Compare commits

...
Author SHA1 Message Date
manuasir 029cbfecfe Updated docker compose 2019-08-07 17:13:55 +02:00
manuasir 95b4f9a69e Removed demo files 2019-08-07 17:12:29 +02:00
manuasir 9d38fd7d64 Demo certificates and open distro security plugin 2019-08-06 16:40:03 +02:00
8 changed files with 38 additions and 140 deletions
+38 -32
View File
@@ -1,7 +1,32 @@
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
version: '2'
version: '3'
services:
elasticsearch:
image: wazuh/wazuh-elasticsearch:3.9.3_7.1.1-opendistro
container_name: elasticsearch
ulimits:
memlock:
soft: -1
hard: -1
nofile:
soft: 65536 # maximum number of open files for the Elasticsearch user, set to at least 65536 on modern systems
hard: 65536
volumes:
- odfe-data1:/usr/share/elasticsearch/data
- ./root-ca.pem:/usr/share/elasticsearch/config/root-ca.pem
- ./node.pem:/usr/share/elasticsearch/config/node.pem
- ./node-key.pem:/usr/share/elasticsearch/config/node-key.pem
- ./admin.pem:/usr/share/elasticsearch/config/admin.pem
- ./admin-key.pem:/usr/share/elasticsearch/config/admin-key.pem
- ./custom-elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml
ports:
- 9200:9200
- 9600:9600 # required for Performance Analyzer
networks:
- odfe-net
wazuh:
image: wazuh/wazuh:3.9.3_7.1.1-opendistro
hostname: wazuh-manager
@@ -11,21 +36,8 @@ services:
- "1515:1515"
- "514:514/udp"
- "55000:55000"
elasticsearch:
image: wazuh/wazuh-elasticsearch:3.9.3_7.1.1-opendistro
hostname: elasticsearch
restart: always
ports:
- "9200:9200"
environment:
- "ES_JAVA_OPTS=-Xms1g -Xmx1g"
- ELASTIC_CLUSTER=false
ulimits:
memlock:
soft: -1
hard: -1
mem_limit: 2g
networks:
- odfe-net
kibana:
image: wazuh/wazuh-kibana:3.9.3_7.1.1-opendistro
@@ -36,17 +48,11 @@ services:
links:
- elasticsearch:elasticsearch
- wazuh:wazuh
nginx:
image: wazuh/wazuh-nginx:3.9.3_7.1.1-opendistro
hostname: nginx
restart: always
environment:
- NGINX_PORT=443
- NGINX_CREDENTIALS
ports:
- "80:80"
- "443:443"
depends_on:
- kibana
links:
- kibana:kibana
networks:
- odfe-net
volumes:
odfe-data1:
networks:
odfe-net:
-3
View File
@@ -41,8 +41,5 @@ RUN ${bin/elasticsearch-plugin install --batch S3_PLUGIN_URL}
COPY config/configure_s3.sh ./config/configure_s3.sh
RUN chmod 755 ./config/configure_s3.sh
COPY --chown=elasticsearch:elasticsearch ./config/config_cluster.sh ./
RUN chmod +x ./config_cluster.sh
ENTRYPOINT ["/entrypoint.sh"]
CMD ["elasticsearch"]
-2
View File
@@ -4,7 +4,6 @@
elastic_config_file="/usr/share/elasticsearch/config/elasticsearch.yml"
