Merge branch '4.14.3' into enhancement/edr-6591-agent-group

This commit is contained in:
Gonzalo Acuña
2025-12-17 16:18:58 -03:00
committed by GitHub
8 changed files with 240 additions and 67 deletions
@@ -11,10 +11,6 @@ on:
docker_reference: docker_reference:
description: 'wazuh-docker reference' description: 'wazuh-docker reference'
required: true required: true
products:
description: 'Comma-separated list of the image names to build and push'
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
required: true
filebeat_module_version: filebeat_module_version:
description: 'Filebeat module version' description: 'Filebeat module version'
default: '0.5' default: '0.5'
@@ -23,11 +19,6 @@ on:
description: 'Package revision' description: 'Package revision'
default: '1' default: '1'
required: true required: true
push_images:
description: 'Push images'
type: boolean
default: true
required: true
id: id:
description: "ID used to identify the workflow uniquely." description: "ID used to identify the workflow uniquely."
type: string type: string
@@ -48,11 +39,6 @@ on:
description: 'wazuh-docker reference' description: 'wazuh-docker reference'
required: false required: false
type: string type: string
products:
description: 'Comma-separated list of the image names to build and push'
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
required: true
type: string
filebeat_module_version: filebeat_module_version:
description: 'Filebeat module version' description: 'Filebeat module version'
default: '0.5' default: '0.5'
@@ -63,11 +49,6 @@ on:
default: '1' default: '1'
required: true required: true
type: string type: string
push_images:
description: 'Push images'
type: boolean
default: true
required: true
id: id:
description: "ID used to identify the workflow uniquely." description: "ID used to identify the workflow uniquely."
type: string type: string
@@ -82,6 +63,16 @@ jobs:
build-and-push: build-and-push:
runs-on: ubuntu-22.04 runs-on: ubuntu-22.04
permissions:
id-token: write
contents: read
env:
IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }}
IMAGE_TAG: ${{ inputs.image_tag }}
FILEBEAT_MODULE_VERSION: ${{ inputs.filebeat_module_version }}
REVISION: ${{ inputs.revision }}
steps: steps:
- name: Print inputs - name: Print inputs
run: | run: |
@@ -96,10 +87,8 @@ jobs:
echo "* id: ${{ inputs.id }}" echo "* id: ${{ inputs.id }}"
echo "* image_tag: ${{ inputs.image_tag }}" echo "* image_tag: ${{ inputs.image_tag }}"
echo "* docker_reference: ${{ inputs.docker_reference }}" echo "* docker_reference: ${{ inputs.docker_reference }}"
echo "* products: ${{ inputs.products }}"
echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}" echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}"
echo "* revision: ${{ inputs.revision }}" echo "* revision: ${{ inputs.revision }}"
echo "* push_images: ${{ inputs.push_images }}"
echo "* dev: ${{ inputs.dev }}" echo "* dev: ${{ inputs.dev }}"
echo "---------------------------------------------" echo "---------------------------------------------"
@@ -108,7 +97,28 @@ jobs:
with: with:
ref: ${{ inputs.docker_reference }} ref: ${{ inputs.docker_reference }}
- name: free disk space
uses: ./.github/free-disk-space
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Configure aws credentials
if: ${{ inputs.dev == true }}
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
aws-region: "${{ secrets.AWS_REGION }}"
- name: Log in to Amazon ECR
if: ${{ inputs.dev == true }}
uses: aws-actions/amazon-ecr-login@v2
- name: Log in to Docker Hub - name: Log in to Docker Hub
if: ${{ inputs.dev == false }}
uses: docker/login-action@v3 uses: docker/login-action@v3
with: with:
username: ${{ secrets.DOCKERHUB_USERNAME }} username: ${{ secrets.DOCKERHUB_USERNAME }}
@@ -116,7 +126,7 @@ jobs:
- name: Build Wazuh images - name: Build Wazuh images
run: | run: |
IMAGE_TAG=${{ inputs.image_tag }} IMAGE_TAG="${{ inputs.image_tag }}"
FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }} FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }}
REVISION=${{ inputs.revision }} REVISION=${{ inputs.revision }}
@@ -128,13 +138,13 @@ jobs:
fi fi
DEV_STAGE=${tokens[1]} DEV_STAGE=${tokens[1]}
WAZUH_VER=${tokens[0]} WAZUH_VER=${tokens[0]}
./build-docker-images/build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION ./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m
else else
./build-docker-images/build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION ./build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m
fi fi
# Save .env file (generated by build-images.sh) contents to $GITHUB_ENV # Save .env file (generated by build-images.sh) contents to $GITHUB_ENV
ENV_FILE_PATH=".env" ENV_FILE_PATH="../.env"
if [ -f $ENV_FILE_PATH ]; then if [ -f $ENV_FILE_PATH ]; then
while IFS= read -r line || [ -n "$line" ]; do while IFS= read -r line || [ -n "$line" ]; do
@@ -144,18 +154,19 @@ jobs:
echo "The environment file $ENV_FILE_PATH does not exist!" echo "The environment file $ENV_FILE_PATH does not exist!"
