forked from wazuh/wazuh-docker
Compare commits
243
Commits
v5.0.0-beta2
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
db3ede43fb | ||
|
|
5fd7f0f1c7 | ||
|
|
8ea05fa853 | ||
|
|
13548e1267 | ||
|
|
7abb956410 | ||
|
|
b1dd5ebed8 | ||
|
|
b17cb513c0 | ||
|
|
d3e0a6085a | ||
|
|
ef900cc676 | ||
|
|
b18c270783 | ||
|
|
245fba32a9 | ||
|
|
ee47a21851 | ||
|
|
5eeada70d0 | ||
|
|
ad50c30947 | ||
|
|
93b0362ee1 | ||
|
|
62d84c3f10 | ||
|
|
6852ecae39 | ||
|
|
fe20f75744 | ||
|
|
1525e2ea18 | ||
|
|
db24a0ea2d | ||
|
|
3d08629d88 | ||
|
|
f471a39e8e | ||
|
|
a55fba80e4 | ||
|
|
8e6e8e54ea | ||
|
|
7228044200 | ||
|
|
6c1b0fbbcf | ||
|
|
01c0d4c7c2 | ||
|
|
544fd8e111 | ||
|
|
3c53858c5a | ||
|
|
355a1a4a90 | ||
|
|
f7f2248185 | ||
|
|
4f51bef735 | ||
|
|
68f81a6f6f | ||
|
|
fc0e170315 | ||
|
|
04a4cdbd1e | ||
|
|
513f4d71ad | ||
|
|
2a8d2d963d | ||
|
|
14fc1019e8 | ||
|
|
d2971cb198 | ||
|
|
fb20a0d1ba | ||
|
|
76be72bc08 | ||
|
|
d68ed9f6b7 | ||
|
|
1176edb859 | ||
|
|
0b9049b6a2 | ||
|
|
a575cb71d5 | ||
|
|
adcc5b57d2 | ||
|
|
ecea95427b | ||
|
|
d83dfe5cfd | ||
|
|
031c66c671 | ||
|
|
6edf9cf598 | ||
|
|
82ada64e37 | ||
|
|
a6558e8f4a | ||
|
|
b92438499b | ||
|
|
af31c08f70 | ||
|
|
1822f025af | ||
|
|
daa919db58 | ||
|
|
d8087b2238 | ||
|
|
495b67251e | ||
|
|
80807a1cf9 | ||
|
|
1c8583f366 | ||
|
|
63b8af98d3 | ||
|
|
3f2ebfac37 | ||
|
|
8357d2c3ad | ||
|
|
577f2e0af7 | ||
|
|
d5dddfbbd8 | ||
|
|
e153333402 | ||
|
|
ffd39b0191 | ||
|
|
1f2b777866 | ||
|
|
4d9cfab272 | ||
|
|
fb0110a1c3 | ||
|
|
b2a559d081 | ||
|
|
b8368a207a | ||
|
|
a153c6fd7b | ||
|
|
0d5f3295bb | ||
|
|
5558b87c88 | ||
|
|
e6f11f8dea | ||
|
|
ae059f2b2e | ||
|
|
07b8ca9d16 | ||
|
|
f8dbec813f | ||
|
|
905b5b9a93 | ||
|
|
024a32bc15 | ||
|
|
bfe8dc4484 | ||
|
|
452e8aa073 | ||
|
|
e18a5a7be9 | ||
|
|
f2dd1d7f79 | ||
|
|
ea6bc171b6 | ||
|
|
04af11919c | ||
|
|
fa8d6b3de9 | ||
|
|
21c6a01579 | ||
|
|
8f0ae452cb | ||
|
|
5a9355c1ae | ||
|
|
b1af5a8357 | ||
|
|
3df074ee9d | ||
|
|
0548e0da2a | ||
|
|
e3d402a190 | ||
|
|
14cdfe9bd6 | ||
|
|
60d80917f5 | ||
|
|
998ac07576 | ||
|
|
ed8970d642 | ||
|
|
fb90896200 | ||
|
|
51572613ab | ||
|
|
20745769bd | ||
|
|
217b7c868a | ||
|
|
90120cd9fc | ||
|
|
b1cfa44f2f | ||
|
|
40d7702ee5 | ||
|
|
a8db1820a6 | ||
|
|
d43ae89451 | ||
|
|
aed6a5f384 | ||
|
|
cc8d5aca64 | ||
|
|
a215bf5a9e | ||
|
|
d67d766983 | ||
|
|
b51db5be38 | ||
|
|
3051d11c55 | ||
|
|
499184cbeb | ||
|
|
a36afdcf36 | ||
|
|
9d34602ce6 | ||
|
|
b24e9558bb | ||
|
|
31b5b475fe | ||
|
|
6a77ef26b2 | ||
|
|
0ff52662f6 | ||
|
|
b6ddd4a66e | ||
|
|
eafea2e8b4 | ||
|
|
8cb1db4eca | ||
|
|
8dd3df1e20 | ||
|
|
2b79c8d412 | ||
|
|
3803e9accd | ||
|
|
b17ef09a00 | ||
|
|
9c5fd31608 | ||
|
|
52070ea312 | ||
|
|
f92b6b1e8a | ||
|
|
3a5e345894 | ||
|
|
704ce6dc07 | ||
|
|
7feacc4403 | ||
|
|
6e2c61d462 | ||
|
|
7899d39155 | ||
|
|
e0ad433d59 | ||
|
|
b14c5535ed | ||
|
|
94f01fb7b0 | ||
|
|
2fceb8c110 | ||
|
|
712489f131 | ||
|
|
aae5a6d44a | ||
|
|
0c04e23e41 | ||
|
|
b31dd86d81 | ||
|
|
10079f4a6c | ||
|
|
6371c2497f | ||
|
|
fa09e68533 | ||
|
|
749763c547 | ||
|
|
