forked from wazuh/wazuh-docker
Delete Wazuh dashboard config files
This commit is contained in:
@@ -40,10 +40,8 @@ FROM amazonlinux:2023
|
|||||||
ENV USER="wazuh-dashboard" \
|
ENV USER="wazuh-dashboard" \
|
||||||
GROUP="wazuh-dashboard" \
|
GROUP="wazuh-dashboard" \
|
||||||
NAME="wazuh-dashboard" \
|
NAME="wazuh-dashboard" \
|
||||||
INSTALL_DIR="/usr/share/wazuh-dashboard"
|
INSTALL_DIR="/usr/share/wazuh-dashboard" \
|
||||||
|
PATTERN="" \
|
||||||
# Set Wazuh app variables
|
|
||||||
ENV PATTERN="" \
|
|
||||||
CHECKS_PATTERN="" \
|
CHECKS_PATTERN="" \
|
||||||
CHECKS_TEMPLATE="" \
|
CHECKS_TEMPLATE="" \
|
||||||
CHECKS_API="" \
|
CHECKS_API="" \
|
||||||
@@ -57,34 +55,31 @@ ENV PATTERN="" \
|
|||||||
WAZUH_MONITORING_SHARDS="" \
|
WAZUH_MONITORING_SHARDS="" \
|
||||||
WAZUH_MONITORING_REPLICAS=""
|
WAZUH_MONITORING_REPLICAS=""
|
||||||
|
|
||||||
# Update and install dependencies
|
# Copy and set permissions to scripts
|
||||||
RUN yum install shadow-utils -y
|
COPY config/entrypoint.sh /
|
||||||
|
COPY config/wazuh_app_config.sh /
|
||||||
|
|
||||||
# Create wazuh-dashboard user and group
|
# Update and install dependencies
|
||||||
RUN getent group $GROUP || groupadd -r -g 1000 $GROUP
|
RUN yum install shadow-utils -y && \
|
||||||
RUN useradd --system \
|
yum clean all && \
|
||||||
|
getent group $GROUP || groupadd -r -g 1000 $GROUP && \
|
||||||
|
useradd --system \
|
||||||
--uid 1000 \
|
--uid 1000 \
|
||||||
--no-create-home \
|
--no-create-home \
|
||||||
--home-dir $INSTALL_DIR \
|
--home-dir $INSTALL_DIR \
|
||||||
--gid $GROUP \
|
--gid $GROUP \
|
||||||
--shell /sbin/nologin \
|
--shell /sbin/nologin \
|
||||||
--comment "$USER user" \
|
--comment "$USER user" \
|
||||||
$USER
|
$USER && \
|
||||||
|
chmod 700 /entrypoint.sh && \
|
||||||
# Copy and set permissions to scripts
|
chmod 700 /wazuh_app_config.sh && \
|
||||||
COPY config/entrypoint.sh /
|
mkdir -p $INSTALL_DIR && \
|
||||||
COPY config/wazuh_app_config.sh /
|
chown 1000:1000 $INSTALL_DIR && \
|
||||||
RUN chmod 700 /entrypoint.sh
|
chown 1000:1000 /*.sh && \
|
||||||
RUN chmod 700 /wazuh_app_config.sh
|
mkdir -p /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom
|
||||||
RUN chown 1000:1000 /*.sh
|
|
||||||
|
|
||||||
# Copy Install dir from builder to current image
|
# Copy Install dir from builder to current image
|
||||||
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR
|
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR
|
||||||
COPY --from=builder --chown=1000:1000 /etc/wazuh-dashboard $INSTALL_DIR/config
|
|
||||||
|
|
||||||
# Create custom directory
|
|
||||||
RUN mkdir -p /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom
|
|
||||||
RUN chown 1000:1000 /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom
|
|
||||||
|
|
||||||
# Set workdir and user
|
# Set workdir and user
|
||||||
WORKDIR $INSTALL_DIR
|
WORKDIR $INSTALL_DIR
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ export CONFIG_DIR=${INSTALLATION_DIR}/config
|
|||||||
## Variables
|
## Variables
|
||||||