exit 1 exit 1
fi fi
working-directory: ./build-docker-images
- name: Image exists validation - name: Image exists validation
if: ${{ inputs.push_images }} if: ${{ inputs.dev == false }}
id: validation id: validation
run: | run: |
IMAGE_TAG=${{ inputs.image_tag }} IMAGE_TAG=${{ inputs.image_tag }}
PURPOSE="" PURPOSE=""
if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
if docker manifest inspect wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then if docker manifest inspect $IMAGE_REGISTRY/wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then
PURPOSE="regeneration" PURPOSE="regeneration"
echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'" echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'"
else else
PURPOSE="new release" PURPOSE="new release"
echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'" echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'"
@@ -170,21 +181,8 @@ jobs:
echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT
- name: Tag and Push Wazuh images
if: ${{ inputs.push_images }}
run: |
IMAGE_TAG="${{ inputs.image_tag }}$( [ "${{ inputs.dev }}" == "true" ] && echo '-dev' || true )"
IMAGE_NAMES=${{ inputs.products }}
IFS=',' read -r -a images <<< "$IMAGE_NAMES"
for image in "${images[@]}"; do
echo "Tagging and pushing wazuh/$image:${WAZUH_VERSION} to wazuh/$image:$IMAGE_TAG"
docker tag wazuh/$image:${WAZUH_VERSION} wazuh/$image:$IMAGE_TAG
echo "Pushing wazuh/$image:$IMAGE_TAG ..."
docker push wazuh/$image:$IMAGE_TAG
done
- name: GH issue notification - name: GH issue notification
if: ${{ inputs.push_images && steps.validation.outputs.purpose != '' }} if: ${{ inputs.dev == false && steps.validation.outputs.purpose != '' }}
run: | run: |
IMAGE_TAG=${{ inputs.image_tag }} IMAGE_TAG=${{ inputs.image_tag }}
GH_TITLE="" GH_TITLE=""
+1
View File
@@ -10,6 +10,7 @@ All notable changes to this project will be documented in this file.
### Changed ### Changed
- Agent group parameter added ([#2127](https://github.com/wazuh/wazuh-docker/pull/2127)) - Agent group parameter added ([#2127](https://github.com/wazuh/wazuh-docker/pull/2127))
- Adapt to multi architecture build ([#2120](https://github.com/wazuh/wazuh-docker/pull/2120))
### Fixed ### Fixed
+49 -11
View File
@@ -1,8 +1,6 @@
WAZUH_IMAGE_VERSION=4.14.3 IMAGE_TAG=4.14.3
WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g')
WAZUH_TAG_REVISION=1
WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g')
IMAGE_VERSION=${WAZUH_IMAGE_VERSION} WAZUH_REGISTRY=docker.io
# Wazuh package generator # Wazuh package generator
# Copyright (C) 2023, Wazuh Inc. # Copyright (C) 2023, Wazuh Inc.
@@ -58,15 +56,32 @@ build() {
fi fi
fi fi
echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > .env
echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> .env
echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> .env
echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> .env
echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> .env
echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> .env
docker compose -f build-docker-images/build-images.yml --env-file .env build --no-cache || clean 1 echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > ../.env
echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> ../.env
echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> ../.env
echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> ../.env
echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> ../.env
echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> ../.env
echo WAZUH_REGISTRY=$WAZUH_REGISTRY >> ../.env
echo IMAGE_TAG=$IMAGE_TAG >> ../.env
set -a
source ../.env
set +a
if [ "${MULTIARCH}" ];then
docker buildx bake \
--file build-images.yml \
--push \
--set *.platform=linux/amd64,linux/arm64 \
--no-cache || clean 1
else
docker buildx bake \
--file build-images.yml \
--load \
--no-cache || clean 1
fi
return 0 return 0
} }
@@ -79,7 +94,10 @@ help() {
echo " -d, --dev <ref> [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default." echo " -d, --dev <ref> [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default."
echo " -f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}." echo " -f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}."
echo " -r, --revision <rev> [Optional] Package revision. By default ${WAZUH_TAG_REVISION}" echo " -r, --revision <rev> [Optional] Package revision. By default ${WAZUH_TAG_REVISION}"
echo " -ref, --reference <ref> [Optional] Set the Wazuh reference to build development images. By default, the latest stable release."
