forked from wazuh/wazuh-docker
Compare commits
35
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dddfc8adb5 | ||
|
|
f51fc2e4ae | ||
|
|
089ce24ffc | ||
|
|
424559518e | ||
|
|
a509f0f8ea | ||
|
|
c6a427af70 | ||
|
|
6675465180 | ||
|
|
08c7cbda53 | ||
|
|
0fe3103940 | ||
|
|
f42ec2ba7c | ||
|
|
982d3a649e | ||
|
|
6aa948d4da | ||
|
|
81a7e11da4 | ||
|
|
2dc7717e81 | ||
|
|
0ba67b1adf | ||
|
|
eecec3db80 | ||
|
|
f4cc1bd838 | ||
|
|
0602ce076d | ||
|
|
2d122e1dc9 | ||
|
|
47a73bdde6 | ||
|
|
fb6be60afb | ||
|
|
2d6c920366 | ||
|
|
d69f5c0c5d | ||
|
|
d52c076e62 | ||
|
|
e5d6ba55cc | ||
|
|
415ddd7271 | ||
|
|
aa98d94f38 | ||
|
|
af2e4589c0 | ||
|
|
6a8d0d6288 | ||
|
|
11b066ef25 | ||
|
|
11c0ae9161 | ||
|
|
ecb486f625 | ||
|
|
16de0735a9 | ||
|
|
5103da8dab | ||
|
|
91cda37b1f |
@@ -1,6 +1,6 @@
|
|||||||
WAZUH_VERSION=4.14.2
|
WAZUH_VERSION=4.14.3
|
||||||
WAZUH_IMAGE_VERSION=4.14.2
|
WAZUH_IMAGE_VERSION=4.14.3
|
||||||
WAZUH_TAG_REVISION=1
|
WAZUH_TAG_REVISION=1
|
||||||
FILEBEAT_TEMPLATE_BRANCH=4.14.2
|
FILEBEAT_TEMPLATE_BRANCH=4.14.3
|
||||||
WAZUH_FILEBEAT_MODULE=wazuh-filebeat-0.4.tar.gz
|
WAZUH_FILEBEAT_MODULE=wazuh-filebeat-0.4.tar.gz
|
||||||
WAZUH_UI_REVISION=1
|
WAZUH_UI_REVISION=1
|
||||||
|
|||||||
+1
-1
@@ -56,7 +56,7 @@ package:
|
|||||||
wazuh-manager:
|
wazuh-manager:
|
||||||
installed: true
|
installed: true
|
||||||
versions:
|
versions:
|
||||||
- 4.14.2
|
- 4.14.3
|
||||||
port:
|
port:
|
||||||
tcp:1514:
|
tcp:1514:
|
||||||
listening: true
|
listening: true
|
||||||
|
|||||||
@@ -6,15 +6,11 @@ on:
|
|||||||
inputs:
|
inputs:
|
||||||
image_tag:
|
image_tag:
|
||||||
description: 'Docker image tag'
|
description: 'Docker image tag'
|
||||||
default: '4.14.2'
|
default: '4.14.3'
|
||||||
required: true
|
required: true
|
||||||
docker_reference:
|
docker_reference:
|
||||||
description: 'wazuh-docker reference'
|
description: 'wazuh-docker reference'
|
||||||
required: true
|
required: true
|
||||||
products:
|
|
||||||
description: 'Comma-separated list of the image names to build and push'
|
|
||||||
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
|
|
||||||
required: true
|
|
||||||
filebeat_module_version:
|
filebeat_module_version:
|
||||||
description: 'Filebeat module version'
|
description: 'Filebeat module version'
|
||||||
default: '0.4'
|
default: '0.4'
|
||||||
@@ -23,11 +19,6 @@ on:
|
|||||||
description: 'Package revision'
|
description: 'Package revision'
|
||||||
default: '1'
|
default: '1'
|
||||||
required: true
|
required: true
|
||||||
push_images:
|
|
||||||
description: 'Push images'
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
required: true
|
|
||||||
id:
|
id:
|
||||||
description: "ID used to identify the workflow uniquely."
|
description: "ID used to identify the workflow uniquely."
|
||||||
type: string
|
type: string
|
||||||
@@ -41,18 +32,13 @@ on:
|
|||||||
inputs:
|
inputs:
|
||||||
image_tag:
|
image_tag:
|
||||||
description: 'Docker image tag'
|
description: 'Docker image tag'
|
||||||
default: '4.14.2'
|
default: '4.14.3'
|
||||||
required: true
|
required: true
|
||||||
type: string
|
type: string
|
||||||
docker_reference:
|
docker_reference:
|
||||||
description: 'wazuh-docker reference'
|
description: 'wazuh-docker reference'
|
||||||
required: false
|
required: false
|
||||||
type: string
|
type: string
|
||||||
products:
|
|
||||||
description: 'Comma-separated list of the image names to build and push'
|
|
||||||
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
|
|
||||||
required: true
|
|
||||||
type: string
|
|
||||||
filebeat_module_version:
|
filebeat_module_version:
|
||||||
description: 'Filebeat module version'
|
description: 'Filebeat module version'
|
||||||
default: '0.4'
|
default: '0.4'
|
||||||
@@ -63,11 +49,6 @@ on:
|
|||||||
default: '1'
|
default: '1'
|
||||||
required: true
|
required: true
|
||||||
type: string
|
type: string
|
||||||
push_images:
|
|
||||||
description: 'Push images'
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
required: true
|
|
||||||
id:
|
id:
|
||||||
description: "ID used to identify the workflow uniquely."
|
description: "ID used to identify the workflow uniquely."
|
||||||
type: string
|
type: string
|
||||||
@@ -82,6 +63,16 @@ jobs:
|
|||||||
build-and-push:
|
build-and-push:
|
||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
id-token: write
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
env:
|
||||||
|
IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }}
|
||||||
|
IMAGE_TAG: ${{ inputs.image_tag }}
|
||||||
|
FILEBEAT_MODULE_VERSION: ${{ inputs.filebeat_module_version }}
|
||||||
|
REVISION: ${{ inputs.revision }}
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Print inputs
|
- name: Print inputs
|
||||||
run: |
|
run: |
|
||||||
@@ -96,10 +87,8 @@ jobs:
|
|||||||
echo "* id: ${{ inputs.id }}"
|
echo "* id: ${{ inputs.id }}"
|
||||||
echo "* image_tag: ${{ inputs.image_tag }}"
|
echo "* image_tag: ${{ inputs.image_tag }}"
|
||||||
echo "* docker_reference: ${{ inputs.docker_reference }}"
|
echo "* docker_reference: ${{ inputs.docker_reference }}"
|
||||||
echo "* products: ${{ inputs.products }}"
|
|
||||||
echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}"
|
echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}"
|
||||||
echo "* revision: ${{ inputs.revision }}"
|
echo "* revision: ${{ inputs.revision }}"
|
||||||
echo "* push_images: ${{ inputs.push_images }}"
|
|
||||||
echo "* dev: ${{ inputs.dev }}"
|
echo "* dev: ${{ inputs.dev }}"
|
||||||
echo "---------------------------------------------"
|
echo "---------------------------------------------"
|
||||||
|
|
||||||
@@ -108,52 +97,147 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
ref: ${{ inputs.docker_reference }}
|
ref: ${{ inputs.docker_reference }}
|
||||||
|
|
||||||
- name: Log in to Docker Hub
|
# - name: free disk space
|
||||||
uses: docker/login-action@v3
|
# uses: ./.github/free-disk-space
|
||||||
with:
|
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
||||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
|
||||||
|
|
||||||
- name: Build Wazuh images
|
# - name: Set up QEMU
|
||||||
|
# uses: docker/setup-qemu-action@v3
|
||||||
|
|
||||||
|
# - name: Set up Docker Buildx
|
||||||
|
# uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
|
# - name: Configure aws credentials
|
||||||
|
# if: ${{ inputs.dev == true }}
|
||||||
|
# uses: aws-actions/configure-aws-credentials@v4
|
||||||
|
# with:
|
||||||
|
# role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
|
||||||
|
# aws-region: "${{ secrets.AWS_REGION }}"
|
||||||
|
|
||||||
|
# - name: Log in to Amazon ECR
|
||||||
|
# if: ${{ inputs.dev == true }}
|
||||||
|
# uses: aws-actions/amazon-ecr-login@v2
|
||||||
|
|
||||||
|
# - name: Log in to Docker Hub
|
||||||
|
# if: ${{ inputs.dev == false }}
|
||||||
|
# uses: docker/login-action@v3
|
||||||
|
# with:
|
||||||
|
# username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
|
# password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||||
|
|
||||||
|
# - name: Build Wazuh images
|
||||||
|
# run: |
|
||||||
|
# IMAGE_TAG="${{ inputs.image_tag }}"
|
||||||
|
# FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }}
|
||||||
|
# REVISION=${{ inputs.revision }}
|
||||||
|
|
||||||
|
# if [[ "$IMAGE_TAG" == *"-"* ]]; then
|
||||||
|
# IFS='-' read -r -a tokens <<< "$IMAGE_TAG"
|
||||||
|
# if [ -z "${tokens[1]}" ]; then
|
||||||
|
# echo "Invalid image tag: $IMAGE_TAG"
|
||||||
|
# exit 1
|
||||||
|
# fi
|
||||||
|
# DEV_STAGE=${tokens[1]}
|
||||||
|
# WAZUH_VER=${tokens[0]}
|
||||||
|
# ./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m
|
||||||
|
# else
|
||||||
|
# ./build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m
|
||||||
|
# fi
|
||||||
|
|
||||||
|
# # Save .env file (generated by build-images.sh) contents to $GITHUB_ENV
|
||||||
|
# ENV_FILE_PATH="../.env"
|
||||||
|
|
||||||
|
# if [ -f $ENV_FILE_PATH ]; then
|
||||||
|
# while IFS= read -r line || [ -n "$line" ]; do
|
||||||
|
# echo "$line" >> $GITHUB_ENV
|
||||||
|
# done < $ENV_FILE_PATH
|
||||||
|
# else
|
||||||
|
# echo "The environment file $ENV_FILE_PATH does not exist!"
|
||||||
|
# exit 1
|
||||||
|
# fi
|
||||||
|
# working-directory: ./build-docker-images
|
||||||
|
|
||||||
|
- name: Image exists validation
|
||||||
|
if: ${{ inputs.dev == false }}
|
||||||
|
id: validation
|
||||||
run: |
|
run: |
|
||||||
IMAGE_TAG=${{ inputs.image_tag }}
|
IMAGE_TAG=${{ inputs.image_tag }}
|
||||||
FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }}
|
PURPOSE=""
|
||||||
REVISION=${{ inputs.revision }}
|
|
||||||
|
|
||||||
if [[ "$IMAGE_TAG" == *"-"* ]]; then
|
if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||||
IFS='-' read -r -a tokens <<< "$IMAGE_TAG"
|
if docker manifest inspect $IMAGE_REGISTRY/wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then
|
||||||
if [ -z "${tokens[1]}" ]; then
|
PURPOSE="regeneration"
|
||||||
echo "Invalid image tag: $IMAGE_TAG"
|
echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'"
|
||||||
exit 1
|
else
|
||||||
|
PURPOSE="new release"
|
||||||
|
echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'"
|
||||||
fi
|
fi
|
||||||
DEV_STAGE=${tokens[1]}
|
echo "✅ Release tag: '$IMAGE_TAG'"
|
||||||
WAZUH_VER=${tokens[0]}
|
elif [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+-(alpha|beta|rc)[0-9]+$ ]]; then
|
||||||
./build-docker-images/build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION
|
PURPOSE="new stage"
|
||||||
|
echo "✅ Stage tag: '$IMAGE_TAG'. Setting PURPOSE to 'new stage'"
|
||||||
else
|
else
|
||||||
./build-docker-images/build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION
|
echo "❌ No release or stage tag ('$IMAGE_TAG'), the GH issue will not be created"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Save .env file (generated by build-images.sh) contents to $GITHUB_ENV
|
echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT
|
||||||
ENV_FILE_PATH=".env"
|
|
||||||
|
|
||||||
if [ -f $ENV_FILE_PATH ]; then
|
- name: GH issue notification
|
||||||
while IFS= read -r line || [ -n "$line" ]; do
|
if: ${{ inputs.dev == false && steps.validation.outputs.purpose != '' }}
|
||||||
echo "$line" >> $GITHUB_ENV
|
|
||||||
done < $ENV_FILE_PATH
|
|
||||||
else
|
|
||||||
echo "The environment file $ENV_FILE_PATH does not exist!"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
- name: Tag and Push Wazuh images
|
|
||||||
if: ${{ inputs.push_images }}
|
|
||||||
run: |
|
run: |
|
||||||
IMAGE_TAG="${{ inputs.image_tag }}$( [ "${{ inputs.dev }}" == "true" ] && echo '-dev' || true )"
|
IMAGE_TAG=${{ inputs.image_tag }}
|
||||||
IMAGE_NAMES=${{ inputs.products }}
|
GH_TITLE=""
|
||||||
IFS=',' read -r -a images <<< "$IMAGE_NAMES"
|
GH_MESSAGE=""
|
||||||
for image in "${images[@]}"; do
|
PURPOSE="${{ steps.validation.outputs.purpose }}"
|
||||||
echo "Tagging and pushing wazuh/$image:${WAZUH_VERSION} to wazuh/$image:$IMAGE_TAG"
|
|
||||||
docker tag wazuh/$image:${WAZUH_VERSION} wazuh/$image:$IMAGE_TAG
|
## Setting GH issue title
|
||||||
echo "Pushing wazuh/$image:$IMAGE_TAG ..."
|
GH_TITLE="Artifactory vulnerabilities update \`v$IMAGE_TAG\`"
|
||||||
docker push wazuh/$image:$IMAGE_TAG
|
|
||||||
done
|
## Setting GH issue body
|
||||||
|
GH_MESSAGE=$(cat <<- EOF | tr -d '\r' | sed 's/^[[:space:]]*//'
|
||||||
|
### Description
|
||||||
|
- [ ] Update the [Artifactory vulnerabilities](${{ secrets.NOTIFICATION_SHEET_URL }}) sheet with the \`v$IMAGE_TAG\` vulnerabilities.
|
||||||
|
|
||||||
|
**Purpose**: $PURPOSE
|
||||||
|
>[!NOTE]
|
||||||
|
>To update the \`Tentative Release\` column, follow these steps:
|
||||||
|
https://github.com/wazuh/${{ secrets.NOTIFICATION_REPO }}/issues/2049#issuecomment-2671590268
|
||||||
|
EOF
|
||||||
|
)
|
||||||
|
|
||||||
|
# Print the GH Variables content
|
||||||
|
echo "--- Variable Content ---"
|
||||||
|
echo "$GH_TITLE"
|
||||||
|
echo "------------------------"
|
||||||
|
|
||||||
|
echo "--- Variable Content ---"
|
||||||
|
echo "$GH_MESSAGE"
|
||||||
|
echo "------------------------"
|
||||||
|
|
||||||
|
## GH issue creation
|
||||||
|
ISSUE_URL=$(gh issue create \
|
||||||
|
-R wazuh/${{ secrets.NOTIFICATION_REPO }} \
|
||||||
|
--title "$GH_TITLE" \
|
||||||
|
--body "$GH_MESSAGE" \
|
||||||
|
--label "level/task" \
|
||||||
|
--label "type/maintenance" \
|
||||||
|
--label "request/operational")
|
||||||
|
|
||||||
|
## Adding the issue to the team project
|
||||||
|
PROJECT_ITEM_ID=$(gh project item-add \
|
||||||
|
${{ secrets.NOTIFICATION_PROJECT_NUMBER }} \
|
||||||
|
--url $ISSUE_URL \
|
||||||
|
--owner wazuh \
|
||||||
|
--format json \
|
||||||
|
| jq -r '.id')
|
||||||
|
|
||||||
|
## Setting Objective
|
||||||
|
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_OBJECTIVE_ID }} --text "Security scans"
|
||||||
|
## Setting Priority
|
||||||
|
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_OPTION_ID }}
|
||||||
|
## Setting Size
|
||||||
|
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_OPTION_ID }}
|
||||||
|
## Setting Subteam
|
||||||
|
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_OPTION_ID }}
|
||||||
|
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.NOTIFICATION_GH_ARTIFACT_TOKEN }}
|
||||||
|
|||||||
+22
-2
@@ -1,7 +1,7 @@
|
|||||||
# Change Log
|
# Change Log
|
||||||
All notable changes to this project will be documented in this file.
|
All notable changes to this project will be documented in this file.
|
||||||
|
|
||||||
## [4.14.2]
|
## [4.14.3]
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
@@ -9,7 +9,7 @@ All notable changes to this project will be documented in this file.
