From b3fde321bfcdacd88b0227566eada01cc3e19ccf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gonzalo=20Acu=C3=B1a?= Date: Tue, 16 Dec 2025 15:45:25 -0300 Subject: [PATCH 01/19] Agent group parameter added --- build-docker-images/wazuh-agent/Dockerfile | 3 ++- .../config/etc/cont-init.d/0-wazuh-init | 4 +++- docs/ref/configuration/environment-variables.md | 14 +++++++++----- wazuh-agent/config/wazuh-agent-conf | 3 ++- 4 files changed, 16 insertions(+), 8 deletions(-) diff --git a/build-docker-images/wazuh-agent/Dockerfile b/build-docker-images/wazuh-agent/Dockerfile index 8a237787..242ca8a3 100644 --- a/build-docker-images/wazuh-agent/Dockerfile +++ b/build-docker-images/wazuh-agent/Dockerfile @@ -10,7 +10,8 @@ ARG WAZUH_MANAGER='CHANGE_MANAGER_IP' ARG WAZUH_MANAGER_PORT='CHANGE_MANAGER_PORT' ARG WAZUH_REGISTRATION_SERVER='CHANGE_ENROLL_IP' ARG WAZUH_REGISTRATION_PORT='CHANGE_ENROLL_PORT' -ARG WAZUH_AGENT_NAME='CHANGEE_AGENT_NAME' +ARG WAZUH_AGENT_NAME='CHANGE_AGENT_NAME' +ARG WAZUH_AGENT_GROUPS='CHANGE_AGENT_GROUPS' COPY config/check_repository.sh / diff --git a/build-docker-images/wazuh-agent/config/etc/cont-init.d/0-wazuh-init b/build-docker-images/wazuh-agent/config/etc/cont-init.d/0-wazuh-init index 2fcf4a88..a50b4662 100644 --- a/build-docker-images/wazuh-agent/config/etc/cont-init.d/0-wazuh-init +++ b/build-docker-images/wazuh-agent/config/etc/cont-init.d/0-wazuh-init @@ -9,6 +9,7 @@ WAZUH_REGISTRATION_SERVER=${WAZUH_REGISTRATION_SERVER:-$WAZUH_MANAGER_SERVER} WAZUH_REGISTRATION_PORT=${WAZUH_REGISTRATION_PORT:-"1515"} WAZUH_REGISTRATION_PASSWORD=$WAZUH_REGISTRATION_PASSWORD WAZUH_AGENT_NAME=${WAZUH_AGENT_NAME:-"wazuh-agent-$HOSTNAME"} +WAZUH_AGENT_GROUPS=${WAZUH_AGENT_GROUPS:-"default"} ############################################################################## # Aux functions @@ -66,7 +67,8 @@ set_manager_conn() { sed -i "s#CHANGE_MANAGER_PORT#$WAZUH_MANAGER_PORT#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf sed -i "s#CHANGE_ENROLL_IP#$WAZUH_REGISTRATION_SERVER#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf sed -i "s#CHANGE_ENROLL_PORT#$WAZUH_REGISTRATION_PORT#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf - sed -i "s#CHANGEE_AGENT_NAME#$WAZUH_AGENT_NAME#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf + sed -i "s#CHANGE_AGENT_NAME#$WAZUH_AGENT_NAME#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf + sed -i "s#CHANGE_AGENT_GROUPS#$WAZUH_AGENT_GROUPS#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf [ -n "$WAZUH_REGISTRATION_PASSWORD" ] && \ echo "$WAZUH_REGISTRATION_PASSWORD" > ${WAZUH_INSTALL_PATH}/etc/authd.pass && \ chown root:wazuh ${WAZUH_INSTALL_PATH}/etc/authd.pass && \ diff --git a/docs/ref/configuration/environment-variables.md b/docs/ref/configuration/environment-variables.md index 003ad165..eac90d9e 100644 --- a/docs/ref/configuration/environment-variables.md +++ b/docs/ref/configuration/environment-variables.md @@ -4,11 +4,14 @@ This document outlines the environment variables applicable to the Wazuh Docker ## Table of Contents -- [Wazuh Manager](#wazuh-manager) -- [Wazuh Indexer](#wazuh-indexer) -- [Wazuh Dashboard](#wazuh-dashboard) -- [Wazuh Agent](#wazuh-agent) -- [Overriding Configuration Files with Environment Variables](#overriding-configuration-files-with-environment-variables) +- [Environment Variables in Wazuh Docker Deployment](#environment-variables-in-wazuh-docker-deployment) + - [Table of Contents](#table-of-contents) + - [Wazuh Manager](#wazuh-manager) + - [Wazuh Indexer](#wazuh-indexer) + - [Wazuh Dashboard](#wazuh-dashboard) + - [Wazuh Agent](#wazuh-agent) + - [Overriding Configuration Files with Environment Variables](#overriding-configuration-files-with-environment-variables) + - [Examples:](#examples) --- @@ -88,6 +91,7 @@ environment: - WAZUH_REGISTRATION_SERVER=wazuh.manager - WAZUH_REGISTRATION_PORT=1515 - WAZUH_AGENT_NAME=my-agent + - WAZUH_AGENT_GROUPS=default - WAZUH_REGISTRATION_PASSWORD=StrongPassword ``` diff --git a/wazuh-agent/config/wazuh-agent-conf b/wazuh-agent/config/wazuh-agent-conf index 51fd9b0f..ad0d8ece 100644 --- a/wazuh-agent/config/wazuh-agent-conf +++ b/wazuh-agent/config/wazuh-agent-conf @@ -20,8 +20,9 @@ yes CHANGE_ENROLL_IP CHANGE_ENROLL_PORT - CHANGEE_AGENT_NAME + CHANGE_AGENT_NAME etc/authd.pass + CHANGE_AGENT_GROUPS From 0fe3103940a988b48b174e4b12dee6e60ce4072c Mon Sep 17 00:00:00 2001 From: Victor Carlos Erenu Date: Tue, 28 Oct 2025 01:09:49 +0700 Subject: [PATCH 02/19] Bring changes from PR #2054 --- .../Procedure_push_docker_images.yml | 81 +++++++++---------- build-docker-images/build-images.sh | 57 ++++++++++--- build-docker-images/build-images.yml | 8 +- 3 files changed, 87 insertions(+), 59 deletions(-) diff --git a/.github/workflows/Procedure_push_docker_images.yml b/.github/workflows/Procedure_push_docker_images.yml index 28fcf085..bf45b917 100644 --- a/.github/workflows/Procedure_push_docker_images.yml +++ b/.github/workflows/Procedure_push_docker_images.yml @@ -11,10 +11,6 @@ on: docker_reference: description: 'wazuh-docker reference' required: true - products: - description: 'Comma-separated list of the image names to build and push' - default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' - required: true filebeat_module_version: description: 'Filebeat module version' default: '0.4' @@ -23,11 +19,6 @@ on: description: 'Package revision' default: '1' required: true - push_images: - description: 'Push images' - type: boolean - default: true - required: true id: description: "ID used to identify the workflow uniquely." type: string @@ -48,11 +39,6 @@ on: description: 'wazuh-docker reference' required: false type: string - products: - description: 'Comma-separated list of the image names to build and push' - default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' - required: true - type: string filebeat_module_version: description: 'Filebeat module version' default: '0.4' @@ -63,11 +49,6 @@ on: default: '1' required: true type: string - push_images: - description: 'Push images' - type: boolean - default: true - required: true id: description: "ID used to identify the workflow uniquely." type: string @@ -82,6 +63,16 @@ jobs: build-and-push: runs-on: ubuntu-22.04 + permissions: + id-token: write + contents: read + + env: + IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }} + IMAGE_TAG: ${{ inputs.image_tag }} + FILEBEAT_MODULE_VERSION: ${{ inputs.filebeat_module_version }} + REVISION: ${{ inputs.revision }} + steps: - name: Print inputs run: | @@ -96,10 +87,8 @@ jobs: echo "* id: ${{ inputs.id }}" echo "* image_tag: ${{ inputs.image_tag }}" echo "* docker_reference: ${{ inputs.docker_reference }}" - echo "* products: ${{ inputs.products }}" echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}" echo "* revision: ${{ inputs.revision }}" - echo "* push_images: ${{ inputs.push_images }}" echo "* dev: ${{ inputs.dev }}" echo "---------------------------------------------" @@ -108,7 +97,28 @@ jobs: with: ref: ${{ inputs.docker_reference }} + - name: free disk space + uses: ./.github/free-disk-space + + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Configure aws credentials + if: ${{ inputs.dev == true }} + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }} + aws-region: "${{ secrets.AWS_REGION }}" + + - name: Log in to Amazon ECR + if: ${{ inputs.dev == true }} + uses: aws-actions/amazon-ecr-login@v2 + - name: Log in to Docker Hub + if: ${{ inputs.dev == false }} uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} @@ -116,7 +126,7 @@ jobs: - name: Build Wazuh images run: | - IMAGE_TAG=${{ inputs.image_tag }} + IMAGE_TAG="${{ inputs.image_tag }}" FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }} REVISION=${{ inputs.revision }} @@ -128,13 +138,13 @@ jobs: fi DEV_STAGE=${tokens[1]} WAZUH_VER=${tokens[0]} - ./build-docker-images/build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION + ./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m else - ./build-docker-images/build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION + ./build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m fi # Save .env file (generated by build-images.sh) contents to $GITHUB_ENV - ENV_FILE_PATH=".env" + ENV_FILE_PATH="../.env" if [ -f $ENV_FILE_PATH ]; then while IFS= read -r line || [ -n "$line" ]; do @@ -144,18 +154,18 @@ jobs: echo "The environment file $ENV_FILE_PATH does not exist!" exit 1 fi + working-directory: ./build-docker-images - name: Image exists validation - if: ${{ inputs.push_images }} id: validation run: | IMAGE_TAG=${{ inputs.image_tag }} PURPOSE="" if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then - if docker manifest inspect wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then + if docker manifest inspect $IMAGE_REGISTRY/wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then PURPOSE="regeneration" - echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'" + echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'" else PURPOSE="new release" echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'" @@ -170,21 +180,8 @@ jobs: echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT - - name: Tag and Push Wazuh images - if: ${{ inputs.push_images }} - run: | - IMAGE_TAG="${{ inputs.image_tag }}$( [ "${{ inputs.dev }}" == "true" ] && echo '-dev' || true )" - IMAGE_NAMES=${{ inputs.products }} - IFS=',' read -r -a images <<< "$IMAGE_NAMES" - for image in "${images[@]}"; do - echo "Tagging and pushing wazuh/$image:${WAZUH_VERSION} to wazuh/$image:$IMAGE_TAG" - docker tag wazuh/$image:${WAZUH_VERSION} wazuh/$image:$IMAGE_TAG - echo "Pushing wazuh/$image:$IMAGE_TAG ..." - docker push wazuh/$image:$IMAGE_TAG - done - - name: GH issue notification - if: ${{ inputs.push_images && steps.validation.outputs.purpose != '' }} + if: ${{ steps.validation.outputs.purpose != '' }} run: | IMAGE_TAG=${{ inputs.image_tag }} GH_TITLE="" diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 2cec68c8..f57d4878 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,8 +1,6 @@ -WAZUH_IMAGE_VERSION=4.14.3 -WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') -WAZUH_TAG_REVISION=1 +IMAGE_TAG=4.14.3 WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') -IMAGE_VERSION=${WAZUH_IMAGE_VERSION} +WAZUH_REGISTRY=docker.io # Wazuh package generator # Copyright (C) 2023, Wazuh Inc. @@ -44,7 +42,7 @@ build() { if [ "${WAZUH_DEV_STAGE}" ];then FILEBEAT_TEMPLATE_BRANCH="v${FILEBEAT_TEMPLATE_BRANCH}-${WAZUH_DEV_STAGE,,}" if ! curl --output /dev/null --silent --head --fail "https://github.com/wazuh/wazuh/tree/${FILEBEAT_TEMPLATE_BRANCH}"; then - echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" + echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" clean 1 fi else @@ -58,15 +56,25 @@ build() { fi fi - echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > .env - echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> .env - echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> .env - echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> .env - echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> .env - echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> .env - docker compose -f build-docker-images/build-images.yml --env-file .env build --no-cache || clean 1 + echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > ../.env + echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> ../.env + echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> ../.env + echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> ../.env + echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> ../.env + echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> ../.env + echo WAZUH_REGISTRY=$WAZUH_REGISTRY >> ../.env + echo IMAGE_TAG=$IMAGE_TAG >> ../.env + set -a + source ../.env + set +a + + if [ "${MULTIARCH}" ];then + docker buildx bake --file build-images.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + else + docker buildx bake --file build-images.yml --no-cache|| clean 1 + fi return 0 } @@ -79,7 +87,10 @@ help() { echo " -d, --dev [Optional] Set the development stage you want to build, example alpha0 or beta1, not used by default." echo " -f, --filebeat-module [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}." echo " -r, --revision [Optional] Package revision. By default ${WAZUH_TAG_REVISION}" + echo " -ref, --reference [Optional] Set the Wazuh reference to build development images. By default, the latest stable release." + echo " -rg, --registry [Optional] Set the Docker registry to push the images." echo " -v, --version [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}." + echo " -m, --multiarch [Optional] Enable multi-architecture builds." echo " -h, --help Show this help." echo exit $1 @@ -110,6 +121,10 @@ main() { help 1 fi ;; + "-m"|"--multiarch") + MULTIARCH="true" + shift + ;; "-r"|"--revision") if [ -n "${2}" ]; then WAZUH_TAG_REVISION="${2}" @@ -118,6 +133,22 @@ main() { help 1 fi ;; + "-ref"|"--reference") + if [ -n "${2}" ]; then + WAZUH_TAG_REFERENCE="${2}" + shift 2 + else + help 1 + fi + ;; + "-rg"|"--registry") + if [ -n "${2}" ]; then + WAZUH_REGISTRY="${2}" + shift 2 + else + help 1 + fi + ;; "-v"|"--version") if [ -n "$2" ]; then WAZUH_IMAGE_VERSION="$2" @@ -136,4 +167,4 @@ main() { clean 0 } -main "$@" +main "$@" \ No newline at end of file diff --git a/build-docker-images/build-images.yml b/build-docker-images/build-images.yml index ed784cec..b77669ca 100644 --- a/build-docker-images/build-images.yml +++ b/build-docker-images/build-images.yml @@ -8,7 +8,7 @@ services: WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} FILEBEAT_TEMPLATE_BRANCH: ${FILEBEAT_TEMPLATE_BRANCH} WAZUH_FILEBEAT_MODULE: ${WAZUH_FILEBEAT_MODULE} - image: wazuh/wazuh-manager:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-manager:${IMAGE_TAG} hostname: wazuh.manager restart: always ports: @@ -40,7 +40,7 @@ services: args: WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} - image: wazuh/wazuh-agent:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-agent:${IMAGE_TAG} hostname: wazuh.agent restart: always @@ -50,7 +50,7 @@ services: args: WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} - image: wazuh/wazuh-indexer:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-indexer:${IMAGE_TAG} hostname: wazuh.indexer restart: always ports: @@ -72,7 +72,7 @@ services: WAZUH_VERSION: ${WAZUH_VERSION} WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION} WAZUH_UI_REVISION: ${WAZUH_UI_REVISION} - image: wazuh/wazuh-dashboard:${WAZUH_IMAGE_VERSION} + image: ${WAZUH_REGISTRY}/wazuh/wazuh-dashboard:${IMAGE_TAG} hostname: wazuh.dashboard restart: always ports: From 08c7cbda5330e27b3ae5c5a139da9d3400dcba59 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Fri, 5 Dec 2025 13:59:53 -0500 Subject: [PATCH 03/19] Modify to build certs gen image --- indexer-certs-creator/build-image.sh | 100 ++++++++++++++++++++++++++ indexer-certs-creator/build-image.yml | 8 +++ 2 files changed, 108 insertions(+) create mode 100755 indexer-certs-creator/build-image.sh create mode 100644 indexer-certs-creator/build-image.yml diff --git a/indexer-certs-creator/build-image.sh b/indexer-certs-creator/build-image.sh new file mode 100755 index 00000000..3fd4c386 --- /dev/null +++ b/indexer-certs-creator/build-image.sh @@ -0,0 +1,100 @@ +#!/bin/bash + +# Wazuh package generator +# Copyright (C) 2023, Wazuh Inc. +# +# This program is a free software; you can redistribute it +# and/or modify it under the terms of the GNU General Public +# License (version 2) as published by the FSF - Free Software +# Foundation. + +WAZUH_CERTS_IMAGE_VERSION="0.0.4" +WAZUH_REGISTRY="docker.io" + +# ----------------------------------------------------------------------------- + +trap ctrl_c INT + +clean() { + exit_code=$1 + exit ${exit_code} +} + +ctrl_c() { + clean 1 +} + +# ----------------------------------------------------------------------------- + +build() { + IMAGE_TAG="${WAZUH_CERTS_IMAGE_VERSION}" + + echo WAZUH_REGISTRY=$WAZUH_REGISTRY > .env + echo IMAGE_TAG=$IMAGE_TAG >> .env + + set -a + source .env + set +a + + if [ "${MULTIARCH}" ]; then + docker buildx bake --file build-image.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + else + docker buildx bake --file build-image.yml --no-cache || clean 1 + fi + return 0 +} + +# ----------------------------------------------------------------------------- + +help() { + echo + echo "Usage: $0 [OPTIONS]" + echo + echo " -v, --version [Optional] Set the image version. By default ${WAZUH_CERTS_IMAGE_VERSION}." + echo " -rg, --registry [Optional] Set the Docker registry to push the images." + echo " -m, --multiarch [Optional] Enable multi-architecture builds." + echo " -h, --help Show this help." + echo + exit $1 +} + +# ----------------------------------------------------------------------------- + +main() { + while [ -n "${1}" ] + do + case "${1}" in + "-h"|"--help") + help 0 + ;; + "-m"|"--multiarch") + MULTIARCH="true" + shift + ;; + "-rg"|"--registry") + if [ -n "${2}" ]; then + WAZUH_REGISTRY="${2}" + shift 2 + else + help 1 + fi + ;; + "-v"|"--version") + if [ -n "$2" ]; then + WAZUH_CERTS_IMAGE_VERSION="$2" + shift 2 + else + help 1 + fi + ;; + *) + help 1 + esac + done + + build || clean 1 + + clean 0 +} + +main "$@" \ No newline at end of file diff --git a/indexer-certs-creator/build-image.yml b/indexer-certs-creator/build-image.yml new file mode 100644 index 00000000..58bb13cf --- /dev/null +++ b/indexer-certs-creator/build-image.yml @@ -0,0 +1,8 @@ +# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) +services: + wazuh.certs.generator: + build: + context: . + dockerfile: Dockerfile + image: ${WAZUH_REGISTRY}/wazuh/wazuh-certs-generator:${IMAGE_TAG} + hostname: wazuh-certs-generator From 6675465180e551dbf14dd0f043c51b750a48d9f6 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Thu, 4 Dec 2025 10:39:15 -0500 Subject: [PATCH 04/19] Adapt manager Dockerfile for multi-architecture builds --- build-docker-images/wazuh-manager/Dockerfile | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/build-docker-images/wazuh-manager/Dockerfile b/build-docker-images/wazuh-manager/Dockerfile index 73c86396..7591cc3c 100644 --- a/build-docker-images/wazuh-manager/Dockerfile +++ b/build-docker-images/wazuh-manager/Dockerfile @@ -11,6 +11,7 @@ ARG FILEBEAT_VERSION=7.10.2 ARG FILEBEAT_REVISION=2 ARG WAZUH_FILEBEAT_MODULE ARG S6_VERSION="v2.2.0.3" +ARG TARGETARCH RUN yum install curl-minimal xz gnupg tar gzip openssl findutils procps -y &&\ yum clean all @@ -27,11 +28,13 @@ RUN yum install wazuh-manager-${WAZUH_VERSION}-${WAZUH_TAG_REVISION} -y && \ chmod 775 /filebeat_module.sh && \ source /filebeat_module.sh && \ rm /filebeat_module.sh && \ - curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-amd64.tar.gz \ - -o /tmp/s6-overlay-amd64.tar.gz && \ - tar xzf /tmp/s6-overlay-amd64.tar.gz -C / --exclude="./bin" && \ - tar xzf /tmp/s6-overlay-amd64.tar.gz -C /usr ./bin && \ - rm /tmp/s6-overlay-amd64.tar.gz && \ + S6_ARCH="amd64" && \ + if [ "${TARGETARCH}" = "arm64" ]; then S6_ARCH="aarch64"; fi && \ + curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-${S6_ARCH}.tar.gz \ + -o /tmp/s6-overlay-${S6_ARCH}.tar.gz && \ + tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C / --exclude="./bin" && \ + tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C /usr ./bin && \ + rm /tmp/s6-overlay-${S6_ARCH}.tar.gz && \ rm -f /var/ossec/etc/sslmanager.key && \ rm -f /var/ossec/etc/sslmanager.cert From c6a427af707cfbb4eb1761a4c70bc17d529c924d Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Fri, 12 Dec 2025 12:44:21 -0500 Subject: [PATCH 05/19] Update documentation of certs-gen procedure --- indexer-certs-creator/README.md | 28 +++++++++++++++++++++++----- indexer-certs-creator/build-image.sh | 4 +++- 2 files changed, 26 insertions(+), 6 deletions(-) diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md index 8ddccdf5..04808a5d 100644 --- a/indexer-certs-creator/README.md +++ b/indexer-certs-creator/README.md @@ -1,9 +1,27 @@ -# Certificate creation image build +# Certificate Creation Image Build -The dockerfile hosted in this directory is used to build the image used to boot Wazuh's single node and multi node stacks. +The dockerfile hosted in this directory is used to build the image required for generating Wazuh Docker single-node and multi-node certificate files -To create the image, the following command must be executed: +## Pre-requisites +### QEMU + +Set up QEMU to enable building multi-architecture Docker images + +Useful documentation: + +- https://www.qemu.org/download/ +- https://docs.docker.com/build/building/multi-platform/#qemu + +## Procedure + +Run the following script to build the wazuh-certs-generator docker image + +```console +./build-image.sh -v [-m] [-rg ] ``` -$ docker build -t wazuh/wazuh-certs-generator:0.0.3 . -``` + +Replace with the new image desired tag. +Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`) +Use the `-rg ` parameter to specify a custom Docker registry (default is Docker Hub) + By default, the script will attempt to push the image to the registry and will only work if credentials are properly configured. diff --git a/indexer-certs-creator/build-image.sh b/indexer-certs-creator/build-image.sh index 3fd4c386..925d15a6 100755 --- a/indexer-certs-creator/build-image.sh +++ b/indexer-certs-creator/build-image.sh @@ -37,7 +37,9 @@ build() { set +a if [ "${MULTIARCH}" ]; then - docker buildx bake --file build-image.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + docker buildx bake --file build-image.yml \ + --set *.platform=linux/amd64,linux/arm64 \ + --no-cache || clean 1 else docker buildx bake --file build-image.yml --no-cache || clean 1 fi From a509f0f8ea18f1d158de24669fb6c20bffee2348 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Fri, 5 Dec 2025 08:51:05 -0500 Subject: [PATCH 06/19] Add changelog --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3b393f0f..e4b8a6b0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,7 +9,7 @@ All notable changes to this project will be documented in this file. ### Changed -- None +- Adapt to multi architecture build ([#2120](https://github.com/wazuh/wazuh-docker/pull/2120)) ### Fixed From 089ce24ffc85bf154932cbf222c1715ee6065847 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Mon, 15 Dec 2025 13:45:38 -0500 Subject: [PATCH 07/19] Enhance script execution of build and improve docs clarity --- build-docker-images/build-images.sh | 15 +++++++++++---- indexer-certs-creator/README.md | 8 ++++---- indexer-certs-creator/build-image.sh | 11 ++++++++--- 3 files changed, 23 insertions(+), 11 deletions(-) diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index f57d4878..00eb853f 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -42,7 +42,7 @@ build() { if [ "${WAZUH_DEV_STAGE}" ];then FILEBEAT_TEMPLATE_BRANCH="v${FILEBEAT_TEMPLATE_BRANCH}-${WAZUH_DEV_STAGE,,}" if ! curl --output /dev/null --silent --head --fail "https://github.com/wazuh/wazuh/tree/${FILEBEAT_TEMPLATE_BRANCH}"; then - echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" + echo "The indicated branch does not exist in the wazuh/wazuh repository: ${FILEBEAT_TEMPLATE_BRANCH}" clean 1 fi else @@ -71,9 +71,16 @@ build() { set +a if [ "${MULTIARCH}" ];then - docker buildx bake --file build-images.yml --push --set *.platform=linux/amd64,linux/arm64 --no-cache || clean 1 + docker buildx bake \ + --file build-images.yml \ + --push \ + --set *.platform=linux/amd64,linux/arm64 \ + --no-cache || clean 1 else - docker buildx bake --file build-images.yml --no-cache|| clean 1 + docker buildx bake \ + --file build-images.yml \ + --load \ + --no-cache || clean 1 fi return 0 } @@ -167,4 +174,4 @@ main() { clean 0 } -main "$@" \ No newline at end of file +main "$@" diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md index 04808a5d..d9b20bf7 100644 --- a/indexer-certs-creator/README.md +++ b/indexer-certs-creator/README.md @@ -21,7 +21,7 @@ Run the following script to build the wazuh-certs-generator docker image ./build-image.sh -v [-m] [-rg ] ``` -Replace with the new image desired tag. -Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`) -Use the `-rg ` parameter to specify a custom Docker registry (default is Docker Hub) - By default, the script will attempt to push the image to the registry and will only work if credentials are properly configured. +- Replace with the new image desired tag. +- Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`) + - If multiarch build is enabled, the script will attempt to push the image to the specified registry. This image upload will only work if credentials are properly configured. +- Use the `-rg ` parameter to specify a custom Docker registry (default is Docker Hub) diff --git a/indexer-certs-creator/build-image.sh b/indexer-certs-creator/build-image.sh index 925d15a6..afa0eea2 100755 --- a/indexer-certs-creator/build-image.sh +++ b/indexer-certs-creator/build-image.sh @@ -37,11 +37,16 @@ build() { set +a if [ "${MULTIARCH}" ]; then - docker buildx bake --file build-image.yml \ + docker buildx bake \ + --file build-image.yml \ --set *.platform=linux/amd64,linux/arm64 \ + --push \ --no-cache || clean 1 else - docker buildx bake --file build-image.yml --no-cache || clean 1 + docker buildx bake \ + --file build-image.yml \ + --load \ + --no-cache || clean 1 fi return 0 } @@ -99,4 +104,4 @@ main() { clean 0 } -main "$@" \ No newline at end of file +main "$@" From f51fc2e4ae7f76c4256e7b32cce3025cd94d2d4a Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Wed, 17 Dec 2025 12:10:46 -0500 Subject: [PATCH 08/19] Add check (input.dev must be false) for image validation and GH issue notification in push workflow --- .github/workflows/Procedure_push_docker_images.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/Procedure_push_docker_images.yml b/.github/workflows/Procedure_push_docker_images.yml index bf45b917..57871a29 100644 --- a/.github/workflows/Procedure_push_docker_images.yml +++ b/.github/workflows/Procedure_push_docker_images.yml @@ -157,6 +157,7 @@ jobs: working-directory: ./build-docker-images - name: Image exists validation + if: ${{ inputs.dev == false }} id: validation run: | IMAGE_TAG=${{ inputs.image_tag }} @@ -181,7 +182,7 @@ jobs: echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT - name: GH issue notification - if: ${{ steps.validation.outputs.purpose != '' }} + if: ${{ inputs.dev == false && steps.validation.outputs.purpose != '' }} run: | IMAGE_TAG=${{ inputs.image_tag }} GH_TITLE="" From f7927bf2381ce156c7ad0898a333ea37e419bd43 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gonzalo=20Acu=C3=B1a?= Date: Wed, 17 Dec 2025 16:13:13 -0300 Subject: [PATCH 09/19] Changelog update --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4d3ab948..d002c91d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,7 +9,7 @@ All notable changes to this project will be documented in this file. ### Changed -- None +- Agent group parameter added ([#2127](https://github.com/wazuh/wazuh-docker/pull/2127)) ### Fixed From 9138f7a9f56c6d4cbc118087e8928d46546bd3d1 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Wed, 17 Dec 2025 15:27:21 -0500 Subject: [PATCH 10/19] Update certs generator image version to 0.0.4 in multi-node and single-node configurations --- multi-node/generate-indexer-certs.yml | 2 +- single-node/generate-indexer-certs.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/multi-node/generate-indexer-certs.yml b/multi-node/generate-indexer-certs.yml index 88927593..c719d22e 100644 --- a/multi-node/generate-indexer-certs.yml +++ b/multi-node/generate-indexer-certs.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: generator: - image: wazuh/wazuh-certs-generator:0.0.3 + image: wazuh/wazuh-certs-generator:0.0.4 hostname: wazuh-certs-generator environment: - CERT_TOOL_VERSION=4.14 diff --git a/single-node/generate-indexer-certs.yml b/single-node/generate-indexer-certs.yml index a941280f..dfcdca57 100644 --- a/single-node/generate-indexer-certs.yml +++ b/single-node/generate-indexer-certs.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: generator: - image: wazuh/wazuh-certs-generator:0.0.3 + image: wazuh/wazuh-certs-generator:0.0.4 hostname: wazuh-certs-generator environment: - CERT_TOOL_VERSION=4.14 From dd165bf3ec6e1cd49c7b102876c309e8956313fd Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Thu, 18 Dec 2025 10:13:47 -0500 Subject: [PATCH 11/19] Update indexer-certs-gen README.md for clarity on procedure --- indexer-certs-creator/README.