Change UID and GID of owner users

This commit is contained in:
Victor Carlos Erenu
2026-05-12 21:04:22 +07:00
parent 388b2c2225
commit c137354203
6 changed files with 55 additions and 38 deletions
+8 -5
View File
@@ -38,25 +38,28 @@ RUN curl --fail --silent -L \
################################################################################ ################################################################################
FROM amazonlinux:2023 FROM amazonlinux:2023
ARG WAZUH_UID=101
ARG WAZUH_GID=101
RUN rm /bin/sh && ln -s /bin/bash /bin/sh RUN rm /bin/sh && ln -s /bin/bash /bin/sh
# Install only runtime dependencies # Install only runtime dependencies
RUN dnf install procps shadow-utils -y && \ RUN dnf install procps shadow-utils -y && \
dnf clean all && \ dnf clean all && \
getent group wazuh || groupadd -r -g 999 wazuh && \ getent group wazuh || groupadd -r -g ${WAZUH_GID} wazuh && \
getent passwd wazuh || useradd --system \ getent passwd wazuh || useradd --system \
--uid 999 \
--no-create-home \ --no-create-home \
--home-dir /var/ossec \ --home-dir /var/ossec \
--gid wazuh \ --uid ${WAZUH_UID} \
--gid ${WAZUH_GID} \
--shell /sbin/nologin \ --shell /sbin/nologin \
wazuh wazuh
# Copy Wazuh Agent installation from builder # Copy Wazuh Agent installation from builder
COPY --from=builder /var/ossec /var/ossec COPY --from=builder --chown=${WAZUH_UID}:${WAZUH_GID} /var/ossec /var/ossec
# Copy tini static binary # Copy tini static binary
COPY --from=builder /usr/local/bin/tini /usr/local/bin/tini COPY --from=builder --chown=${WAZUH_UID}:${WAZUH_GID} /usr/local/bin/tini /usr/local/bin/tini
# Copy entrypoint and init scripts # Copy entrypoint and init scripts
COPY config/entrypoint.sh /entrypoint.sh COPY config/entrypoint.sh /entrypoint.sh
@@ -34,6 +34,9 @@ RUN setcap 'cap_net_bind_service=-ep' /usr/share/wazuh-dashboard/node/bin/node
################################################################################ ################################################################################
FROM amazonlinux:2023 FROM amazonlinux:2023
ARG WAZUH_UID=101
ARG WAZUH_GID=101
# Set environment variables # Set environment variables
ENV USER="wazuh-dashboard" \ ENV USER="wazuh-dashboard" \
GROUP="wazuh-dashboard" \ GROUP="wazuh-dashboard" \
@@ -60,9 +63,9 @@ COPY config/wazuh_dashboard_config.sh /
# Update and install dependencies # Update and install dependencies
RUN yum install shadow-utils -y && \ RUN yum install shadow-utils -y && \
yum clean all && \ yum clean all && \
getent group $GROUP || groupadd -r -g 1000 $GROUP && \ getent group $GROUP || groupadd -r -g ${WAZUH_GID} $GROUP && \
useradd --system \ useradd --system \
--uid 1000 \ --uid ${WAZUH_UID} \
--no-create-home \ --no-create-home \
--home-dir $INSTALL_DIR \ --home-dir $INSTALL_DIR \
--gid $GROUP \ --gid $GROUP \
@@ -72,13 +75,13 @@ RUN yum install shadow-utils -y && \
chmod 700 /entrypoint.sh && \ chmod 700 /entrypoint.sh && \
chmod 700 /wazuh_dashboard_config.sh && \ chmod 700 /wazuh_dashboard_config.sh && \
mkdir -p $INSTALL_DIR && \ mkdir -p $INSTALL_DIR && \