|
|||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- None
|
- Adapt to multi architecture build ([#2120](https://github.com/wazuh/wazuh-docker/pull/2120))
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
@@ -19,6 +19,26 @@ All notable changes to this project will be documented in this file.
|
|||||||
|
|
||||||
- None
|
- None
|
||||||
|
|
||||||
|
## [4.14.2]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Code improvements for 4.14.2 ([#2090](https://github.com/wazuh/wazuh-docker/pull/2090))
|
||||||
|
- Artifactory vulnerabilities notification ([#2078](https://github.com/wazuh/wazuh-docker/pull/2078))
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- The location of the remove command for the wazuh-authd certificates has been changed. ([#2094](https://github.com/wazuh/wazuh-docker/pull/2094))
|
||||||
|
- Removed sslmanager key from the docker manager image to 4.14.2. ([#2093](https://github.com/wazuh/wazuh-docker/pull/2093))
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Add missing SSL ciphers and protocols and remove outdated ports parameters from opensearch.yml template ([#2104](https://github.com/wazuh/wazuh-docker/pull/2104))
|
||||||
|
|
||||||
|
### Deleted
|
||||||
|
|
||||||
|
- None
|
||||||
|
|
||||||
## [4.14.1]
|
## [4.14.1]
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ The `wazuh/wazuh-docker` repository provides resources to deploy the Wazuh cyber
|
|||||||
## Branch Convention
|
## Branch Convention
|
||||||
|
|
||||||
- `main`: Developing and testing of new features.
|
- `main`: Developing and testing of new features.
|
||||||
- `X.Y.Z`: Version-specific branches (e.g., `4.14.2`, `4.13.0`, etc.).
|
- `X.Y.Z`: Version-specific branches (e.g., `4.14.3`, `4.13.0`, etc.).
|
||||||
|
|
||||||
## Documentation
|
## Documentation
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
{
|
{
|
||||||
"version": "4.14.2",
|
"version": "4.14.3",
|
||||||
"stage": "alpha0"
|
"stage": "alpha0"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ This script initializes the environment variables needed to build each of the im
|
|||||||
The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument:
|
The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument:
|
||||||
|
|
||||||
```
|
```
|
||||||
$ build-docker-images/build-images.sh -v 4.14.2
|
$ build-docker-images/build-images.sh -v 4.14.3
|
||||||
```
|
```
|
||||||
|
|
||||||
To get all the available script options use the -h or --help option:
|
To get all the available script options use the -h or --help option:
|
||||||
@@ -26,7 +26,7 @@ Usage: build-docker-images/build-images.sh [OPTIONS]
|
|||||||
-d, --dev <ref> [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default.
|
-d, --dev <ref> [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default.
|
||||||
-f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default 0.4.
|
-f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default 0.4.
|
||||||
-r, --revision <rev> [Optional] Package revision. By default 1
|
-r, --revision <rev> [Optional] Package revision. By default 1
|
||||||
-v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, 4.14.2.
|
-v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, 4.14.3.
|
||||||
-h, --help Show this help.
|
-h, --help Show this help.
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -1,8 +1,6 @@
|
|||||||
WAZUH_IMAGE_VERSION=4.14.2
|
IMAGE_TAG=4.14.3
|
||||||
WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g')
|
|
||||||
WAZUH_TAG_REVISION=1
|
|
||||||
WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g')
|
WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g')
|
||||||
IMAGE_VERSION=${WAZUH_IMAGE_VERSION}
|
WAZUH_REGISTRY=docker.io
|
||||||
|
|
||||||
# Wazuh package generator
|
# Wazuh package generator
|
||||||
# Copyright (C) 2023, Wazuh Inc.
|
# Copyright (C) 2023, Wazuh Inc.
|
||||||
@@ -12,7 +10,7 @@ IMAGE_VERSION=${WAZUH_IMAGE_VERSION}
|
|||||||
# License (version 2) as published by the FSF - Free Software
|
# License (version 2) as published by the FSF - Free Software
|
||||||
# Foundation.
|
# Foundation.
|
||||||
|
|
||||||
WAZUH_IMAGE_VERSION="4.14.2"
|
WAZUH_IMAGE_VERSION="4.14.3"
|
||||||
WAZUH_TAG_REVISION="1"
|
WAZUH_TAG_REVISION="1"
|
||||||
WAZUH_DEV_STAGE=""
|
WAZUH_DEV_STAGE=""
|
||||||
FILEBEAT_MODULE_VERSION="0.4"
|
FILEBEAT_MODULE_VERSION="0.4"
|
||||||
@@ -58,15 +56,32 @@ build() {
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > .env
|
|
||||||
echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> .env
|
|
||||||
echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> .env
|
|
||||||
echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> .env
|
|
||||||
echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> .env
|
|
||||||
echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> .env
|
|
||||||
|
|
||||||
docker compose -f build-docker-images/build-images.yml --env-file .env build --no-cache || clean 1
|
echo WAZUH_VERSION=$WAZUH_IMAGE_VERSION > ../.env
|
||||||
|
echo WAZUH_IMAGE_VERSION=$WAZUH_IMAGE_VERSION >> ../.env
|
||||||
|
echo WAZUH_TAG_REVISION=$WAZUH_TAG_REVISION >> ../.env
|
||||||
|
echo FILEBEAT_TEMPLATE_BRANCH=$FILEBEAT_TEMPLATE_BRANCH >> ../.env
|
||||||
|
echo WAZUH_FILEBEAT_MODULE=$WAZUH_FILEBEAT_MODULE >> ../.env
|
||||||
|
echo WAZUH_UI_REVISION=$WAZUH_UI_REVISION >> ../.env
|
||||||
|
echo WAZUH_REGISTRY=$WAZUH_REGISTRY >> ../.env
|
||||||
|
echo IMAGE_TAG=$IMAGE_TAG >> ../.env
|
||||||
|
|
||||||
|
set -a
|
||||||
|
source ../.env
|
||||||
|
set +a
|
||||||
|
|
||||||
|
if [ "${MULTIARCH}" ];then
|
||||||
|
docker buildx bake \
|
||||||
|
--file build-images.yml \
|
||||||
|
--push \
|
||||||
|
--set *.platform=linux/amd64,linux/arm64 \
|
||||||
|
--no-cache || clean 1
|
||||||
|
else
|
||||||
|
docker buildx bake \
|
||||||
|
--file build-images.yml \
|
||||||
|
--load \
|
||||||
|
--no-cache || clean 1
|
||||||
|
fi
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -79,7 +94,10 @@ help() {
|
|||||||
echo " -d, --dev <ref> [Optional] Set the development stage you want to build, example alpha0 or beta1, not used by default."
|
echo " -d, --dev <ref> [Optional] Set the development stage you want to build, example alpha0 or beta1, not used by default."
|
||||||
echo " -f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}."
|
echo " -f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default ${FILEBEAT_MODULE_VERSION}."
|
||||||
echo " -r, --revision <rev> [Optional] Package revision. By default ${WAZUH_TAG_REVISION}"
|
echo " -r, --revision <rev> [Optional] Package revision. By default ${WAZUH_TAG_REVISION}"
|
||||||
|
echo " -ref, --reference <ref> [Optional] Set the Wazuh reference to build development images. By default, the latest stable release."
|
||||||
|
echo " -rg, --registry <reg> [Optional] Set the Docker registry to push the images."
|
||||||
echo " -v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}."
|
echo " -v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, ${WAZUH_IMAGE_VERSION}."
|
||||||
|
echo " -m, --multiarch [Optional] Enable multi-architecture builds."
|
||||||
echo " -h, --help Show this help."
|
echo " -h, --help Show this help."
