diff --git a/.env b/.env index a552278a..53477fda 100755 --- a/.env +++ b/.env @@ -1,6 +1,6 @@ -WAZUH_VERSION=4.10.2 -WAZUH_IMAGE_VERSION=4.10.2 +WAZUH_VERSION=4.11.0 +WAZUH_IMAGE_VERSION=4.11.0 WAZUH_TAG_REVISION=1 -FILEBEAT_TEMPLATE_BRANCH=4.10.2 +FILEBEAT_TEMPLATE_BRANCH=4.11.0 WAZUH_FILEBEAT_MODULE=wazuh-filebeat-0.4.tar.gz WAZUH_UI_REVISION=1 diff --git a/.github/.goss.yaml b/.github/.goss.yaml index 1761d2c3..c7b1ac8e 100644 --- a/.github/.goss.yaml +++ b/.github/.goss.yaml @@ -56,7 +56,7 @@ package: wazuh-manager: installed: true versions: - - 4.10.2-1 + - 4.11.0-1 port: tcp:1514: listening: true diff --git a/.github/free-disk-space/action.yml b/.github/free-disk-space/action.yml new file mode 100644 index 00000000..3bdfefb0 --- /dev/null +++ b/.github/free-disk-space/action.yml @@ -0,0 +1,245 @@ +name: "Free Disk Space (Ubuntu)" +description: "A configurable GitHub Action to free up disk space on an Ubuntu GitHub Actions runner." + +# Thanks @jlumbroso for the action code https://github.com/jlumbroso/free-disk-space/ +# See: https://docs.github.com/en/actions/creating-actions/metadata-syntax-for-github-actions#branding + +inputs: + android: + description: "Remove Android runtime" + required: false + default: "true" + dotnet: + description: "Remove .NET runtime" + required: false + default: "true" + haskell: + description: "Remove Haskell runtime" + required: false + default: "true" + + # option inspired by: + # https://github.com/apache/flink/blob/master/tools/azure-pipelines/free_disk_space.sh + large-packages: + description: "Remove large packages" + required: false + default: "true" + + docker-images: + description: "Remove Docker images" + required: false + default: "true" + + # option inspired by: + # https://github.com/actions/virtual-environments/issues/2875#issuecomment-1163392159 + tool-cache: + description: "Remove image tool cache" + required: false + default: "false" + + swap-storage: + description: "Remove swap storage" + required: false + default: "true" + +runs: + using: "composite" + steps: + - shell: bash + run: | + + # ====== + # MACROS + # ====== + + # macro to print a line of equals + # (silly but works) + printSeparationLine() { + str=${1:=} + num=${2:-80} + counter=1 + output="" + while [ $counter -le $num ] + do + output="${output}${str}" + counter=$((counter+1)) + done + echo "${output}" + } + + # macro to compute available space + # REF: https://unix.stackexchange.com/a/42049/60849 + # REF: https://stackoverflow.com/a/450821/408734 + getAvailableSpace() { echo $(df -a $1 | awk 'NR > 1 {avail+=$4} END {print avail}'); } + + # macro to make Kb human readable (assume the input is Kb) + # REF: https://unix.stackexchange.com/a/44087/60849 + formatByteCount() { echo $(numfmt --to=iec-i --suffix=B --padding=7 $1'000'); } + + # macro to output saved space + printSavedSpace() { + saved=${1} + title=${2:-} + + echo "" + printSeparationLine '*' 80 + if [ ! -z "${title}" ]; then + echo "=> ${title}: Saved $(formatByteCount $saved)" + else + echo "=> Saved $(formatByteCount $saved)" + fi + printSeparationLine '*' 80 + echo "" + } + + # macro to print output of dh with caption + printDH() { + caption=${1:-} + + printSeparationLine '=' 80 + echo "${caption}" + echo "" + echo "$ dh -h /" + echo "" + df -h / + echo "$ dh -a /" + echo "" + df -a / + echo "$ dh -a" + echo "" + df -a + printSeparationLine '=' 80 + } + + + + # ====== + # SCRIPT + # ====== + + # Display initial disk space stats + + AVAILABLE_INITIAL=$(getAvailableSpace) + AVAILABLE_ROOT_INITIAL=$(getAvailableSpace '/') + + printDH "BEFORE CLEAN-UP:" + echo "" + + + # Option: Remove Android library + + if [[ ${{ inputs.android }} == 'true' ]]; then + BEFORE=$(getAvailableSpace) + + sudo rm -rf /usr/local/lib/android || true + + AFTER=$(getAvailableSpace) + SAVED=$((AFTER-BEFORE)) + printSavedSpace $SAVED "Android library" + fi + + # Option: Remove .NET runtime + + if [[ ${{ inputs.dotnet }} == 'true' ]]; then + BEFORE=$(getAvailableSpace) + + # https://github.community/t/bigger-github-hosted-runners-disk-space/17267/11 + sudo rm -rf /usr/share/dotnet || true + + AFTER=$(getAvailableSpace) + SAVED=$((AFTER-BEFORE)) + printSavedSpace $SAVED ".NET runtime" + fi + + # Option: Remove Haskell runtime + + if [[ ${{ inputs.haskell }} == 'true' ]]; then + BEFORE=$(getAvailableSpace) + + sudo rm -rf /opt/ghc || true + sudo rm -rf /usr/local/.ghcup || true + + AFTER=$(getAvailableSpace) + SAVED=$((AFTER-BEFORE)) + printSavedSpace $SAVED "Haskell runtime" + fi + + # Option: Remove large packages + # REF: https://github.com/apache/flink/blob/master/tools/azure-pipelines/free_disk_space.sh + + if [[ ${{ inputs.large-packages }} == 'true' ]]; then + BEFORE=$(getAvailableSpace) + + sudo apt-get remove -y '^aspnetcore-.*' || echo "::warning::The command [sudo apt-get remove -y '^aspnetcore-.*'] failed to complete successfully. Proceeding..." + sudo apt-get remove -y '^dotnet-.*' --fix-missing || echo "::warning::The command [sudo apt-get remove -y '^dotnet-.*' --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get remove -y '^llvm-.*' --fix-missing || echo "::warning::The command [sudo apt-get remove -y '^llvm-.*' --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get remove -y 'php.*' --fix-missing || echo "::warning::The command [sudo apt-get remove -y 'php.*' --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get remove -y '^mongodb-.*' --fix-missing || echo "::warning::The command [sudo apt-get remove -y '^mongodb-.*' --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get remove -y '^mysql-.*' --fix-missing || echo "::warning::The command [sudo apt-get remove -y '^mysql-.*' --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get remove -y azure-cli google-chrome-stable firefox powershell mono-devel libgl1-mesa-dri --fix-missing || echo "::warning::The command [sudo apt-get remove -y azure-cli google-chrome-stable firefox powershell mono-devel libgl1-mesa-dri --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get remove -y google-cloud-sdk --fix-missing || echo "::debug::The command [sudo apt-get remove -y google-cloud-sdk --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get remove -y google-cloud-cli --fix-missing || echo "::debug::The command [sudo apt-get remove -y google-cloud-cli --fix-missing] failed to complete successfully. Proceeding..." + sudo apt-get autoremove -y || echo "::warning::The command [sudo apt-get autoremove -y] failed to complete successfully. Proceeding..." + sudo apt-get clean || echo "::warning::The command [sudo apt-get clean] failed to complete successfully. Proceeding..." + + AFTER=$(getAvailableSpace) + SAVED=$((AFTER-BEFORE)) + printSavedSpace $SAVED "Large misc. packages" + fi + + # Option: Remove Docker images + + if [[ ${{ inputs.docker-images }} == 'true' ]]; then + BEFORE=$(getAvailableSpace) + + sudo docker image prune --all --force || true + + AFTER=$(getAvailableSpace) + SAVED=$((AFTER-BEFORE)) + printSavedSpace $SAVED "Docker images" + fi + + # Option: Remove tool cache + # REF: https://github.com/actions/virtual-environments/issues/2875#issuecomment-1163392159 + + if [[ ${{ inputs.tool-cache }} == 'true' ]]; then + BEFORE=$(getAvailableSpace) + + sudo rm -rf "$AGENT_TOOLSDIRECTORY" || true + + AFTER=$(getAvailableSpace) + SAVED=$((AFTER-BEFORE)) + printSavedSpace $SAVED "Tool cache" + fi + + # Option: Remove Swap storage + + if [[ ${{ inputs.swap-storage }} == 'true' ]]; then + BEFORE=$(getAvailableSpace) + + sudo swapoff -a || true + sudo rm -f /mnt/swapfile || true + free -h + + AFTER=$(getAvailableSpace) + SAVED=$((AFTER-BEFORE)) + printSavedSpace $SAVED "Swap storage" + fi + + + + # Output saved space statistic + + AVAILABLE_END=$(getAvailableSpace) + AVAILABLE_ROOT_END=$(getAvailableSpace '/') + + echo "" + printDH "AFTER CLEAN-UP:" + + echo "" + echo "" + + echo "/dev/root:" + printSavedSpace $((AVAILABLE_ROOT_END - AVAILABLE_ROOT_INITIAL)) + echo "overall:" + printSavedSpace $((AVAILABLE_END - AVAILABLE_INITIAL)) \ No newline at end of file diff --git a/.github/workflows/Procedure_push_docker_images.yml b/.github/workflows/Procedure_push_docker_images.yml index 43619b7b..717afa01 100644 --- a/.github/workflows/Procedure_push_docker_images.yml +++ b/.github/workflows/Procedure_push_docker_images.yml @@ -6,12 +6,12 @@ on: inputs: image_tag: description: 'Docker image tag' - default: '4.10.2' + default: '4.11.0' required: true docker_reference: description: 'wazuh-docker reference' - default: 'v4.10.2' - required: false + default: 'v4.11.0' + required: true products: description: 'Comma-separated list of the image names to build and push' default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer' @@ -42,12 +42,12 @@ on: inputs: image_tag: description: 'Docker image tag' - default: '4.10.2' + default: '4.11.0' required: true type: string docker_reference: description: 'wazuh-docker reference' - default: 'v4.10.2' + default: 'v4.11.0' required: false type: string products: diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml index c7d34d61..2c2d7e46 100644 --- a/.github/workflows/push.yml +++ b/.github/workflows/push.yml @@ -29,21 +29,21 @@ jobs: docker save wazuh/wazuh-dashboard:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar - name: Temporarily save Wazuh manager Docker image - uses: actions/upload-artifact@v3 + uses: actions/upload-artifact@v4 with: name: docker-artifact-manager path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-manager.tar retention-days: 1 - name: Temporarily save Wazuh indexer Docker image - uses: actions/upload-artifact@v3 + uses: actions/upload-artifact@v4 with: name: docker-artifact-indexer path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-indexer.tar retention-days: 1 - name: Temporarily save Wazuh dashboard Docker image - uses: actions/upload-artifact@v3 + uses: actions/upload-artifact@v4 with: name: docker-artifact-dashboard path: /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar @@ -77,17 +77,17 @@ jobs: run: cat .env > $GITHUB_ENV - name: Retrieve saved Wazuh indexer Docker image - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: docker-artifact-indexer - name: Retrieve saved Wazuh manager Docker image - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: docker-artifact-manager - name: Retrieve saved Wazuh dashboard Docker image - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: docker-artifact-dashboard @@ -205,25 +205,20 @@ jobs: run: cat .env > $GITHUB_ENV - name: free disk space - run: | - sudo swapoff -a - sudo rm -f /swapfile - sudo apt clean - docker rmi $(docker image ls -aq) - df -h + uses: ./.github/free-disk-space - name: Retrieve saved Wazuh dashboard Docker image - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: docker-artifact-dashboard - name: Retrieve saved Wazuh manager Docker image - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: docker-artifact-manager - name: Retrieve saved Wazuh indexer Docker image - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: docker-artifact-indexer diff --git a/CHANGELOG.md b/CHANGELOG.md index 81dd3ec5..514e76d8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,24 @@ # Change Log All notable changes to this project will be documented in this file. +## [4.11.0] + +### Added + +- None + +### Changed + +- None + +### Fixed + +- Change the cleaning disk step ([#1663](https://github.com/wazuh/wazuh-docker/pull/1663)) + +### Deleted + +- None + ## [4.10.2] ### Added diff --git a/README.md b/README.md index 515d8c3c..953522ae 100644 --- a/README.md +++ b/README.md @@ -178,6 +178,7 @@ WAZUH_MONITORING_REPLICAS=0 ## | Wazuh version | ODFE | XPACK | |---------------|---------|--------| +| v4.11.0 | | | | v4.10.2 | | | | v4.10.1 | | | | v4.10.0 | | | diff --git a/VERSION b/VERSION index 42eb9ba1..2ef68c0e 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="4.10.2" -REVISION="41020" +WAZUH-DOCKER_VERSION="4.11.0" +REVISION="41101" diff --git a/build-docker-images/README.md b/build-docker-images/README.md index e65cda78..35bbdc1b 100644 --- a/build-docker-images/README.md +++ b/build-docker-images/README.md @@ -13,7 +13,7 @@ This script initializes the environment variables needed to build each of the im The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument: ``` -$ build-docker-images/build-images.sh -v 4.10.2 +$ build-docker-images/build-images.sh -v 4.11.0 ``` To get all the available script options use the -h or --help option: @@ -26,7 +26,7 @@ Usage: build-docker-images/build-images.sh [OPTIONS] -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default. -f, --filebeat-module [Optional] Set Filebeat module version. By default 0.4. -r, --revision [Optional] Package revision. By default 1 - -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.10.2. + -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.11.0. -h, --help Show this help. ``` \ No newline at end of file diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 9d64121f..2730a56a 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,4 +1,4 @@ -WAZUH_IMAGE_VERSION=4.10.2 +WAZUH_IMAGE_VERSION=4.11.0 WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') WAZUH_TAG_REVISION=1 WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') @@ -12,7 +12,7 @@ IMAGE_VERSION=${WAZUH_IMAGE_VERSION} # License (version 2) as published by the FSF - Free Software # Foundation. -WAZUH_IMAGE_VERSION="4.10.2" +WAZUH_IMAGE_VERSION="4.11.0" WAZUH_TAG_REVISION="1" WAZUH_DEV_STAGE="" FILEBEAT_MODULE_VERSION="0.4" diff --git a/multi-node/docker-compose.yml b/multi-node/docker-compose.yml index 10187cfd..f1a671d5 100644 --- a/multi-node/docker-compose.yml +++ b/multi-node/docker-compose.yml @@ -3,7 +3,7 @@ version: '3.7' services: wazuh.master: - image: wazuh/wazuh-manager:4.10.2 + image: wazuh/wazuh-manager:4.11.0 hostname: wazuh.master restart: always ulimits: @@ -45,7 +45,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.worker: - image: wazuh/wazuh-manager:4.10.2 + image: wazuh/wazuh-manager:4.11.0 hostname: wazuh.worker restart: always ulimits: @@ -81,7 +81,7 @@ services: - ./config/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf wazuh1.indexer: - image: wazuh/wazuh-indexer:4.10.2 + image: wazuh/wazuh-indexer:4.11.0 hostname: wazuh1.indexer restart: always ports: @@ -107,7 +107,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh2.indexer: - image: wazuh/wazuh-indexer:4.10.2 + image: wazuh/wazuh-indexer:4.11.0 hostname: wazuh2.indexer restart: always environment: @@ -129,7 +129,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh3.indexer: - image: wazuh/wazuh-indexer:4.10.2 + image: wazuh/wazuh-indexer:4.11.0 hostname: wazuh3.indexer restart: always environment: @@ -151,7 +151,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.10.2 + image: wazuh/wazuh-dashboard:4.11.0 hostname: wazuh.dashboard restart: always ports: diff --git a/single-node/docker-compose.yml b/single-node/docker-compose.yml index 94cb7025..90df4be8 100644 --- a/single-node/docker-compose.yml +++ b/single-node/docker-compose.yml @@ -3,7 +3,7 @@ version: '3.7' services: wazuh.manager: - image: wazuh/wazuh-manager:4.10.2 + image: wazuh/wazuh-manager:4.11.0 hostname: wazuh.manager restart: always ulimits: @@ -46,7 +46,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.indexer: - image: wazuh/wazuh-indexer:4.10.2 + image: wazuh/wazuh-indexer:4.11.0 hostname: wazuh.indexer restart: always ports: @@ -71,7 +71,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.10.2 + image: wazuh/wazuh-dashboard:4.11.0 hostname: wazuh.dashboard restart: always ports: