WAZUH_MINOR_VERSION: ${{ steps.dotenv.outputs.WAZUH_MINOR_VERSION }} + steps: + + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Export .env variables + id: dotenv + shell: bash + run: | + if [ ! -f .env ]; then echo "::error::.env missing"; exit 1; fi + grep -v '^#' .env | grep -v '^\s*$' >> "$GITHUB_OUTPUT" + FULL_VERSION=$(grep "^WAZUH_VERSION=" .env | cut -d'=' -f2) + MINOR_VERSION=$(echo "$FULL_VERSION" | cut -d'.' -f1,2) + echo "WAZUH_MINOR_VERSION=$MINOR_VERSION" >> "$GITHUB_OUTPUT" + + + build-images: + needs: prepare-variables + uses: ./.github/workflows/Procedure_push_docker_images.yml + secrets: inherit + with: + image_tag: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }} + docker_reference: ${{ github.head_ref }} + revision: ${{ needs.prepare-variables.outputs.WAZUH_TAG_REVISION }} + reference: "latest" + id: ${{ github.run_id }} + dev: true + + Execute-Goss-tests: + needs: [prepare-variables, build-images] + runs-on: ubuntu-22.04 + env: + WAZUH_IMAGE_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }} + WAZUH_REGISTRY: ${{ needs.prepare-variables.outputs.WAZUH_REGISTRY }} + steps: + + - name: Check out code + uses: actions/checkout@v4 + + - name: Install Goss + uses: e1himself/goss-installation-action@v1.0.3 + with: + version: 'v0.4.4' + + - name: Configure aws credentials + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }} + aws-region: "${{ secrets.AWS_REGION }}" + + - name: Log in to Amazon ECR + uses: aws-actions/amazon-ecr-login@v2 + + - name: Execute Goss tests (wazuh-manager) + run: dgoss run ${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-manager:${{ env.WAZUH_IMAGE_VERSION }} + env: + GOSS_SLEEP: 30 + GOSS_FILE: .github/.goss.yaml + + check-single-node: + name: Check single node on ${{ matrix.os }} + runs-on: ${{ matrix.os }} + strategy: + matrix: + os: [ubuntu-22.04, ubuntu-22.04-arm] + fail-fast: false + needs: [prepare-variables, Execute-Goss-tests, build-images] + env: + WAZUH_IMAGE_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }} + WAZUH_MINOR_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_MINOR_VERSION }} + WAZUH_REGISTRY: ${{ needs.prepare-variables.outputs.WAZUH_REGISTRY }} + INDEXER_USERNAME: admin + INDEXER_PASSWORD: admin + API_USERNAME: wazuh-wui + API_PASSWORD: MyS3cr37P450r.*- + MANAGER_NODES: "manager" + steps: + + - name: Check out code + uses: actions/checkout@v4 + + - name: free disk space + uses: ./.github/free-disk-space + + - name: Configure aws credentials + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }} + aws-region: "${{ secrets.AWS_REGION }}" + + - name: Log in to Amazon ECR + uses: aws-actions/amazon-ecr-login@v2 + + - name: Create single node certficates + run: | + wazuh_certs_tool_url=$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/secondary/installation-assistant/${{ env.WAZUH_IMAGE_VERSION }}/wazuh-certs-tool.sh --expires-in 3600 --region us-west-1) + curl -sL "$wazuh_certs_tool_url" -o ./wazuh-certs-tool.sh + cat > config.yml </$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml + + - name: Edit Wazuh agent docker-compose file + shell: bash + env: + WAZUH_REGISTRY: ${{ env.WAZUH_REGISTRY }} + run: | + TARGET_FILE="wazuh-agent/docker-compose.yml" + if [ -f "$TARGET_FILE" ]; then + echo "Updating registry in $TARGET_FILE to: ${{ env.WAZUH_REGISTRY }}" + sed -i "s|wazuh/wazuh-|${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-|g" "$TARGET_FILE" + else + echo "File $TARGET_FILE not found" + exit 1 + fi + + - name: Start Wazuh agent + run: docker compose up -d + working-directory: ./wazuh-agent + + - name: Check Wazuh agent enrollment + run: | + for i in {1..5}; do + TOKEN=$(curl -s -u ${{ env.API_USERNAME }}:${{ env.API_PASSWORD }} -k -X GET "https://127.0.0.1:55000/security/user/authenticate?raw=true") + agents="`curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items | grep active | wc -l`" + if [[ $agents -gt 1 ]]; then + echo "Wazuh agents: ${agents}" + echo "OK" + break + else + curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}" + echo "Wazuh agents: ${agents}. Retrying in 10s" + [ $i -lt 5 ] && sleep 10 + fi + done + + - name: Check errors in ossec.log for Wazuh manager + run: ./.github/single-node-log-check.sh + + - name: Docker logs + if: always() + run: | + INDEXER_CONTAINERS=$(docker ps --format '{{.Names}}') + for CONTAINER_NAME in $INDEXER_CONTAINERS; do + echo "" + echo "=========================================================" + echo "Container logs for $CONTAINER_NAME" + echo "=========================================================" + docker logs "$CONTAINER_NAME" + echo "---------------------------------------------------------" + done + working-directory: ./single-node + + check-multi-node: + name: Check multi node on ${{ matrix.os }} + runs-on: ${{ matrix.os }} + strategy: + matrix: + os: [ubuntu-22.04, ubuntu-22.04-arm] + fail-fast: false + needs: [prepare-variables, Execute-Goss-tests, build-images] + env: + WAZUH_IMAGE_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }} + WAZUH_MINOR_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_MINOR_VERSION }} + WAZUH_REGISTRY: ${{ needs.prepare-variables.outputs.WAZUH_REGISTRY }} + INDEXER_USERNAME: admin + INDEXER_PASSWORD: admin + API_USERNAME: wazuh-wui + API_PASSWORD: MyS3cr37P450r.*- + MANAGER_NODES: "master,worker01" + steps: + + - name: Check out code + uses: actions/checkout@v4 + + - name: free disk space + uses: ./.github/free-disk-space + + - name: Configure aws credentials + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }} + aws-region: "${{ secrets.AWS_REGION }}" + + - name: Log in to Amazon ECR + uses: aws-actions/amazon-ecr-login@v2 + + - name: Create multi node certficates + run: | + wazuh_certs_tool_url=$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/secondary/installation-assistant/${{ env.WAZUH_IMAGE_VERSION }}/wazuh-certs-tool.sh --expires-in 3600 --region us-west-1) + curl -sL "$wazuh_certs_tool_url" -o ./wazuh-certs-tool.sh + cat > config.yml </$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml + + - name: Edit Wazuh agent docker-compose file + shell: bash + env: + WAZUH_REGISTRY: ${{ env.WAZUH_REGISTRY }} + run: | + TARGET_FILE="wazuh-agent/docker-compose.yml" + if [ -f "$TARGET_FILE" ]; then + echo "Updating registry in $TARGET_FILE to: ${{ env.WAZUH_REGISTRY }}" + sed -i "s|wazuh/wazuh-|${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-|g" "$TARGET_FILE" + else + echo "File $TARGET_FILE not found" + exit 1 + fi + + - name: Start Wazuh agent + run: docker compose -f wazuh-agent/docker-compose.yml up -d + + - name: Check Wazuh agent enrollment + run: | + for i in {1..5}; do + TOKEN=$(curl -s -u ${{ env.API_USERNAME }}:${{ env.API_PASSWORD }} -k -X GET "https://127.0.0.1:55000/security/user/authenticate?raw=true") + agents="`curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items | grep active | wc -l`" + if [[ $agents -gt 1 ]]; then + echo "Wazuh agents: ${agents}" + echo "OK" + break + else + curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}" + echo "Wazuh agents: ${agents}. Retrying in 10s" + [ $i -lt 5 ] && sleep 10 + fi + done + + - name: Check errors in ossec.log for Wazuh manager + run: ./.github/multi-node-log-check.sh + + - name: Docker logs + if: always() + run: | + INDEXER_CONTAINERS=$(docker ps --format '{{.Names}}') + for CONTAINER_NAME in $INDEXER_CONTAINERS; do + echo "" + echo "=========================================================" + echo "Container logs for $CONTAINER_NAME" + echo "=========================================================" + docker logs "$CONTAINER_NAME" + echo "---------------------------------------------------------" + done + working-directory: ./single-node diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml deleted file mode 100644 index 0fb975b3..00000000 --- a/.github/workflows/push.yml +++ /dev/null @@ -1,363 +0,0 @@ -name: Wazuh Docker pipeline - -on: [pull_request] - -jobs: - build-docker-images: - runs-on: ubuntu-22.04 - steps: - - - name: Check out code - uses: actions/checkout@v4 - - - name: Build Wazuh images - run: ./build-images.sh - working-directory: ./build-docker-images - - - name: Create enviroment variables - run: cat .env > $GITHUB_ENV - - - name: Create backup Docker images - run: | - mkdir -p /home/runner/work/wazuh-docker/wazuh-docker/docker-images/ - docker save wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-manager.tar - docker save wazuh/wazuh-indexer:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-indexer.tar - docker save wazuh/wazuh-dashboard:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar - docker save wazuh/wazuh-agent:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-agent.tar - - - name: Temporarily save Wazuh manager Docker image - uses: actions/upload-artifact@v4 - with: - name: docker-artifact-manager - path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-manager.tar - retention-days: 1 - - - name: Temporarily save Wazuh indexer Docker image - uses: actions/upload-artifact@v4 - with: - name: docker-artifact-indexer - path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-indexer.tar - retention-days: 1 - - - name: Temporarily save Wazuh dashboard Docker image - uses: actions/upload-artifact@v4 - with: - name: docker-artifact-dashboard - path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar - retention-days: 1 - - - name: Temporarily save Wazuh agent Docker image - uses: actions/upload-artifact@v4 - with: - name: docker-artifact-agent - path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-agent.tar - retention-days: 1 - - - name: Install Goss - uses: e1himself/goss-installation-action@v1.0.3 - with: - version: v0.3.16 - - - name: Execute Goss tests (wazuh-manager) - run: dgoss run wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}} - env: - GOSS_SLEEP: 30 - GOSS_FILE: .github/.goss.yaml - - check-single-node: - runs-on: ubuntu-22.04 - needs: build-docker-images - steps: - - - name: Check out code - uses: actions/checkout@v4 - - - name: Create enviroment variables - run: cat .env > $GITHUB_ENV - - - name: Retrieve saved Wazuh indexer Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-indexer - - - name: Retrieve saved Wazuh manager Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-manager - - - name: Retrieve saved Wazuh dashboard Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-dashboard - - - name: Retrieve saved Wazuh agent Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-agent - - - name: Docker load - run: | - docker load --input ./wazuh-indexer.tar - docker load --input ./wazuh-dashboard.tar - docker load --input ./wazuh-manager.tar - docker load --input ./wazuh-agent.tar - - - name: Create single node certficates - run: docker compose -f single-node/generate-indexer-certs.yml run --rm generator - - - name: Start single node stack - run: docker compose -f single-node/docker-compose.yml up -d - - - name: Check Wazuh indexer start - run: | - sleep 60 - status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`" - if [[ $status_green -eq 1 ]]; then - curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s - else - curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s - exit 1 - fi - status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`" - status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep "green" | wc -l`" - if [[ $status_index_green -eq $status_index ]]; then - curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s - else - curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s - exit 1 - fi - - - - name: Check Wazuh indexer nodes - run: | - nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`" - if [[ $nodes -eq 1 ]]; then - echo "Wazuh indexer nodes: ${nodes}" - else - echo "Wazuh indexer nodes: ${nodes}" - exit 1 - fi - - - name: Check documents into wazuh-alerts index - run: | - sleep 120 - docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`" - if [[ $docs -gt 0 ]]; then - echo "wazuh-alerts index documents: ${docs}" - else - echo "wazuh-alerts index documents: ${docs}" - exit 1 - fi - - - name: Check Wazuh templates - run: | - qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics" | wc -l`" - templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics"`" - if [[ $qty_templates -gt 3 ]]; then - echo "wazuh templates:" - echo "${templates}" - else - echo "wazuh templates:" - echo "${templates}" - exit 1 - fi - - - name: Check Wazuh manager start - run: | - services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`" - if [[ $services -gt 9 ]]; then - echo "Wazuh Manager Services: ${services}" - echo "OK" - else - echo "Wazuh indexer nodes: ${nodes}" - curl -k -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items - exit 1 - fi - env: - TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - - - name: Check Wazuh dashboard service URL - run: | - status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I -s | grep -E "^HTTP" | awk '{print $2}') - if [[ $status -eq 200 ]]; then - echo "Wazuh dashboard status: ${status}" - else - echo "Wazuh dashboard status: ${status}" - exit 1 - fi - - - name: Modify Docker endpoint into Wazuh agent docker-compose.yml file - run: sed -i "s//$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml - - - name: Start Wazuh agent - run: docker compose -f wazuh-agent/docker-compose.yml up -d - - - name: Check Wazuh agent enrollment - run: | - sleep 20 - curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" - env: - TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - - - name: Check errors in ossec.log for Wazuh manager - run: ./.github/single-node-log-check.sh - - check-multi-node: - runs-on: ubuntu-22.04 - needs: build-docker-images - steps: - - - name: Check out code - uses: actions/checkout@v4 - - - name: Create enviroment variables - run: cat .env > $GITHUB_ENV - - - name: free disk space - uses: ./.github/free-disk-space - - - name: Retrieve saved Wazuh dashboard Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-dashboard - - - name: Retrieve saved Wazuh manager Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-manager - - - name: Retrieve saved Wazuh indexer Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-indexer - - - name: Retrieve saved Wazuh agent Docker image - uses: actions/download-artifact@v4 - with: - name: docker-artifact-agent - - - name: Docker load - run: | - docker load --input ./wazuh-manager.tar - docker load --input ./wazuh-indexer.tar - docker load --input ./wazuh-dashboard.tar - docker load --input ./wazuh-agent.tar - rm -rf wazuh-manager.tar wazuh-indexer.tar wazuh-dashboard.tar wazuh-agent.tar - - - name: Create multi node certficates - run: docker compose -f multi-node/generate-indexer-certs.yml run --rm generator - - - name: Start multi node stack - run: docker compose -f multi-node/docker-compose.yml up -d - - - name: Check Wazuh indexer start - run: | - until [[ `curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l` -eq 1 ]] - do - echo 'Waiting for Wazuh indexer start' - free -m - df -h - sleep 120 - done - status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`" - if [[ $status_green -eq 1 ]]; then - curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s - else - curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s - exit 1 - fi - status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`" - status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep -E "green" | wc -l`" - if [[ $status_index_green -eq $status_index ]]; then - curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s - else - curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s - exit 1 - fi - - - name: Check Wazuh indexer nodes - run: | - nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`" - if [[ $nodes -eq 3 ]]; then - echo "Wazuh indexer nodes: ${nodes}" - else - echo "Wazuh indexer nodes: ${nodes}" - exit 1 - fi - - - name: Check documents into wazuh-alerts index - run: | - until [[ $(``curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"``) -gt 0 ]] - do - echo 'Waiting for Wazuh indexer events' - free -m - df -h - sleep 10 - done - docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`" - if [[ $docs -gt 0 ]]; then - echo "wazuh-alerts index documents: ${docs}" - else - echo "wazuh-alerts index documents: ${docs}" - exit 1 - fi - - - name: Check Wazuh templates - run: | - qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh" | wc -l`" - templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh"`" - if [[ $qty_templates -gt 3 ]]; then - echo "wazuh templates:" - echo "${templates}" - else - echo "wazuh templates:" - echo "${templates}" - exit 1 - fi - - - name: Check Wazuh manager start - run: | - services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`" - if [[ $services -gt 10 ]]; then - echo "Wazuh Manager Services: ${services}" - echo "OK" - else - echo "Wazuh indexer nodes: ${nodes}" - curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items - exit 1 - fi - nodes=$(curl -k -s -X GET "https://0.0.0.0:55000/cluster/nodes" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r ".data.affected_items[].name" | wc -l) - if [[ $nodes -eq 2 ]]; then - echo "Wazuh manager nodes: ${nodes}" - else - echo "Wazuh manager nodes: ${nodes}" - exit 1 - fi - env: - TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - - - name: Check Wazuh dashboard service URL - run: | - status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I | grep -E "^HTTP" | awk '{print $2}') - if [[ $status -eq 200 ]]; then - echo "Wazuh dashboard status: ${status}" - else - echo "Wazuh dashboard status: ${status}" - exit 1 - fi - - - name: Modify Docker endpoint into Wazuh agent docker-compose.yml file - run: sed -i "s//$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml - - - name: Start Wazuh agent - run: docker compose -f wazuh-agent/docker-compose.yml up -d - - - name: Check Wazuh agent enrollment - run: | - sleep 20 - curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" - env: - TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - - - name: Check errors in ossec.log for Wazuh manager - run: ./.github/multi-node-log-check.sh diff --git a/.github/workflows/trivy-dashboard.yml b/.github/workflows/trivy-dashboard.yml deleted file mode 100644 index 5239d93c..00000000 --- a/.github/workflows/trivy-dashboard.yml +++ /dev/null @@ -1,76 +0,0 @@ -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. - -name: Trivy scan Wazuh dashboard - -on: - release: - types: - - published - pull_request: - branches: - - main - schedule: - - cron: '34 2 * * 1' - workflow_dispatch: - -permissions: - contents: read - -jobs: - build: - permissions: - contents: read # for actions/checkout to fetch code - security-events: write # for github/codeql-action/upload-sarif to upload SARIF results - - name: Build images and upload Trivy results - runs-on: "ubuntu-22.04" - steps: - - name: Checkout code - uses: actions/checkout@v3 - - - name: Installing dependencies - run: | - sudo apt-get update - sudo apt-get install -y jq - - - name: Checkout latest tag - run: | - latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') - git fetch origin - git checkout $latest - - - name: Build Wazuh images - run: build-docker-images/build-images.sh - - - name: Create enviroment variables - run: | - cat .env > $GITHUB_ENV - echo "GITHUB_REF_NAME="${GITHUB_REF_NAME%/*} >> $GITHUB_ENV - - - name: Run Trivy vulnerability scanner for Wazuh dashboard - uses: aquasecurity/trivy-action@2a2157eb22c08c9a1fac99263430307b8d1bc7a2 - with: - image-ref: 'wazuh/wazuh-dashboard:${{env.WAZUH_IMAGE_VERSION}}' - format: 'template' - template: '@/contrib/sarif.tpl' - output: 'trivy-results-dashboard.sarif' - severity: 'LOW,MEDIUM,CRITICAL,HIGH' - - - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v2 - with: - sarif_file: 'trivy-results-dashboard.sarif' - - - name: Slack notification - uses: rtCamp/action-slack-notify@v2 - env: - SLACK_CHANNEL: cicd-monitoring - SLACK_COLOR: ${{ job.status }} # or a specific color like 'good' or '#ff00ff' - #SLACK_ICON: https://github.com/rtCamp.png?size=48 - SLACK_MESSAGE: "Check the results: https://github.com/wazuh/wazuh-docker/security/code-scanning?query=is%3Aopen+branch%3A${{ env.GITHUB_REF_NAME }}" - SLACK_TITLE: Wazuh docker Trivy vulnerability scan finished. - SLACK_USERNAME: github_actions - SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} \ No newline at end of file diff --git a/.github/workflows/trivy-indexer.yml b/.github/workflows/trivy-indexer.yml deleted file mode 100644 index 6f69f206..00000000 --- a/.github/workflows/trivy-indexer.yml +++ /dev/null @@ -1,76 +0,0 @@ -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. - -name: Trivy scan