|
||||||
echo
|
echo
|
||||||
exit $1
|
exit $1
|
||||||
@@ -110,6 +128,10 @@ main() {
|
|||||||
help 1
|
help 1
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
|
"-m"|"--multiarch")
|
||||||
|
MULTIARCH="true"
|
||||||
|
shift
|
||||||
|
;;
|
||||||
"-r"|"--revision")
|
"-r"|"--revision")
|
||||||
if [ -n "${2}" ]; then
|
if [ -n "${2}" ]; then
|
||||||
WAZUH_TAG_REVISION="${2}"
|
WAZUH_TAG_REVISION="${2}"
|
||||||
@@ -118,6 +140,22 @@ main() {
|
|||||||
help 1
|
help 1
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
|
"-ref"|"--reference")
|
||||||
|
if [ -n "${2}" ]; then
|
||||||
|
WAZUH_TAG_REFERENCE="${2}"
|
||||||
|
shift 2
|
||||||
|
else
|
||||||
|
help 1
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
"-rg"|"--registry")
|
||||||
|
if [ -n "${2}" ]; then
|
||||||
|
WAZUH_REGISTRY="${2}"
|
||||||
|
shift 2
|
||||||
|
else
|
||||||
|
help 1
|
||||||
|
fi
|
||||||
|
;;
|
||||||
"-v"|"--version")
|
"-v"|"--version")
|
||||||
if [ -n "$2" ]; then
|
if [ -n "$2" ]; then
|
||||||
WAZUH_IMAGE_VERSION="$2"
|
WAZUH_IMAGE_VERSION="$2"
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ services:
|
|||||||
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
||||||
FILEBEAT_TEMPLATE_BRANCH: ${FILEBEAT_TEMPLATE_BRANCH}
|
FILEBEAT_TEMPLATE_BRANCH: ${FILEBEAT_TEMPLATE_BRANCH}
|
||||||
WAZUH_FILEBEAT_MODULE: ${WAZUH_FILEBEAT_MODULE}
|
WAZUH_FILEBEAT_MODULE: ${WAZUH_FILEBEAT_MODULE}
|
||||||
image: wazuh/wazuh-manager:${WAZUH_IMAGE_VERSION}
|
image: ${WAZUH_REGISTRY}/wazuh/wazuh-manager:${IMAGE_TAG}
|
||||||
hostname: wazuh.manager
|
hostname: wazuh.manager
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -40,7 +40,7 @@ services:
|
|||||||
args:
|
args:
|
||||||
WAZUH_VERSION: ${WAZUH_VERSION}
|
WAZUH_VERSION: ${WAZUH_VERSION}
|
||||||
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
||||||
image: wazuh/wazuh-agent:${WAZUH_IMAGE_VERSION}
|
image: ${WAZUH_REGISTRY}/wazuh/wazuh-agent:${IMAGE_TAG}
|
||||||
hostname: wazuh.agent
|
hostname: wazuh.agent
|
||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
@@ -50,7 +50,7 @@ services:
|
|||||||
args:
|
args:
|
||||||
WAZUH_VERSION: ${WAZUH_VERSION}
|
WAZUH_VERSION: ${WAZUH_VERSION}
|
||||||
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
||||||
image: wazuh/wazuh-indexer:${WAZUH_IMAGE_VERSION}
|
image: ${WAZUH_REGISTRY}/wazuh/wazuh-indexer:${IMAGE_TAG}
|
||||||
hostname: wazuh.indexer
|
hostname: wazuh.indexer
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -72,7 +72,7 @@ services:
|
|||||||
WAZUH_VERSION: ${WAZUH_VERSION}
|
WAZUH_VERSION: ${WAZUH_VERSION}
|
||||||
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
WAZUH_TAG_REVISION: ${WAZUH_TAG_REVISION}
|
||||||
WAZUH_UI_REVISION: ${WAZUH_UI_REVISION}
|
WAZUH_UI_REVISION: ${WAZUH_UI_REVISION}
|
||||||
image: wazuh/wazuh-dashboard:${WAZUH_IMAGE_VERSION}
|
image: ${WAZUH_REGISTRY}/wazuh/wazuh-dashboard:${IMAGE_TAG}
|
||||||
hostname: wazuh.dashboard
|
hostname: wazuh.dashboard
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
|
|||||||
@@ -62,7 +62,6 @@ chmod 755 $CERT_TOOL && bash /$CERT_TOOL -A
|
|||||||
|
|
||||||
# copy to target
|
# copy to target
|
||||||
mkdir -p ${TARGET_DIR}${INSTALLATION_DIR}
|
mkdir -p ${TARGET_DIR}${INSTALLATION_DIR}
|
||||||
mkdir -p ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
|
||||||
mkdir -p ${TARGET_DIR}${CONFIG_DIR}
|
mkdir -p ${TARGET_DIR}${CONFIG_DIR}
|
||||||
mkdir -p ${TARGET_DIR}${LIB_DIR}
|
mkdir -p ${TARGET_DIR}${LIB_DIR}
|
||||||
mkdir -p ${TARGET_DIR}${LOG_DIR}
|
mkdir -p ${TARGET_DIR}${LOG_DIR}
|
||||||
@@ -73,10 +72,10 @@ mkdir -p ${TARGET_DIR}/usr/lib/sysctl.d
|
|||||||
mkdir -p ${TARGET_DIR}/usr/lib/systemd/system
|
mkdir -p ${TARGET_DIR}/usr/lib/systemd/system
|
||||||
mkdir -p ${TARGET_DIR}${CONFIG_DIR}/certs
|
mkdir -p ${TARGET_DIR}${CONFIG_DIR}/certs
|
||||||
# Copy Wazuh's config files for the security plugin
|
# Copy Wazuh's config files for the security plugin
|
||||||
cp -pr /roles_mapping.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
cp -pr /roles_mapping.yml ${TARGET_DIR}${CONFIG_DIR}/opensearch-security/
|
||||||
cp -pr /roles.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
cp -pr /roles.yml ${TARGET_DIR}${CONFIG_DIR}/opensearch-security/
|
||||||
cp -pr /action_groups.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
cp -pr /action_groups.yml ${TARGET_DIR}${CONFIG_DIR}/opensearch-security/
|
||||||
cp -pr /internal_users.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
cp -pr /internal_users.yml ${TARGET_DIR}${CONFIG_DIR}/opensearch-security/
|
||||||
cp -pr /opensearch.yml ${TARGET_DIR}${CONFIG_DIR}
|
cp -pr /opensearch.yml ${TARGET_DIR}${CONFIG_DIR}
|
||||||
# Copy Wazuh indexer's certificates
|
# Copy Wazuh indexer's certificates
|
||||||
cp -pr /wazuh-certificates/demo.indexer.pem ${TARGET_DIR}${CONFIG_DIR}/certs/indexer.pem
|
cp -pr /wazuh-certificates/demo.indexer.pem ${TARGET_DIR}${CONFIG_DIR}/certs/indexer.pem
|
||||||
|
|||||||
@@ -14,6 +14,13 @@ plugins.security.ssl.transport.pemtrustedcas_filepath: /usr/share/wazuh-indexer/
|
|||||||
plugins.security.ssl.http.enabled: true
|
plugins.security.ssl.http.enabled: true
|
||||||
plugins.security.ssl.transport.enforce_hostname_verification: false
|
plugins.security.ssl.transport.enforce_hostname_verification: false
|
||||||
plugins.security.ssl.transport.resolve_hostname: false
|
plugins.security.ssl.transport.resolve_hostname: false
|
||||||
|
plugins.security.ssl.http.enabled_ciphers:
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
plugins.security.ssl.http.enabled_protocols:
|
||||||
|
- "TLSv1.2"
|
||||||
plugins.security.authcz.admin_dn:
|
plugins.security.authcz.admin_dn:
|
||||||
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
||||||
plugins.security.check_snapshot_restore_write_privileges: true
|
plugins.security.check_snapshot_restore_write_privileges: true
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ ARG FILEBEAT_VERSION=7.10.2
|
|||||||
ARG FILEBEAT_REVISION=2
|
ARG FILEBEAT_REVISION=2
|
||||||
ARG WAZUH_FILEBEAT_MODULE
|
ARG WAZUH_FILEBEAT_MODULE
|
||||||
ARG S6_VERSION="v2.2.0.3"
|
ARG S6_VERSION="v2.2.0.3"
|
||||||
|
ARG TARGETARCH
|
||||||
|
|
||||||
RUN yum install curl-minimal xz gnupg tar gzip openssl findutils procps -y &&\
|
RUN yum install curl-minimal xz gnupg tar gzip openssl findutils procps -y &&\
|
||||||
yum clean all
|
yum clean all
|
||||||
@@ -27,11 +28,15 @@ RUN yum install wazuh-manager-${WAZUH_VERSION}-${WAZUH_TAG_REVISION} -y && \
|
|||||||
chmod 775 /filebeat_module.sh && \
|
chmod 775 /filebeat_module.sh && \
|
||||||
source /filebeat_module.sh && \
|
source /filebeat_module.sh && \
|
||||||
rm /filebeat_module.sh && \
|
rm /filebeat_module.sh && \
|
||||||
curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-amd64.tar.gz \
|
S6_ARCH="amd64" && \
|
||||||
-o /tmp/s6-overlay-amd64.tar.gz && \
|
if [ "${TARGETARCH}" = "arm64" ]; then S6_ARCH="aarch64"; fi && \
|
||||||
tar xzf /tmp/s6-overlay-amd64.tar.gz -C / --exclude="./bin" && \
|
curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-${S6_ARCH}.tar.gz \
|
||||||
tar xzf /tmp/s6-overlay-amd64.tar.gz -C /usr ./bin && \
|
-o /tmp/s6-overlay-${S6_ARCH}.tar.gz && \
|
||||||
rm /tmp/s6-overlay-amd64.tar.gz
|
tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C / --exclude="./bin" && \
|
||||||
|
tar xzf /tmp/s6-overlay-${S6_ARCH}.tar.gz -C /usr ./bin && \
|
||||||
|
rm /tmp/s6-overlay-${S6_ARCH}.tar.gz && \
|
||||||
|
rm -f /var/ossec/etc/sslmanager.key && \
|
||||||
|
rm -f /var/ossec/etc/sslmanager.cert
|
||||||
|
|
||||||
COPY config/etc/ /etc/
|
COPY config/etc/ /etc/
|
||||||
COPY --chown=root:wazuh config/create_user.py /var/ossec/framework/scripts/create_user.py
|
COPY --chown=root:wazuh config/create_user.py /var/ossec/framework/scripts/create_user.py
|
||||||
|
|||||||
@@ -6,8 +6,6 @@ source /permanent_data.env
|
|||||||
|
|
||||||
WAZUH_INSTALL_PATH=/var/ossec
|
WAZUH_INSTALL_PATH=/var/ossec
|
||||||
WAZUH_CONFIG_MOUNT=/wazuh-config-mount
|
WAZUH_CONFIG_MOUNT=/wazuh-config-mount
|
||||||
AUTO_ENROLLMENT_ENABLED=${AUTO_ENROLLMENT_ENABLED:-true}
|
|
||||||
|
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
# Aux functions
|
# Aux functions
|
||||||
@@ -70,8 +68,17 @@ apply_exclusion_data() {
|
|||||||
mkdir -p ${DIR}
|
mkdir -p ${DIR}
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
safe_cp() {
|
||||||
|
if cp -p "$1" "$2" 2>/dev/null; then
|
||||||
|
return 0
|
||||||
|
else
|
||||||
|
echo "Warning: Could not copy $1 (may be read-only)"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
print "Updating ${exclusion_file}"
|
print "Updating ${exclusion_file}"
|
||||||
exec_cmd "cp -p ${WAZUH_INSTALL_PATH}/data_tmp/exclusion/${exclusion_file} ${exclusion_file}"
|
exec_cmd "safe_cp ${WAZUH_INSTALL_PATH}/data_tmp/exclusion/${exclusion_file} ${exclusion_file}"
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
}
|
}
|
||||||
@@ -206,13 +213,10 @@ main() {
|
|||||||
# Remove some files in permanent_data (i.e. .template.db)
|
# Remove some files in permanent_data (i.e. .template.db)
|
||||||
remove_data_files
|
remove_data_files
|
||||||
|
|
||||||
# Generate wazuh-authd certs if AUTO_ENROLLMENT_ENABLED is true and does not exist
|
# Create wazuh-authd key and cert if not present
|
||||||
if [ $AUTO_ENROLLMENT_ENABLED == true ]
|
if [ ! -e ${WAZUH_INSTALL_PATH}/etc/sslmanager.key ]
|
||||||
then
|
then
|
||||||
if [ ! -e ${WAZUH_INSTALL_PATH}/etc/sslmanager.key ]
|
create_ossec_key_cert
|
||||||
then
|
|
||||||
create_ossec_key_cert
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Mount selected files (WAZUH_CONFIG_MOUNT) to container
|
# Mount selected files (WAZUH_CONFIG_MOUNT) to container
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ This script initializes the environment variables needed to build each of the im
|
|||||||
The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument:
|
The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument:
|
||||||
|
|
||||||
```
|
```
|
||||||
$ build-docker-images/build-images.sh -v 4.14.2
|
$ build-docker-images/build-images.sh -v 4.14.3
|
||||||
```
|
```
|
||||||
|
|
||||||
To get all the available script options use the -h or --help option:
|
To get all the available script options use the -h or --help option:
|
||||||
@@ -26,7 +26,7 @@ Usage: build-docker-images/build-images.sh [OPTIONS]
|
|||||||
-d, --dev <ref> [Optional] Set the development stage you want to build, example alpha0 or beta1, not used by default.
|
-d, --dev <ref> [Optional] Set the development stage you want to build, example alpha0 or beta1, not used by default.
|
||||||
-f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default 0.4.
|
-f, --filebeat-module <ref> [Optional] Set Filebeat module version. By default 0.4.
|
||||||
-r, --revision <rev> [Optional] Package revision. By default 1
|
-r, --revision <rev> [Optional] Package revision. By default 1
|
||||||
-v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, 4.14.2.
|
-v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, 4.14.3.
|
||||||
-h, --help Show this help.
|
-h, --help Show this help.
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
# Development Guide - Introduction
|
# Development Guide - Introduction
|
||||||
|
|
||||||
Welcome to the Development Guide for Wazuh-docker version 4.14.2. This guide is intended for developers, contributors, and advanced users who wish to understand the development aspects of the Wazuh-Docker project, build custom Docker images, or contribute to its development.
|
Welcome to the Development Guide for Wazuh-docker version 4.14.3. This guide is intended for developers, contributors, and advanced users who wish to understand the development aspects of the Wazuh-Docker project, build custom Docker images, or contribute to its development.
|
||||||
|
|
||||||
## Purpose of This Guide
|
## Purpose of This Guide
|
||||||
|
|
||||||
|
|||||||
+3
-3
@@ -1,6 +1,6 @@
|
|||||||
# Development Guide - Setup Environment
|
# Development Guide - Setup Environment
|
||||||
|
|
||||||
This section outlines the steps required to set up your local development environment for working with the Wazuh-Docker project (version 4.14.2). A proper setup is crucial for building images, running tests, and contributing effectively.
|
This section outlines the steps required to set up your local development environment for working with the Wazuh-Docker project (version 4.14.3). A proper setup is crucial for building images, running tests, and contributing effectively.
|
||||||
|
|
||||||
## Prerequisites
|
## Prerequisites
|
||||||
|
|
||||||
@@ -26,12 +26,12 @@ Before you begin, ensure your system meets the following requirements:
|
|||||||
Follow these steps to prepare your development environment:
|
Follow these steps to prepare your development environment:
|
||||||
|
|
||||||
1. **Clone the Repository**:
|
1. **Clone the Repository**:
|
||||||
Clone the `wazuh-docker` repository from GitHub. It's important to check out the specific branch you intend to work with, in this case, `4.14.2`.
|
Clone the `wazuh-docker` repository from GitHub. It's important to check out the specific branch you intend to work with, in this case, `4.14.3`.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
||||||
cd wazuh-docker
|
cd wazuh-docker
|
||||||
git checkout v4.14.2
|
git checkout v4.14.3
|
||||||
```
|
```
|
||||||
|
|
||||||
2. **Verify Docker Installation**:
|
2. **Verify Docker Installation**:
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Reference Manual - Description
|
# Reference Manual - Description
|
||||||
|
|
||||||
This section provides a detailed description of Wazuh-docker (version 4.14.2), its components, and its architecture when deployed using Docker containers. Understanding these aspects is key to effectively deploying and managing your Wazuh environment.
|
This section provides a detailed description of Wazuh-docker (version 4.14.3), its components, and its architecture when deployed using Docker containers. Understanding these aspects is key to effectively deploying and managing your Wazuh environment.
|
||||||
|
|
||||||
## What is Wazuh?
|
## What is Wazuh?
|
||||||
|
|
||||||
@@ -18,7 +18,7 @@ Wazuh-docker is a project that provides Docker images and `docker compose` confi
|
|||||||
|
|
||||||
## Core Components in Wazuh-Docker
|
## Core Components in Wazuh-Docker
|
||||||
|
|
||||||
The Wazuh-Docker project typically provides images for the following core Wazuh components, adapted for version 4.14.2:
|
The Wazuh-Docker project typically provides images for the following core Wazuh components, adapted for version 4.14.3:
|
||||||
|
|
||||||
1. **Wazuh Manager**:
|
1. **Wazuh Manager**:
|
||||||
- The central component that collects and analyzes data from deployed Wazuh agents.