33d0fc3462 | ||
|
|
fde156181a | ||
|
|
4ad604f33c | ||
|
|
67df871d7d | ||
|
|
97f687c409 | ||
|
|
95d142a9b7 | ||
|
|
b6fb072693 | ||
|
|
27287b1e19 | ||
|
|
a185f0dc75 | ||
|
|
92866daabb | ||
|
|
fd6e53b1e3 | ||
|
|
82027cf53f | ||
|
|
564bd29e9b | ||
|
|
c6c00fa9db | ||
|
|
ef52a72417 | ||
|
|
32b5377e53 | ||
|
|
70f585de4d | ||
|
|
271f6c2eb8 | ||
|
|
07368ab1e7 | ||
|
|
669560769a | ||
|
|
01b7e6de60 | ||
|
|
644cdba3a9 | ||
|
|
68faac3ac1 | ||
|
|
b509441887 | ||
|
|
1ec0ec5fbe | ||
|
|
f6a7b9765c | ||
|
|
f73b2a9946 | ||
|
|
d121ebc067 | ||
|
|
4d1530fc97 | ||
|
|
16d0b02ff5 | ||
|
|
e181132921 | ||
|
|
e7d724e631 | ||
|
|
2436b23032 | ||
|
|
77c66b89b7 | ||
|
|
0a25b40745 | ||
|
|
22617992ce | ||
|
|
91af732e64 | ||
|
|
143a0bb598 | ||
|
|
b5ab0bb116 | ||
|
|
7eb415ae3c | ||
|
|
4879dba2ce | ||
|
|
ad96562a5b | ||
|
|
68a50f2bc5 | ||
|
|
7598697f3b | ||
|
|
6dd0716918 | ||
|
|
f79abbf64a | ||
|
|
3f27301ba1 | ||
|
|
31d8b1566c | ||
|
|
9bed763ce5 | ||
|
|
9966909cc3 | ||
|
|
2f4ab3f71e | ||
|
|
35eb02d856 | ||
|
|
1106e7cdb4 | ||
|
|
f26185d10a | ||
|
|
fb2148da39 | ||
|
|
df1ef1cb1f | ||
|
|
29d43e591e | ||
|
|
af388f132a | ||
|
|
ced3ac5b63 | ||
|
|
5d3d85c690 | ||
|
|
3a68597fa9 | ||
|
|
4c1a286578 | ||
|
|
072f5f1407 | ||
|
|
6fbb0c5af5 | ||
|
|
c71ff5e51f | ||
|
|
2bef0aa78c | ||
|
|
2698ef8c2c | ||
|
|
47287f7ee3 | ||
|
|
ded51b6e96 | ||
|
|
b34ab60fdb | ||
|
|
3f16c3b9b9 | ||
|
|
f4f7af55ff | ||
|
|
d46f24c707 | ||
|
|
96308e55ce | ||
|
|
3b3ad41314 | ||
|
|
6c5d14cb55 | ||
|
|
1bb1ddda73 | ||
|
|
d888b01e9e | ||
|
|
89174ffc61 | ||
|
|
306acecc48 | ||
|
|
aa275c4f1e | ||
|
|
9093e85c18 | ||
|
|
d60510a2ac | ||
|
|
13cad85988 | ||
|
|
07c3948dce | ||
|
|
c2a385083b | ||
|
|
e774a93f9a | ||
|
|
3811e886a0 | ||
|
|
d47e4a43e9 | ||
|
|
d168d7d86f | ||
|
|
d7a27eb63a | ||
|
|
03c6ea62ca | ||
|
|
61050a7dd2 | ||
|
|
b07223d1d3 | ||
|
|
7fe0c468e8 |
@@ -1,4 +1,4 @@
|
||||
WAZUH_VERSION=5.0.0
|
||||
WAZUH_IMAGE_VERSION=5.0.0
|
||||
WAZUH_VERSION=5.1.0
|
||||
WAZUH_IMAGE_VERSION=5.1.0
|
||||
WAZUH_REGISTRY=docker.io
|
||||
IMAGE_TAG=5.0.0
|
||||
IMAGE_TAG=5.1.0
|
||||
|
||||
@@ -0,0 +1,309 @@
|
||||
run-name: (4.x) Build and push images - ${{ inputs.dev && 'dev' || 'release' }} - ${{ inputs.id }}
|
||||
name: (4.x) Build and push images
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: '4.14.9'
|
||||
required: true
|
||||
docker_reference:
|
||||
description: 'wazuh-docker reference'
|
||||
required: true
|
||||
filebeat_module_version:
|
||||
description: 'Filebeat module version'
|
||||
default: '0.5'
|
||||
required: true
|
||||
type: string
|
||||
products:
|
||||
description: 'Comma-separated list of the image names to build and push'
|
||||
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
|
||||
required: false
|
||||
type: string
|
||||
revision:
|
||||
description: 'Package revision'
|
||||
default: '1'
|
||||
required: true
|
||||
id:
|
||||
description: "ID used to identify the workflow uniquely."
|
||||
type: string
|
||||
required: false
|
||||
dev:
|
||||
description: "Add tag suffix '-dev' to the image tag ?"
