From 0fe3103940a988b48b174e4b12dee6e60ce4072c Mon Sep 17 00:00:00 2001 From: Victor Carlos Erenu Date: Tue, 28 Oct 2025 01:09:49 +0700 Subject: [PATCH 1/7] Bring changes from PR #2054 --- .../Procedure_push_docker_images.yml | 81 +++++++++---------- build-docker-images/build-images.sh | 57 ++++++++++--- build-docker-images/build-images.yml | 8 +- 3 files changed, 87 insertions(+), 59 deletions(-) diff --git a/.github/workflows/Procedure_push_docker_images.yml b/.github/workflows/Procedure_push_docker_images.yml index 28fcf085..bf45b917 100644 --- a/.github/workflows/Procedure_push_docker_images.yml +++ b/.github/workflows/Procedure_push_docker_images.yml @@ -11,10 +11,6 @@ on: docker_reference: description: 'wazuh-docker reference' required: true - products: - description: 'Comma-separated list of the image names to build and push' - default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' - required: true filebeat_module_version: description: 'Filebeat module version' default: '0.4' @@ -23,11 +19,6 @@ on: description: 'Package revision' default: '1' required: true - push_images: - description: 'Push images' - type: boolean - default: true - required: true id: description: "ID used to identify the workflow uniquely." type: string @@ -48,11 +39,6 @@ on: description: 'wazuh-docker reference' required: false type: string - products: - description: 'Comma-separated list of the image names to build and push' - default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' - required: true - type: string filebeat_module_version: description: 'Filebeat module version' default: '0.4' @@ -63,11 +49,6 @@ on: default: '1' required: true type: string - push_images: - description: 'Push images' - type: boolean - default: true - required: true id: description: "ID used to identify the workflow uniquely." type: string @@ -82,6 +63,16 @@ jobs: build-and-push: runs-on: ubuntu-22.04 + permissions: + id-token: write + contents: read + + env: + IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }} + IMAGE_TAG: ${{ inputs.image_tag }} + FILEBEAT_MODULE_VERSION: ${{ inputs.filebeat_module_version }} + REVISION: ${{ inputs.revision }} + steps: - name: Print inputs run: | @@ -96,10 +87,8 @@ jobs: echo "* id: ${{ inputs.id }}" echo "* image_tag: ${{ inputs.image_tag }}" echo "* docker_reference: ${{ inputs.docker_reference }}" - echo "* products: ${{ inputs.products }}" echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}" echo "* revision: ${{ inputs.revision }}" - echo "* push_images: ${{ inputs.push_images }}" echo "* dev: ${{ inputs.dev }}" echo "---------------------------------------------" @@ -108,7 +97,28 @@ jobs: with: ref: ${{ inputs.docker_reference }} + - name: free disk space + uses: ./.github/free-disk-space + + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Configure aws credentials + if: ${{ inputs.dev == true }} + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }} + aws-region: "${{ secrets.AWS_REGION }}" + + - name: Log in to Amazon ECR + if: ${{ inputs.dev == true }} + uses: aws-actions/amazon-ecr-login@v2 + - name: Log in to Docker Hub + if: ${{ inputs.dev == false }} uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} @@ -116,7 +126,7 @@ jobs: - name: Build Wazuh images run: | - IMAGE_TAG=${{ inputs.image_tag }} + IMAGE_TAG="${{ inputs.image_tag }}" FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }} REVISION=${{ inputs.revision }} @@ -128,13 +138,13 @@ jobs: fi DEV_STAGE=${tokens[1]} WAZUH_VER=${tokens[0]} - ./build-docker-images/build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION + ./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m else - ./build-docker-images/build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION + ./build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m fi # Save .env file (generated by build-images.sh) contents to $GITHUB_ENV - ENV_FILE_PATH=".env" + ENV_FILE_PATH="../.env" if [ -f $ENV_FILE_PATH ]; then while IFS= read -r line || [ -n "$line" ]; do @@ -144,18 +154,18 @@ jobs: echo "The environment file $ENV_FILE_PATH does not exist!" exit 1 fi + working-directory: ./build-docker-images - name: Image exists validation - if: ${{ inputs.push_images }} id: validation run: | IMAGE_TAG=${{ inputs.image_tag }} PURPOSE="" if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then - if docker manifest inspect wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then + if