|
- The central component that collects and analyzes data from deployed Wazuh agents.
|
||||||
@@ -28,7 +28,7 @@ The Wazuh-Docker project typically provides images for the following core Wazuh
|
|||||||
2. **Wazuh Indexer**:
|
2. **Wazuh Indexer**:
|
||||||
- A highly scalable, full-text search and analytics engine.
|
- A highly scalable, full-text search and analytics engine.
|
||||||
- Based on OpenSearch (or historically Elasticsearch), it stores and indexes alerts and monitoring data generated by the Wazuh manager.
|
- Based on OpenSearch (or historically Elasticsearch), it stores and indexes alerts and monitoring data generated by the Wazuh manager.
|
||||||
- The Wazuh indexer container provides the data persistence layer for Wazuh alerts and events. For version 4.14.2, this is typically an OpenSearch-based component.
|
- The Wazuh indexer container provides the data persistence layer for Wazuh alerts and events. For version 4.14.3, this is typically an OpenSearch-based component.
|
||||||
|
|
||||||
3. **Wazuh Dashboard**:
|
3. **Wazuh Dashboard**:
|
||||||
- A flexible visualization tool based on OpenSearch Dashboards (or historically Kibana).
|
- A flexible visualization tool based on OpenSearch Dashboards (or historically Kibana).
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Reference Manual - Introduction
|
# Reference Manual - Introduction
|
||||||
|
|
||||||
Welcome to the Reference Manual for Wazuh-Docker, version 4.14.2. This manual provides comprehensive information about deploying, configuring, and managing your Wazuh environment using Docker.
|
Welcome to the Reference Manual for Wazuh-Docker, version 4.14.3. This manual provides comprehensive information about deploying, configuring, and managing your Wazuh environment using Docker.
|
||||||
|
|
||||||
## Purpose of This Manual
|
## Purpose of This Manual
|
||||||
|
|
||||||
@@ -44,4 +44,4 @@ This manual is structured to help you find information efficiently:
|
|||||||
- If you need to customize your deployment, refer to the [Configuration](configuration/configuration.md) section.
|
- If you need to customize your deployment, refer to the [Configuration](configuration/configuration.md) section.
|
||||||
- For specific terms or concepts, consult the [Glossary](glossary.md).
|
- For specific terms or concepts, consult the [Glossary](glossary.md).
|
||||||
|
|
||||||
This manual refers to version 4.14.2 of Wazuh-Docker. Ensure you are using the documentation that corresponds to your deployed version.
|
This manual refers to version 4.14.3 of Wazuh-Docker. Ensure you are using the documentation that corresponds to your deployed version.
|
||||||
|
|||||||
@@ -29,4 +29,4 @@
|
|||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
Consult the official Wazuh documentation for version 4.14.2 for detailed information on all possible configuration parameters for each component.
|
Consult the official Wazuh documentation for version 4.14.3 for detailed information on all possible configuration parameters for each component.
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Reference Manual - Configuration
|
# Reference Manual - Configuration
|
||||||
|
|
||||||
This section details how to configure your Wazuh-Docker deployment (version 4.14.2). Proper configuration is key to tailoring the Wazuh stack to your specific needs, managing data persistence, and integrating with your environment.
|
This section details how to configure your Wazuh-Docker deployment (version 4.14.3). Proper configuration is key to tailoring the Wazuh stack to your specific needs, managing data persistence, and integrating with your environment.
|
||||||
|
|
||||||
## Overview of Configuration Methods
|
## Overview of Configuration Methods
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Reference Manual - Deployment
|
# Reference Manual - Deployment
|
||||||
|
|
||||||
This section provides detailed instructions for deploying Wazuh-Docker (version 4.14.2) in various configurations. Choose the deployment model that best suits your needs, from simple single-node setups for testing to more robust multi-node configurations for production environments.
|
This section provides detailed instructions for deploying Wazuh-Docker (version 4.14.3) in various configurations. Choose the deployment model that best suits your needs, from simple single-node setups for testing to more robust multi-node configurations for production environments.
|
||||||
|
|
||||||
## Overview of Deployment Options
|
## Overview of Deployment Options
|
||||||
|
|
||||||
@@ -24,11 +24,11 @@ Ensure you have:
|
|||||||
|
|
||||||
- Met all the [System Requirements](ref/getting-started/requirements.md).
|
- Met all the [System Requirements](ref/getting-started/requirements.md).
|
||||||
- Installed Docker and Docker Compose on your host(s).
|
- Installed Docker and Docker Compose on your host(s).
|
||||||
- Cloned the `wazuh-docker` repository (version `4.14.2`) or downloaded the necessary deployment files.
|
- Cloned the `wazuh-docker` repository (version `4.14.3`) or downloaded the necessary deployment files.
|
||||||
```bash
|
```bash
|
||||||
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
||||||
cd wazuh-docker
|
cd wazuh-docker
|
||||||
git checkout v4.14.2
|
git checkout v4.14.3
|
||||||
```
|
```
|
||||||
- Made a backup of any existing Wazuh data if you are migrating or upgrading.
|
- Made a backup of any existing Wazuh data if you are migrating or upgrading.
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Reference Manual - Getting Started
|
# Reference Manual - Getting Started
|
||||||
|
|
||||||
This section guides you through the initial steps to get your Wazuh-docker (version 4.14.2) environment up and running. We will cover the prerequisites and point you to the deployment instructions.
|
This section guides you through the initial steps to get your Wazuh-docker (version 4.14.3) environment up and running. We will cover the prerequisites and point you to the deployment instructions.
|
||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|
||||||
@@ -27,11 +27,11 @@ Before diving into the deployment, please ensure you have reviewed:
|
|||||||
Verify that your host system has sufficient RAM, CPU, and disk space. Ensure Docker and Docker Compose are installed and functioning correctly.
|
Verify that your host system has sufficient RAM, CPU, and disk space. Ensure Docker and Docker Compose are installed and functioning correctly.
|
||||||
|
|
||||||
2. **Obtain Wazuh-docker Configuration**:
|
2. **Obtain Wazuh-docker Configuration**:
|
||||||
You'll need the Docker Compose files and any associated configuration files from the `wazuh-docker` repository for version 4.14.2.
|
You'll need the Docker Compose files and any associated configuration files from the `wazuh-docker` repository for version 4.14.3.
|
||||||
```bash
|
```bash
|
||||||
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
||||||
cd wazuh-docker
|
cd wazuh-docker
|
||||||
git checkout v4.14.2
|
git checkout v4.14.3
|
||||||
# Navigate to the specific docker-compose directory, e.g., single-node or multi-node
|
# Navigate to the specific docker-compose directory, e.g., single-node or multi-node
|
||||||
# cd docker-compose/single-node/ (example path)
|
# cd docker-compose/single-node/ (example path)
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Reference Manual - Requirements
|
# Reference Manual - Requirements
|
||||||
|
|
||||||
Before deploying Wazuh-Docker (version 4.14.2), it's essential to ensure your environment meets the necessary hardware and software requirements. Meeting these prerequisites will help ensure a stable and performant Wazuh deployment.
|
Before deploying Wazuh-Docker (version 4.14.3), it's essential to ensure your environment meets the necessary hardware and software requirements. Meeting these prerequisites will help ensure a stable and performant Wazuh deployment.
|
||||||
|
|
||||||
## Host System Requirements
|
## Host System Requirements
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Reference Manual - Glossary
|
# Reference Manual - Glossary
|
||||||
|
|
||||||
This glossary defines key terms and concepts related to Wazuh, Docker, and their use together in the Wazuh-Docker project (version 4.14.2).
|
This glossary defines key terms and concepts related to Wazuh, Docker, and their use together in the Wazuh-Docker project (version 4.14.3).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -22,7 +22,7 @@ This glossary defines key terms and concepts related to Wazuh, Docker, and their
|
|||||||
|
|
||||||
**D**
|
**D**
|
||||||
|
|
||||||
- **Dashboard (Wazuh Dashboard / OpenSearch Dashboards / Kibana)**: A web-based visualization tool used to explore, analyze, and visualize data stored in the Wazuh Indexer. It provides dashboards, visualizations, and a query interface for security events and alerts. For Wazuh 4.14.2, this is typically OpenSearch Dashboards.
|
- **Dashboard (Wazuh Dashboard / OpenSearch Dashboards / Kibana)**: A web-based visualization tool used to explore, analyze, and visualize data stored in the Wazuh Indexer. It provides dashboards, visualizations, and a query interface for security events and alerts. For Wazuh 4.14.3, this is typically OpenSearch Dashboards.