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md index d9b20bf7..3f979e6f 100644 --- a/indexer-certs-creator/README.md +++ b/indexer-certs-creator/README.md @@ -4,14 +4,15 @@ The dockerfile hosted in this directory is used to build the image required for ## Pre-requisites -### QEMU - -Set up QEMU to enable building multi-architecture Docker images +1. Verify the Docker Buildx plugin is properly set up +2. For multi-architecture image builds: + - Ensure QEMU is installed + - Check permissions to push images to a Docker registry Useful documentation: +- https://docs.docker.com/build/building/multi-platform/ - https://www.qemu.org/download/ -- https://docs.docker.com/build/building/multi-platform/#qemu ## Procedure From 3a5e30b8882c51e83e6d744c17d3b1871824e7e7 Mon Sep 17 00:00:00 2001 From: wazuhci <22834044+wazuhci@users.noreply.github.com> Date: Fri, 19 Dec 2025 09:56:23 +0000 Subject: [PATCH 12/19] feat: bump 4.14.2 --- VERSION.json | 2 +- build-docker-images/build-images.sh | 2 +- docs/dev/build-image.md | 2 +- multi-node/docker-compose.yml | 12 ++++++------ single-node/docker-compose.yml | 6 +++--- wazuh-agent/docker-compose.yml | 2 +- 6 files changed, 13 insertions(+), 13 deletions(-) diff --git a/VERSION.json b/VERSION.json index c0140fe7..1a7f8ca1 100644 --- a/VERSION.json +++ b/VERSION.json @@ -1,4 +1,4 @@ { "version": "4.14.2", - "stage": "rc1" + "stage": "rc2" } diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index f4086e42..f1f65ccb 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -76,7 +76,7 @@ help() { echo echo "Usage: $0 [OPTIONS]" echo - echo " -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default." + echo " -d, --dev [Optional] Set the development stage you want to build, example rc2 or beta1, not used by default." echo " -f, --filebeat-module [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}." echo " -r, --revision [Optional] Package revision. By default ${WAZUH_TAG_REVISION}" echo " -v, --version [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}." diff --git a/docs/dev/build-image.md b/docs/dev/build-image.md index 041ad1a5..1103f502 100644 --- a/docs/dev/build-image.md +++ b/docs/dev/build-image.md @@ -23,7 +23,7 @@ $ build-docker-images/build-images.sh -h Usage: build-docker-images/build-images.sh [OPTIONS] - -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default. + -d, --dev [Optional] Set the development stage you want to build, example rc2 or beta1, not used by default. -f, --filebeat-module [Optional] Set Filebeat module version. By default 0.5. -r, --revision [Optional] Package revision. By default 1 -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.14.2. diff --git a/multi-node/docker-compose.yml b/multi-node/docker-compose.yml index d0091d51..aa167337 100644 --- a/multi-node/docker-compose.yml +++ b/multi-node/docker-compose.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: wazuh.master: - image: wazuh/wazuh-manager:4.14.2 + image: wazuh/wazuh-manager:4.14.2-rc2 hostname: wazuh.master restart: always ulimits: @@ -43,7 +43,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.worker: - image: wazuh/wazuh-manager:4.14.2 + image: wazuh/wazuh-manager:4.14.2-rc2 hostname: wazuh.worker restart: always ulimits: @@ -79,7 +79,7 @@ services: - ./config/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf wazuh1.indexer: - image: wazuh/wazuh-indexer:4.14.2 + image: wazuh/wazuh-indexer:4.14.2-rc2 hostname: wazuh1.indexer restart: always ports: @@ -105,7 +105,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh2.indexer: - image: wazuh/wazuh-indexer:4.14.2 + image: wazuh/wazuh-indexer:4.14.2-rc2 hostname: wazuh2.indexer restart: always environment: @@ -127,7 +127,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh3.indexer: - image: wazuh/wazuh-indexer:4.14.2 + image: wazuh/wazuh-indexer:4.14.2-rc2 hostname: wazuh3.indexer restart: always environment: @@ -149,7 +149,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.14.2 + image: wazuh/wazuh-dashboard:4.14.2-rc2 hostname: wazuh.dashboard restart: always ports: diff --git a/single-node/docker-compose.yml b/single-node/docker-compose.yml index 9dd70a6b..600a7284 100644 --- a/single-node/docker-compose.yml +++ b/single-node/docker-compose.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: wazuh.manager: - image: wazuh/wazuh-manager:4.14.2 + image: wazuh/wazuh-manager:4.14.2-rc2 hostname: wazuh.manager restart: always ulimits: @@ -44,7 +44,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.indexer: - image: wazuh/wazuh-indexer:4.14.2 + image: wazuh/wazuh-indexer:4.14.2-rc2 hostname: wazuh.indexer restart: always ports: @@ -69,7 +69,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.14.2 + image: wazuh/wazuh-dashboard:4.14.2-rc2 hostname: wazuh.dashboard restart: always ports: diff --git a/wazuh-agent/docker-compose.yml b/wazuh-agent/docker-compose.yml index 67142ad1..91fdb29f 100644 --- a/wazuh-agent/docker-compose.yml +++ b/wazuh-agent/docker-compose.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: wazuh.agent: - image: wazuh/wazuh-agent:4.14.2 + image: wazuh/wazuh-agent:4.14.2-rc2 restart: always environment: - WAZUH_MANAGER_SERVER= From a95ec0dac9befb769b18a176a66955f91d8cda64 Mon Sep 17 00:00:00 2001 From: Victor Carlos Erenu Date: Fri, 19 Dec 2025 17:58:18 +0700 Subject: [PATCH 13/19] Revert image tag --- multi-node/docker-compose.yml | 12 ++++++------ single-node/docker-compose.yml | 6 +++--- wazuh-agent/docker-compose.yml | 2 +- 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/multi-node/docker-compose.yml b/multi-node/docker-compose.yml index aa167337..d0091d51 100644 --- a/multi-node/docker-compose.yml +++ b/multi-node/docker-compose.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: wazuh.master: - image: wazuh/wazuh-manager:4.14.2-rc2 + image: wazuh/wazuh-manager:4.14.2 hostname: wazuh.master restart: always ulimits: @@ -43,7 +43,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.worker: - image: wazuh/wazuh-manager:4.14.2-rc2 + image: wazuh/wazuh-manager:4.14.2 hostname: wazuh.worker restart: always ulimits: @@ -79,7 +79,7 @@ services: - ./config/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf wazuh1.indexer: - image: wazuh/wazuh-indexer:4.14.2-rc2 + image: wazuh/wazuh-indexer:4.14.2 hostname: wazuh1.indexer restart: always ports: @@ -105,7 +105,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh2.indexer: - image: wazuh/wazuh-indexer:4.14.2-rc2 + image: wazuh/wazuh-indexer:4.14.2 hostname: wazuh2.indexer restart: always environment: @@ -127,7 +127,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh3.indexer: - image: wazuh/wazuh-indexer:4.14.2-rc2 + image: wazuh/wazuh-indexer:4.14.2 hostname: wazuh3.indexer restart: always environment: @@ -149,7 +149,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.14.2-rc2 + image: wazuh/wazuh-dashboard:4.14.2 hostname: wazuh.dashboard restart: always ports: diff --git a/single-node/docker-compose.yml b/single-node/docker-compose.yml index 600a7284..9dd70a6b 100644 --- a/single-node/docker-compose.yml +++ b/single-node/docker-compose.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: wazuh.manager: - image: wazuh/wazuh-manager:4.14.2-rc2 + image: wazuh/wazuh-manager:4.14.2 hostname: wazuh.manager restart: always ulimits: @@ -44,7 +44,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.indexer: - image: wazuh/wazuh-indexer:4.14.2-rc2 + image: wazuh/wazuh-indexer:4.14.2 hostname: wazuh.indexer restart: always ports: @@ -69,7 +69,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.14.2-rc2 + image: wazuh/wazuh-dashboard:4.14.2 hostname: wazuh.dashboard restart: always ports: diff --git a/wazuh-agent/docker-compose.yml b/wazuh-agent/docker-compose.yml index 91fdb29f..67142ad1 100644 --- a/wazuh-agent/docker-compose.yml +++ b/wazuh-agent/docker-compose.yml @@ -1,7 +1,7 @@ # Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) services: wazuh.agent: - image: wazuh/wazuh-agent:4.14.2-rc2 + image: wazuh/wazuh-agent:4.14.2 restart: always environment: - WAZUH_MANAGER_SERVER= From f04ed6e6088a8a099dd35d15a0c0e2a9036a8e21 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Mon, 22 Dec 2025 08:36:09 -0500 Subject: [PATCH 14/19] Update documentation for Wazuh Docker image builder and workflow usage --- - All relevant content of README.md files was migrated to docs/ section in their respective section. - These README files has been deleted (4 files) - All README.md files (additional to the project's root and docs/) have been edited. --- - Both files build-docker-images/README.md and docs/dev/build-image.md have almost same content, so it was discarded the README file - As the directory and docker image are going to be disused, the certs-gen documentation contents of indexer-certs-creator/README.md was not mig> - The 'bash' command added to the docs/dev/build-image.md was removed - Added workflow usage docs file to the the SUMMARY.md file --- - Removed '$' parameter and added 'bash' to all markdown code blocks headings (```) --- --- CHANGELOG.md | 1 + build-docker-images/README.md | 34 ---------- docs/SUMMARY.md | 1 + docs/dev/build-image.md | 37 ++++++----- docs/dev/run-tests.md | 2 + docs/dev/workflow-usage.md | 61 ++++++++++++++++++ .../getting-started/deployment/deployment.md | 4 +- .../getting-started/deployment/multi-node.md | 63 ++++++++++++++++--- .../getting-started/deployment/single-node.md | 56 +++++++++++++---- indexer-certs-creator/README.md | 9 --- multi-node/README.md | 62 ------------------ single-node/README.md | 53 ---------------- 12 files changed, 188 insertions(+), 195 deletions(-) delete mode 100644 build-docker-images/README.md create mode 100644 docs/dev/workflow-usage.md delete mode 100644 indexer-certs-creator/README.md delete mode 100644 multi-node/README.md delete mode 100644 single-node/README.md diff --git a/CHANGELOG.md b/CHANGELOG.md index 74b1b78e..2b4bccec 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,7 @@ All notable changes to this project will be documented in this file. ### Changed +- Update documentation for Wazuh Docker image builder and workflow usage ([#2136](https://github.com/wazuh/wazuh-puppet/issues/2136)) - Configure deployment with environment variables ([#2081](https://github.com/wazuh/wazuh-puppet/issues/2081)) - Modify Wazuh components install method ([#2058](https://github.com/wazuh/wazuh-puppet/issues/2058)) - Image builder Workflow Rebuild ([#2054](https://github.com/wazuh/wazuh-puppet/issues/2054)) diff --git a/build-docker-images/README.md b/build-docker-images/README.md deleted file mode 100644 index f0a1e338..00000000 --- a/build-docker-images/README.md +++ /dev/null @@ -1,34 +0,0 @@ -# Wazuh Docker Image Builder - -The creation of the images for the Wazuh stack deployment in Docker is done with the build-images.yml script - -To execute the process, the following must be executed in the root of the wazuh-docker repository: - -``` -$ build-docker-images/build-images.sh -``` - -This script initializes the environment variables needed to build each of the images. - -The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument: - -``` -$ build-docker-images/build-images.sh -v 5.0.0 -``` - -To get all the available script options use the -h or --help option: - -``` -$ build-docker-images/build-images.sh -h - -Usage: build-docker-images/build-images.sh [OPTIONS] - - -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default. - -r, --revision [Optional] Package revision. By default 1 - -ref, --reference [Optional] Set the Wazuh reference to build development images. By default, the latest stable release. - -rg, --registry [Optional] Set the Docker registry to push the images. - -v, --version [Optional] Set the Wazuh version should be builded. By default, 5.0.0. - -m, --multiarch [Optional] Enable multi-architecture builds. - -h, --help Show this help. - -``` \ No newline at end of file diff --git a/docs/SUMMARY.md b/docs/SUMMARY.md index fa09fd2c..be59f772 100644 --- a/docs/SUMMARY.md +++ b/docs/SUMMARY.md @@ -8,6 +8,7 @@ - [Setup Environment](dev/setup.md) - [Build Image](dev/build-image.md) - [Run Tests](dev/run-tests.md) +- [Workflow Usage](dev/workflow-usage.md) # Reference Manual diff --git a/docs/dev/build-image.md b/docs/dev/build-image.md index 4c2c4512..a9a95edd 100644 --- a/docs/dev/build-image.md +++ b/docs/dev/build-image.md @@ -1,31 +1,40 @@ # Wazuh Docker Image Builder -The creation of the images for the Wazuh stack deployment in Docker is done with the build-images.yml script - -To execute the process, the following must be executed in the root of the wazuh-docker repository: - -``` -$ build-docker-images/build-images.sh -``` +The creation of the images for the Wazuh stack deployment in Docker is done with the `build-docker-images/build-images.sh` script This script initializes the environment variables needed to build each of the images. -The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument: +To execute it, make sure to be in the `build-docker-images` directory: -``` -$ build-docker-images/build-images.sh -v 5.0.0 +```bash +cd build-docker-images ``` -To get all the available script options use the -h or --help option: +Then execute: +```bash +./build-images.sh ``` -$ build-docker-images/build-images.sh -h -Usage: build-docker-images/build-images.sh [OPTIONS] +The script also allows to build images from other versions of Wazuh by using the `-v` or `--version` argument: + +```bash +./build-images.sh -v 5.0.0 +``` + +To get all the available script options use the `-h` or `--help` option: + +```bash +./build-images.sh -h + +Usage: build-images.sh [OPTIONS] -d, --dev [Optional] Set the development stage you want to build, example rc2 or beta1, not used by default. -r, --revision [Optional] Package revision. By default 1 + -ref, --reference [Optional] Set the Wazuh reference to build development images. By default, the latest stable release. + -rg, --registry [Optional] Set the Docker registry to push the images. -v, --version [Optional] Set the Wazuh version should be builded. By default, 5.0.0. + -m, --multiarch [Optional] Enable multi-architecture builds. -h, --help Show this help. -``` \ No newline at end of file +``` diff --git a/docs/dev/run-tests.md b/docs/dev/run-tests.md index e4b1a9d3..c9718f10 100644 --- a/docs/dev/run-tests.md +++ b/docs/dev/run-tests.md @@ -2,6 +2,8 @@ This repository includes automated tests designed to validate the correct deployment of Wazuh using Docker. These tests are executed on every pull request (PR) to ensure the integrity and stability of the system when changes are introduced. +Check more information on the [Workflow usage](workflow-usage.md) page. + ## Purpose The main objective of the tests is to verify that the Wazuh Docker environment can be successfully deployed and that all its core components (Wazuh Manager, Indexer, Dashboard, and Agents) operate as expected after any modification in the codebase. diff --git a/docs/dev/workflow-usage.md b/docs/dev/workflow-usage.md new file mode 100644 index 00000000..236786d2 --- /dev/null +++ b/docs/dev/workflow-usage.md @@ -0,0 +1,61 @@ +# Workflow usage + +The Procedure_push_docker_images.yml workflow builds and pushes multi-architecture Docker images (amd64/arm64) of Wazuh core components (Indexer, Manager, Dashboard, and Agent) to container registries. + +## Input Parameters + +| Parameter | Description | Default | Required | +|-----------|-------------|---------|----------| +| `image_tag` | Docker image version tag | `5.0.0` | Yes | +| `docker_reference` | Branch/tag to build from | - | Yes | +| `revision` | Package revision number | `1` | Yes | +| `reference` | Dev reference (for pre-release builds) | `latest` | No | +| `id` | Workflow run identifier | - | No | +| `dev` | Enable development mode (adds `-dev` suffix) | `false`/`true` | No | + +## Development vs Production Mode + +**Development Mode** (`dev: true`): + +- Pushes to AWS ECR (Elastic Container Registry) +- Uses pre-signed S3 URLs for packages +- Generates dynamic `artifact_urls.yml` from S3 bucket +- Adds development reference to image tags +- Authenticates via AWS IAM role + +**Production Mode** (`dev: false`): + +- Pushes to Docker Hub +- Uses public package repositories +- Authenticates with Docker Hub credentials +- Supports version stages (rc, beta, etc.) + +## Build Process + +1. **Artifact Resolution**: + - Dev mode: Creates pre-signed URLs for all Wazuh packages from S3 + - Prod mode: Uses packages from public repositories + +2. **Multi-architecture Build**: + - Uses Docker Buildx with QEMU for cross-platform builds + - Builds for `linux/amd64` and `linux/arm64` + - Leverages `build-images.yml` for build configuration + +3. **Image Publishing**: + - Tags images appropriately based on mode + - Pushes to the configured registry + - Generates .env file with build metadata + +## Log Collection Feature + +When tests fail, the workflows automatically collect and display relevant logs to help diagnose issues quickly. + +This is implemented via two scripts, executed depending on the test setup: +Single-node: `single-node-log-check.sh` +Multi-node: `multi-node-log-check.sh` + +Capabilities include: + +- Collects ERROR, WARNING, and CRITICAL messages from all nodes. +- Automatically gathers logs on test failures for faster debugging. + diff --git a/docs/ref/getting-started/deployment/deployment.md b/docs/ref/getting-started/deployment/deployment.md index 48360ef6..61fcb922 100644 --- a/docs/ref/getting-started/deployment/deployment.md +++ b/docs/ref/getting-started/deployment/deployment.md @@ -22,11 +22,11 @@ Wazuh-Docker offers flexibility in how you can deploy the Wazuh stack. The prima Ensure you have: -- Met all the [System Requirements](ref/getting-started/requirements.md). +- Met all the [System Requirements](../requirements.md). - Installed Docker and Docker Compose on your host(s). - Cloned the `wazuh-docker` repository (version `5.0.0`) or downloaded the necessary deployment files. ```bash - git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git) + git clone https://github.com/wazuh/wazuh-docker.git cd wazuh-docker git checkout v5.0.0 ``` diff --git a/docs/ref/getting-started/deployment/multi-node.md b/docs/ref/getting-started/deployment/multi-node.md index 19f9e968..6ee10934 100644 --- a/docs/ref/getting-started/deployment/multi-node.md +++ b/docs/ref/getting-started/deployment/multi-node.md @@ -2,31 +2,74 @@ ## Deploying Wazuh Docker in a Multi-Node Configuration -This deployment utilizes the `multi-node/docker-compose.yml` file, which defines a cluster setup with two Wazuh manager containers, three Wazuh indexer containers, and one Wazuh dashboard