|
||||
type: boolean
|
||||
default: true
|
||||
required: false
|
||||
workflow_call:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: '4.14.9'
|
||||
required: true
|
||||
type: string
|
||||
docker_reference:
|
||||
description: 'wazuh-docker reference'
|
||||
required: false
|
||||
type: string
|
||||
filebeat_module_version:
|
||||
description: 'Filebeat module version'
|
||||
default: '0.5'
|
||||
required: true
|
||||
type: string
|
||||
products:
|
||||
description: 'Comma-separated list of the image names to build and push'
|
||||
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
|
||||
required: false
|
||||
type: string
|
||||
revision:
|
||||
description: 'Package revision'
|
||||
default: '1'
|
||||
required: true
|
||||
type: string
|
||||
id:
|
||||
description: "ID used to identify the workflow uniquely."
|
||||
type: string
|
||||
required: false
|
||||
dev:
|
||||
description: "Add tag suffix '-dev' to the image tag ?"
|
||||
type: boolean
|
||||
default: false
|
||||
required: false
|
||||
|
||||
jobs:
|
||||
setup:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
|
||||
env:
|
||||
IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }}
|
||||
IMAGE_TAG: ${{ inputs.image_tag }}
|
||||
FILEBEAT_MODULE_VERSION: ${{ inputs.filebeat_module_version }}
|
||||
REVISION: ${{ inputs.revision }}
|
||||
|
||||
outputs:
|
||||
WAZUH_COMPONENTS: ${{ steps.compute-outputs.outputs.WAZUH_COMPONENTS }}
|
||||
ALL_PRODUCTS_SELECTED: ${{ steps.compute-outputs.outputs.ALL_PRODUCTS_SELECTED }}
|
||||
|
||||
steps:
|
||||
- name: Print inputs
|
||||
run: |
|
||||
echo "---------------------------------------------"
|
||||
echo "Running 4_build_and_push_images workflow"
|
||||
echo "---------------------------------------------"
|
||||
echo "* BRANCH: ${{ github.ref }}"
|
||||
echo "* COMMIT: ${{ github.sha }}"
|
||||
echo "---------------------------------------------"
|
||||
echo "Inputs provided:"
|
||||
echo "---------------------------------------------"
|
||||
echo "* id: ${{ inputs.id }}"
|
||||
echo "* image_tag: ${{ inputs.image_tag }}"
|
||||
echo "* docker_reference: ${{ inputs.docker_reference }}"
|
||||
echo "* filebeat_module_version: ${{ inputs.filebeat_module_version }}"
|
||||
echo "* products: ${{ inputs.products }}"
|
||||
echo "* revision: ${{ inputs.revision }}"
|
||||
echo "* dev: ${{ inputs.dev }}"
|
||||
echo "---------------------------------------------"
|
||||
|
||||
- name: Set up variables
|
||||
id: compute-outputs
|
||||
run: |
|
||||
# Use the default list if products is empty
|
||||
PRODUCTS="${{ inputs.products }}"
|
||||
if [[ -z "$PRODUCTS" || "$PRODUCTS" == "null" ]]; then
|
||||
PRODUCTS="wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent"
|
||||
fi
|
||||
|
||||
# Check if all 4 core components are present in the string
|
||||
if [[ "$PRODUCTS" == *"wazuh-manager"* && "$PRODUCTS" == *"wazuh-dashboard"* && "$PRODUCTS" == *"wazuh-indexer"* && "$PRODUCTS" == *"wazuh-agent"* ]]; then
|
||||
echo "ALL_PRODUCTS_SELECTED=true" >> $GITHUB_OUTPUT
|
||||
else
|
||||
echo "ALL_PRODUCTS_SELECTED=false" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
# Convert to JSON for the matrix (Your existing logic)
|
||||
IFS=',' read -ra COMPONENTS <<< "$PRODUCTS"
|
||||
JSON_ARRAY=$(printf '%s\n' "${COMPONENTS[@]}" | jq -R . | jq -s -c .)
|
||||
echo "WAZUH_COMPONENTS=$JSON_ARRAY" >> $GITHUB_OUTPUT
|
||||
|
||||
build-and-push:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
|
||||
needs:
|
||||
- setup
|
||||
|
||||
strategy:
|
||||
fail-fast: false # all jobs will run even if one fails
|
||||
matrix:
|
||||
wazuh_component: ${{ fromJson(needs.setup.outputs.WAZUH_COMPONENTS) }}
|
||||
|
||||
env:
|
||||
IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }}
|
||||
IMAGE_TAG: ${{ inputs.image_tag }}
|
||||
REVISION: ${{ inputs.revision }}
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: ${{ inputs.docker_reference }}
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v4
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v4
|
||||
|
||||
- name: Configure aws credentials
|
||||
if: ${{ inputs.dev == true }}
|
||||
uses: aws-actions/configure-aws-credentials@v6
|
||||
with:
|
||||
role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
|
||||
aws-region: "${{ secrets.AWS_REGION }}"
|
||||
|
||||
- name: Log in to Amazon ECR
|
||||
if: ${{ inputs.dev == true }}
|
||||
uses: aws-actions/amazon-ecr-login@v2
|
||||
|
||||
- name: Build Wazuh images
|
||||
run: |
|
||||
IMAGE_TAG="${{ inputs.image_tag }}"
|
||||
FILEBEAT_MODULE_VERSION=${{ inputs.filebeat_module_version }}
|
||||
REVISION=${{ inputs.revision }}
|
||||
|
||||
if [[ "$IMAGE_TAG" == *"-"* ]]; then
|
||||
IFS='-' read -r -a tokens <<< "$IMAGE_TAG"
|
||||
if [ -z "${tokens[1]}" ]; then
|
||||
echo "Invalid image tag: $IMAGE_TAG"
|
||||
exit 1
|
||||
fi
|
||||
DEV_STAGE=${tokens[1]}
|
||||
WAZUH_VER=${tokens[0]}
|
||||
./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m -c ${{ matrix.wazuh_component }}
|
||||
else
|
||||
./build-images.sh -v $IMAGE_TAG -r $REVISION -f $FILEBEAT_MODULE_VERSION -rg $IMAGE_REGISTRY -m -c ${{ matrix.wazuh_component }}
|
||||
fi
|
||||
|
||||
# Save .env file (generated by build-images.sh) contents to $GITHUB_ENV
|
||||
ENV_FILE_PATH="../.env"
|
||||
|
||||
if [ -f $ENV_FILE_PATH ]; then
|
||||
while IFS= read -r line || [ -n "$line" ]; do
|
||||
echo "$line" >> $GITHUB_ENV
|
||||
done < $ENV_FILE_PATH
|
||||
else
|
||||
echo "The environment file $ENV_FILE_PATH does not exist!"
