Merge branch '3.9.0_6.7.1' into k8s

This commit is contained in:
Mayte Ariza
2019-05-06 11:56:05 +02:00
10 changed files with 74 additions and 26 deletions
+37 -1
View File
@@ -1,6 +1,43 @@
# Change Log # Change Log
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
## Wazuh Docker v3.9.0_6.7.1
### Added
- Support for xPACK authorized requests ([@manuasir](https://github.com/manuasir)) ([#119](https://github.com/wazuh/wazuh-docker/pull/119))
- Add Elasticsearch cluster configuration ([@SitoRBJ](https://github.com/SitoRBJ)). ([#146](https://github.com/wazuh/wazuh-docker/pull/146))
- Add Elasticsearch cluster configuration ([@Phandora](https://github.com/Phandora)) ([#140](https://github.com/wazuh/wazuh-docker/pull/140))
- Setting Nginx to support several user/passwords in Kibana ([@toniMR](https://github.com/toniMR)) ([#136](https://github.com/wazuh/wazuh-docker/pull/136))
### Changed
- Use LS_JAVA_OPTS instead of old LS_HEAP_SIZE ([@ruffy91](https://github.com/ruffy91)) ([#139](https://github.com/wazuh/wazuh-docker/pull/139))
- Changing the original Wazuh docker image to allow adding code in the entrypoint ([@Phandora](https://github.com/phandora)) ([#151](https://github.com/wazuh/wazuh-docker/pull/151))
### Removed
- Removing files from Wazuh image ([@Phandora](https://github.com/phandora)) ([#153](https://github.com/wazuh/wazuh-docker/pull/153))
## Wazuh Docker v3.8.2_6.7.0
### Changed
- Update Elastic Stack version to 6.7.0. ([#144](https://github.com/wazuh/wazuh-docker/pull/144))
## Wazuh Docker v3.8.2_6.6.2
### Changed
- Update Elastic Stack version to 6.6.2. ([#130](https://github.com/wazuh/wazuh-docker/pull/130))
## Wazuh Docker v3.8.2_6.6.1
### Changed
- Update Elastic Stack version to 6.6.1. ([#129](https://github.com/wazuh/wazuh-docker/pull/129))
## Wazuh Docker v3.8.2_6.5.4 ## Wazuh Docker v3.8.2_6.5.4
### Added ### Added
@@ -12,7 +49,6 @@ All notable changes to this project will be documented in this file.
- Adding env variables for alerts data flow. ([#118](https://github.com/wazuh/wazuh-docker/pull/118)) - Adding env variables for alerts data flow. ([#118](https://github.com/wazuh/wazuh-docker/pull/118))
- New Logstash entrypoint added. ([#135](https://github.com/wazuh/wazuh-docker/pull/135/files)) - New Logstash entrypoint added. ([#135](https://github.com/wazuh/wazuh-docker/pull/135/files))
- Welcome screen management. ([#133](https://github.com/wazuh/wazuh-docker/pull/133)) - Welcome screen management. ([#133](https://github.com/wazuh/wazuh-docker/pull/133))
- Add Elasticsearch cluster configuration. ([#146](https://github.com/wazuh/wazuh-docker/pull/146))
### Changed ### Changed
+4 -3
View File
@@ -11,8 +11,9 @@ In this repository you will find the containers to run:
* wazuh-logstash: It is used to receive alerts generated by the manager and feed Elasticsearch using an alerts template * wazuh-logstash: It is used to receive alerts generated by the manager and feed Elasticsearch using an alerts template
* wazuh-kibana: Provides a web user interface to browse through alerts data. It includes Wazuh plugin for Kibana, that allows you to visualize agents configuration and status. * wazuh-kibana: Provides a web user interface to browse through alerts data. It includes Wazuh plugin for Kibana, that allows you to visualize agents configuration and status.
* wazuh-nginx: Proxies the Kibana container, adding HTTPS (via self-signed SSL certificate) and [Basic authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Basic_authentication_scheme). * wazuh-nginx: Proxies the Kibana container, adding HTTPS (via self-signed SSL certificate) and [Basic authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Basic_authentication_scheme).
* wazuh-elasticsearch: An Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images. **Be aware to increase the `vm.max_map_count` setting, as it's detailed in the [Wazuh documentation](https://documentation.wazuh.com/current/docker/wazuh-container.html#increase-max-map-count-on-your-host-linux).**
In addition, a docker-compose file is provided to launch the containers mentioned above. It also launches an Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images. In addition, a docker-compose file is provided to launch the containers mentioned above.
* Elasticsearch cluster. In the Elasticsearch Dockerfile we can visualize variables to configure an Elasticsearch Cluster. These variables are used in the file *config_cluster.sh* to set them in the *elasticsearch.yml* configuration file. You can see the meaning of the node variables [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html) and other cluster settings [here](https://github.com/elastic/elasticsearch/blob/master/distribution/src/config/elasticsearch.yml). * Elasticsearch cluster. In the Elasticsearch Dockerfile we can visualize variables to configure an Elasticsearch Cluster. These variables are used in the file *config_cluster.sh* to set them in the *elasticsearch.yml* configuration file. You can see the meaning of the node variables [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html) and other cluster settings [here](https://github.com/elastic/elasticsearch/blob/master/distribution/src/config/elasticsearch.yml).
@@ -60,9 +61,9 @@ In addition, a docker-compose file is provided to launch the containers mentione
## Branches ## Branches
* `stable` branch on correspond to the last Wazuh-Docker stable version. * `stable` branch on correspond to the latest Wazuh-Docker stable version.
* `master` branch contains the latest code, be aware of possible bugs on this branch. * `master` branch contains the latest code, be aware of possible bugs on this branch.
* `Wazuh.Version_ElasticStack.Version` (for example 3.7.0_6.4.3) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch. * `Wazuh.Version_ElasticStack.Version` (for example 3.9.0_6.7.1) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch.
## Credits and Thank you ## Credits and Thank you
+2 -2
View File
@@ -1,2 +1,2 @@
WAZUH-DOCKER_VERSION="3.8.2_6.5.4" WAZUH-DOCKER_VERSION="3.9.0_6.7.1"
REVISION="3802" REVISION="3900"
+5 -5
View File
@@ -3,7 +3,7 @@ version: '2'
services: services:
wazuh: wazuh:
image: wazuh/wazuh:3.8.2_6.5.4 image: wazuh/wazuh:3.9.0_6.7.1
hostname: wazuh-manager hostname: wazuh-manager
restart: always restart: always
ports: ports:
@@ -14,7 +14,7 @@ services:
depends_on: depends_on:
- logstash - logstash
logstash: logstash:
image: wazuh/wazuh-logstash:3.8.2_6.5.4 image: wazuh/wazuh-logstash:3.9.0_6.7.1
hostname: logstash hostname: logstash
restart: always restart: always
links: links:
@@ -26,7 +26,7 @@ services:
environment: environment:
- LS_HEAP_SIZE=2048m - LS_HEAP_SIZE=2048m
elasticsearch: elasticsearch:
image: wazuh/wazuh-elasticsearch:3.8.2_6.5.4 image: wazuh/wazuh-elasticsearch:3.9.0_6.7.1
hostname: elasticsearch hostname: elasticsearch
restart: always restart: always
ports: ports:
@@ -43,7 +43,7 @@ services:
hard: -1 hard: -1
mem_limit: 2g mem_limit: 2g
kibana: kibana:
image: wazuh/wazuh-kibana:3.8.2_6.5.4 image: wazuh/wazuh-kibana:3.9.0_6.7.1
hostname: kibana hostname: kibana
restart: always restart: always
depends_on: depends_on:
@@ -52,7 +52,7 @@ services:
- elasticsearch:elasticsearch - elasticsearch:elasticsearch
- wazuh:wazuh - wazuh:wazuh
nginx: nginx:
image: wazuh/wazuh-nginx:3.8.2_6.5.4 image: wazuh/wazuh-nginx:3.9.0_6.7.1
hostname: nginx hostname: nginx
restart: always restart: always
environment: environment:
+3 -3
View File
@@ -1,5 +1,5 @@
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
FROM docker.elastic.co/elasticsearch/elasticsearch:6.5.4 FROM docker.elastic.co/elasticsearch/elasticsearch:6.7.1
ENV ELASTICSEARCH_URL="http://elasticsearch:9200" ENV ELASTICSEARCH_URL="http://elasticsearch:9200"
@@ -13,7 +13,7 @@ ENV XPACK_ML="true"
ENV ENABLE_CONFIGURE_S3="false" ENV ENABLE_CONFIGURE_S3="false"
ENV TEMPLATE_VERSION=v3.8.2 ENV TEMPLATE_VERSION=v3.9.0
# Elasticearch cluster configuration environment variables # Elasticearch cluster configuration environment variables
# If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration # If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration
@@ -39,7 +39,7 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./
RUN chmod +x ./load_settings.sh RUN chmod +x ./load_settings.sh