CERT_TOOL=wazuh-certs-tool.sh
|
CERT_TOOL=wazuh-certs-tool.sh
|
||||||
CERT_CONFIG_FILE=config.yml
|
CERT_CONFIG_FILE=config.yml
|
||||||
CERT_TOOL_VERSION="4.14"
|
CERT_TOOL_VERSION="${WAZUH_VERSION%.*}"
|
||||||
PACKAGES_URL=https://packages.wazuh.com/$CERT_TOOL_VERSION/
|
PACKAGES_URL=https://packages.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/$CERT_TOOL_VERSION/
|
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
|
|
||||||
@@ -53,19 +53,8 @@ else
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
awk '
|
# Modify the config file to set the IP to localhost
|
||||||
/^ dashboard:/ {dashboard=1}
|
sed -i 's/ ip:.*/ ip: "127.0.0.1"/' $CERT_CONFIG_FILE
|
||||||
/^ # Wazuh server nodes/ {dashboard=0}
|
|
||||||
dashboard && /^[[:space:]]*[^#].*name:/ {sub(/name:.*/, "name: dashboard")}
|
|
||||||
dashboard && /^[[:space:]]*[^#].*ip:/ {sub(/ip:.*/, "ip: \"127.0.0.1\"")}
|
|
||||||
|
|
||||||
{print}
|
|
||||||
' config.yml > config.yml.tmp && mv config.yml config.yml.bak && mv config.yml.tmp config.yml
|
|
||||||
|
|
||||||
sed -i \
|
|
||||||
-e 's/^ *ip: "<wazuh-manager-ip>"$/ ip: "127.0.0.1"/' \
|
|
||||||
-e 's/^ *ip: "<indexer-node-ip>"$/ ip: "127.0.0.1"/' \
|
|
||||||
config.yaml
|
|
||||||
|
|
||||||
chmod 700 "$CERT_CONFIG_FILE"
|
chmod 700 "$CERT_CONFIG_FILE"
|
||||||
# Create the certificates
|
# Create the certificates
|
||||||
@@ -75,9 +64,16 @@ chmod 755 "$CERT_TOOL" && bash "$CERT_TOOL" -A
|
|||||||
mkdir -p ${CONFIG_DIR}/certs
|
mkdir -p ${CONFIG_DIR}/certs
|
||||||
|
|
||||||
# Copy Wazuh dashboard certs to install config dir
|
# Copy Wazuh dashboard certs to install config dir
|
||||||
cp /wazuh-certificates/demo.dashboard.pem ${CONFIG_DIR}/certs/dashboard.pem
|
mv /etc/wazuh-dashboard/* ${CONFIG_DIR}/
|
||||||
cp /wazuh-certificates/demo.dashboard-key.pem ${CONFIG_DIR}/certs/dashboard-key.pem
|
cp -pr /wazuh-certificates/dashboard.pem ${CONFIG_DIR}/certs/dashboard.pem
|
||||||
cp /wazuh-certificates/root-ca.pem ${CONFIG_DIR}/certs/root-ca.pem
|
cp -pr /wazuh-certificates/dashboard-key.pem ${CONFIG_DIR}/certs/dashboard-key.pem
|
||||||
|
cp -pr /wazuh-certificates/root-ca.key ${CONFIG_DIR}/certs/root-ca.key
|
||||||
|
cp -pr /wazuh-certificates/root-ca.pem ${CONFIG_DIR}/certs/root-ca.pem
|
||||||
|
cp -pr /wazuh-certificates/admin.pem ${CONFIG_DIR}/certs/admin.pem
|
||||||
|
cp -pr /wazuh-certificates/admin-key.pem ${CONFIG_DIR}/certs/admin-key.pem
|
||||||
|
|
||||||
|
# Modify opensearch.yml config paths
|
||||||
|
sed -i "s|/etc/wazuh-dashboard|${CONFIG_DIR}|g" ${CONFIG_DIR}/opensearch_dashboards.yml
|
||||||
|
|
||||||
chmod -R 500 ${CONFIG_DIR}/certs
|
chmod -R 500 ${CONFIG_DIR}/certs
|
||||||
chmod -R 400 ${CONFIG_DIR}/certs/*
|
chmod -R 400 ${CONFIG_DIR}/certs/*
|
||||||
@@ -22,5 +22,51 @@ RUN bash config.sh
|
|||||||
#
|
#
|
||||||
# Copy wazuh-indexer from stage 0
|
# Copy wazuh-indexer from stage 0
|
||||||
# Add entrypoint
|
# Add entrypoint
|
||||||
|
|
||||||
################################################################################
|