chown 1000:1000 $INSTALL_DIR && \ chown ${WAZUH_UID}:${WAZUH_GID} $INSTALL_DIR && \
chown 1000:1000 /*.sh && \ chown ${WAZUH_UID}:${WAZUH_GID} /*.sh && \
mkdir -p /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom mkdir -p /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom
# Copy Install dir from builder to current image # Copy Install dir from builder to current image
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR COPY --from=builder --chown=${WAZUH_UID}:${WAZUH_GID} $INSTALL_DIR $INSTALL_DIR
COPY --from=builder --chown=1000:1000 /etc/wazuh-dashboard $INSTALL_DIR/config/ COPY --from=builder --chown=${WAZUH_UID}:${WAZUH_GID} /etc/wazuh-dashboard $INSTALL_DIR/config/
# Set workdir and user # Set workdir and user
WORKDIR $INSTALL_DIR WORKDIR $INSTALL_DIR
+13 -10
View File
@@ -29,6 +29,9 @@ RUN RPM_ARCH="x86_64" && \
################################################################################ ################################################################################
FROM amazonlinux:2023 FROM amazonlinux:2023
ARG WAZUH_UID=101
ARG WAZUH_GID=101
ENV USER="wazuh-indexer" \ ENV USER="wazuh-indexer" \
GROUP="wazuh-indexer" \ GROUP="wazuh-indexer" \
NAME="wazuh-indexer" \ NAME="wazuh-indexer" \
@@ -41,25 +44,25 @@ COPY config/securityadmin.sh /
RUN yum install curl-minimal shadow-utils findutils hostname -y && \ RUN yum install curl-minimal shadow-utils findutils hostname -y && \
yum clean all && \ yum clean all && \
getent group $GROUP || groupadd -r -g 1000 $GROUP && \ getent group $GROUP || groupadd -r -g ${WAZUH_GID} $GROUP && \
useradd --system \ useradd --system \
--uid 1000 \ --uid ${WAZUH_UID} \
--no-create-home \ --no-create-home \
--home-dir $INSTALL_DIR \ --home-dir $INSTALL_DIR \
--gid $GROUP \ --gid ${WAZUH_GID} \
--shell /sbin/nologin \ --shell /sbin/nologin \
--comment "$USER user" \ --comment "$USER user" \
$USER && \ $USER && \
chmod 700 /entrypoint.sh && chmod 700 /securityadmin.sh && \ chmod 700 /entrypoint.sh && chmod 700 /securityadmin.sh && \
mkdir -p $INSTALL_DIR && \ mkdir -p $INSTALL_DIR && \
chown 1000:1000 $INSTALL_DIR && \ chown ${WAZUH_UID}:${WAZUH_GID} $INSTALL_DIR && \
chown 1000:1000 /*.sh && \ chown ${WAZUH_UID}:${WAZUH_GID} /*.sh && \
mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer && \ mkdir -p /var/lib/wazuh-indexer && chown ${WAZUH_UID}:${WAZUH_GID} /var/lib/wazuh-indexer && \
mkdir -p $INSTALL_DIR/logs && chown 1000:1000 $INSTALL_DIR/logs && \ mkdir -p $INSTALL_DIR/logs && chown ${WAZUH_UID}:${WAZUH_GID} $INSTALL_DIR/logs && \
mkdir -p /run/wazuh-indexer && chown 1000:1000 /run/wazuh-indexer && \ mkdir -p /run/wazuh-indexer && chown ${WAZUH_UID}:${WAZUH_GID} /run/wazuh-indexer && \
mkdir -p /var/log/wazuh-indexer && chown 1000:1000 /var/log/wazuh-indexer mkdir -p /var/log/wazuh-indexer && chown ${WAZUH_UID}:${WAZUH_GID} /var/log/wazuh-indexer
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR COPY --from=builder --chown=${WAZUH_UID}:${WAZUH_GID} $INSTALL_DIR $INSTALL_DIR
RUN chmod 700 $INSTALL_DIR && \ RUN chmod 700 $INSTALL_DIR && \
chmod 700 $INSTALL_DIR/config && \ chmod 700 $INSTALL_DIR/config && \