container. Follow these steps to deploy this configuration: +This deployment utilizes the `multi-node/docker-compose.yml` file, which defines a cluster setup with two Wazuh Manager, three Wazuh Indexer, and one Wazuh Dashboard containers. Follow these steps to deploy this configuration: + +1. Increase `vm.max_map_count` on each Docker host that will run a Wazuh Indexer container (Linux). This setting is crucial for Wazuh Indexer to operate correctly. This command requires root permissions: + + ```bash + sudo sysctl -w vm.max_map_count=262144 + ``` + + **Note:** This change is temporary and will revert upon reboot. To make it permanent on each relevant host, you'll need to edit the `/etc/sysctl.conf` file, add `vm.max_map_count=262144`, and then apply the change with `sudo sysctl -p`. + +2. Navigate to the `multi-node` directory within your repository: -1. Navigate to the `multi-node` directory within your repository: ```bash cd multi-node ``` -2. Increase `vm.max_map_count` on each Docker host that will run a Wazuh Indexer container (Linux). This setting is crucial for Wazuh Indexer to operate correctly. This command requires root permissions: - ```bash - sudo sysctl -w vm.max_map_count=262144 - ``` - **Note:** This change is temporary and will revert upon reboot. To make it permanent on each relevant host, you'll need to edit the `/etc/sysctl.conf` file, add `vm.max_map_count=262144`, and then apply the change with `sudo sysctl -p`. +3. Download the certificate creation script and config.yml file: -3. Run the script to generate the necessary certificates for the Wazuh Stack. This ensures secure communication between the nodes: ```bash - docker compose -f generate-indexer-certs.yml run --rm generator + curl -sO https://packages.wazuh.com/5.0/wazuh-certs-tool.sh + curl -sO https://packages.wazuh.com/5.0/config.yml ``` -4. Start the Wazuh environment using `docker compose`: +4. Edit the `config.yml` file with the configuration of the Wazuh components to be deployed + + ```bash + nodes: + # Wazuh indexer server nodes + indexer: + - name: wazuh1.indexer + ip: wazuh1.indexer + - name: wazuh2.indexer + ip: wazuh2.indexer + - name: wazuh3.indexer + ip: wazuh3.indexer + + # Wazuh server nodes + # Use node_type only with more than one Wazuh manager + server: + - name: wazuh.master + ip: wazuh.master + node_type: master + - name: wazuh.worker + ip: wazuh.worker + node_type: worker + + # Wazuh dashboard node + dashboard: + - name: wazuh.dashboard + ip: wazuh.dashboard + ``` + +5. Run the certificate creation script: + + ```bash + bash ./wazuh-certs-tool.sh -A + ``` + +6. Start the Wazuh environment using `docker compose`: * To run in the foreground (logs will be displayed in your current terminal; press `Ctrl+C` to stop): + ```bash docker compose up ``` + * To run in the background (detached mode, allowing the containers to run independently of your terminal): + ```bash docker compose up -d ``` diff --git a/docs/ref/getting-started/deployment/single-node.md b/docs/ref/getting-started/deployment/single-node.md index f5ab7eb8..f058fe3b 100644 --- a/docs/ref/getting-started/deployment/single-node.md +++ b/docs/ref/getting-started/deployment/single-node.md @@ -2,34 +2,68 @@ ## Deploying Wazuh Docker in a Single-Node Configuration -This deployment uses the `single-node/docker-compose.yml` file, which defines a setup with one Wazuh manager container, one Wazuh indexer container, and one Wazuh dashboard container. Follow these steps to deploy it: +This deployment uses the `single-node/docker-compose.yml` file, which defines a setup with one Wazuh Manager, one Wazuh Indexer, and one Wazuh Dashboard container. Follow these steps to deploy it: + +1. Increase `vm.max_map_count` on each Docker host that will run a Wazuh Indexer container (Linux). This setting is crucial for Wazuh Indexer to operate correctly. This command requires root permissions: + + ```bash + sudo sysctl -w vm.max_map_count=262144 + ``` + + **Note:** This change is temporary and will revert upon reboot. To make it permanent, you'll need to edit the `/etc/sysctl.conf` file and add `vm.max_map_count=262144`, then apply with `sudo sysctl -p`. + +2. Navigate to the `single-node` directory within your repository: -1. Navigate to the `single-node` directory within your repository: ```bash cd single-node ``` -2. Increase `vm.max_map_count` on each Docker host that will run a Wazuh Indexer container (Linux). This setting is crucial for Wazuh Indexer to operate correctly. This command requires root permissions: - ```bash - sudo sysctl -w vm.max_map_count=262144 - ``` - **Note:** This change is temporary and will revert upon reboot. To make it permanent, you'll need to edit the `/etc/sysctl.conf` file and add `vm.max_map_count=262144`, then apply with `sudo sysctl -p`. +3. Download the certificate creation script and `config.yml` file: -3. Run the script to generate the necessary certificates for the Wazuh Stack. This ensures secure communication between the nodes: ```bash - docker compose -f generate-indexer-certs.yml run --rm generator + curl -sO https://packages.wazuh.com/5.0/wazuh-certs-tool.sh + curl -sO https://packages.wazuh.com/5.0/config.yml ``` -4. Start the Wazuh environment using `docker compose`: +4. Edit the config.yml file with the configuration of the Wazuh components to be deployed + + ```bash + nodes: + # Wazuh indexer server nodes + indexer: + - name: wazuh.indexer + ip: wazuh.indexer + + # Wazuh server nodes + # Use node_type only with more than one Wazuh manager + server: + - name: wazuh.manager + ip: wazuh.manager + + # Wazuh dashboard node + dashboard: + - name: wazuh.dashboard + ip: wazuh.dashboard + ``` + +5. Run the certificate creation script: + + ```bash + bash ./wazuh-certs-tool.sh -A + ``` + +5. Start the Wazuh environment using `docker compose`: * To run in the foreground (logs will be displayed in your current terminal; press `Ctrl+C` to stop): + ```bash docker compose up ``` + * To run in the background (detached mode, allowing the containers to run independently of your terminal): + ```bash docker compose up -d ``` Please allow some time for the environment to initialize, especially on the first run. It can take approximately a minute or two (depending on your host's resources) as the Wazuh Indexer starts up and generates the necessary indexes and index patterns. - diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md deleted file mode 100644 index 8ddccdf5..00000000 --- a/indexer-certs-creator/README.md +++ /dev/null @@ -1,9 +0,0 @@ -# Certificate creation image build - -The dockerfile hosted in this directory is used to build the image used to boot Wazuh's single node and multi node stacks. - -To create the image, the following command must be executed: - -``` -$ docker build -t wazuh/wazuh-certs-generator:0.0.3 . -``` diff --git a/multi-node/README.md b/multi-node/README.md deleted file mode 100644 index 9a300fc7..00000000 --- a/multi-node/README.md +++ /dev/null @@ -1,62 +0,0 @@ -# Deploy Wazuh Docker in multi node configuration - -This deployment is defined in the `docker-compose.yml` file with two Wazuh manager containers, three Wazuh indexer containers, and one Wazuh dashboard container. It can be deployed by following these steps: - -1) Increase max_map_count on your host (Linux). This command must be run with root permissions: -``` -$ sysctl -w vm.max_map_count=262144 -``` - -2) Download the certificate creation script and config.yml file: -``` -$ curl -sO https://packages.wazuh.com/5.0/wazuh-certs-tool.sh -$ curl -sO https://packages.wazuh.com/5.0/config.yml -``` - -3) Edit the config.yml file with the configuration of the Wazuh components to be deployed -``` -nodes: - # Wazuh indexer server nodes - indexer: - - name: wazuh1.indexer - ip: wazuh1.indexer - - name: wazuh2.indexer - ip: wazuh2.indexer - - name: wazuh3.indexer - ip: wazuh3.indexer - - # Wazuh server nodes - # Use node_type only with more than one Wazuh manager - server: - - name: wazuh.master - ip: wazuh.master - node_type: master - - name: wazuh.worker - ip: wazuh.worker - node_type: worker - - # Wazuh dashboard node - dashboard: - - name: wazuh.dashboard - ip: wazuh.dashboard -``` - -4) Run the certificate creation script: -``` -bash ./wazuh-certs-tool.sh -A -``` - -5) Start the environment with docker compose: - -- In the foregroud: -``` -$ docker compose up -``` - -- In the background: -``` -$ docker compose up -d -``` - - -The environment takes about 1 minute to get up (depending on your Docker host) for the first time since Wazuh Indexer must be started for the first time and the indexes and index patterns must be generated. diff --git a/single-node/README.md b/single-node/README.md deleted file mode 100644 index fbded2be..00000000 --- a/single-node/README.md +++ /dev/null @@ -1,53 +0,0 @@ -# Deploy Wazuh Docker in single node configuration - -This deployment is defined in the `docker-compose.yml` file with one Wazuh manager containers, one Wazuh indexer containers, and one Wazuh dashboard container. It can be deployed by following these steps: - -1) Increase max_map_count on your host (Linux). This command must be run with root permissions: -``` -$ sysctl -w vm.max_map_count=262144 -``` - -2) Download the certificate creation script and config.yml file: -``` -$ curl -sO https://packages.wazuh.com/5.0/wazuh-certs-tool.sh -$ curl -sO https://packages.wazuh.com/5.0/config.yml -``` - -3) Edit the config.yml file with the configuration of the Wazuh components to be deployed -``` -nodes: - # Wazuh indexer server nodes - indexer: - - name: wazuh.indexer - ip: wazuh.indexer - - # Wazuh server nodes - # Use node_type only with more than one Wazuh manager - server: - - name: wazuh.manager - ip: wazuh.manager - - # Wazuh dashboard node - dashboard: - - name: wazuh.dashboard - ip: wazuh.dashboard -``` - -4) Run the certificate creation script: -``` -bash ./wazuh-certs-tool.sh -A -``` - -5) Start the environment with docker compose: - -- In the foregroud: -``` -$ docker compose up -``` - -- In the background: -``` -$ docker compose up -d -``` - -The environment takes about 1 minute to get up (depending on your Docker host) for the first time since Wazuh Indexer must be started for the first time and the indexes and index patterns must be generated. From a5fc8fd88c9c4fbfa5ac6eeba69fd69623b1023e Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Mon, 22 Dec 2025 10:17:01 -0500 Subject: [PATCH 15/19] Improve documentation for Docker image building process and remove unused reference option --- build-docker-images/README.md | 32 ++++++++++++++++++----------- build-docker-images/build-images.sh | 9 -------- indexer-certs-creator/README.md | 6 +++++- 3 files changed, 25 insertions(+), 22 deletions(-) diff --git a/build-docker-images/README.md b/build-docker-images/README.md index d4640644..8502b8c6 100644 --- a/build-docker-images/README.md +++ b/build-docker-images/README.md @@ -1,32 +1,40 @@ # Wazuh Docker Image Builder -The creation of the images for the Wazuh stack deployment in Docker is done with the build-images.yml script - -To execute the process, the following must be executed in the root of the wazuh-docker repository: - -``` -$ build-docker-images/build-images.sh -``` +The creation of the images for the Wazuh stack deployment in Docker is done with the `build-docker-images/build-images.sh` script This script initializes the environment variables needed to build each of the images. -The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument: +To execute it, make sure to be in the `build-docker-images` directory: +```bash +cd build-docker-images ``` -$ build-docker-images/build-images.sh -v 4.14.3 + +Then execute: + +```bash +./build-images.sh +``` + +The script also allows to build images from other versions of Wazuh by using the `-v` or `--version` argument: + +```bash +./build-images.sh -v 4.14.3 ``` To get all the available script options use the -h or --help option: -``` -$ build-docker-images/build-images.sh -h +```bash +./build-images.sh -h -Usage: build-docker-images/build-images.sh [OPTIONS] +Usage: ./build-images.sh [OPTIONS] -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default. -f, --filebeat-module [Optional] Set Filebeat module version. By default 0.5. -r, --revision [Optional] Package revision. By default 1 + -rg, --registry [Optional] Set the Docker registry to push the images. -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.14.3. + -m, --multiarch [Optional] Enable multi-architecture builds. -h, --help Show this help. ``` \ No newline at end of file diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 5cc8e1ae..a284b1fb 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -94,7 +94,6 @@ help() { echo " -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default." echo " -f, --filebeat-module [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}." echo " -r, --revision [Optional] Package revision. By default ${WAZUH_TAG_REVISION}" - echo " -ref, --reference [Optional] Set the Wazuh reference to build development images. By default, the latest stable release." echo " -rg, --registry [Optional] Set the Docker registry to push the images." echo " -v, --version [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}." echo " -m, --multiarch [Optional] Enable multi-architecture builds." @@ -140,14 +139,6 @@ main() { help 1 fi ;; - "-ref"|"--reference") - if [ -n "${2}" ]; then - WAZUH_TAG_REFERENCE="${2}" - shift 2 - else - help 1 - fi - ;; "-rg"|"--registry") if [ -n "${2}" ]; then WAZUH_REGISTRY="${2}" diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md index 3f979e6f..1a6e05e3 100644 --- a/indexer-certs-creator/README.md +++ b/indexer-certs-creator/README.md @@ -16,7 +16,11 @@ Useful documentation: ## Procedure -Run the following script to build the wazuh-certs-generator docker image +Execute the following to run the script used to build the wazuh-certs-generator docker image + +```console +cd indexer-certs-creator +``` ```console ./build-image.sh -v [-m] [-rg ] From 024bb8553acdd7d2ced184c8b99eccb824911995 Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Mon, 22 Dec 2025 11:03:55 -0500 Subject: [PATCH 16/19] Add working directory to push.yml workflow and add shebang to image build script --- .github/workflows/push.yml | 3 ++- build-docker-images/build-images.sh | 8 +++++--- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml index e67a9a5b..02d83a2c 100644 --- a/.github/workflows/push.yml +++ b/.github/workflows/push.yml @@ -11,7 +11,8 @@ jobs: uses: actions/checkout@v4 - name: Build Wazuh images - run: build-docker-images/build-images.sh + run: ./build-images.sh + working-directory: ./build-docker-images - name: Create enviroment variables run: cat .env > $GITHUB_ENV diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index a284b1fb..7ccf4c81 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,6 +1,4 @@ -IMAGE_TAG=4.14.3 -WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') -WAZUH_REGISTRY=docker.io +#!/bin/bash # Wazuh package generator # Copyright (C) 2023, Wazuh Inc. @@ -10,6 +8,10 @@ WAZUH_REGISTRY=docker.io # License (version 2) as published by the FSF - Free Software # Foundation. +IMAGE_TAG=4.14.3 +WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') +WAZUH_REGISTRY=docker.io + WAZUH_IMAGE_VERSION="4.14.3" WAZUH_TAG_REVISION="1" WAZUH_DEV_STAGE="" From e4e41ef4bac3b69b3f522725c92cd9fa7430fa0f Mon Sep 17 00:00:00 2001 From: Jesus Garcia Date: Mon, 22 Dec 2025 09:54:24 -0500 Subject: [PATCH 17/19] Add shebang to build-images.sh script, enhance script structure, update push.yml workflow file to use working-directory, and remove indexer-certs-creator directory --- .github/workflows/push.yml | 3 +- build-docker-images/build-images.sh | 16 ++--- indexer-certs-creator/Dockerfile | 12 ---- indexer-certs-creator/config/entrypoint.sh | 68 ---------------------- 4 files changed, 11 insertions(+), 88 deletions(-) delete mode 100644 indexer-certs-creator/Dockerfile delete mode 100644 indexer-certs-creator/config/entrypoint.sh diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml index 75e3cf97..0fb975b3 100644 --- a/.github/workflows/push.yml +++ b/.github/workflows/push.yml @@ -11,7 +11,8 @@ jobs: uses: actions/checkout@v4 - name: Build Wazuh images - run: build-docker-images/build-images.sh + run: ./build-images.sh + working-directory: ./build-docker-images - name: Create enviroment variables run: cat .env > $GITHUB_ENV diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 5e558e2c..1a0802fc 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,10 +1,4 @@ -WAZUH_IMAGE_VERSION=5.0.0 -IMAGE_TAG=5.0.0 -WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') -WAZUH_TAG_REVISION=1 -WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') -IMAGE_VERSION=${WAZUH_IMAGE_VERSION} -WAZUH_REGISTRY=docker.io +#!/bin/bash # Wazuh package generator # Copyright (C) 2023, Wazuh Inc. @@ -14,6 +8,14 @@ WAZUH_REGISTRY=docker.io # License (version 2) as published by the FSF - Free Software # Foundation. +WAZUH_IMAGE_VERSION=5.0.0 +IMAGE_TAG=5.0.0 +WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') +WAZUH_TAG_REVISION=1 +WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') +IMAGE_VERSION=${WAZUH_IMAGE_VERSION} +WAZUH_REGISTRY=docker.io + WAZUH_IMAGE_VERSION="5.0.0" WAZUH_TAG_REVISION="1" WAZUH_DEV_STAGE="" diff --git a/indexer-certs-creator/Dockerfile b/indexer-certs-creator/Dockerfile deleted file mode 100644 index b9772abf..00000000 --- a/indexer-certs-creator/Dockerfile +++ /dev/null @@ -1,12 +0,0 @@ -# Wazuh Docker Copyright (C) 2017, Wazuh Inc. (License GPLv2) -FROM amazonlinux:2023 - -RUN yum update -y && yum install openssl curl-minimal -y - -WORKDIR / - -COPY config/entrypoint.sh / - -RUN chmod 700 /entrypoint.sh - -ENTRYPOINT ["/entrypoint.sh"] \ No newline at end of file diff --git a/indexer-certs-creator/config/entrypoint.sh b/indexer-certs-creator/config/entrypoint.sh deleted file mode 100644 index a222a5b9..00000000 --- a/indexer-certs-creator/config/entrypoint.sh +++ /dev/null @@ -1,68 +0,0 @@ -#!