docker manifest inspect $IMAGE_REGISTRY/wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then PURPOSE="regeneration" - echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'" + echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'" else PURPOSE="new release" echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'" @@ -170,21 +180,8 @@ jobs: echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT - - name: Tag and Push Wazuh images - if: ${{ inputs.push_images }} - run: | - IMAGE_TAG="${{ inputs.image_tag }}$( [ "${{ inputs.dev }}" == "true" ] && echo '-dev' || true )" - IMAGE_NAMES=${{ inputs.products }} - IFS=',' read -r -a images <<< "$IMAGE_NAMES" - for image in "${images[@]}"; do - echo "Tagging and pushing wazuh/$image:${WAZUH_VERSION} to wazuh/$image:$IMAGE_TAG" - docker tag wazuh/$image:${WAZUH_VERSION} wazuh/$image:$IMAGE_TAG - echo "Pushing wazuh/$image:$IMAGE_TAG ..." - docker push wazuh/$image:$IMAGE_TAG - done - - name: GH issue notification - if: ${{ inputs.push_images && steps.validation.outputs.purpose != '' }} + if: ${{ steps.validation.outputs.purpose != '' }} run: | IMAGE_TAG=${{ inputs.image_tag }} GH_TITLE="" diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 2cec68c8..f57d4878 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,8 +1,6 @@ -WAZUH_IMAGE_VERSION=4.14.3 -WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') -WAZUH_TAG_REVISION=1 +IMAGE_TAG=4.14.3 WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') -IMAGE_VERSION=${WAZUH_IMAGE_VERSION} +WAZUH_REGISTRY=docker.io # Wazuh package generator # Copyright (C) 2023, Wazuh Inc. @@ -44,7 +42,7 @@ build() { if [ "${WAZUH_DEV_STAGE}" ];then FILEBEAT_TEMPLATE_BRANCH="v${FILEBEAT_TEMPLATE_BRANCH}-${WAZUH_DEV_STAGE,,}" if ! curl --output /dev/null --silent --head --fail "https://github.com/wazuh/wazuh/tree/${FILEBEAT_TEMPLATE_BRANCH}"; then - echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" + echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" clean 1 fi else @@ -58,15 +56,25 @@ build() { fi fi - echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > .env - echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> .env - echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> .env - echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> .env - echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> .env - echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> .env - docker compose -f build-docker-images/build-images.yml --env-file .env build --no-cache || clean 1 + echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > ../.env + echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> ../.env + echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> ../.env + echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> ../.env + echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> ../.env + echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> ../.env + echo WAZUH_REGISTRY=$WAZUH_REGISTRY >> ../.env + echo IMAGE_TAG=$IMAGE_TAG >> ../.env + set -a + source ../.env + set +a + + if [ "${MULTIARCH}" ];then + docker buildx bake --file build-images.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + else + docker buildx bake --file build-images.yml --no-cache|| clean 1 + fi return 0 } @@ -79,7 +87,10 @@ help() { echo " -d, --dev [Optional] Set the development stage you want to build, example alpha0 or beta1, not used by default." echo " -f, --filebeat-module [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}." echo " -r, --revision [Optional] Package revision. By default ${WAZUH_TAG_REVISION}" + echo " -ref, --reference [Optional] Set the Wazuh reference to build development images. By default, the latest stable release." + echo " -rg, --registry [Optional] Set the Docker registry to push the images." echo " -v, --version [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}." + echo " -m, --multiarch [Optional] Enable multi-architecture builds." echo " -h, --help Show this help." echo exit $1 @@ -110,6 +121,10 @@ main() { help 1 fi ;; + "-m"|"--multiarch") + MULTIARCH="true" + shift + ;; "-r"|"--revision") if [ -n "${2}" ]; then WAZUH_TAG_REVISION="${2}" @@ -118,6 +133,22 @@ main() { help 1 fi ;; + "-ref"|"--reference") + if [ -n "${2}" ]; then + WAZUH_TAG_REFERENCE="${2}" + shift 2 + else + help 1 + fi + ;; + "-rg"|"--registry") + if [ -n "${2}" ]; then + WAZUH_REGISTRY="${2}" + shift 2 + else + help 