|
||||
exit 1
|
||||
fi
|
||||
working-directory: ./build-docker-images
|
||||
|
||||
|
||||
notify:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
needs: [setup, build-and-push]
|
||||
# Only run if NOT dev AND all products were selected
|
||||
if: ${{ inputs.dev == false && needs.setup.outputs.ALL_PRODUCTS_SELECTED == 'true' }}
|
||||
|
||||
steps:
|
||||
- name: Image exists validation
|
||||
id: validation
|
||||
run: |
|
||||
IMAGE_TAG=${{ inputs.image_tag }}
|
||||
IMAGE_REGISTRY="${{ vars.IMAGE_REGISTRY_PROD }}"
|
||||
PURPOSE=""
|
||||
|
||||
if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||
if docker manifest inspect $IMAGE_REGISTRY/wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then
|
||||
PURPOSE="regeneration"
|
||||
echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'"
|
||||
else
|
||||
PURPOSE="new release"
|
||||
echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'"
|
||||
fi
|
||||
echo "✅ Release tag: '$IMAGE_TAG'"
|
||||
elif [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+-(alpha|beta|rc)[0-9]+$ ]]; then
|
||||
PURPOSE="new stage"
|
||||
echo "✅ Stage tag: '$IMAGE_TAG'. Setting PURPOSE to 'new stage'"
|
||||
else
|
||||
echo "❌ No release or stage tag ('$IMAGE_TAG'), the GH issue will not be created"
|
||||
fi
|
||||
|
||||
echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: GH issue notification
|
||||
if: ${{ steps.validation.outputs.purpose != '' }}
|
||||
env:
|
||||
GH_TOKEN: ${{ secrets.NOTIFICATION_GH_ARTIFACT_TOKEN }}
|
||||
run: |
|
||||
IMAGE_TAG=${{ inputs.image_tag }}
|
||||
PURPOSE="${{ steps.validation.outputs.purpose }}"
|
||||
|
||||
GH_TITLE=""
|
||||
GH_MESSAGE=""
|
||||
|
||||
## Setting GH issue title
|
||||
GH_TITLE="Artifactory vulnerabilities update \`v$IMAGE_TAG\`"
|
||||
|
||||
## Setting GH issue body
|
||||
GH_MESSAGE=$(cat <<- EOF | tr -d '\r' | sed 's/^[[:space:]]*//'
|
||||
### Description
|
||||
- [ ] Update the [Artifactory vulnerabilities](${{ secrets.NOTIFICATION_SHEET_URL }}) sheet with the \`v$IMAGE_TAG\` vulnerabilities.
|
||||
|
||||
**Purpose**: $PURPOSE
|
||||
>[!NOTE]
|
||||
>To update the \`Tentative Release\` column, follow these steps:
|
||||
https://github.com/wazuh/${{ secrets.NOTIFICATION_REPO }}/issues/2049#issuecomment-2671590268
|
||||
EOF
|
||||
)
|
||||
|
||||
# Print the GH Variables content
|
||||
echo "--- Variable Content ---"
|
||||
echo "$GH_TITLE"
|
||||
echo "------------------------"
|
||||
|
||||
echo "--- Variable Content ---"
|
||||
echo "$GH_MESSAGE"
|
||||
echo "------------------------"
|
||||
|
||||
## GH issue creation
|
||||
ISSUE_URL=$(gh issue create \
|
||||
-R wazuh/${{ secrets.NOTIFICATION_REPO }} \
|
||||
--title "$GH_TITLE" \
|
||||
--body "$GH_MESSAGE" \
|
||||
--label "level/task" \
|
||||
--label "type/maintenance" \
|
||||
--label "request/operational")
|
||||
|
||||
## Adding the issue to the team project
|
||||
PROJECT_ITEM_ID=$(gh project item-add \
|
||||
${{ secrets.NOTIFICATION_PROJECT_NUMBER }} \
|
||||
--url $ISSUE_URL \
|
||||
--owner wazuh \
|
||||
--format json \
|
||||
| jq -r '.id')
|
||||
|
||||
## Setting Objective
|
||||
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_OBJECTIVE_ID }} --text "Security scans"
|
||||
## Setting Priority
|
||||
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_OPTION_ID }}
|
||||
## Setting Size
|
||||
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_OPTION_ID }}
|
||||
## Setting Subteam
|
||||
gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_OPTION_ID }}
|
||||
@@ -1,4 +1,4 @@
|
||||
name: Repository bumper 4.x
|
||||
name: (4.x) Repository bumper
|
||||
run-name: Bump ${{ github.ref_name }} (${{ inputs.id }})
|
||||
|
||||
on:
|
||||
@@ -31,7 +31,7 @@ on:
|
||||
jobs:
|
||||
bump:
|
||||
name: Repository bumper 4.x
|
||||
runs-on: ubuntu-24.04
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
permissions:
|
||||
contents: write
|
||||
pull-requests: write
|
||||
@@ -110,13 +110,21 @@ jobs:
|
||||
bash ${{ env.BUMP_SCRIPT_PATH }} ${{ steps.vars.outputs.script_params }}
|
||||
|
||||
- name: Commit and push changes
|
||||
id: bump_commit
|
||||
run: |
|
||||
git add .
