From 8f97d174f94f412f48d464399238b014adae84cb Mon Sep 17 00:00:00 2001 From: manuasir Date: Tue, 20 Aug 2019 16:33:01 +0200 Subject: [PATCH] First refactor commit --- docker-compose.yml | 11 +- wazuh/Dockerfile | 143 +++++++++------ wazuh/config/00-wazuh.sh | 135 -------------- wazuh/config/01-config_filebeat.sh | 19 -- wazuh/config/01-wazuh.sh | 264 +++++++++++++++++++++++++++ wazuh/config/data_dirs.env | 15 -- wazuh/config/entrypoint.sh | 1 - wazuh/config/filebeat.runit.service | 1 - wazuh/config/filebeat.yml | 2 +- wazuh/config/init.bash | 11 -- wazuh/config/permanent_data.env | 44 +++++ wazuh/config/permanent_data.sh | 40 ++++ wazuh/config/postfix.runit.service | 1 - wazuh/config/wazuh-api.runit.service | 3 +- wazuh/config/wazuh.runit.service | 3 +- 15 files changed, 440 insertions(+), 253 deletions(-) delete mode 100644 wazuh/config/00-wazuh.sh delete mode 100644 wazuh/config/01-config_filebeat.sh create mode 100644 wazuh/config/01-wazuh.sh delete mode 100644 wazuh/config/data_dirs.env delete mode 100644 wazuh/config/init.bash create mode 100644 wazuh/config/permanent_data.env create mode 100644 wazuh/config/permanent_data.sh diff --git a/docker-compose.yml b/docker-compose.yml index 28c91e96..e47acf93 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,9 +1,9 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) version: '2' services: wazuh: - image: wazuh/wazuh:3.9.5_7.2.1 + build: wazuh hostname: wazuh-manager restart: always ports: @@ -13,7 +13,7 @@ services: - "55000:55000" elasticsearch: - image: wazuh/wazuh-elasticsearch:3.9.5_7.2.1 + build: elasticsearch hostname: elasticsearch restart: always ports: @@ -30,7 +30,7 @@ services: mem_limit: 2g kibana: - image: wazuh/wazuh-kibana:3.9.5_7.2.1 + build: kibana hostname: kibana restart: always depends_on: @@ -38,8 +38,9 @@ services: links: - elasticsearch:elasticsearch - wazuh:wazuh + nginx: - image: wazuh/wazuh-nginx:3.9.5_7.2.1 + build: nginx hostname: nginx restart: always environment: diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index 4bbfeb71..b1b2ea3c 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -1,66 +1,52 @@ # Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM phusion/baseimage:latest +FROM phusion/baseimage:master +# Arguments ARG FILEBEAT_VERSION=7.3.0 - ARG WAZUH_VERSION=3.9.5-1 +# Environment variables ENV API_USER="foo" \ - API_PASS="bar" + API_PASS="bar" -ARG TEMPLATE_VERSION="v3.9.5" +# Install packages +RUN set -x && \ + echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \ + curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | apt-key add - && \ + curl --silent --location https://deb.nodesource.com/setup_8.x | bash - && \ + echo "postfix postfix/mailname string wazuh-manager" | debconf-set-selections && \ + echo "postfix postfix/main_mailer_type string 'Internet Site'" | debconf-set-selections && \ + groupadd -g 1000 ossec && \ + useradd -u 1000 -g 1000 -d /var/ossec ossec && \ + add-apt-repository universe && \ + apt-get update && \ + apt-get upgrade -y -o Dpkg::Options::="--force-confold" && \ + apt-get --no-install-recommends --no-install-suggests -y install openssl apt-transport-https vim expect python-boto python-pip python-cryptography && \ + apt-get --no-install-recommends --no-install-suggests -y install postfix bsd-mailx mailutils libsasl2-2 ca-certificates libsasl2-modules && \ + apt-get --no-install-recommends --no-install-suggests -y install wazuh-manager=${WAZUH_VERSION} && \ + apt-get --no-install-recommends --no-install-suggests -y install nodejs wazuh-api=${WAZUH_VERSION} && \ + apt-get clean && \ + rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* && \ + rm -f /var/ossec/logs/alerts/*/*/* && \ + rm -f /var/ossec/logs/archives/*/*/* && \ + rm -f /var/ossec/logs/firewall/*/*/* && \ + rm -f /var/ossec/logs/api/*/*/* && \ + rm -f /var/ossec/logs/cluster/*/*/* && \ + rm -f /var/ossec/logs/ossec/*/*/* && \ + rm /var/ossec/var/run/* && \ + curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-${FILEBEAT_VERSION}-amd64.deb && \ + dpkg -i filebeat-${FILEBEAT_VERSION}-amd64.deb && rm -f filebeat-${FILEBEAT_VERSION}-amd64.deb && \ + curl -so /etc/filebeat/wazuh-template.json https://raw.githubusercontent.com/wazuh/wazuh/v3.9.5/extensions/elasticsearch/7.x/wazuh-template.json && \ + chmod go+r /etc/filebeat/wazuh-template.json && \ + curl -s https://packages.wazuh.com/3.x/filebeat/wazuh-filebeat-0.1.tar.gz | tar -xvz -C /usr/share/filebeat/module && \ + mkdir -p /usr/share/filebeat/module/wazuh && \ + chmod 755 -R /usr/share/filebeat/module/wazuh -# Set repositories. -RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \ - curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | apt-key add - && \ - curl --silent --location https://deb.nodesource.com/setup_8.x | bash - && \ - echo "postfix postfix/mailname string wazuh-manager" | debconf-set-selections && \ - echo "postfix postfix/main_mailer_type string 'Internet Site'" | debconf-set-selections && \ - groupadd -g 1000 ossec && useradd -u 1000 -g 1000 -d /var/ossec ossec - -RUN add-apt-repository universe && apt-get update && apt-get upgrade -y -o Dpkg::Options::="--force-confold" && \ - apt-get --no-install-recommends --no-install-suggests -y install openssl postfix bsd-mailx python-boto python-pip \ - apt-transport-https vim expect nodejs python-cryptography mailutils libsasl2-modules wazuh-manager=${WAZUH_VERSION} \ - wazuh-api=${WAZUH_VERSION} && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* && rm -f \ - /var/ossec/logs/alerts/*/*/*.log && rm -f /var/ossec/logs/alerts/*/*/*.json && rm -f \ - /var/ossec/logs/archives/*/*/*.log && rm -f /var/ossec/logs/archives/*/*/*.json && rm -f \ - /var/ossec/logs/firewall/*/*/*.log && rm -f /var/ossec/logs/firewall/*/*/*.json - -# Adding first run script and entrypoint -COPY config/data_dirs.env /data_dirs.env -COPY config/init.bash /init.bash -RUN mkdir /entrypoint-scripts -COPY config/entrypoint.sh /entrypoint.sh -COPY config/00-wazuh.sh /entrypoint-scripts/00-wazuh.sh -COPY config/01-config_filebeat.sh /entrypoint-scripts/01-config_filebeat.sh - -# Sync calls are due to https://github.com/docker/docker/issues/9547 -RUN chmod 755 /init.bash && \ - sync && /init.bash && \ - sync && rm /init.bash && \ - curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-${FILEBEAT_VERSION}-amd64.deb &&\ - dpkg -i filebeat-${FILEBEAT_VERSION}-amd64.deb && rm -f filebeat-${FILEBEAT_VERSION}-amd64.deb && \ - chmod 755 /entrypoint.sh && \ - chmod 755 /entrypoint-scripts/00-wazuh.sh && \ - chmod 755 /entrypoint-scripts/01-config_filebeat.sh - -COPY config/filebeat.yml /etc/filebeat/ -RUN chmod go-w /etc/filebeat/filebeat.yml - -# Setting volumes -VOLUME ["/var/ossec/data"] -VOLUME ["/etc/filebeat"] -VOLUME ["/etc/postfix"] -VOLUME ["/var/lib/filebeat"] - -# Services ports -EXPOSE 55000/tcp 1514/udp 1515/tcp 514/udp 1516/tcp - -# Adding services +# Services RUN mkdir /etc/service/wazuh && \ - mkdir /etc/service/wazuh-api && \ - mkdir /etc/service/postfix && \ - mkdir /etc/service/filebeat + mkdir /etc/service/wazuh-api && \ + mkdir /etc/service/postfix && \ + mkdir /etc/service/filebeat COPY config/wazuh.runit.service /etc/service/wazuh/run COPY config/wazuh-api.runit.service /etc/service/wazuh-api/run @@ -68,13 +54,50 @@ COPY config/postfix.runit.service /etc/service/postfix/run COPY config/filebeat.runit.service /etc/service/filebeat/run RUN chmod +x /etc/service/wazuh-api/run && \ - chmod +x /etc/service/wazuh/run && \ - chmod +x /etc/service/postfix/run && \ - chmod +x /etc/service/filebeat/run + chmod +x /etc/service/wazuh/run && \ + chmod +x /etc/service/postfix/run && \ + chmod +x /etc/service/filebeat/run +# Copy configuration files from repository +COPY config/filebeat.yml /etc/filebeat/ +RUN chmod go-w /etc/filebeat/filebeat.yml -ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat -RUN chmod go-w /etc/filebeat/wazuh-template.json +# Prepare permanent data +# Sync calls are due to https://github.com/docker/docker/issues/9547 +COPY config/permanent_data.env /permanent_data.env +COPY config/permanent_data.sh /permanent_data.sh +RUN chmod 755 /permanent_data.sh && \ + sync && \ + /permanent_data.sh && \ + sync && \ + rm /permanent_data.sh + +# Expose ports +EXPOSE 55000/tcp 1514/udp 1515/tcp 514/udp 1516/tcp + +# Setting volumes +# Once we declared a volume in the Dockerfile, changes made to that path will have no effect. In other words, any changes made +# to the these paths from here to the end of the Dockerfile will not be taken into account when mounting the volume. +VOLUME ["/var/ossec/api/configuration"] +VOLUME ["/var/ossec/etc"] +VOLUME ["/var/ossec/logs"] +VOLUME ["/var/ossec/queue"] +VOLUME ["/var/ossec/var/multigroups"] +VOLUME ["/var/ossec/integrations"] +VOLUME ["/var/ossec/active-response/bin"] +VOLUME ["/etc/filebeat"] +VOLUME ["/etc/postfix"] +VOLUME ["/var/lib/filebeat"] + +# Prepare entrypoint scripts +# Entrypoint scripts must be added to the entrypoint-scripts directory +RUN mkdir /entrypoint-scripts + +COPY config/entrypoint.sh /entrypoint.sh +COPY config/01-wazuh.sh /entrypoint-scripts/01-wazuh.sh + +RUN chmod 755 /entrypoint.sh && \ + chmod 755 /entrypoint-scripts/01-wazuh.sh # Run all services -ENTRYPOINT ["/entrypoint.sh"] \ No newline at end of file +ENTRYPOINT ["/entrypoint.sh"] diff --git a/wazuh/config/00-wazuh.sh b/wazuh/config/00-wazuh.sh deleted file mode 100644 index 32fdd4f4..00000000 --- a/wazuh/config/00-wazuh.sh +++ /dev/null @@ -1,135 +0,0 @@ -#!/bin/bash -# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) - -# Wazuh container bootstrap. See the README for information of the environment -# variables expected by this script. - -# Startup the services -source /data_dirs.env - -FIRST_TIME_INSTALLATION=false - -WAZUH_INSTALL_PATH=/var/ossec -DATA_PATH=${WAZUH_INSTALL_PATH}/data - -WAZUH_CONFIG_MOUNT=/wazuh-config-mount - -print() { - echo -e $1 -} - -error_and_exit() { - echo "Error executing command: '$1'." - echo 'Exiting.' - exit 1 -} - -exec_cmd() { - eval $1 > /dev/null 2>&1 || error_and_exit "$1" -} - -exec_cmd_stdout() { - eval $1 2>&1 || error_and_exit "$1" -} - -edit_configuration() { # $1 -> setting, $2 -> value - sed -i "s/^config.$1\s=.*/config.$1 = \"$2\";/g" "${DATA_PATH}/api/configuration/config.js" || error_and_exit "sed (editing configuration)" -} - -for ossecdir in "${DATA_DIRS[@]}"; do - if [ ! -e "${DATA_PATH}/${ossecdir}" ] - then - print "Installing ${ossecdir}" - exec_cmd "mkdir -p $(dirname ${DATA_PATH}/${ossecdir})" - exec_cmd "cp -pr /var/ossec/${ossecdir}-template ${DATA_PATH}/${ossecdir}" - FIRST_TIME_INSTALLATION=true - fi -done - -if [ -e ${WAZUH_INSTALL_PATH}/etc-template ] -then - cp -p /var/ossec/etc-template/internal_options.conf /var/ossec/etc/internal_options.conf -fi -rm /var/ossec/queue/db/.template.db - -touch ${DATA_PATH}/process_list -chgrp ossec ${DATA_PATH}/process_list -chmod g+rw ${DATA_PATH}/process_list - -AUTO_ENROLLMENT_ENABLED=${AUTO_ENROLLMENT_ENABLED:-true} -API_GENERATE_CERTS=${API_GENERATE_CERTS:-true} - -if [ $FIRST_TIME_INSTALLATION == true ] -then - if [ $AUTO_ENROLLMENT_ENABLED == true ] - then - if [ ! -e ${DATA_PATH}/etc/sslmanager.key ] - then - print "Creating ossec-authd key and cert" - exec_cmd "openssl genrsa -out ${DATA_PATH}/etc/sslmanager.key 4096" - exec_cmd "openssl req -new -x509 -key ${DATA_PATH}/etc/sslmanager.key -out ${DATA_PATH}/etc/sslmanager.cert -days 3650 -subj /CN=${HOSTNAME}/" - fi - fi - if [ $API_GENERATE_CERTS == true ] - then - if [ ! -e ${DATA_PATH}/api/configuration/ssl/server.crt ] - then - print "Enabling