/bin/bash -# Wazuh Docker Copyright (C) 2017, Wazuh Inc. (License GPLv2) - -############################################################################## -# Downloading Cert Gen Tool -############################################################################## - -## Variables -CERT_TOOL=wazuh-certs-tool.sh -PASSWORD_TOOL=wazuh-passwords-tool.sh -PACKAGES_URL=https://packages.wazuh.com/$CERT_TOOL_VERSION/ -PACKAGES_DEV_URL=https://packages-dev.wazuh.com/$CERT_TOOL_VERSION/ - -OUTPUT_FILE="/$CERT_TOOL" - -download_package() { - local url=$1 - echo "Checking $url$CERT_TOOL ..." - if curl -fsL "$url$CERT_TOOL" -o "$OUTPUT_FILE"; then - echo "Downloaded $CERT_TOOL from $url" - return 0 - else - return 1 - fi -} - -# Try first the prod URL, if it fails try the dev URL -if download_package "$PACKAGES_URL"; then - : -elif download_package "$PACKAGES_DEV_URL"; then - : -else - echo "The tool to create the certificates does not exist in any bucket" - echo "ERROR: certificates were not created" - exit 1 -fi - -cp /config/certs.yml /config.yml -chmod 700 "$OUTPUT_FILE" - -############################################################################## -# Creating Cluster certificates -############################################################################## - -## Execute cert tool and parsin cert.yml to set UID permissions -source /$CERT_TOOL -A -nodes_server=$( cert_parseYaml /config.yml | grep -E "nodes[_]+server[_]+[0-9]+=" | sed -e 's/nodes__server__[0-9]=//' | sed 's/"//g' ) -node_names=($nodes_server) - -echo "Moving created certificates to the destination directory" -cp /wazuh-certificates/* /certificates/ -echo "Changing certificate permissions" -chmod -R 500 /certificates -chmod -R 400 /certificates/* -echo "Setting UID indexer and dashboard" -chown 1000:1000 /certificates/* -echo "Setting UID for wazuh manager and worker" -cp /certificates/root-ca.pem /certificates/root-ca-manager.pem -cp /certificates/root-ca.key /certificates/root-ca-manager.key -chown 999:999 /certificates/root-ca-manager.pem -chown 999:999 /certificates/root-ca-manager.key - -for i in ${node_names[@]}; -do - chown 999:999 "/certificates/${i}.pem" - chown 999:999 "/certificates/${i}-key.pem" -done - From 960efa9cda4afecb051aea22f933341bafd1cc91 Mon Sep 17 00:00:00 2001 From: Carlos Bordon Date: Wed, 24 Dec 2025 09:10:09 -0300 Subject: [PATCH 18/19] Removed certificates files from main --- build-docker-images/README.md | 40 --------- indexer-certs-creator/README.md | 32 -------- indexer-certs-creator/build-image.sh | 107 ------------------------- indexer-certs-creator/build-image.yml | 8 -- multi-node/generate-indexer-certs.yml | 10 --- single-node/generate-indexer-certs.yml | 10 --- 6 files changed, 207 deletions(-) delete mode 100644 build-docker-images/README.md delete mode 100644 indexer-certs-creator/README.md delete mode 100755 indexer-certs-creator/build-image.sh delete mode 100644 indexer-certs-creator/build-image.yml delete mode 100644 multi-node/generate-indexer-certs.yml delete mode 100644 single-node/generate-indexer-certs.yml diff --git a/build-docker-images/README.md b/build-docker-images/README.md deleted file mode 100644 index 8502b8c6..00000000 --- a/build-docker-images/README.md +++ /dev/null @@ -1,40 +0,0 @@ -# Wazuh Docker Image Builder - -The creation of the images for the Wazuh stack deployment in Docker is done with the `build-docker-images/build-images.sh` script - -This script initializes the environment variables needed to build each of the images. - -To execute it, make sure to be in the `build-docker-images` directory: - -```bash -cd build-docker-images -``` - -Then execute: - -```bash -./build-images.sh -``` - -The script also allows to build images from other versions of Wazuh by using the `-v` or `--version` argument: - -```bash -./build-images.sh -v 4.14.3 -``` - -To get all the available script options use the -h or --help option: - -```bash -./build-images.sh -h - -Usage: ./build-images.sh [OPTIONS] - - -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default. - -f, --filebeat-module [Optional] Set Filebeat module version. By default 0.5. - -r, --revision [Optional] Package revision. By default 1 - -rg, --registry [Optional] Set the Docker registry to push the images. - -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.14.3. - -m, --multiarch [Optional] Enable multi-architecture builds. - -h, --help Show this help. - -``` \ No newline at end of file diff --git a/indexer-certs-creator/README.md b/indexer-certs-creator/README.md deleted file mode 100644 index 1a6e05e3..00000000 --- a/indexer-certs-creator/README.md +++ /dev/null @@ -1,32 +0,0 @@ -# Certificate Creation Image Build - -The dockerfile hosted in this directory is used to build the image required for generating Wazuh Docker single-node and multi-node certificate files - -## Pre-requisites - -1. Verify the Docker Buildx plugin is properly set up -2. For multi-architecture image builds: - - Ensure QEMU is installed - - Check permissions to push images to a Docker registry - -Useful documentation: - -- https://docs.docker.com/build/building/multi-platform/ -- https://www.qemu.org/download/ - -## Procedure - -Execute the following to run the script used to build the wazuh-certs-generator docker image - -```console -cd indexer-certs-creator -``` - -```console -./build-image.sh -v [-m] [-rg ] -``` - -- Replace with the new image desired tag. -- Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`) - - If multiarch build is enabled, the script will attempt to push the image to the specified registry. This image upload will only work if credentials are properly configured. -- Use the `-rg ` parameter to specify a custom Docker registry (default is Docker Hub) diff --git a/indexer-certs-creator/build-image.sh b/indexer-certs-creator/build-image.sh deleted file mode 100755 index afa0eea2..00000000 --- a/indexer-certs-creator/build-image.sh +++ /dev/null @@ -1,107 +0,0 @@ -#!/bin/bash - -# Wazuh package generator -# Copyright (C) 2023, Wazuh Inc. -# -# This program is a free software; you can redistribute it -# and/or modify it under the terms of the GNU General Public -# License (version 2) as published by the FSF - Free Software -# Foundation. - -WAZUH_CERTS_IMAGE_VERSION="0.0.4" -WAZUH_REGISTRY="docker.io" - -# ----------------------------------------------------------------------------- - -trap ctrl_c INT - -clean() { - exit_code=$1 - exit ${exit_code} -} - -ctrl_c() { - clean 1 -} - -# ----------------------------------------------------------------------------- - -build() { - IMAGE_TAG="${WAZUH_CERTS_IMAGE_VERSION}" - - echo WAZUH_REGISTRY=$WAZUH_REGISTRY > .env - echo IMAGE_TAG=$IMAGE_TAG >> .env - - set -a - source .env - set +a - - if [ "${MULTIARCH}" ]; then - docker buildx bake \ - --file build-image.yml \ - --set *.platform=linux/amd64,linux/arm64 \ - --push \ - --no-cache || clean 1 - else - docker buildx bake \ - --file build-image.yml \ - --load \ - --no-cache || clean 1 - fi - return 0 -} - -# ----------------------------------------------------------------------------- - -help() { - echo - echo "Usage: $0 [OPTIONS]" - echo - echo " -v, --version [Optional] Set the image version. By default ${WAZUH_CERTS_IMAGE_VERSION}." - echo " -rg, --registry [Optional] Set the Docker registry to push the images." - echo " -m, --multiarch [Optional] Enable multi-architecture builds." - echo " -h, --help Show this help." - echo - exit $1 -} - -# ----------------------------------------------------------------------------- - -main() { - while [ -n "${1}" ] - do - case "${1}" in - "-h"|"--help") - help 0 - ;; - "-m"|"--multiarch") - MULTIARCH="true" - shift - ;; - "-rg"|"--registry") - if [ -n "${2}" ]; then - WAZUH_REGISTRY="${2}" - shift 2 - else - help 1 - fi - ;; - "-v"|"--version") - if [ -n "$2" ]; then - WAZUH_CERTS_IMAGE_VERSION="$2" - shift 2 - else - help 1 - fi - ;; - *) - help 1 - esac - done - - build || clean 1 - - clean 0 -} - -main "$@" diff --git a/indexer-certs-creator/build-image.yml b/indexer-certs-creator/build-image.yml deleted file mode 100644 index 58bb13cf..00000000 --- a/indexer-certs-creator/build-image.yml +++ /dev/null @@ -1,8 +0,0 @@ -# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) -services: - wazuh.certs.generator: - build: - context: . - dockerfile: Dockerfile - image: ${WAZUH_REGISTRY}/wazuh/wazuh-certs-generator:${IMAGE_TAG} - hostname: wazuh-certs-generator diff --git a/multi-node/generate-indexer-certs.yml b/multi-node/generate-indexer-certs.yml deleted file mode 100644 index c719d22e..00000000 --- a/multi-node/generate-indexer-certs.yml +++ /dev/null @@ -1,10 +0,0 @@ -# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) -services: - generator: - image: wazuh/wazuh-certs-generator:0.0.4 - hostname: wazuh-certs-generator - environment: - - CERT_TOOL_VERSION=4.14 - volumes: - - ./config/wazuh_indexer_ssl_certs/:/certificates/ - - ./config/certs.yml:/config/certs.yml \ No newline at end of file diff --git a/single-node/generate-indexer-certs.yml b/single-node/generate-indexer-certs.yml deleted file mode 100644 index dfcdca57..00000000 --- a/single-node/generate-indexer-certs.yml +++ /dev/null @@ -1,10 +0,0 @@ -# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2) -services: - generator: - image: wazuh/wazuh-certs-generator:0.0.4 - hostname: wazuh-certs-generator - environment: - - CERT_TOOL_VERSION=4.14 - volumes: - - ./config/wazuh_indexer_ssl_certs/:/certificates/ - - ./config/certs.yml:/config/certs.yml From 5a803bc877985c6eece60f3ae13edc2a19bfbe23 Mon Sep 17 00:00:00 2001 From: Carlos Bordon Date: Wed, 24 Dec 2025 09:24:00 -0300 Subject: [PATCH 19/19] Updated build images parameters --- build-docker-images/build-images.sh | 12 ------------ 1 file changed, 12 deletions(-) diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 2c937af5..1a0802fc 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -128,10 +128,6 @@ main() { help 1 fi ;; - "-m"|"--multiarch") - MULTIARCH="true" - shift - ;; "-ref"|"--reference") if [ -n "${2}" ]; then WAZUH_TAG_REFERENCE="${2}" @@ -148,14 +144,6 @@ main() { help 1 fi ;; - "-rg"|"--registry") - if [ -n "${2}" ]; then - WAZUH_REGISTRY="${2}" - shift 2 - else - help 1 - fi - ;; "-v"|"--version") if [ -n "$2" ]; then WAZUH_IMAGE_VERSION="$2"