RUN elasticsearch-plugin install --batch repository-s3 RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.7.1.zip
COPY config/configure_s3.sh ./config/configure_s3.sh COPY config/configure_s3.sh ./config/configure_s3.sh
RUN chmod 755 ./config/configure_s3.sh RUN chmod 755 ./config/configure_s3.sh
+10 -5
View File
@@ -11,8 +11,13 @@ else
wazuh_url="${WAZUH_API_URL}" wazuh_url="${WAZUH_API_URL}"
fi fi
if [ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]; then
auth=""
else
auth="--user ${ELASTICSEARCH_USERNAME}:${ELASTICSEARCH_PASSWORD}"
fi
until curl -XGET $el_url; do until curl ${auth} -XGET $el_url; do
>&2 echo "Elastic is unavailable - sleeping" >&2 echo "Elastic is unavailable - sleeping"
sleep 5 sleep 5
done done
@@ -42,7 +47,7 @@ fi
sed -i 's| "index.refresh_interval": "5s"| "index.refresh_interval": "5s", "number_of_shards" : '"${ALERTS_SHARDS}"', "number_of_replicas" : '"${ALERTS_REPLICAS}"'|' /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json sed -i 's| "index.refresh_interval": "5s"| "index.refresh_interval": "5s", "number_of_shards" : '"${ALERTS_SHARDS}"', "number_of_replicas" : '"${ALERTS_REPLICAS}"'|' /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json
cat /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json | curl -XPUT "$el_url/_template/wazuh" -H 'Content-Type: application/json' -d @- cat /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json | curl -XPUT "$el_url/_template/wazuh" ${auth} -H 'Content-Type: application/json' -d @-
sleep 5 sleep 5
@@ -51,9 +56,9 @@ API_USER_Q=`echo "$API_USER" | tr -d '"'`
API_PASSWORD=`echo -n $API_PASS_Q | base64` API_PASSWORD=`echo -n $API_PASS_Q | base64`
echo "Setting API credentials into Wazuh APP" echo "Setting API credentials into Wazuh APP"
CONFIG_CODE=$(curl -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/wazuh-configuration/1513629884013) CONFIG_CODE=$(curl -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/wazuh-configuration/1513629884013 ${auth})
if [ "x$CONFIG_CODE" = "x404" ]; then if [ "x$CONFIG_CODE" = "x404" ]; then
curl -s -XPOST $el_url/.wazuh/wazuh-configuration/1513629884013 -H 'Content-Type: application/json' -d' curl -s -XPOST $el_url/.wazuh/wazuh-configuration/1513629884013 ${auth} -H 'Content-Type: application/json' -d'
{ {
"api_user": "'"$API_USER_Q"'", "api_user": "'"$API_USER_Q"'",
"api_password": "'"$API_PASSWORD"'", "api_password": "'"$API_PASSWORD"'",
@@ -82,7 +87,7 @@ else
fi fi
sleep 5 sleep 5
curl -XPUT "$el_url/_cluster/settings" -H 'Content-Type: application/json' -d' curl -XPUT "$el_url/_cluster/settings" ${auth} -H 'Content-Type: application/json' -d'
{ {
"persistent": { "persistent": {
"xpack.monitoring.collection.enabled": true "xpack.monitoring.collection.enabled": true
+2 -2
View File
@@ -1,6 +1,6 @@
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
FROM docker.elastic.co/kibana/kibana:6.5.4 FROM docker.elastic.co/kibana/kibana:6.7.1
ARG WAZUH_APP_VERSION=3.8.2_6.5.4 ARG WAZUH_APP_VERSION=3.9.0_6.7.1
USER root USER root
ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp
+8 -2
View File
@@ -13,8 +13,14 @@ else
el_url="${ELASTICSEARCH_URL}" el_url="${ELASTICSEARCH_URL}"
fi fi
until curl -XGET $el_url; do if [ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]; then
>&2 echo "Elastic is unavailable - sleeping." auth=""
else
auth="--user ${ELASTICSEARCH_USERNAME}:${ELASTICSEARCH_PASSWORD}"
fi
until curl -XGET $el_url ${auth}; do
>&2 echo "Elastic is unavailable - sleeping"
sleep 5 sleep 5
done done
+1 -1
View File
@@ -1,5 +1,5 @@
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
FROM docker.elastic.co/logstash/logstash:6.5.4 FROM docker.elastic.co/logstash/logstash:6.7.0
COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh
+2 -2
View File
@@ -1,7 +1,7 @@
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) # Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
FROM phusion/baseimage:latest FROM phusion/baseimage:latest
ARG FILEBEAT_VERSION=6.5.4 ARG FILEBEAT_VERSION=6.7.0
ARG WAZUH_VERSION=3.8.2-1 ARG WAZUH_VERSION=3.9.0-1
ENV API_USER="foo" \ ENV API_USER="foo" \
API_PASS="bar" API_PASS="bar"