Wazuh API HTTPS" - edit_configuration "https" "yes" - print "Create Wazuh API key and cert" - exec_cmd "openssl genrsa -out ${DATA_PATH}/api/configuration/ssl/server.key 4096" - exec_cmd "openssl req -new -x509 -key ${DATA_PATH}/api/configuration/ssl/server.key -out ${DATA_PATH}/api/configuration/ssl/server.crt -days 3650 -subj /CN=${HOSTNAME}/" - fi - fi -fi - -############################################################################## -# Copy all files from $WAZUH_CONFIG_MOUNT to $DATA_PATH and respect -# destination files permissions -# -# For example, to mount the file /var/ossec/data/etc/ossec.conf, mount it at -# $WAZUH_CONFIG_MOUNT/etc/ossec.conf in your container and this code will -# replace the ossec.conf file in /var/ossec/data/etc with yours. -############################################################################## -if [ -e "$WAZUH_CONFIG_MOUNT" ] -then - print "Identified Wazuh configuration files to mount..." - - exec_cmd_stdout "cp --verbose -r $WAZUH_CONFIG_MOUNT/* $DATA_PATH" -else - print "No Wazuh configuration files to mount..." -fi - -function ossec_shutdown(){ - ${WAZUH_INSTALL_PATH}/bin/ossec-control stop; -} - -# Trap exit signals and do a proper shutdown -trap "ossec_shutdown; exit" SIGINT SIGTERM - -chmod -R g+rw ${DATA_PATH} - -############################################################################## -# Interpret any passed arguments (via docker command to this entrypoint) as -# paths or commands, and execute them. -# -# This can be useful for actions that need to be run before the services are -# started, such as "/var/ossec/bin/ossec-control enable agentless". -############################################################################## -for CUSTOM_COMMAND in "$@" -do - echo "Executing command \`${CUSTOM_COMMAND}\`" - exec_cmd_stdout "${CUSTOM_COMMAND}" -done - -############################################################################## -# Change Wazuh API user credentials. -############################################################################## - -pushd /var/ossec/api/configuration/auth/ - -echo "Change Wazuh API user credentials" -change_user="node htpasswd -b -c user $API_USER $API_PASS" -eval $change_user - -popd \ No newline at end of file diff --git a/wazuh/config/01-config_filebeat.sh b/wazuh/config/01-config_filebeat.sh deleted file mode 100644 index 818878c0..00000000 --- a/wazuh/config/01-config_filebeat.sh +++ /dev/null @@ -1,19 +0,0 @@ -#!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) - -set -e - -WAZUH_FILEBEAT_MODULE=wazuh-filebeat-0.1.tar.gz - -# Modify the output to Elasticsearch if th ELASTICSEARCH_URL is set -if [ "$ELASTICSEARCH_URL" != "" ]; then - >&2 echo "Customize Elasticsearch ouput IP." - sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_URL'|g' /etc/filebeat/filebeat.yml -fi - -# Install Wazuh Filebeat Module - -curl -s "https://packages.wazuh.com/3.x/filebeat/${WAZUH_FILEBEAT_MODULE}" | tar -xvz -C /usr/share/filebeat/module -mkdir -p /usr/share/filebeat/module/wazuh -chmod 755 -R /usr/share/filebeat/module/wazuh - diff --git a/wazuh/config/01-wazuh.sh b/wazuh/config/01-wazuh.sh new file mode 100644 index 00000000..283e13cb --- /dev/null +++ b/wazuh/config/01-wazuh.sh @@ -0,0 +1,264 @@ +#!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) + +# Variables +source /permanent_data.env + +WAZUH_INSTALL_PATH=/var/ossec +WAZUH_CONFIG_MOUNT=/wazuh-config-mount +AUTO_ENROLLMENT_ENABLED=${AUTO_ENROLLMENT_ENABLED:-true} +API_GENERATE_CERTS=${API_GENERATE_CERTS:-true} + + +############################################################################## +# Aux functions +############################################################################## +print() { + echo -e $1 +} + +error_and_exit() { + echo "Error executing command: '$1'." + echo 'Exiting.' + exit 1 +} + +exec_cmd() { + eval $1 > /dev/null 2>&1 || error_and_exit "$1" +} + +exec_cmd_stdout() { + eval $1 2>&1 || error_and_exit "$1" +} + + +############################################################################## +# Edit configuration +############################################################################## + +edit_configuration() { # $1 -> setting, $2 -> value + sed -i "s/^config.