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
git push origin ${{ steps.vars.outputs.branch_name }}
|
||||
if git diff --staged --quiet; then
|
||||
echo "Nothing to bump: the repository is already at the requested version/stage. Skipping commit."
|
||||
echo "has_changes=false" >> $GITHUB_OUTPUT
|
||||
else
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
git push origin ${{ steps.vars.outputs.branch_name }}
|
||||
echo "has_changes=true" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Create pull request
|
||||
id: create_pr
|
||||
if: steps.bump_commit.outputs.has_changes == 'true'
|
||||
run: |
|
||||
gh auth setup-git
|
||||
PR_URL=$(gh pr create \
|
||||
@@ -129,14 +137,19 @@ jobs:
|
||||
echo "pull_request_url=${PR_URL}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Merge pull request
|
||||
if: steps.bump_commit.outputs.has_changes == 'true'
|
||||
run: |
|
||||
# Any checks for the PR are bypassed since the branch is expected to be functional (i.e. the bump process does not introduce any bugs)
|
||||
gh pr merge "${{ steps.create_pr.outputs.pull_request_url }}" --merge --admin
|
||||
|
||||
- name: Show logs
|
||||
run: |
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
if [[ "${{ steps.bump_commit.outputs.has_changes }}" == "true" ]]; then
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
else
|
||||
echo "Bump skipped: the repository is already at the requested version/stage."
|
||||
fi
|
||||
echo "Bumper scripts logs:"
|
||||
cat ${BUMP_LOG_PATH}/repository_bumper*log
|
||||
@@ -0,0 +1,355 @@
|
||||
name: (4.x) Docker PR check
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize, reopened, ready_for_review]
|
||||
branches:
|
||||
- 4.*
|
||||
paths:
|
||||
- 'build-docker-images/**'
|
||||
- 'multi-node/**'
|
||||
- 'single-node/**'
|
||||
- 'wazuh-agent/**'
|
||||
- '.github/**'
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
ARTIFACTS_LOCAL_DIR: /home/runner/work/wazuh-docker/wazuh-docker/docker-images
|
||||
ARTIFACT_NAMES: |
|
||||
wazuh-manager.tar
|
||||
wazuh-indexer.tar
|
||||
wazuh-dashboard.tar
|
||||
wazuh-agent.tar
|
||||
|
||||
jobs:
|
||||
build-docker-images:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
steps:
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v6
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||
|
||||
- name: Build Wazuh images
|
||||
run: ./build-images.sh
|
||||
working-directory: ./build-docker-images
|
||||
|
||||
- name: Create enviroment variables
|
||||
run: cat .env > $GITHUB_ENV
|
||||
|
||||
- name: Create backup Docker images
|
||||
run: |
|
||||
mkdir -p /home/runner/work/wazuh-docker/wazuh-docker/docker-images/
|
||||
docker save wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-manager.tar
|
||||
docker save wazuh/wazuh-indexer:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-indexer.tar
|
||||
docker save wazuh/wazuh-dashboard:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar
|
||||
docker save wazuh/wazuh-agent:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-agent.tar
|
||||
|
||||
- name: Temporarily save Wazuh Docker images
|
||||
env:
|
||||
S3_ARTIFACTS_PATH: ${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/4_pr_check/${{ github.run_id }}
|
||||
run: |
|
||||
echo "Uploading Docker image artifacts to S3..."
|
||||
while IFS= read -r artifact; do
|
||||
[ -z "$artifact" ] && continue
|
||||
echo " Uploading: $artifact"
|
||||
aws s3 cp "${ARTIFACTS_LOCAL_DIR}/${artifact}" "${S3_ARTIFACTS_PATH}/${artifact}"
|
||||
done <<< "$ARTIFACT_NAMES"
|
||||
echo "All artifacts uploaded successfully."
|
||||
|
||||
check-single-node:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
needs: build-docker-images
|
||||
steps:
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v6
|
||||
|
||||
- name: Create enviroment variables
|
||||
run: cat .env > $GITHUB_ENV
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||
|
||||
- name: Retrieve saved Wazuh Docker images and load them into Docker
|
||||
env:
|
||||
S3_ARTIFACTS_PATH: s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/4_pr_check/${{ github.run_id }}
|
||||
ARTIFACTS_LOCAL_DIR: /home/runner/work/wazuh-docker/wazuh-docker/docker-images
|
||||
run: |
|
||||
mkdir -p "${ARTIFACTS_LOCAL_DIR}"
|
||||
echo "Downloading and loading Docker image artifacts from S3..."