# Disable the Open distro security plugin
sed -i '/opendistro_security/d' $elastic_config_file
remove_single_node_conf(){
if grep -Fq "discovery.type" $1; then
@@ -58,4 +57,3 @@ else
remove_cluster_config $elastic_config_file
echo "discovery.type: single-node" >> $elastic_config_file
fi
echo "opendistro_security.disabled: true" >> $elastic_config_file
-2
View File
@@ -21,8 +21,6 @@ run_as_other_user_if_needed() {
# Run load settings script.
./config_cluster.sh
./load_settings.sh &
# Execute elasticsearch
-2
View File
@@ -60,6 +60,4 @@ RUN ./welcome_wazuh.sh
RUN /usr/local/bin/kibana-docker --optimize
RUN /usr/share/kibana/bin/kibana-plugin remove opendistro_security
ENTRYPOINT ./entrypoint.sh
-1
View File
@@ -18,7 +18,6 @@ WAZUH_MAJOR=3
# Customize elasticsearch ip
##############################################################################
sed -i 's|https://localhost:9200|http://elasticsearch:9200|g' /usr/share/kibana/config/kibana.yml
sed -i '/opendistro_security/d' /usr/share/kibana/config/kibana.yml
if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then
sed -i '/elasticsearch.hosts/d' /usr/share/kibana/config/kibana.yml
-19
View File
@@ -1,19 +0,0 @@
# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2)
FROM nginx:latest
ENV DEBIAN_FRONTEND noninteractive
RUN apt-get update && apt-get install -y openssl apache2-utils
COPY config/entrypoint.sh /entrypoint.sh
RUN chmod 755 /entrypoint.sh
RUN apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
VOLUME ["/etc/nginx/conf.d"]
ENV NGINX_NAME="foo" \
NGINX_PWD="bar"
ENTRYPOINT /entrypoint.sh
-79
View File
@@ -1,79 +0,0 @@
#!/bin/bash
# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2)
set -e
# Generating certificates.
if [ ! -d /etc/nginx/conf.d/ssl ]; then
echo "Generating SSL certificates"
mkdir -p /etc/nginx/conf.d/ssl/certs /etc/nginx/conf.d/ssl/private
openssl req -x509 -batch -nodes -days 365 -newkey rsa:2048 -keyout /etc/nginx/conf.d/ssl/private/kibana-access.key -out /etc/nginx/conf.d/ssl/certs/kibana-access.pem >/dev/null
else
echo "SSL certificates already present"
fi
# Setting users credentials.
# In order to set NGINX_CREDENTIALS, before "docker-compose up -d" run (a or b):
#
# a) export NGINX_CREDENTIALS="user1:pass1;user2:pass2;" or
# export NGINX_CREDENTIALS="user1:pass1;user2:pass2"
#
# b) Set NGINX_CREDENTIALS in docker-compose.yml:
# NGINX_CREDENTIALS=user1:pass1;user2:pass2; or
# NGINX_CREDENTIALS=user1:pass1;user2:pass2
#
if [ ! -f /etc/nginx/conf.d/kibana.htpasswd ]; then
echo "Setting users credentials"
if [ ! -z "$NGINX_CREDENTIALS" ]; then
IFS=';' read -r -a users <<< "$NGINX_CREDENTIALS"
for index in "${!users[@]}"
do
IFS=':' read -r -a credentials <<< "${users[index]}"
if [ $index -eq 0 ]; then
echo ${credentials[1]}|htpasswd -i -c /etc/nginx/conf.d/kibana.htpasswd ${credentials[0]} >/dev/null
else
echo ${credentials[1]}|htpasswd -i /etc/nginx/conf.d/kibana.htpasswd ${credentials[0]} >/dev/null
fi
done
else
# NGINX_PWD and NGINX_NAME are declared in nginx/Dockerfile
echo $NGINX_PWD|htpasswd -i -c /etc/nginx/conf.d/kibana.htpasswd $NGINX_NAME >/dev/null
fi
else
echo "Kibana credentials already configured"
fi
if [ "x${NGINX_PORT}" = "x" ]; then
NGINX_PORT=443
fi
if [ "x${KIBANA_HOST}" = "x" ]; then
KIBANA_HOST="kibana:5601"
fi
echo "Configuring NGINX"
cat > /etc/nginx/conf.d/default.conf <<EOF
server {
listen 80;
listen [::]:80;
return 301 https://\$host:${NGINX_PORT}\$request_uri;
}
server {
listen ${NGINX_PORT} default_server;
listen [::]:${NGINX_PORT};
ssl on;
ssl_certificate /etc/nginx/conf.d/ssl/certs/kibana-access.pem;
ssl_certificate_key /etc/nginx/conf.d/ssl/private/kibana-access.key;
location / {
auth_basic "Restricted";
auth_basic_user_file /etc/nginx/conf.d/kibana.htpasswd;
proxy_pass http://${KIBANA_HOST}/;
proxy_buffer_size 128k;
proxy_buffers 4 256k;
proxy_busy_buffers_size 256k;
}
}
EOF
nginx -g 'daemon off;'