$1\s=.*/config.$1 = \"$2\";/g" "${WAZUH_INSTALL_PATH}/api/configuration/config.js" || error_and_exit "sed (editing configuration)" +} + +############################################################################## +# This function will attempt to mount every directory in PERMANENT_DATA +# into the respective path. +# If the path is empty means permanent data volume is also empty, so a backup +# will be copied into it. Otherwise it will not be copied because there is +# already data inside the volume for the specified path. +############################################################################## + +mount_permanent_data() { + for permanent_dir in "${PERMANENT_DATA[@]}"; do + # Check if the path is not empty + if find ${permanent_dir} -mindepth 1 | read; then + print "The path ${permanent_dir} is already mounted" + else + print "Installing ${permanent_dir}" + exec_cmd "cp -a ${WAZUH_INSTALL_PATH}/data_tmp/permanent${permanent_dir}/. ${permanent_dir}" + fi + done +} + +############################################################################## +# This function will replace from the permanent data volume every file +# contained in PERMANENT_DATA_EXCP +# Some files as 'internal_options.conf' are saved as permanent data, but +# they must be updated to work properly if wazuh version is changed. +############################################################################## + +apply_exclusion_data() { + for exclusion_file in "${PERMANENT_DATA_EXCP[@]}"; do + if [ -e ${WAZUH_INSTALL_PATH}/data_tmp/exclusion/${exclusion_file} ] + then + print "Updating ${exclusion_file}" + exec_cmd "cp -p ${WAZUH_INSTALL_PATH}/data_tmp/exclusion/${exclusion_file} ${exclusion_file}" + fi + done +} + +############################################################################## +# This function will delete from the permanent data volume every file +# contained in PERMANENT_DATA_DEL +############################################################################## + +remove_data_files() { + for del_file in "${PERMANENT_DATA_DEL[@]}"; do + if [ -e ${del_file} ] + then + print "Removing ${del_file}" + exec_cmd "rm ${del_file}" + fi + done +} + +############################################################################## +# Create certificates: Manager +############################################################################## + +create_ossec_key_cert() { + print "Creating ossec-authd key and cert" + exec_cmd "openssl genrsa -out ${WAZUH_INSTALL_PATH}/etc/sslmanager.key 4096" + exec_cmd "openssl req -new -x509 -key ${WAZUH_INSTALL_PATH}/etc/sslmanager.key -out ${WAZUH_INSTALL_PATH}/etc/sslmanager.cert -days 3650 -subj /CN=${HOSTNAME}/" +} + +############################################################################## +# Create certificates: API +############################################################################## + +create_api_key_cert() { + print "Enabling Wazuh API HTTPS" + edit_configuration "https" "yes" + print "Create Wazuh API key and cert" + exec_cmd "openssl genrsa -out ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.key 4096" + exec_cmd "openssl req -new -x509 -key ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.key -out ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.crt -days 3650 -subj /CN=${HOSTNAME}/" + + # Granting proper permissions + chmod 400 ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.key + chmod 400 ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.crt +} + +############################################################################## +# Copy all files from $WAZUH_CONFIG_MOUNT to $WAZUH_INSTALL_PATH and respect +# destination files permissions +# +# For example, to mount the file /var/ossec/data/etc/ossec.conf, mount it at +# $WAZUH_CONFIG_MOUNT/etc/ossec.conf in your container and this code will +# replace the ossec.conf file in /var/ossec/data/etc with yours. +############################################################################## + +mount_files() { + if [ -e "$WAZUH_CONFIG_MOUNT" ] + then + print "Identified Wazuh configuration files to mount..." + exec_cmd_stdout "cp --verbose -r $WAZUH_CONFIG_MOUNT/* $WAZUH_INSTALL_PATH" + else + print "No Wazuh configuration files to mount..." + fi +} + +############################################################################## +# Stop OSSEC +############################################################################## + +function ossec_shutdown(){ + ${WAZUH_INSTALL_PATH}/bin/ossec-control stop; +} + +############################################################################## +# Interpret any passed arguments (via docker command to this entrypoint) as +# paths or commands, and execute them. +# +# This can be useful for actions that need to be run before the services are +# started, such as "/var/ossec/bin/ossec-control enable agentless". +############################################################################## + +docker_custom_args() { + for CUSTOM_COMMAND in "$@" + do + echo "Executing command \`${CUSTOM_COMMAND}\`" + exec_cmd_stdout "${CUSTOM_COMMAND}" + done +} + +############################################################################## +# Change Wazuh API user credentials. +############################################################################## + +change_api_user_credentials() { + pushd /var/ossec/api/configuration/auth/ + if [[ "x${SECURITY_CREDENTIALS_FILE}" == "x" ]]; then + WAZUH_API_USER=${API_USER} + WAZUH_API_PASS=${API_PASS} + else + input=${SECURITY_CREDENTIALS_FILE} + while IFS= read -r line + do + if [[ $line == *"WAZUH_API_USER"* ]]; then + arrIN=(${line//:/ }) + WAZUH_API_USER=${arrIN[1]} + elif [[ $line == *"WAZUH_API_PASS"* ]]; then + arrIN=(${line//:/ }) + WAZUH_API_PASS=${arrIN[1]} + fi + done < "$input" + fi + + echo "Change Wazuh API user credentials" + change_user="node htpasswd -b -c user $WAZUH_API_USER $WAZUH_API_PASS" + eval $change_user + popd +} + + + + +############################################################################## +# Customize filebeat output ip +############################################################################## + + +custom_filebeat_output_ip() { + if [ "$FILEBEAT_OUTPUT" != "" ]; then + sed 's|http://elasticsearch:9200|$FILEBEAT_OUTPUT|g' filebeat.yml + fi +} + + +############################################################################## +# Main function +############################################################################## + +main() { + # Mount permanent data (i.e. ossec.conf) + mount_permanent_data + + # Restore files stored in permanent data that are not permanent (i.e. internal_options.conf) + apply_exclusion_data + + # Remove some files in permanent_data (i.e. .template.db) + remove_data_files + + # Generate ossec-authd certs if AUTO_ENROLLMENT_ENABLED is true and does not exist + if [ $AUTO_ENROLLMENT_ENABLED == true ] + then + if [ ! -e ${WAZUH_INSTALL_PATH}/etc/sslmanager.key ] + then + create_ossec_key_cert + fi + fi + + # Generate API certs if API_GENERATE_CERTS is true and does not exist + if [ $API_GENERATE_CERTS == true ] + then + if [ ! -e ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.crt ] + then + create_api_key_cert + fi + fi + + # Mount selected files (WAZUH_CONFIG_MOUNT) to container + mount_files + + # Trap exit signals and do a proper shutdown + trap "ossec_shutdown; exit" SIGINT SIGTERM + + # Execute custom args + docker_custom_args + + # Change API user credentials + change_api_user_credentials + + # Update filebeat configuration + custom_filebeat_output_ip + + # Delete temporary data folder + rm -rf ${WAZUH_INSTALL_PATH}/data_tmp + + # Grant proper permissions + # When modifiying some files using the Wazuh API (i.e. /var/ossec/etc/ossec.conf), group rw permissions are needed for changes to take place. + # https://github.com/wazuh/wazuh/issues/3647 + chmod -R g+rw ${WAZUH_INSTALL_PATH} +} + +main diff --git a/wazuh/config/data_dirs.env b/wazuh/config/data_dirs.env deleted file mode 100644 index b91f4cc7..00000000 --- a/wazuh/config/data_dirs.env +++ /dev/null @@ -1,15 +0,0 @@ -i=0 -DATA_DIRS[((i++))]="api/configuration" -DATA_DIRS[((i++))]="etc" -DATA_DIRS[((i++))]="logs" -DATA_DIRS[((i++))]="queue/db" -DATA_DIRS[((i++))]="queue/rootcheck" -DATA_DIRS[((i++))]="queue/agent-groups" -DATA_DIRS[((i++))]="queue/agent-info" -DATA_DIRS[((i++))]="queue/agents-timestamp" -DATA_DIRS[((i++))]="queue/agentless" -DATA_DIRS[((i++))]="queue/cluster" -DATA_DIRS[((i++))]="queue/rids" -DATA_DIRS[((i++))]="queue/fts" -DATA_DIRS[((i++))]="var/multigroups" -export DATA_DIRS diff --git a/wazuh/config/entrypoint.sh b/wazuh/config/entrypoint.sh index d8ae1163..36c776bd 100644 --- a/wazuh/config/entrypoint.sh +++ b/wazuh/config/entrypoint.sh @@ -4,7 +4,6 @@ # It will run every .sh script located in entrypoint-scripts folder in lexicographical order for script in `ls /entrypoint-scripts/*.sh | sort -n`; do bash "$script" - done ############################################################################## diff --git a/wazuh/config/filebeat.runit.service b/wazuh/config/filebeat.runit.service index 9b048caa..2a46f7b0 100644 --- a/wazuh/config/filebeat.runit.service +++ b/wazuh/config/filebeat.runit.service @@ -1,4 +1,3 @@ #!/bin/sh -# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service filebeat start tail -f /var/log/filebeat/filebeat diff --git a/wazuh/config/filebeat.yml b/wazuh/config/filebeat.yml index 628e4479..df57ed78 100644 --- a/wazuh/config/filebeat.yml +++ b/wazuh/config/filebeat.yml @@ -50,4 +50,4 @@ output.elasticsearch: hosts: ['http://elasticsearch:9200'] #pipeline: geoip indices: - - index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}' + - index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}' \ No newline at end of file diff --git a/wazuh/config/init.bash b/wazuh/config/init.bash deleted file mode 100644 index e40fab94..00000000 --- a/wazuh/config/init.bash +++ /dev/null @@ -1,11 +0,0 @@ -#!/bin/bash -# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) - -# Initialize the custom data directory layout -source /data_dirs.env - -cd /var/ossec -for ossecdir in "${DATA_DIRS[@]}"; do - mv ${ossecdir} ${ossecdir}-template - ln -s $(realpath --relative-to=$(dirname ${ossecdir}) data)/${ossecdir} ${ossecdir} -done diff --git a/wazuh/config/permanent_data.env b/wazuh/config/permanent_data.env new file mode 100644 index 00000000..2ae1126c --- /dev/null +++ b/wazuh/config/permanent_data.env @@ -0,0 +1,44 @@ +# Permanent data mounted in volumes +i=0 +PERMANENT_DATA[((i++))]="/var/ossec/api/configuration" +PERMANENT_DATA[((i++))]="/var/ossec/etc" +PERMANENT_DATA[((i++))]="/var/ossec/logs" +PERMANENT_DATA[((i++))]="/var/ossec/queue" +PERMANENT_DATA[((i++))]="/var/ossec/var/multigroups" +PERMANENT_DATA[((i++))]="/var/ossec/integrations" +PERMANENT_DATA[((i++))]="/var/ossec/active-response/bin" +PERMANENT_DATA[((i++))]="/etc/filebeat" +PERMANENT_DATA[((i++))]="/etc/postfix" +export PERMANENT_DATA + +# Files mounted in a volume that should not be permanent +i=0 +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/etc/internal_options.conf" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/pagerduty" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/slack" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/slack.