|
||||||
- **Decoder**: A component in the Wazuh Manager that parses and extracts relevant information (fields) from raw log messages or event data.
|
- **Decoder**: A component in the Wazuh Manager that parses and extracts relevant information (fields) from raw log messages or event data.
|
||||||
- **Docker**: An open platform for developing, shipping, and running applications inside containers.
|
- **Docker**: An open platform for developing, shipping, and running applications inside containers.
|
||||||
- **Docker Compose**: A tool for defining and running multi-container Docker applications. It uses a YAML file (`docker-compose.yml`) to configure the application's services, networks, and volumes.
|
- **Docker Compose**: A tool for defining and running multi-container Docker applications. It uses a YAML file (`docker-compose.yml`) to configure the application's services, networks, and volumes.
|
||||||
@@ -42,7 +42,7 @@ This glossary defines key terms and concepts related to Wazuh, Docker, and their
|
|||||||
|
|
||||||
**I**
|
**I**
|
||||||
|
|
||||||
- **Indexer (Wazuh Indexer / OpenSearch / Elasticsearch)**: The component responsible for storing, indexing, and making searchable the alerts and event data generated by the Wazuh Manager. For Wazuh 4.14.2, this is typically OpenSearch.
|
- **Indexer (Wazuh Indexer / OpenSearch / Elasticsearch)**: The component responsible for storing, indexing, and making searchable the alerts and event data generated by the Wazuh Manager. For Wazuh 4.14.3, this is typically OpenSearch.
|
||||||
|
|
||||||
**L**
|
**L**
|
||||||
|
|
||||||
|
|||||||
@@ -1,9 +1,27 @@
|
|||||||
# Certificate creation image build
|
# Certificate Creation Image Build
|
||||||
|
|
||||||
The dockerfile hosted in this directory is used to build the image used to boot Wazuh's single node and multi node stacks.
|
The dockerfile hosted in this directory is used to build the image required for generating Wazuh Docker single-node and multi-node certificate files
|
||||||
|
|
||||||
To create the image, the following command must be executed:
|
## Pre-requisites
|
||||||
|
|
||||||
|
### QEMU
|
||||||
|
|
||||||
|
Set up QEMU to enable building multi-architecture Docker images
|
||||||
|
|
||||||
|
Useful documentation:
|
||||||
|
|
||||||
|
- https://www.qemu.org/download/
|
||||||
|
- https://docs.docker.com/build/building/multi-platform/#qemu
|
||||||
|
|
||||||
|
## Procedure
|
||||||
|
|
||||||
|
Run the following script to build the wazuh-certs-generator docker image
|
||||||
|
|
||||||
|
```console
|
||||||
|
./build-image.sh -v <IMAGE_TAG> [-m] [-rg <REGISTRY>]
|
||||||
```
|
```
|
||||||
$ docker build -t wazuh/wazuh-certs-generator:0.0.3 .
|
|
||||||
```
|
- Replace <IMAGE_TAG> with the new image desired tag.
|
||||||
|
- Use the `-m` flag to build a multi-architecture image (supports both `amd64` and `arm64`)
|
||||||
|
- If multiarch build is enabled, the script will attempt to push the image to the specified registry. This image upload will only work if credentials are properly configured.
|
||||||
|
- Use the `-rg <REGISTRY>` parameter to specify a custom Docker registry (default is Docker Hub)
|
||||||
|
|||||||
Executable
+107
@@ -0,0 +1,107 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
# Wazuh package generator
|
||||||
|
# Copyright (C) 2023, Wazuh Inc.
|
||||||
|
#
|
||||||
|
# This program is a free software; you can redistribute it
|
||||||
|
# and/or modify it under the terms of the GNU General Public
|
||||||
|
# License (version 2) as published by the FSF - Free Software
|
||||||
|
# Foundation.
|
||||||
|
|
||||||
|
WAZUH_CERTS_IMAGE_VERSION="0.0.4"
|
||||||
|
WAZUH_REGISTRY="docker.io"
|
||||||
|
|
||||||
|
# -----------------------------------------------------------------------------
|
||||||
|
|
||||||
|
trap ctrl_c INT
|
||||||
|
|
||||||
|
clean() {
|
||||||
|
exit_code=$1
|
||||||
|
exit ${exit_code}
|
||||||
|
}
|
||||||
|
|
||||||
|
ctrl_c() {
|
||||||
|
clean 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# -----------------------------------------------------------------------------
|
||||||
|
|
||||||
|
build() {
|
||||||
|
IMAGE_TAG="${WAZUH_CERTS_IMAGE_VERSION}"
|
||||||
|
|
||||||
|
echo WAZUH_REGISTRY=$WAZUH_REGISTRY > .env
|
||||||
|
echo IMAGE_TAG=$IMAGE_TAG >> .env
|
||||||
|
|
||||||
|
set -a
|
||||||
|
source .env
|
||||||
|
set +a
|
||||||
|
|
||||||
|
if [ "${MULTIARCH}" ]; then
|
||||||
|
docker buildx bake \
|
||||||
|
--file build-image.yml \
|
||||||
|
--set *.platform=linux/amd64,linux/arm64 \
|
||||||
|
--push \
|
||||||
|
--no-cache || clean 1
|
||||||
|
else
|
||||||
|
docker buildx bake \
|
||||||
|
--file build-image.yml \
|
||||||
|
--load \
|
||||||
|
--no-cache || clean 1
|
||||||
|
fi
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
# -----------------------------------------------------------------------------
|
||||||
|
|
||||||
|
help() {
|
||||||
|
echo
|
||||||
|
echo "Usage: $0 [OPTIONS]"
|
||||||
|
echo
|
||||||
|
echo " -v, --version <ver> [Optional] Set the image version. By default ${WAZUH_CERTS_IMAGE_VERSION}."
|
||||||
|
echo " -rg, --registry <reg> [Optional] Set the Docker registry to push the images."
|
||||||
|
echo " -m, --multiarch [Optional] Enable multi-architecture builds."
|
||||||
|
echo " -h, --help Show this help."
|
||||||
|
echo
|
||||||
|
exit $1
|
||||||
|
}
|
||||||
|
|
||||||
|
# -----------------------------------------------------------------------------
|
||||||
|
|
||||||
|
main() {
|
||||||
|
while [ -n "${1}" ]
|
||||||
|
do
|
||||||
|
case "${1}" in
|
||||||
|
"-h"|"--help")
|
||||||
|
help 0
|
||||||
|
;;
|
||||||
|
"-m"|"--multiarch")
|
||||||
|
MULTIARCH="true"
|
||||||
|
shift
|
||||||
|
;;
|
||||||
|
"-rg"|"--registry")
|
||||||
|
if [ -n "${2}" ]; then
|
||||||
|
WAZUH_REGISTRY="${2}"
|
||||||
|
shift 2
|
||||||
|
else
|
||||||
|
help 1
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
"-v"|"--version")
|
||||||
|
if [ -n "$2" ]; then
|
||||||
|
WAZUH_CERTS_IMAGE_VERSION="$2"
|
||||||
|
shift 2
|
||||||
|
else
|
||||||
|
help 1
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
help 1
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
build || clean 1
|
||||||
|
|
||||||
|
clean 0
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||||
|
services:
|
||||||
|
wazuh.certs.generator:
|
||||||
|
build:
|
||||||
|
context: .