|
||||
while IFS= read -r artifact; do
|
||||
[ -z "$artifact" ] && continue
|
||||
echo " Downloading: $artifact"
|
||||
aws s3 cp "${S3_ARTIFACTS_PATH}/${artifact}" "${ARTIFACTS_LOCAL_DIR}/${artifact}"
|
||||
echo " Loading into Docker: $artifact"
|
||||
docker load -i "${ARTIFACTS_LOCAL_DIR}/${artifact}"
|
||||
done <<< "$ARTIFACT_NAMES"
|
||||
echo "All artifacts downloaded and loaded successfully."
|
||||
|
||||
- name: Create single node certficates
|
||||
run: docker compose -f single-node/generate-indexer-certs.yml run --rm generator
|
||||
|
||||
- name: Start single node stack
|
||||
run: docker compose -f single-node/docker-compose.yml up -d
|
||||
|
||||
- name: Check Wazuh indexer start
|
||||
run: |
|
||||
sleep 60
|
||||
status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`"
|
||||
if [[ $status_green -eq 1 ]]; then
|
||||
curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s
|
||||
else
|
||||
curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s
|
||||
exit 1
|
||||
fi
|
||||
status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`"
|
||||
status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep "green" | wc -l`"
|
||||
if [[ $status_index_green -eq $status_index ]]; then
|
||||
curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s
|
||||
else
|
||||
curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s
|
||||
exit 1
|
||||
fi
|
||||
|
||||
|
||||
- name: Check Wazuh indexer nodes
|
||||
run: |
|
||||
nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`"
|
||||
if [[ $nodes -eq 1 ]]; then
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
else
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh templates
|
||||
run: |
|
||||
qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics" | wc -l`"
|
||||
templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics"`"
|
||||
if [[ $qty_templates -gt 3 ]]; then
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
else
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh manager start
|
||||
run: |
|
||||
services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`"
|
||||
if [[ $services -gt 9 ]]; then
|
||||
echo "Wazuh Manager Services: ${services}"
|
||||
echo "OK"
|
||||
else
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
curl -k -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items
|
||||
exit 1
|
||||
fi
|
||||
env:
|
||||
TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true")
|
||||
|
||||
- name: Check filebeat output
|
||||
run: ./.github/single-node-filebeat-check.sh
|
||||
|
||||
- name: Check Wazuh dashboard service URL
|
||||
run: |
|
||||
status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I -s | grep -E "^HTTP" | awk '{print $2}')
|
||||
if [[ $status -eq 200 ]]; then
|
||||
echo "Wazuh dashboard status: ${status}"
|
||||
else
|
||||
echo "Wazuh dashboard status: ${status}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Modify Docker endpoint into Wazuh agent docker-compose.yml file
|
||||
run: sed -i "s/<WAZUH_MANAGER_IP>/$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml
|
||||
|
||||
- name: Start Wazuh agent
|
||||
run: docker compose -f wazuh-agent/docker-compose.yml up -d
|
||||
|
||||
- name: Check Wazuh agent enrollment
|
||||
run: |
|
||||
sleep 20
|
||||
curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}"
|
||||
env:
|
||||
TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true")
|
||||
|
||||
- name: Check documents into wazuh-alerts index
|
||||
run: |
|
||||
sleep 120
|
||||
docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`"
|
||||
if [[ $docs -gt 0 ]]; then
|
||||
echo "wazuh-alerts index documents: ${docs}"
|
||||
else
|
||||
echo "wazuh-alerts index documents: ${docs}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check errors in ossec.log for Wazuh manager
|
||||
run: ./.github/single-node-log-check.sh
|
||||
|
||||
check-multi-node:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
needs: build-docker-images
|
||||
steps:
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v6
|
||||
|
||||
- name: Create enviroment variables
|
||||
run: cat .env > $GITHUB_ENV
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||
|
||||
- name: Retrieve saved Wazuh Docker images and load them into Docker
|
||||
env:
|
||||
S3_ARTIFACTS_PATH: s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/4_pr_check/${{ github.run_id }}
|
||||
ARTIFACTS_LOCAL_DIR: /home/runner/work/wazuh-docker/wazuh-docker/docker-images
|
||||
run: |
|
||||
mkdir -p "${ARTIFACTS_LOCAL_DIR}"
|
||||
echo "Downloading and loading Docker image artifacts from S3..."
|
||||
while IFS= read -r artifact; do
|
||||
[ -z "$artifact" ] && continue
|
||||
echo " Downloading: $artifact"
|
||||
aws s3 cp "${S3_ARTIFACTS_PATH}/${artifact}" "${ARTIFACTS_LOCAL_DIR}/${artifact}"
|
||||
echo " Loading into Docker: $artifact"
|
||||
docker load -i "${ARTIFACTS_LOCAL_DIR}/${artifact}"
|
||||
done <<< "$ARTIFACT_NAMES"
|
||||
echo "All artifacts downloaded and loaded successfully."