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/virustotal" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/virustotal.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/default-firewall-drop.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/disable-account.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/firewalld-drop.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/firewall-drop.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/host-deny.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ip-customblock.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ipfw_mac.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ipfw.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/kaspersky.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/kaspersky.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/npf.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ossec-slack.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ossec-tweeter.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/pf.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/restart-ossec.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/restart.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/route-null.sh" +export PERMANENT_DATA_EXCP + +# Files mounted in a volume that should be deleted +i=0 +PERMANENT_DATA_DEL[((i++))]="/var/ossec/queue/db/.template.db" +export PERMANENT_DATA_DEL \ No newline at end of file diff --git a/wazuh/config/permanent_data.sh b/wazuh/config/permanent_data.sh new file mode 100644 index 00000000..0a08800a --- /dev/null +++ b/wazuh/config/permanent_data.sh @@ -0,0 +1,40 @@ +#!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) + +# Variables +source /permanent_data.env + +WAZUH_INSTALL_PATH=/var/ossec +DATA_TMP_PATH=${WAZUH_INSTALL_PATH}/data_tmp +mkdir ${DATA_TMP_PATH} + +# Move exclusion files to EXCLUSION_PATH +EXCLUSION_PATH=${DATA_TMP_PATH}/exclusion +mkdir ${EXCLUSION_PATH} + +for exclusion_file in "${PERMANENT_DATA_EXCP[@]}"; do + # Create the directory for the exclusion file if it does not exist + DIR=$(dirname "${exclusion_file}") + if [ ! -e ${EXCLUSION_PATH}/${DIR} ] + then + mkdir -p ${EXCLUSION_PATH}/${DIR} + fi + + mv ${exclusion_file} ${EXCLUSION_PATH}/${exclusion_file} +done + +# Move permanent files to PERMANENT_PATH +PERMANENT_PATH=${DATA_TMP_PATH}/permanent +mkdir ${PERMANENT_PATH} + +for permanent_dir in "${PERMANENT_DATA[@]}"; do + # Create the directory for the permanent file if it does not exist + DIR=$(dirname "${permanent_dir}") + if [ ! -e ${PERMANENT_PATH}${DIR} ] + then + mkdir -p ${PERMANENT_PATH}${DIR} + fi + + mv ${permanent_dir} ${PERMANENT_PATH}${permanent_dir} + +done \ No newline at end of file diff --git a/wazuh/config/postfix.runit.service b/wazuh/config/postfix.runit.service index e900b5e5..02856a35 100644 --- a/wazuh/config/postfix.runit.service +++ b/wazuh/config/postfix.runit.service @@ -1,4 +1,3 @@ #!/bin/sh -# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service postfix start tail -f /var/log/mail.log diff --git a/wazuh/config/wazuh-api.runit.service b/wazuh/config/wazuh-api.runit.service index 198fa4a1..a2bce18d 100644 --- a/wazuh/config/wazuh-api.runit.service +++ b/wazuh/config/wazuh-api.runit.service @@ -1,5 +1,4 @@ #!/bin/sh -# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service wazuh-api start -tail -f /var/ossec/data/logs/api.log +tail -f /var/ossec/logs/api.log diff --git a/wazuh/config/wazuh.runit.service b/wazuh/config/wazuh.runit.service index 7ab6f1e1..03c10850 100644 --- a/wazuh/config/wazuh.runit.service +++ b/wazuh/config/wazuh.runit.service @@ -1,5 +1,4 @@ #!/bin/sh -# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service wazuh-manager start -tail -f /var/ossec/data/logs/ossec.log +tail -f /var/ossec/logs/ossec.log