################################################################################
|
||||||
|
FROM amazonlinux:2023
|
||||||
|
|
||||||
|
ENV USER="wazuh-indexer" \
|
||||||
|
GROUP="wazuh-indexer" \
|
||||||
|
NAME="wazuh-indexer" \
|
||||||
|
INSTALL_DIR="/usr/share/wazuh-indexer"
|
||||||
|
|
||||||
|
|
||||||
|
COPY config/entrypoint.sh /
|
||||||
|
COPY config/securityadmin.sh /
|
||||||
|
|
||||||
|
RUN yum install curl-minimal shadow-utils findutils hostname -y && \
|
||||||
|
yum clean all && \
|
||||||
|
getent group $GROUP || groupadd -r -g 1000 $GROUP && \
|
||||||
|
useradd --system \
|
||||||
|
--uid 1000 \
|
||||||
|
--no-create-home \
|
||||||
|
--home-dir $INSTALL_DIR \
|
||||||
|
--gid $GROUP \
|
||||||
|
--shell /sbin/nologin \
|
||||||
|
--comment "$USER user" \
|
||||||
|
$USER && \
|
||||||
|
chmod 700 /entrypoint.sh && chmod 700 /securityadmin.sh && \
|
||||||
|
mkdir -p $INSTALL_DIR && \
|
||||||
|
chown 1000:1000 $INSTALL_DIR && \
|
||||||
|
chown 1000:1000 /*.sh && \
|
||||||
|
mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer && \
|
||||||
|
mkdir -p $INSTALL_DIR/logs && chown 1000:1000 $INSTALL_DIR/logs && \
|
||||||
|
mkdir -p /run/wazuh-indexer && chown 1000:1000 /run/wazuh-indexer && \
|
||||||
|
mkdir -p /var/log/wazuh-indexer && chown 1000:1000 /var/log/wazuh-indexer
|
||||||
|
|
||||||
|
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR
|
||||||
|
|
||||||
|
RUN chmod 700 $INSTALL_DIR && \
|
||||||
|
chmod 700 $INSTALL_DIR/config && \
|
||||||
|
chmod 600 $INSTALL_DIR/config/jvm.options && \
|
||||||
|
chmod 600 $INSTALL_DIR/config/opensearch.yml
|
||||||
|
|
||||||
|
USER wazuh-indexer
|
||||||
|
WORKDIR $INSTALL_DIR
|
||||||
|
|
||||||
|
# Services ports
|
||||||
|
EXPOSE 9200
|
||||||
|
|
||||||
|
ENTRYPOINT ["/entrypoint.sh"]
|
||||||
|
# Dummy overridable parameter parsed by entrypoint
|
||||||
|
CMD ["opensearchwrapper"]
|
||||||
@@ -22,7 +22,7 @@ export CONFIG_DIR=${INSTALLATION_DIR}/config
|
|||||||
## Variables
|
## Variables
|
||||||
CERT_TOOL=wazuh-certs-tool.sh
|
CERT_TOOL=wazuh-certs-tool.sh
|
||||||
CERT_CONFIG_FILE=config.yml
|
CERT_CONFIG_FILE=config.yml
|
||||||
CERT_TOOL_VERSION="4.14"
|
CERT_TOOL_VERSION="${WAZUH_VERSION%.*}"
|
||||||
PACKAGES_URL=https://packages.wazuh.com/$CERT_TOOL_VERSION/
|
PACKAGES_URL=https://packages.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/$CERT_TOOL_VERSION/
|
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
|
|
||||||
@@ -65,35 +65,28 @@ else
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
awk '
|
# Modify the config file to set the IP to localhost
|
||||||
/^ indexer:/ {in_indexer=1}
|
sed -i 's/ ip:.*/ ip: "127.0.0.1"/' $CERT_CONFIG_FILE
|
||||||
/^ # Wazuh server nodes/ {in_indexer=0}
|
|
||||||
in_indexer && /^[[:space:]]*[^#].*name:/ {sub(/name:.*/, "name: indexer")}
|
|
||||||
/^[[:space:]]*[^#].*ip:/ {sub(/ip:.*/, "ip: \"127.0.0.1\"")}
|
|
||||||
|
|
||||||
{print}
|
|
||||||
' config.yml > config.yml.tmp && mv config.yml config.yml.bak && mv config.yml.tmp config.yml
|
|
||||||
|
|
||||||
sed -i \