|
||||
|
||||
- name: Create multi node certficates
|
||||
run: docker compose -f multi-node/generate-indexer-certs.yml run --rm generator
|
||||
|
||||
- name: Start multi node stack
|
||||
run: docker compose -f multi-node/docker-compose.yml up -d
|
||||
|
||||
- name: Check Wazuh indexer start
|
||||
run: |
|
||||
until [[ `curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l` -eq 1 ]]
|
||||
do
|
||||
echo 'Waiting for Wazuh indexer start'
|
||||
free -m
|
||||
df -h
|
||||
sleep 120
|
||||
done
|
||||
status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`"
|
||||
if [[ $status_green -eq 1 ]]; then
|
||||
curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s
|
||||
else
|
||||
curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s
|
||||
exit 1
|
||||
fi
|
||||
status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`"
|
||||
status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep -E "green" | wc -l`"
|
||||
if [[ $status_index_green -eq $status_index ]]; then
|
||||
curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s
|
||||
else
|
||||
curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh indexer nodes
|
||||
run: |
|
||||
nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`"
|
||||
if [[ $nodes -eq 3 ]]; then
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
else
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh templates
|
||||
run: |
|
||||
qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh" | wc -l`"
|
||||
templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh"`"
|
||||
if [[ $qty_templates -gt 3 ]]; then
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
else
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh manager start
|
||||
run: |
|
||||
services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`"
|
||||
if [[ $services -gt 10 ]]; then
|
||||
echo "Wazuh Manager Services: ${services}"
|
||||
echo "OK"
|
||||
else
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items
|
||||
exit 1
|
||||
fi
|
||||
nodes=$(curl -k -s -X GET "https://0.0.0.0:55000/cluster/nodes" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r ".data.affected_items[].name" | wc -l)
|
||||
if [[ $nodes -eq 2 ]]; then
|
||||
echo "Wazuh manager nodes: ${nodes}"
|
||||
else
|
||||
echo "Wazuh manager nodes: ${nodes}"
|
||||
exit 1
|
||||
fi
|
||||
env:
|
||||
TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true")
|
||||
|
||||
- name: Check filebeat output
|
||||
run: ./.github/multi-node-filebeat-check.sh
|
||||
|
||||
- name: Check Wazuh dashboard service URL
|
||||
run: |
|
||||
status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I | grep -E "^HTTP" | awk '{print $2}')
|
||||
if [[ $status -eq 200 ]]; then
|
||||
echo "Wazuh dashboard status: ${status}"
|
||||
else
|
||||
echo "Wazuh dashboard status: ${status}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Modify Docker endpoint into Wazuh agent docker-compose.yml file
|
||||
run: sed -i "s/<WAZUH_MANAGER_IP>/$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml
|
||||
|
||||
- name: Start Wazuh agent
|
||||
run: docker compose -f wazuh-agent/docker-compose.yml up -d
|
||||
|
||||
- name: Check Wazuh agent enrollment
|
||||
run: |
|
||||
sleep 20
|
||||
curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}"
|
||||
env:
|
||||
TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true")
|
||||
|
||||
- name: Check documents into wazuh-alerts index
|
||||
run: |
|
||||
until [[ $(``curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"``) -gt 0 ]]
|
||||
do
|
||||
echo 'Waiting for Wazuh indexer events'
|
||||
free -m
|
||||
df -h
|
||||
sleep 10
|
||||
done
|
||||
docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`"
|
||||
if [[ $docs -gt 0 ]]; then
|
||||
echo "wazuh-alerts index documents: ${docs}"
|
||||
else
|
||||
echo "wazuh-alerts index documents: ${docs}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check errors in ossec.log for Wazuh manager
|
||||
run: ./.github/multi-node-log-check.sh
|
||||
+70
-58
@@ -1,12 +1,12 @@
|
||||
run-name: Launch Push Docker Images - ${{ inputs.id }}
|
||||
name: Push Docker Images
|
||||
run-name: Build and push images 5.x - ${{ inputs.dev && 'dev' || 'release' }} - ${{ inputs.id }}
|
||||
name: (5.x) Build and push images
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: 'v5.0.0-beta2'
|
||||
default: '5.1.0'
|
||||
required: true
|
||||
docker_reference:
|
||||
description: 'wazuh-docker reference'
|
||||
@@ -14,7 +14,7 @@ on:
|
||||
wazuh_automation_reference:
|
||||
description: 'Branch or tag of the wazuh-automation repository'
|
||||
required: false
|
||||
default: 'v5.0.0-beta2'
|
||||
default: 'main'
|
||||
products:
|
||||
description: 'Comma-separated list of the image names to build and push'
|
||||
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
|
||||
@@ -42,7 +42,7 @@ on:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: 'v5.0.0-beta2'