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
image: ${WAZUH_REGISTRY}/wazuh/wazuh-certs-generator:${IMAGE_TAG}
|
||||||
|
hostname: wazuh-certs-generator
|
||||||
@@ -21,6 +21,13 @@ plugins.security.ssl.transport.pemtrustedcas_filepath: ${OPENSEARCH_PATH_CONF}/c
|
|||||||
plugins.security.ssl.http.enabled: true
|
plugins.security.ssl.http.enabled: true
|
||||||
plugins.security.ssl.transport.enforce_hostname_verification: false
|
plugins.security.ssl.transport.enforce_hostname_verification: false
|
||||||
plugins.security.ssl.transport.resolve_hostname: false
|
plugins.security.ssl.transport.resolve_hostname: false
|
||||||
|
plugins.security.ssl.http.enabled_ciphers:
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
plugins.security.ssl.http.enabled_protocols:
|
||||||
|
- "TLSv1.2"
|
||||||
plugins.security.authcz.admin_dn:
|
plugins.security.authcz.admin_dn:
|
||||||
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
||||||
plugins.security.check_snapshot_restore_write_privileges: true
|
plugins.security.check_snapshot_restore_write_privileges: true
|
||||||
|
|||||||
@@ -21,6 +21,13 @@ plugins.security.ssl.transport.pemtrustedcas_filepath: ${OPENSEARCH_PATH_CONF}/c
|
|||||||
plugins.security.ssl.http.enabled: true
|
plugins.security.ssl.http.enabled: true
|
||||||
plugins.security.ssl.transport.enforce_hostname_verification: false
|
plugins.security.ssl.transport.enforce_hostname_verification: false
|
||||||
plugins.security.ssl.transport.resolve_hostname: false
|
plugins.security.ssl.transport.resolve_hostname: false
|
||||||
|
plugins.security.ssl.http.enabled_ciphers:
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
plugins.security.ssl.http.enabled_protocols:
|
||||||
|
- "TLSv1.2"
|
||||||
plugins.security.authcz.admin_dn:
|
plugins.security.authcz.admin_dn:
|
||||||
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
||||||
plugins.security.check_snapshot_restore_write_privileges: true
|
plugins.security.check_snapshot_restore_write_privileges: true
|
||||||
|
|||||||
@@ -21,6 +21,13 @@ plugins.security.ssl.transport.pemtrustedcas_filepath: ${OPENSEARCH_PATH_CONF}/c
|
|||||||
plugins.security.ssl.http.enabled: true
|
plugins.security.ssl.http.enabled: true
|
||||||
plugins.security.ssl.transport.enforce_hostname_verification: false
|
plugins.security.ssl.transport.enforce_hostname_verification: false
|
||||||
plugins.security.ssl.transport.resolve_hostname: false
|
plugins.security.ssl.transport.resolve_hostname: false
|
||||||
|
plugins.security.ssl.http.enabled_ciphers:
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
plugins.security.ssl.http.enabled_protocols:
|
||||||
|
- "TLSv1.2"
|
||||||
plugins.security.authcz.admin_dn:
|
plugins.security.authcz.admin_dn:
|
||||||
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
||||||
plugins.security.check_snapshot_restore_write_privileges: true
|
plugins.security.check_snapshot_restore_write_privileges: true
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||||
services:
|
services:
|
||||||
wazuh.master:
|
wazuh.master:
|
||||||
image: wazuh/wazuh-manager:4.14.2
|
image: wazuh/wazuh-manager:4.14.3
|
||||||
hostname: wazuh.master
|
hostname: wazuh.master
|
||||||
restart: always
|
restart: always
|
||||||
ulimits:
|
ulimits:
|
||||||
@@ -43,7 +43,7 @@ services:
|
|||||||
- ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf
|
- ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf
|
||||||
|
|
||||||
wazuh.worker:
|
wazuh.worker:
|
||||||
image: wazuh/wazuh-manager:4.14.2
|
image: wazuh/wazuh-manager:4.14.3
|
||||||
hostname: wazuh.worker
|
hostname: wazuh.worker
|
||||||
restart: always
|
restart: always
|
||||||
ulimits:
|
ulimits:
|
||||||
@@ -79,7 +79,7 @@ services:
|
|||||||
- ./config/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf
|
- ./config/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf
|
||||||
|
|
||||||
wazuh1.indexer:
|
wazuh1.indexer:
|
||||||
image: wazuh/wazuh-indexer:4.14.2
|
image: wazuh/wazuh-indexer:4.14.3
|
||||||
hostname: wazuh1.indexer
|
hostname: wazuh1.indexer
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -105,7 +105,7 @@ services:
|
|||||||
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
||||||
|
|
||||||
wazuh2.indexer:
|
wazuh2.indexer:
|
||||||
image: wazuh/wazuh-indexer:4.14.2
|
image: wazuh/wazuh-indexer:4.14.3
|
||||||
hostname: wazuh2.indexer
|
hostname: wazuh2.indexer
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
@@ -127,7 +127,7 @@ services:
|
|||||||
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
||||||
|
|
||||||
wazuh3.indexer:
|
wazuh3.indexer:
|
||||||
image: wazuh/wazuh-indexer:4.14.2
|
image: wazuh/wazuh-indexer:4.14.3
|
||||||
hostname: wazuh3.indexer
|
hostname: wazuh3.indexer
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
@@ -149,7 +149,7 @@ services:
|
|||||||
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
||||||
|
|
||||||
wazuh.dashboard:
|
wazuh.dashboard:
|
||||||
image: wazuh/wazuh-dashboard:4.14.2
|
image: wazuh/wazuh-dashboard:4.14.3
|
||||||
hostname: wazuh.dashboard
|
hostname: wazuh.dashboard
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
|
|||||||
@@ -4,8 +4,6 @@ cluster.name: "wazuh-cluster"
|
|||||||
path.data: /var/lib/wazuh-indexer
|
path.data: /var/lib/wazuh-indexer
|
||||||
path.logs: /var/log/wazuh-indexer
|
path.logs: /var/log/wazuh-indexer
|
||||||
discovery.type: single-node
|
discovery.type: single-node
|
||||||
http.port: 9200-9299
|
|
||||||
transport.tcp.port: 9300-9399
|
|
||||||
compatibility.override_main_response_version: true
|
compatibility.override_main_response_version: true
|
||||||
plugins.security.ssl.http.pemcert_filepath: /usr/share/wazuh-indexer/config/certs/wazuh.indexer.pem
|
plugins.security.ssl.http.pemcert_filepath: /usr/share/wazuh-indexer/config/certs/wazuh.indexer.pem
|
||||||
plugins.security.ssl.http.pemkey_filepath: /usr/share/wazuh-indexer/config/certs/wazuh.indexer.key
|
plugins.security.ssl.http.pemkey_filepath: /usr/share/wazuh-indexer/config/certs/wazuh.indexer.key
|
||||||
@@ -16,6 +14,13 @@ plugins.security.ssl.transport.pemtrustedcas_filepath: /usr/share/wazuh-indexer/
|
|||||||
plugins.security.ssl.http.enabled: true
|
plugins.security.ssl.http.enabled: true
|
||||||
plugins.security.ssl.transport.enforce_hostname_verification: false
|
plugins.security.ssl.transport.enforce_hostname_verification: false
|
||||||
plugins.security.ssl.transport.resolve_hostname: false
|
plugins.security.ssl.transport.resolve_hostname: false
|
||||||
|
plugins.security.ssl.http.enabled_ciphers:
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
|
||||||
|
- "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
|
||||||
|
plugins.security.ssl.http.enabled_protocols:
|
||||||
|
- "TLSv1.2"
|
||||||
plugins.security.authcz.admin_dn:
|
plugins.security.authcz.admin_dn:
|
||||||
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
||||||
plugins.security.check_snapshot_restore_write_privileges: true
|
plugins.security.check_snapshot_restore_write_privileges: true
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||||
services:
|
services:
|
||||||
wazuh.manager:
|
wazuh.manager:
|
||||||
image: wazuh/wazuh-manager:4.14.2
|
image: wazuh/wazuh-manager:4.14.3
|
||||||
hostname: wazuh.manager
|
hostname: wazuh.manager
|
||||||
restart: always
|
restart: always
|
||||||
ulimits:
|
ulimits:
|
||||||
@@ -44,7 +44,7 @@ services:
|
|||||||
- ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf
|
- ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf
|
||||||
|
|
||||||
wazuh.indexer:
|
wazuh.indexer:
|
||||||
image: wazuh/wazuh-indexer:4.14.2
|
image: wazuh/wazuh-indexer:4.14.3
|
||||||
hostname: wazuh.indexer
|
hostname: wazuh.indexer
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -69,7 +69,7 @@ services:
|
|||||||
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
- ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/config/opensearch-security/internal_users.yml
|
||||||
|
|
||||||
wazuh.dashboard:
|
wazuh.dashboard:
|
||||||
image: wazuh/wazuh-dashboard:4.14.2
|
image: wazuh/wazuh-dashboard:4.14.3
|
||||||
hostname: wazuh.dashboard
|
hostname: wazuh.dashboard
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||||
services:
|
services:
|
||||||
wazuh.agent:
|
wazuh.agent:
|
||||||
image: wazuh/wazuh-agent:4.14.2
|
image: wazuh/wazuh-agent:4.14.3
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
- WAZUH_MANAGER_SERVER=<WAZUH_MANAGER_IP>
|
- WAZUH_MANAGER_SERVER=<WAZUH_MANAGER_IP>
|
||||||
|
|||||||
Reference in New Issue
Block a user