|
|
||||||
-e 's/^ *ip: "<wazuh-manager-ip>"$/ ip: "127.0.0.1"/' \
|
|
||||||
-e 's/^ *ip: "<indexer-node-ip>"$/ ip: "127.0.0.1"/' \
|
|
||||||
config.yaml
|
|
||||||
|
|
||||||
chmod 700 "$CERT_CONFIG_FILE"
|
chmod 700 "$CERT_CONFIG_FILE"
|
||||||
# Create the certificates
|
# Create the certificates
|
||||||
chmod 755 "$CERT_TOOL" && bash "$CERT_TOOL" -A
|
chmod 755 "$CERT_TOOL" && bash "$CERT_TOOL" -A
|
||||||
|
|
||||||
# Copy Wazuh indexer's certificates
|
# Copy Wazuh indexer's certificates and config files to $CONFIG_DIR
|
||||||
mkdir -p ${CONFIG_DIR}/certs
|
mkdir -p ${CONFIG_DIR}/certs
|
||||||
cp -pr /wazuh-certificates/indexer.pem ${CONFIG_DIR}/certs/indexer.pem
|
mv /etc/wazuh-indexer/* ${CONFIG_DIR}/
|
||||||
cp -pr /wazuh-certificates/indexer-key.pem ${CONFIG_DIR}/certs/indexer-key.pem
|
cp -pr /wazuh-certificates/node-1.pem ${CONFIG_DIR}/certs/indexer.pem
|
||||||
|
cp -pr /wazuh-certificates/node-1-key.pem ${CONFIG_DIR}/certs/indexer-key.pem
|
||||||
cp -pr /wazuh-certificates/root-ca.key ${CONFIG_DIR}/certs/root-ca.key
|
cp -pr /wazuh-certificates/root-ca.key ${CONFIG_DIR}/certs/root-ca.key
|
||||||
cp -pr /wazuh-certificates/root-ca.pem ${CONFIG_DIR}/certs/root-ca.pem
|
cp -pr /wazuh-certificates/root-ca.pem ${CONFIG_DIR}/certs/root-ca.pem
|
||||||
cp -pr /wazuh-certificates/admin.pem ${CONFIG_DIR}/certs/admin.pem
|
cp -pr /wazuh-certificates/admin.pem ${CONFIG_DIR}/certs/admin.pem
|
||||||
cp -pr /wazuh-certificates/admin-key.pem ${CONFIG_DIR}/certs/admin-key.pem
|
cp -pr /wazuh-certificates/admin-key.pem ${CONFIG_DIR}/certs/admin-key.pem
|
||||||
|
|
||||||
|
# Modify opensearch.yml config paths
|
||||||
|
sed -i "s|/etc/wazuh-indexer|${CONFIG_DIR}|g" ${CONFIG_DIR}/opensearch.yml
|
||||||
|
|
||||||
|
# Delete xms and xmx parameters in jvm.options
|
||||||
sed -i 's/-Djava.security.policy=file:\/\/\/etc\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/-Djava.security.policy=file:\/\/\/usr\/share\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/g' /etc/wazuh-indexer/jvm.options
|
sed -i 's/-Djava.security.policy=file:\/\/\/etc\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/-Djava.security.policy=file:\/\/\/usr\/share\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/g' /etc/wazuh-indexer/jvm.options
|
||||||
sed -i 's|/etc/wazuh-indexer|/usr/share/wazuh-indexer/config|g' /etc/wazuh-indexer/opensearch.yml
|
|
||||||
|
|
||||||
chown -R ${USER}:${GROUP} ${CONFIG_DIR}
|
chown -R ${USER}:${GROUP} ${CONFIG_DIR}
|
||||||
chmod -R 500 ${CONFIG_DIR}/certs
|
chmod -R 500 ${CONFIG_DIR}/certs
|
||||||
|
|||||||
@@ -5,3 +5,101 @@ hosts:
|
|||||||
username: wazuh-wui
|
username: wazuh-wui
|
||||||
password: "MyS3cr37P450r.*-"
|
password: "MyS3cr37P450r.*-"
|
||||||
run_as: false
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
hosts:
|
||||||
|
- 1513629884013:
|
||||||
|
url: https://wazuh.manager
|
||||||
|
port: 55000
|
||||||
|
username: wazuh-wui
|
||||||
|
password: MyS3cr37P450r.*-
|
||||||
|
run_as: false
|
||||||
|
|||||||
Reference in New Issue
Block a user