+8 -5
View File
@@ -53,25 +53,28 @@ RUN curl --fail --silent -L \
################################################################################ ################################################################################
FROM amazonlinux:2023 FROM amazonlinux:2023
ARG WAZUH_UID=101
ARG WAZUH_GID=101
RUN rm /bin/sh && ln -s /bin/bash /bin/sh RUN rm /bin/sh && ln -s /bin/bash /bin/sh
# Install only runtime dependencies (no curl, tar, gzip, xz, or full dnf stack) # Install only runtime dependencies (no curl, tar, gzip, xz, or full dnf stack)
RUN dnf install openssl findutils procps shadow-utils -y && \ RUN dnf install openssl findutils procps shadow-utils -y && \
dnf clean all && \ dnf clean all && \
getent group wazuh-manager || groupadd -r -g 999 wazuh-manager && \ getent group wazuh-manager || groupadd -r -g ${WAZUH_GID} wazuh-manager && \
getent passwd wazuh-manager || useradd --system \ getent passwd wazuh-manager || useradd --system \
--uid 999 \
--no-create-home \ --no-create-home \
--home-dir /var/wazuh-manager \ --home-dir /var/wazuh-manager \
--gid wazuh-manager \ --uid ${WAZUH_UID} \
--gid ${WAZUH_GID} \
--shell /sbin/nologin \ --shell /sbin/nologin \
wazuh-manager wazuh-manager
# Copy Wazuh Manager installation (includes permanent data snapshot) # Copy Wazuh Manager installation (includes permanent data snapshot)
COPY --from=builder /var/wazuh-manager /var/wazuh-manager COPY --from=builder --chown=${WAZUH_UID}:${WAZUH_GID} /var/wazuh-manager /var/wazuh-manager
# Copy tini static binary # Copy tini static binary
COPY --from=builder /usr/local/bin/tini /usr/local/bin/tini COPY --from=builder --chown=${WAZUH_UID}:${WAZUH_GID} /usr/local/bin/tini /usr/local/bin/tini
# Copy entrypoint, init scripts and runtime config # Copy entrypoint, init scripts and runtime config
COPY config/entrypoint.sh /entrypoint.sh COPY config/entrypoint.sh /entrypoint.sh
@@ -252,9 +252,9 @@ configure_permissions() {
############################################################################## ##############################################################################
set_correct_permOwner() { set_correct_permOwner() {
find /var/wazuh-manager/ -group 997 -exec chown :999 {} +; find /var/wazuh-manager/ -group 997 -exec chown :101 {} +;
find /var/wazuh-manager/ -group 101 -exec chown :999 {} +; find /var/wazuh-manager/ -group 999 -exec chown :101 {} +;
find /var/wazuh-manager/ -user 101 -exec chown 999 {} +; find /var/wazuh-manager/ -user 999 -exec chown 101:{} {} +;
} }
############################################################################## ##############################################################################
+14 -9
View File
@@ -77,6 +77,8 @@ node_to_dir() {
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
# Parse config.yml # Parse config.yml
export WAZUH_UID=101
export WAZUH_GID=101
if $DO_COPY || $DO_PRIV; then if $DO_COPY || $DO_PRIV; then
if [ ! -f "$CONFIG_FILE" ]; then if [ ! -f "$CONFIG_FILE" ]; then
echo "Error: Configuration file $CONFIG_FILE not found." echo "Error: Configuration file $CONFIG_FILE not found."
