forked from wazuh/wazuh-docker
Compare commits
10
Commits
v3.13.1_7.8.0
...
devel
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e9fec0e497 | ||
|
|
7042854bfa | ||
|
|
b63c294288 | ||
|
|
9df61de961 | ||
|
|
86ff04c0b3 | ||
|
|
0992111200 | ||
|
|
a1a27922de | ||
|
|
eba6bc6752 | ||
|
|
2df878f040 | ||
|
|
4acc3b402b |
@@ -23,6 +23,7 @@ ARG TEMPLATE_VERSION=v3.13.1
|
|||||||
# CLUSTER_INITIAL_MASTER_NODES set to own node by default.
|
# CLUSTER_INITIAL_MASTER_NODES set to own node by default.
|
||||||
ENV ELASTIC_CLUSTER="false" \
|
ENV ELASTIC_CLUSTER="false" \
|
||||||
CLUSTER_NAME="wazuh" \
|
CLUSTER_NAME="wazuh" \
|
||||||
|
CLUSTER_NETWORK_HOST="0.0.0.0" \
|
||||||
CLUSTER_NODE_MASTER="false" \
|
CLUSTER_NODE_MASTER="false" \
|
||||||
CLUSTER_NODE_DATA="true" \
|
CLUSTER_NODE_DATA="true" \
|
||||||
CLUSTER_NODE_INGEST="true" \
|
CLUSTER_NODE_INGEST="true" \
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ if [[ $CLUSTER_NODE_MASTER == "true" ]]; then
|
|||||||
# cluster.initial_master_nodes for bootstrap the cluster
|
# cluster.initial_master_nodes for bootstrap the cluster
|
||||||
cat > $elastic_config_file << EOF
|
cat > $elastic_config_file << EOF
|
||||||
# cluster node
|
# cluster node
|
||||||
network.host: 0.0.0.0
|
network.host: $CLUSTER_NETWORK_HOST
|
||||||
node.name: $CLUSTER_MASTER_NODE_NAME
|
node.name: $CLUSTER_MASTER_NODE_NAME
|
||||||
node.master: $CLUSTER_NODE_MASTER
|
node.master: $CLUSTER_NODE_MASTER
|
||||||
cluster.initial_master_nodes:
|
cluster.initial_master_nodes:
|
||||||
@@ -39,7 +39,7 @@ remove_cluster_config $elastic_config_file
|
|||||||
|
|
||||||
cat > $elastic_config_file << EOF
|
cat > $elastic_config_file << EOF
|
||||||
# cluster node
|
# cluster node
|
||||||
network.host: 0.0.0.0
|
network.host: $CLUSTER_NETWORK_HOST
|
||||||
node.name: $CLUSTER_NODE_NAME
|
node.name: $CLUSTER_NODE_NAME
|
||||||
node.master: false
|
node.master: false
|
||||||
discovery.seed_hosts:
|
discovery.seed_hosts:
|
||||||
|
|||||||
@@ -52,11 +52,14 @@ if [ "x${KIBANA_HOST}" = "x" ]; then
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
echo "Configuring NGINX"
|
echo "Configuring NGINX"
|
||||||
|
|
||||||
|
|
||||||
|
if [ "${NGINX_PORT}" = "443" ]; then
|
||||||
cat > /etc/nginx/conf.d/default.conf <<EOF
|
cat > /etc/nginx/conf.d/default.conf <<EOF
|
||||||
server {
|
server {
|
||||||
listen 80;
|
listen 80;
|
||||||
listen [::]:80;
|
listen [::]:80;
|
||||||
return 301 https://\$host:${NGINX_PORT}\$request_uri;
|
return 301 https://\$host\$request_uri;
|
||||||
}
|
}
|
||||||
|
|
||||||
server {
|
server {
|
||||||
@@ -74,5 +77,21 @@ server {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
EOF
|
EOF
|
||||||
|
else
|
||||||
|
cat > /etc/nginx/conf.d/default.conf <<EOF
|
||||||
|
server {
|
||||||
|
listen ${NGINX_PORT};
|
||||||
|
listen [::]:${NGINX_PORT};
|
||||||
|
location / {
|
||||||
|
auth_basic "Restricted";
|
||||||
|
auth_basic_user_file /etc/nginx/conf.d/kibana.htpasswd;
|
||||||
|
proxy_pass http://${KIBANA_HOST}/;
|
||||||
|
proxy_buffer_size 128k;
|
||||||
|
proxy_buffers 4 256k;
|
||||||
|
proxy_busy_buffers_size 256k;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
EOF
|
||||||
|
fi
|
||||||
|
|
||||||
exec nginx -g 'daemon off;'
|
exec nginx -g 'daemon off;'
|
||||||
|
|||||||
+4
-1
@@ -1,5 +1,5 @@
|
|||||||
# Wazuh Docker Copyright (C) 2020 Wazuh Inc. (License GPLv2)
|
# Wazuh Docker Copyright (C) 2020 Wazuh Inc. (License GPLv2)
|
||||||
FROM phusion/baseimage:latest
|
FROM phusion/baseimage:0.10.2
|
||||||
|
|
||||||
ARG FILEBEAT_VERSION=7.8.0
|
ARG FILEBEAT_VERSION=7.8.0
|
||||||
|
|
||||||
@@ -76,5 +76,8 @@ RUN chmod +x /etc/service/wazuh-api/run && \
|
|||||||
ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat
|
ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat
|
||||||
RUN chmod go-w /etc/filebeat/wazuh-template.json
|
RUN chmod go-w /etc/filebeat/wazuh-template.json
|
||||||
|
|
||||||
|
ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.1.tar.gz"
|
||||||
|
RUN curl -s https://packages.wazuh.com/3.x/filebeat/${WAZUH_FILEBEAT_MODULE} | tar -xvz -C /usr/share/filebeat/module
|
||||||
|
|
||||||
# Run all services
|
# Run all services
|
||||||
ENTRYPOINT ["/entrypoint.sh"]
|
ENTRYPOINT ["/entrypoint.sh"]
|
||||||
|
|||||||
@@ -3,16 +3,8 @@
|
|||||||
|
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
WAZUH_FILEBEAT_MODULE=wazuh-filebeat-0.1.tar.gz
|
|
||||||
|
|
||||||
# Modify the output to Elasticsearch if th ELASTICSEARCH_URL is set
|
# Modify the output to Elasticsearch if th ELASTICSEARCH_URL is set
|
||||||
if [ "$ELASTICSEARCH_URL" != "" ]; then
|
if [ "$ELASTICSEARCH_URL" != "" ]; then
|
||||||
>&2 echo "Customize Elasticsearch ouput IP."
|
>&2 echo "Customize Elasticsearch ouput IP."
|
||||||
sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_URL'|g' /etc/filebeat/filebeat.yml
|
sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_URL'|g' /etc/filebeat/filebeat.yml
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Install Wazuh Filebeat Module
|
|
||||||
|
|
||||||
curl -s "https://packages.wazuh.com/3.x/filebeat/${WAZUH_FILEBEAT_MODULE}" | tar -xvz -C /usr/share/filebeat/module
|
|
||||||
mkdir -p /usr/share/filebeat/module/wazuh
|
|
||||||
chmod 755 -R /usr/share/filebeat/module/wazuh
|
|
||||||
|
|||||||
Reference in New Issue
Block a user