echo " -rg, --registry <reg> [Optional] Set the Docker registry to push the images."
echo " -v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}." echo " -v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}."
echo " -m, --multiarch [Optional] Enable multi-architecture builds."
echo " -h, --help Show this help." echo " -h, --help Show this help."
echo echo
exit $1 exit $1
@@ -110,6 +128,10 @@ main() {
help 1 help 1
fi fi
;; ;;
"-m"|"--multiarch")
MULTIARCH="true"
shift
;;
"-r"|"--revision") "-r"|"--revision")
if [ -n "${2}" ]; then if [ -n "${2}" ]; then
WAZUH_TAG_REVISION="${2}" WAZUH_TAG_REVISION="${2}"
@@ -118,6 +140,22 @@ main() {
help 1 help 1
fi fi
;; ;;
"-ref"|"--reference")
if [ -n "${2}" ]; then
WAZUH_TAG_REFERENCE="${2}"
shift 2
else
help 1
fi
;;
"-rg"|"--registry")
if [ -n "${2}" ]; then
WAZUH_REGISTRY="${2}"
shift 2
else
help 1
fi
;;
"-v"|"--version") "-v"|"--version")
if [ -n "$2" ]; then if [ -n "$2" ]; then
WAZUH_IMAGE_VERSION="$2" WAZUH_IMAGE_VERSION="$2"
+4 -4
View File
@@ -8,7 +8,7 @@ services:
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
FILEBEAT_TEMPLATE_BRANCH: ${FILEBEAT_TEMPLATE_BRANCH} FILEBEAT_TEMPLATE_BRANCH: ${FILEBEAT_TEMPLATE_BRANCH}
WAZUH_FILEBEAT_MODULE: ${WAZUH_FILEBEAT_MODULE} WAZUH_FILEBEAT_MODULE: ${WAZUH_FILEBEAT_MODULE}
image: wazuh/wazuh-manager:${WAZUH_IMAGE_VERSION} image: ${WAZUH_REGISTRY}/wazuh/wazuh-manager:${IMAGE_TAG}
hostname: wazuh.manager hostname: wazuh.manager
restart: always restart: always
ports: ports:
@@ -40,7 +40,7 @@ services:
args: args:
WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_VERSION: ${WAZUH_VERSION}
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
image: wazuh/wazuh-agent:${WAZUH_IMAGE_VERSION} image: ${WAZUH_REGISTRY}/wazuh/wazuh-agent:${IMAGE_TAG}
hostname: wazuh.agent hostname: wazuh.agent
restart: always restart: always
@@ -50,7 +50,7 @@ services:
args: args:
WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_VERSION: ${WAZUH_VERSION}
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
image: wazuh/wazuh-indexer:${WAZUH_IMAGE_VERSION} image: ${WAZUH_REGISTRY}/wazuh/wazuh-indexer:${IMAGE_TAG}
hostname: wazuh.indexer hostname: wazuh.indexer
restart: always restart: always
ports: ports:
@@ -72,7 +72,7 @@ services:
WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_VERSION: ${WAZUH_VERSION}
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
WAZUH_UI_REVISION: ${WAZUH_UI_REVISION} WAZUH_UI_REVISION: ${WAZUH_UI_REVISION}
image: wazuh/wazuh-dashboard:${WAZUH_IMAGE_VERSION} image: ${WAZUH_REGISTRY}/wazuh/wazuh-dashboard:${IMAGE_TAG}
hostname: wazuh.dashboard hostname: wazuh.dashboard
restart: always restart: always
ports: ports:
+8 -5
View File
@@ -11,6 +11,7 @@ ARG FILEBEAT_VERSION=7.10.2
ARG FILEBEAT_REVISION=2 ARG FILEBEAT_REVISION=2
ARG WAZUH_FILEBEAT_MODULE ARG WAZUH_FILEBEAT_MODULE
ARG S6_VERSION="v2.2.0.3" ARG S6_VERSION="v2.2.0.3"
ARG TARGETARCH
RUN yum install curl-minimal xz gnupg tar gzip openssl findutils procps -y &&\ RUN yum install curl-minimal xz gnupg tar gzip openssl findutils procps -y &&\
yum clean all yum clean all
@@ -27,11 +28,13 @@ RUN yum install wazuh-manager-${WAZUH_VERSION}-${WAZUH_TAG_REVISION} -y && \
chmod 775 /filebeat_module.sh && \ chmod 775 /filebeat_module.sh && \
source /filebeat_module.sh && \ source /filebeat_module.sh && \
rm /filebeat_module.sh && \ rm /filebeat_module.sh && \
curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-amd64.tar.gz \ S6_ARCH="amd64" && \
-o /tmp/s6-overlay-amd64.tar.gz && \ if [ "${TARGETARCH}" = "arm64" ]; then S6_ARCH="aarch64"; fi && \
tar xzf /tmp/s6-overlay-amd64.tar.gz -C / --exclude="./bin" && \ curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-${S6_ARCH}.tar.gz \
tar xzf /tmp/s6-overlay-amd64.tar.gz -C /usr ./bin && \ -o /tmp/s6-overlay-${S6_ARCH}.tar.gz && \
rm /tmp/s6-overlay-amd64.tar.gz && \ tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C / --exclude="./bin" && \
tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C /usr ./bin && \
rm /tmp/s6-overlay-${S6_ARCH}.tar.gz && \
rm -f /var/ossec/etc/sslmanager.key && \ rm -f /var/ossec/etc/sslmanager.key && \
rm -f /var/ossec/etc/sslmanager.cert rm -f /var/ossec/etc/sslmanager.cert
+23 -5
View File
@@ -1,9 +1,27 @@
# Certificate creation image build # Certificate Creation Image Build
The dockerfile hosted in this directory is used to build the image used to boot Wazuh's single node and multi node stacks. The dockerfile hosted in this directory is used to build the image required for generating Wazuh Docker single-node and multi-node certificate files
To create the image, the following command must be executed: ## Pre-requisites
### QEMU
Set up QEMU to enable building multi-architecture Docker images
Useful documentation:
- https://www.qemu.org/download/
- https://docs.docker.com/build/building/multi-platform/#qemu
## Procedure
Run the following script to build the wazuh-certs-generator docker image
```console
./build-image.sh -v <IMAGE_TAG> [-m] [-rg <REGISTRY>]
``` ```
$ docker build -t wazuh/wazuh-certs-generator:0.0.3 .
``` - Replace <IMAGE_TAG> with the new image desired tag.
- Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`)
- If multiarch build is enabled, the script will attempt to push the image to the specified registry. This image upload will only work if credentials are properly configured.
- Use the `-rg <REGISTRY>` parameter to specify a custom Docker registry (default is Docker Hub)
+107
View File
@@ -0,0 +1,107 @@
#!/bin/bash
# Wazuh package generator
# Copyright (C) 2023, Wazuh Inc.
#
# This program is a free software; you can redistribute it
# and/or modify it under the terms of the GNU General Public
# License (version 2) as published by the FSF - Free Software
# Foundation.
WAZUH_CERTS_IMAGE_VERSION="0.0.4"
WAZUH_REGISTRY="docker.io"
# -----------------------------------------------------------------------------
trap ctrl_c INT
clean() {
exit_code=$1
exit ${exit_code}
}
ctrl_c() {
clean 1
}
# -----------------------------------------------------------------------------
build() {
IMAGE_TAG="${WAZUH_CERTS_IMAGE_VERSION}"
echo WAZUH_REGISTRY=$WAZUH_REGISTRY > .env
echo IMAGE_TAG=$IMAGE_TAG >> .env
set -a
source .env
set +a
if [ "${MULTIARCH}" ]; then
docker buildx bake \
--file build-image.yml \
--set *.platform=linux/amd64,linux/arm64 \
--push \
--no-cache || clean 1
else
docker buildx bake \
--file build-image.yml \
--load \
--no-cache || clean 1
fi
return 0
}
# -----------------------------------------------------------------------------
help() {
echo
echo "Usage: $0 [OPTIONS]"
echo
echo " -v, --version <ver> [Optional] Set the image version. By default ${WAZUH_CERTS_IMAGE_VERSION}."
echo " -rg, --registry <reg> [Optional] Set the Docker registry to push the images."
echo " -m, --multiarch [Optional] Enable multi-architecture builds."
echo " -h, --help Show this help."
echo
exit $1
}
# -----------------------------------------------------------------------------
main() {
while [ -n "${1}" ]
do
case "${1}" in
"-h"|"--help")
help 0
;;
"-m"|"--multiarch")
MULTIARCH="true"
shift
;;
"-rg"|"--registry")
if [ -n "${2}" ]; then
WAZUH_REGISTRY="${2}"
shift 2
else
help 1
fi
;;
"-v"|"--version")
if [ -n "$2" ]; then
WAZUH_CERTS_IMAGE_VERSION="$2"
shift 2
else
help 1
fi
;;
*)
help 1
esac
done
build || clean 1
clean 0
}
main "$@"
+8
View File
@@ -0,0 +1,8 @@
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
services:
wazuh.certs.generator:
build:
context: .
dockerfile: Dockerfile
image: ${WAZUH_REGISTRY}/wazuh/wazuh-certs-generator:${IMAGE_TAG}
hostname: wazuh-certs-generator