@@ -102,7 +104,6 @@ if $DO_COPY; then
echo "Copying certificates for indexer: $node -> config/$dir_name/certs/" echo "Copying certificates for indexer: $node -> config/$dir_name/certs/"
mkdir -p "./config/$dir_name/certs" mkdir -p "./config/$dir_name/certs"
cp "$OUTPUT_DIR/${node}"* "./config/$dir_name/certs/" cp "$OUTPUT_DIR/${node}"* "./config/$dir_name/certs/"
cp "$OUTPUT_DIR"/root-ca* "./config/$dir_name/certs/"
if $FIRST_INDEXER; then if $FIRST_INDEXER; then
cp "$OUTPUT_DIR"/admin* "./config/$dir_name/certs/" cp "$OUTPUT_DIR"/admin* "./config/$dir_name/certs/"
FIRST_INDEXER=false FIRST_INDEXER=false
@@ -114,7 +115,6 @@ if $DO_COPY; then
echo "Copying certificates for manager: $node -> config/$dir_name/certs/" echo "Copying certificates for manager: $node -> config/$dir_name/certs/"
mkdir -p "./config/$dir_name/certs" mkdir -p "./config/$dir_name/certs"
cp "$OUTPUT_DIR/${node}"* "./config/$dir_name/certs/" cp "$OUTPUT_DIR/${node}"* "./config/$dir_name/certs/"
cp "$OUTPUT_DIR"/root-ca* "./config/$dir_name/certs/"
done done
for node in "${DASHBOARD_NODES[@]}"; do for node in "${DASHBOARD_NODES[@]}"; do
@@ -122,32 +122,37 @@ if $DO_COPY; then
echo "Copying certificates for dashboard: $node -> config/$dir_name/certs/" echo "Copying certificates for dashboard: $node -> config/$dir_name/certs/"
mkdir -p "./config/$dir_name/certs" mkdir -p "./config/$dir_name/certs"
cp "$OUTPUT_DIR/${node}"* "./config/$dir_name/certs/" cp "$OUTPUT_DIR/${node}"* "./config/$dir_name/certs/"
cp "$OUTPUT_DIR"/root-ca* "./config/$dir_name/certs/"
done done
echo "Copying root-ca certificates -> config/root-ca/certs/"
mkdir -p "./config/root-ca/certs"
cp "$OUTPUT_DIR"/root-ca* "./config/root-ca/certs/"
fi fi
# 3. Set ownership and permissions # 3. Set ownership and permissions
if $DO_PRIV; then if $DO_PRIV; then
for node in "${INDEXER_NODES[@]}"; do for node in "${INDEXER_NODES[@]}"; do
dir_name=$(node_to_dir "$node") dir_name=$(node_to_dir "$node")
echo "Setting permissions for indexer $node (1000:1000)" echo "Setting permissions for indexer $node (${WAZUH_UID}:${WAZUH_GID})"
chown -R 1000:1000 "./config/$dir_name/certs" chown -R ${WAZUH_UID}:${WAZUH_GID} "./config/$dir_name/certs"
chmod 400 "./config/$dir_name/certs/"* chmod 400 "./config/$dir_name/certs/"*
done done
for node in "${MANAGER_NODES[@]}"; do for node in "${MANAGER_NODES[@]}"; do
dir_name=$(node_to_dir "$node") dir_name=$(node_to_dir "$node")
echo "Setting permissions for manager $node (999:999)" echo "Setting permissions for manager $node (${WAZUH_UID}:${WAZUH_GID})"
chown -R 999:999 "./config/$dir_name/certs" chown -R ${WAZUH_UID}:${WAZUH_GID} "./config/$dir_name/certs"
chmod 400 "./config/$dir_name/certs/"* chmod 400 "./config/$dir_name/certs/"*
done done
for node in "${DASHBOARD_NODES[@]}"; do for node in "${DASHBOARD_NODES[@]}"; do
dir_name=$(node_to_dir "$node") dir_name=$(node_to_dir "$node")
echo "Setting permissions for dashboard $node (1000:1000)" echo "Setting permissions for dashboard $node (${WAZUH_UID}:${WAZUH_GID})"
chown -R 1000:1000 "./config/$dir_name/certs" chown -R ${WAZUH_UID}:${WAZUH_GID} "./config/$dir_name/certs"
chmod 400 "./config/$dir_name/certs/"* chmod 400 "./config/$dir_name/certs/"*
done done
echo "Setting permissions for root-ca certificates (${WAZUH_UID}:${WAZUH_GID})"
chown -R ${WAZUH_UID}:${WAZUH_GID} "./config/root-ca/certs"
chmod 400 "./config/root-ca/certs/"*
fi fi
echo "Process completed." echo "Process completed."