Wazuh indexer - -on: - release: - types: - - published - pull_request: - branches: - - main - schedule: - - cron: '34 2 * * 1' - workflow_dispatch: - -permissions: - contents: read - -jobs: - build: - permissions: - contents: read # for actions/checkout to fetch code - security-events: write # for github/codeql-action/upload-sarif to upload SARIF results - - name: Build images and upload Trivy results - runs-on: "ubuntu-22.04" - steps: - - name: Checkout code - uses: actions/checkout@v3 - - - name: Installing dependencies - run: | - sudo apt-get update - sudo apt-get install -y jq - - - name: Checkout latest tag - run: | - latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') - git fetch origin - git checkout $latest - - - name: Build Wazuh images - run: build-docker-images/build-images.sh - - - name: Create enviroment variables - run: | - cat .env > $GITHUB_ENV - echo "GITHUB_REF_NAME="${GITHUB_REF_NAME%/*} >> $GITHUB_ENV - - - name: Run Trivy vulnerability scanner for Wazuh indexer - uses: aquasecurity/trivy-action@2a2157eb22c08c9a1fac99263430307b8d1bc7a2 - with: - image-ref: 'wazuh/wazuh-indexer:${{env.WAZUH_IMAGE_VERSION}}' - format: 'template' - template: '@/contrib/sarif.tpl' - output: 'trivy-results-indexer.sarif' - severity: 'LOW,MEDIUM,CRITICAL,HIGH' - - - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v2 - with: - sarif_file: 'trivy-results-indexer.sarif' - - - name: Slack notification - uses: rtCamp/action-slack-notify@v2 - env: - SLACK_CHANNEL: cicd-monitoring - SLACK_COLOR: ${{ job.status }} # or a specific color like 'good' or '#ff00ff' - #SLACK_ICON: https://github.com/rtCamp.png?size=48 - SLACK_MESSAGE: "Check the results: https://github.com/wazuh/wazuh-docker/security/code-scanning?query=is%3Aopen+branch%3A${{ env.GITHUB_REF_NAME }}" - SLACK_TITLE: Wazuh docker Trivy vulnerability scan finished. - SLACK_USERNAME: github_actions - SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} \ No newline at end of file diff --git a/.github/workflows/trivy-manager.yml b/.github/workflows/trivy-manager.yml deleted file mode 100644 index da75bcc7..00000000 --- a/.github/workflows/trivy-manager.yml +++ /dev/null @@ -1,76 +0,0 @@ -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. - -name: Trivy scan Wazuh manager - -on: - release: - types: - - published - pull_request: - branches: - - main - schedule: - - cron: '34 2 * * 1' - workflow_dispatch: - -permissions: - contents: read - -jobs: - build: - permissions: - contents: read # for actions/checkout to fetch code - security-events: write # for github/codeql-action/upload-sarif to upload SARIF results - - name: Build images and upload Trivy results - runs-on: "ubuntu-22.04" - steps: - - name: Checkout code - uses: actions/checkout@v3 - - - name: Installing dependencies - run: | - sudo apt-get update - sudo apt-get install -y jq - - - name: Checkout latest tag - run: | - latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') - git fetch origin - git checkout $latest - - - name: Build Wazuh images - run: build-docker-images/build-images.sh - - - name: Create enviroment variables - run: | - cat .env > $GITHUB_ENV - echo "GITHUB_REF_NAME="${GITHUB_REF_NAME%/*} >> $GITHUB_ENV - - - name: Run Trivy vulnerability scanner for Wazuh manager - uses: aquasecurity/trivy-action@2a2157eb22c08c9a1fac99263430307b8d1bc7a2 - with: - image-ref: 'wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}}' - format: 'template' - template: '@/contrib/sarif.tpl' - output: 'trivy-results-manager.sarif' - severity: 'LOW,MEDIUM,CRITICAL,HIGH' - - - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v2 - with: - sarif_file: 'trivy-results-manager.sarif' - - - name: Slack notification - uses: rtCamp/action-slack-notify@v2 - env: - SLACK_CHANNEL: cicd-monitoring - SLACK_COLOR: ${{ job.status }} # or a specific color like 'good' or '#ff00ff' - #SLACK_ICON: https://github.com/rtCamp.png?size=48 - SLACK_MESSAGE: "Check the results: https://github.com/wazuh/wazuh-docker/security/code-scanning?query=is%3Aopen+branch%3A${{ env.GITHUB_REF_NAME }}" - SLACK_TITLE: Wazuh docker Trivy vulnerability scan finished. - SLACK_USERNAME: github_actions - SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 96f4a5c8..825717c5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,7 @@ All notable changes to this project will be documented in this file. ### Changed +- Modify docker build image process ([#2131](https://github.com/wazuh/wazuh-docker/issues/2131)) - Update documentation for Wazuh Docker image builder and workflow usage ([#2136](https://github.com/wazuh/wazuh-docker/issues/2136)) - Configure deployment with environment variables ([#2081](https://github.com/wazuh/wazuh-docker/pull/2081)) - Modify Wazuh components install method ([#2058](https://github.com/wazuh/wazuh-docker/pull/2058)) diff --git a/build-docker-images/wazuh-agent/Dockerfile b/build-docker-images/wazuh-agent/Dockerfile index 46bcab1c..c8fc26ca 100644 --- a/build-docker-images/wazuh-agent/Dockerfile +++ b/build-docker-images/wazuh-agent/Dockerfile @@ -23,12 +23,13 @@ RUN URL_VAR="wazuh_agent_url_${TARGETARCH}_rpm" && \ rm -rf /wazuh-agent.rpm && \ dnf clean all && \ sed -i '//d' /var/ossec/etc/ossec.conf && \ - curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-amd64.tar.gz \ - -o /tmp/s6-overlay-amd64.tar.gz && \ - tar xzf /tmp/s6-overlay-amd64.tar.gz -C / --exclude="./bin" && \ - tar xzf /tmp/s6-overlay-amd64.tar.gz -C /usr ./bin && \ - rm /tmp/s6-overlay-amd64.tar.gz - + S6_ARCH="amd64" && \ + if [ "${TARGETARCH}" = "arm64" ]; then S6_ARCH="aarch64"; fi && \ + curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-${S6_ARCH}.tar.gz \ + -o /tmp/s6-overlay-${S6_ARCH}.tar.gz && \ + tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C / --exclude="./bin" && \ + tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C /usr ./bin && \ + rm /tmp/s6-overlay-${S6_ARCH}.tar.gz COPY config/etc/ /etc/ ENTRYPOINT [ "/init" ] diff --git a/multi-node/docker-compose.yml b/multi-node/docker-compose.yml index f1b7f63a..2e69f4d0 100644 --- a/multi-node/docker-compose.yml +++ b/multi-node/docker-compose.yml @@ -3,6 +3,7 @@ services: wazuh.master: image: wazuh/wazuh-manager:5.0.0 hostname: wazuh.master + container_name: multi-node-wazuh.master restart: always ulimits: memlock: @@ -39,6 +40,7 @@ services: wazuh.worker: image: wazuh/wazuh-manager:5.0.0 hostname: wazuh.worker + container_name: multi-node-wazuh.worker restart: always ulimits: memlock: @@ -72,6 +74,7 @@ services: wazuh1.indexer: image: wazuh/wazuh-indexer:5.0.0 hostname: wazuh1.indexer + container_name: multi-node-wazuh1.indexer restart: always ports: - "9200:9200" @@ -103,6 +106,7 @@ services: wazuh2.indexer: image: wazuh/wazuh-indexer:5.0.0 hostname: wazuh2.indexer + container_name: multi-node-wazuh2.indexer restart: always environment: - OPENSEARCH_JAVA_OPTS=-Xms1g -Xmx1g @@ -130,6 +134,7 @@ services: wazuh3.indexer: image: wazuh/wazuh-indexer:5.0.0 hostname: wazuh3.indexer + container_name: multi-node-wazuh3.indexer restart: always environment: - OPENSEARCH_JAVA_OPTS=-Xms1g -Xmx1g @@ -157,6 +162,7 @@ services: wazuh.dashboard: image: wazuh/wazuh-dashboard:5.0.0 hostname: wazuh.dashboard + container_name: multi-node-wazuh.dashboard restart: always ports: - 443:5601 @@ -190,6 +196,7 @@ services: nginx: image: nginx:stable hostname: nginx + container_name: multi-node-nginx restart: always ports: - "1514:1514" diff --git a/single-node/docker-compose.yml b/single-node/docker-compose.yml index 2481aeff..6c74802c 100644 --- a/single-node/docker-compose.yml +++ b/single-node/docker-compose.yml @@ -3,6 +3,7 @@ services: wazuh.manager: image: wazuh/wazuh-manager:5.0.0 hostname: wazuh.manager + container_name: single-node-wazuh.manager restart: always ulimits: memlock: @@ -40,6 +41,7 @@ services: wazuh.indexer: image: wazuh/wazuh-indexer:5.0.0 hostname: wazuh.indexer + container_name: single-node-wazuh.indexer restart: always ports: - "9200:9200" @@ -70,10 +72,12 @@ services: wazuh.dashboard: image: wazuh/wazuh-dashboard:5.0.0 hostname: wazuh.dashboard + container_name: single-node-wazuh.dashboard restart: always ports: - - 443:443 + - 443:5601 environment: + - SERVER_PORT=5601 - SERVER_HOST=0.0.0.0 - OPENSEARCH_HOSTS=https://wazuh.indexer:9200 - INDEXER_USERNAME=admin