1 + fi + ;; "-v"|"--version") if [ -n "$2" ]; then WAZUH_IMAGE_VERSION="$2" @@ -136,4 +167,4 @@ main() { clean 0 } -main "$@" +main "$@" \ No newline at end of file diff --git a/build-docker-images/build-images.yml b/build-docker-images/build-images.yml index ed784cec..b77669ca 100644 --- a/build-docker-images/build-images.yml +++ b/build-docker-images/build-images.yml @@ -8,7 +8,7 @@ services: WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} FILEBEAT_TEMPLATE_BRANCH: ${FILEBEAT_TEMPLATE_BRANCH} WAZUH_FILEBEAT_MODULE: ${WAZUH_FILEBEAT_MODULE} - image: wazuh/wazuh-manager:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-manager:${IMAGE_TAG} hostname: wazuh.manager restart: always ports: @@ -40,7 +40,7 @@ services: args: WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} - image: wazuh/wazuh-agent:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-agent:${IMAGE_TAG} hostname: wazuh.agent restart: always @@ -50,7 +50,7 @@ services: args: WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} - image: wazuh/wazuh-indexer:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-indexer:${IMAGE_TAG} hostname: wazuh.indexer restart: always ports: @@ -72,7 +72,7 @@ services: WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} WAZUH_UI_REVISION: ${WAZUH_UI_REVISION} - image: wazuh/wazuh-dashboard:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-dashboard:${IMAGE_TAG} hostname: wazuh.dashboard restart: always ports: From 08c7cbda5330e27b3ae5c5a139da9d3400dcba59 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Fri, 5 Dec 2025 13:59:53 -0500 Subject: [PATCH 2/7] Modify to build certs gen image --- indexer-certs-creator/build-image.sh | 100 ++++++++++++++++++++++++++ indexer-certs-creator/build-image.yml | 8 +++ 2 files changed, 108 insertions(+) create mode 100755 indexer-certs-creator/build-image.sh create mode 100644 indexer-certs-creator/build-image.yml diff --git a/indexer-certs-creator/build-image.sh b/indexer-certs-creator/build-image.sh new file mode 100755 index 00000000..3fd4c386 --- /dev/null +++ b/indexer-certs-creator/build-image.sh @@ -0,0 +1,100 @@ +#!/bin/bash + +# Wazuh package generator +# Copyright (C) 2023, Wazuh Inc. +# +# This program is a free software; you can redistribute it +# and/or modify it under the terms of the GNU General Public +# License (version 2) as published by the FSF - Free Software +# Foundation. + +WAZUH_CERTS_IMAGE_VERSION="0.0.4" +WAZUH_REGISTRY="docker.io" + +# ----------------------------------------------------------------------------- + +trap ctrl_c INT + +clean() { + exit_code=$1 + exit ${exit_code} +} + +ctrl_c() { + clean 1 +} + +# ----------------------------------------------------------------------------- + +build() { + IMAGE_TAG="${WAZUH_CERTS_IMAGE_VERSION}" + + echo WAZUH_REGISTRY=$WAZUH_REGISTRY > .env + echo IMAGE_TAG=$IMAGE_TAG >> .env + + set -a + source .env + set +a + + if [ "${MULTIARCH}" ]; then + docker buildx bake --file build-image.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + else + docker buildx bake --file build-image.yml --no-cache || clean 1 + fi + return 0 +} + +# ----------------------------------------------------------------------------- + +help() { + echo + echo "Usage: $0 [OPTIONS]" + echo + echo " -v, --version [Optional] Set the image version. By default ${WAZUH_CERTS_IMAGE_VERSION}." + echo " -rg, --registry [Optional] Set the Docker registry to push the images." + echo " -m, --multiarch [Optional] Enable multi-architecture builds." + echo " -h, --help Show this help." + echo + exit $1 +} + +# ----------------------------------------------------------------------------- + +main() { + while [ -n "${1}" ] + do + case "${1}" in + "-h"|"--help") + help 0 + ;; + "-m"|"--multiarch") + MULTIARCH="true" + shift + ;; + "-rg"|"--registry") + if [ -n "${2}" ]; then + WAZUH_REGISTRY="${2}" + shift 2 + else + help 1 + fi + ;; + "-v"|"--version") + if [ -n "$2" ]; then + WAZUH_CERTS_IMAGE_VERSION="$2" + shift 2 + else + help 1 + fi + ;; + *) + help 1 + esac + done + + build || clean 1 + + clean 0 +} + +main "$@" \ No newline at end of file diff --git a/indexer-certs-creator/build-image.yml b/indexer-certs-creator/build-image.yml new file mode 100644 index 00000000..58bb13cf --- /dev/null +++ b/indexer-certs-creator/build-image.yml @@ -0,0 +1,8 @@ +# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) +services: + wazuh.certs.generator: + build: + context: . + dockerfile: Dockerfile + image: ${WAZUH_REGISTRY}/wazuh/wazuh-certs-generator:${IMAGE_TAG} + hostname: wazuh-certs-generator From 6675465180e551dbf14dd0f043c51b750a48d9f6 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Thu, 4 Dec 2025 10:39:15 -0500 Subject: [PATCH 3/7] Adapt manager Dockerfile for multi-architecture builds --- build-docker-images/wazuh-manager/Dockerfile | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/build-docker-images/wazuh-manager/Dockerfile b/build-docker-images/wazuh-manager/Dockerfile index 73c86396..7591cc3c 100644 --- a/build-docker-images/wazuh-manager/Dockerfile +++ b/build-docker-images/wazuh-manager/Dockerfile @@ -11,6 +11,7 @@ ARG FILEBEAT_VERSION=7.10.2 ARG FILEBEAT_REVISION=2 ARG WAZUH_FILEBEAT_MODULE ARG S6_VERSION="v2.2.0.3" +ARG TARGETARCH RUN yum install curl-minimal xz gnupg tar gzip openssl findutils procps -y &&\ yum clean all @@ -27,11 +28,13 @@ RUN yum install wazuh-manager-${WAZUH_VERSION}-${WAZUH_TAG_REVISION} -y && \ chmod 775 /filebeat_module.sh && \ source /filebeat_module.sh && \ rm /filebeat_module.sh && \ - curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-amd64.tar.gz \ - -o /tmp/s6-overlay-amd64.tar.gz && \ - tar xzf /tmp/s6-overlay-amd64.tar.gz -C / --exclude="./bin" && \ - tar xzf /tmp/s6-overlay-amd64.tar.gz -C /usr ./bin && \ - rm /tmp/s6-overlay-amd64.tar.gz && \ + S6_ARCH="amd64" && \ + if [ "${TARGETARCH}" = "arm64" ]; then S6_ARCH="aarch64"; fi && \ + curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-${S6_ARCH}.tar.gz \ + -o /tmp/s6-overlay-${S6_ARCH}.tar.gz && \ + tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C / --exclude="./bin" && \ + tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C /usr ./bin && \ + rm /tmp/s6-overlay-${S6_ARCH}.tar.gz && \ rm -f /var/ossec/etc/sslmanager.key && \ rm -f /var/ossec/etc/sslmanager.cert From c6a427af707cfbb4eb1761a4c70bc17d529c924d Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Fri, 12 Dec 2025 12:44:21 -0500 Subject: [PATCH 4/7] Update documentation of certs-gen procedure --- indexer-certs-creator/README.md | 28 +++++++++++++++++++++++----- indexer-certs-creator/build-image.sh | 4 +++- 2 files changed, 26 insertions(+), 6 deletions(-) diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md index 8ddccdf5..04808a5d 100644 --- a/indexer-certs-creator/README.md +++ b/indexer-certs-creator/README.md @@ -1,9 +1,27 @@ -# Certificate creation image build +# Certificate Creation Image Build -The dockerfile hosted in this directory is used to build the image used to boot Wazuh's single node and multi node stacks. +The dockerfile hosted in this directory is used to build the image required for generating Wazuh Docker single-node and multi-node certificate files -To create the image, the following command must be executed: +## Pre-requisites +### QEMU + +Set up QEMU to enable building multi-architecture Docker images + +Useful documentation: + +- https://www.qemu.org/download/ +- https://docs.docker.com/build/building/multi-platform/#qemu + +## Procedure + +Run the following script to build the wazuh-certs-generator docker image + +```console +./build-image.sh -v [-m] [-rg ] ``` -$ docker build -t wazuh/wazuh-certs-generator:0.0.3 . -``` + +Replace with the new image desired tag. +Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`) +Use the `-rg ` parameter to specify a custom Docker registry (default is Docker Hub) + By default, the script will attempt to push the image to the registry and will only work if credentials are properly configured. diff --git a/indexer-certs-creator/build-image.sh b/indexer-certs-creator/build-image.sh index 3fd4c386..925d15a6 100755 --- a/indexer-certs-creator/build-image.sh +++ b/indexer-certs-creator/build-image.sh @@ -37,7 +37,9 @@ build() { set +a if [ "${MULTIARCH}" ]; then - docker buildx bake --file build-image.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + docker buildx bake --file build-image.yml \ + --set *.platform=linux/amd64,linux/arm64 \ + --no-cache || clean 1 else docker buildx bake --file build-image.yml --no-cache || clean 1 fi From a509f0f8ea18f1d158de24669fb6c20bffee2348 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Fri, 5 Dec 2025 08:51:05 -0500 Subject: [PATCH 5/7] Add changelog --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3b393f0f..e4b8a6b0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,7 +9,7 @@ All notable changes to this project will be documented in this file. ### Changed -- None +- Adapt to multi architecture build ([#2120](https://github.com/wazuh/wazuh-docker/pull/2120)) ### Fixed From 089ce24ffc85bf154932cbf222c1715ee6065847 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Mon, 15 Dec 2025 13:45:38 -0500 Subject: [PATCH 6/7] Enhance script execution of build and improve docs clarity --- build-docker-images/build-images.sh | 15 +++++++++++---- indexer-certs-creator/README.md | 8 ++++---- indexer-certs-creator/build-image.sh | 11 ++++++++--- 3 files changed, 23 insertions(+), 11 deletions(-) diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index f57d4878..00eb853f 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -42,7 +42,7 @@ build() { if [ "${WAZUH_DEV_STAGE}" ];then FILEBEAT_TEMPLATE_BRANCH="v${FILEBEAT_TEMPLATE_BRANCH}-${WAZUH_DEV_STAGE,,}" if ! curl --output /dev/null --silent --head --fail "https://github.com/wazuh/wazuh/tree/${FILEBEAT_TEMPLATE_BRANCH}"; then - echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" + echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" clean 1 fi else @@ -71,9 +71,16 @@ build() { set +a if [ "${MULTIARCH}" ];then - docker buildx bake --file build-images.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + docker buildx bake \ + --file build-images.yml \ + --push \ + --set *.platform=linux/amd64,linux/arm64 \ + --no-cache || clean 1 else - docker buildx bake --file build-images.yml --no-cache|| clean 1 + docker buildx bake \ + --file build-images.yml \ + --load \ + --no-cache || clean 1 fi return 0 } @@ -167,4 +174,4 @@ main() { clean 0 } -main "$@" \ No newline at end of file +main "$@" diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md index 04808a5d..d9b20bf7 100644 --- a/indexer-certs-creator/README.md +++ b/indexer-certs-creator/README.md @@ -21,7 +21,7 @@ Run the following script to build the wazuh-certs-generator docker image ./build-image.sh -v [-m] [-rg ] ``` -Replace with the new image desired tag. -Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`) -Use the `-rg ` parameter to specify a custom Docker registry (default is Docker Hub) - By default, the script will attempt to push the image to the registry and will only work if credentials are properly configured. +- Replace with the new image desired tag. +- Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`) + - If multiarch build is enabled, the script will attempt to push the image to the specified registry. This image upload will only work if credentials are properly configured. +- Use the `-rg ` parameter to specify a custom Docker registry (default is Docker Hub) diff --git a/indexer-certs-creator/build-image.sh b/indexer-certs-creator/build-image.sh index 925d15a6..afa0eea2 100755 --- a/indexer-certs-creator/build-image.sh +++ b/indexer-certs-creator/build-image.sh @@ -37,11 +37,16 @@ build() { set +a if [ "${MULTIARCH}" ]; then - docker buildx bake --file build-image.yml \ + docker buildx bake \ + --file build-image.yml \ --set *.platform=linux/amd64,linux/arm64 \ + --push \ --no-cache || clean 1 else - docker buildx bake --file build-image.yml --no-cache || clean 1 + docker buildx bake \ + --file build-image.yml \ + --load \ + --no-cache || clean 1 fi return 0 } @@ -99,4 +104,4 @@ main() { clean 0 } -main "$@" \ No newline at end of file +main "$@" From f51fc2e4ae7f76c4256e7b32cce3025cd94d2d4a Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Wed, 17 Dec 2025 12:10:46 -0500 Subject: [PATCH 7/7] Add check (input.dev must be false) for image validation and GH issue notification in push workflow --- .github/workflows/Procedure_push_docker_images.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/Procedure_push_docker_images.yml b/.github/workflows/Procedure_push_docker_images.yml index bf45b917..57871a29 100644 --- a/.github/workflows/Procedure_push_docker_images.yml +++ b/.github/workflows/Procedure_push_docker_images.yml @@ -157,6 +157,7 @@ jobs: working-directory: ./build-docker-images - name: Image exists validation + if: ${{ inputs.dev == false }} id: validation run: | IMAGE_TAG=${{ inputs.image_tag }} @@ -181,7 +182,7 @@ jobs: echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT - name: GH issue notification - if: ${{ steps.validation.outputs.purpose != '' }} + if: ${{ inputs.dev == false && steps.validation.outputs.purpose != '' }} run: | IMAGE_TAG=${{ inputs.image_tag }} GH_TITLE=""