|
||||
default: '5.1.0'
|
||||
required: true
|
||||
type: string
|
||||
docker_reference:
|
||||
@@ -52,7 +52,7 @@ on:
|
||||
wazuh_automation_reference:
|
||||
description: 'Branch or tag of the wazuh-automation repository'
|
||||
required: false
|
||||
default: 'v5.0.0-beta2'
|
||||
default: 'main'
|
||||
type: string
|
||||
products:
|
||||
description: 'Comma-separated list of the image names to build and push'
|
||||
@@ -81,11 +81,12 @@ on:
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
env:
|
||||
LOCAL_ARTIFACT_URLS_FILEPATH: /tmp/${{ vars.ARTIFACT_URL_FILE_NAME }}
|
||||
|
||||
jobs:
|
||||
setup:
|
||||
runs-on:
|
||||
group: wz-linux-amd64
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
|
||||
outputs:
|
||||
WAZUH_COMPONENTS: ${{ steps.compute-outputs.outputs.WAZUH_COMPONENTS }}
|
||||
@@ -96,7 +97,7 @@ jobs:
|
||||
- name: Print inputs
|
||||
run: |
|
||||
echo "---------------------------------------------"
|
||||
echo "Running Procedure_push_docker_images workflow"
|
||||
echo "Running 5_build_and_push_images workflow"
|
||||
echo "---------------------------------------------"
|
||||
echo "* BRANCH: ${{ github.ref }}"
|
||||
echo "* COMMIT: ${{ github.sha }}"
|
||||
@@ -115,9 +116,13 @@ jobs:
|
||||
|
||||
- name: Set up variables
|
||||
id: compute-outputs
|
||||
env:
|
||||
PRODUCTS_INPUT: ${{ inputs.products }}
|
||||
DEV_INPUT: ${{ inputs.dev }}
|
||||
COMMIT_LIST_INPUT: ${{ inputs.commit_list }}
|
||||
run: |
|
||||
# Use the default list if products is empty
|
||||
PRODUCTS="${{ inputs.products }}"
|
||||
PRODUCTS="$PRODUCTS_INPUT"
|
||||
if [[ -z "$PRODUCTS" || "$PRODUCTS" == "null" ]]; then
|
||||
PRODUCTS="wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent"
|
||||
fi
|
||||
@@ -135,9 +140,9 @@ jobs:
|
||||
|
||||
# Set COMMIT_LIST
|
||||
WC_COMMIT_LIST=""
|
||||
if [[ "${{ inputs.dev }}" == "true" ]]; then
|
||||
if [[ "${{ inputs.commit_list }}" != "null" && "${{ inputs.commit_list }}" != "" ]]; then
|
||||
WC_COMMIT_LIST='${{ inputs.commit_list }}'
|
||||
if [[ "$DEV_INPUT" == "true" ]]; then
|
||||
if [[ "$COMMIT_LIST_INPUT" != "null" && "$COMMIT_LIST_INPUT" != "" ]]; then
|
||||
WC_COMMIT_LIST="$COMMIT_LIST_INPUT"
|
||||
else
|
||||
# Set commit list to "latest" for all components using WAZUH_COMPONENTS
|
||||
COMPONENTS=($(echo "$WC_JSON_ARRAY" | jq -r '.[]'))
|
||||
@@ -156,15 +161,13 @@ jobs:
|
||||
|
||||
package-urls:
|
||||
name: generate package urls
|
||||
runs-on:
|
||||
group: wz-linux-amd64
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
needs: setup
|
||||
|
||||
env:
|
||||
WORKFLOW_VENV: "${{ github.workspace }}/workflow_venv"
|
||||
GENERATE_PRESIGNED_URLS_SCRIPT_PATH: ${{ github.workspace }}/wazuh-automation/tools/sign_urls/generate_presigned_dev_urls.py
|
||||
PRESIGNED_URLS_SCRIPT_PROCESS: "build_docker"
|
||||
LOCAL_ARTIFACT_URLS_FILEPATH: /tmp/${{ vars.ARTIFACT_URL_FILE_NAME }}
|
||||
COMMIT_LIST: ${{ inputs.commit_list }}
|
||||
ASSISTANT_REVISION: ${{ inputs.assistant_revision }}
|
||||
|
||||
@@ -174,6 +177,7 @@ jobs:
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ inputs.docker_reference }}
|
||||
persist-credentials: false
|
||||
|
||||
- name: Checkout wazuh/wazuh-automation repository
|
||||
if: ${{ inputs.dev == true }}
|
||||
@@ -183,6 +187,7 @@ jobs:
|
||||
ref: ${{ inputs.wazuh_automation_reference }}
|
||||
token: ${{ secrets.GH_CLONE_TOKEN }}
|
||||
path: wazuh-automation
|
||||
persist-credentials: false
|
||||
|
||||
- name: Configure AWS credentials
|
||||
if: ${{ inputs.dev == true }}
|
||||
@@ -215,11 +220,15 @@ jobs:
|
||||
if: ${{ inputs.dev == true }}
|
||||
run: |
|
||||
WAZUH_VERSION=$(jq -r '.version' VERSION.json)
|
||||
if ! [[ "$WAZUH_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||
echo "Invalid version format: $WAZUH_VERSION"
|
||||
exit 1
|
||||
fi
|
||||
WAZUH_MAJOR=$(echo "$WAZUH_VERSION" | cut -d '.' -f 1)
|
||||
WAZUH_MINOR=$(echo "$WAZUH_VERSION" | cut -d '.' -f 1-2)
|
||||
echo WAZUH_VERSION=$WAZUH_VERSION >> $GITHUB_ENV
|
||||
echo WAZUH_MAJOR=$WAZUH_MAJOR >> $GITHUB_ENV
|
||||
echo WAZUH_MINOR=$WAZUH_MINOR >> $GITHUB_ENV
|
||||
echo "WAZUH_VERSION=$WAZUH_VERSION" >> $GITHUB_ENV
|
||||
echo "WAZUH_MAJOR=$WAZUH_MAJOR" >> $GITHUB_ENV
|
||||
echo "WAZUH_MINOR=$WAZUH_MINOR" >> $GITHUB_ENV
|
||||
|
||||
- name: Get artifacts URLs file
|
||||
if: ${{ inputs.dev == true }}
|
||||
@@ -229,13 +238,14 @@ jobs:
|
||||
|
||||
- name: Generate presigned URLs for artifacts for dev packages
|
||||
if: ${{ inputs.dev == true }}
|
||||
env:
|
||||
WAZUH_COMPONENTS: ${{ needs.setup.outputs.WAZUH_COMPONENTS }}
|
||||
COMMIT_LIST: ${{ needs.setup.outputs.COMMIT_LIST }}
|
||||
run: |
|
||||
source ${{ env.WORKFLOW_VENV }}/bin/activate
|
||||
WAZUH_COMPONENTS='${{ needs.setup.outputs.WAZUH_COMPONENTS }}'
|
||||
COMMIT_LIST='${{ needs.setup.outputs.COMMIT_LIST }}'
|
||||
SCRIPT_PARAMS="--process ${{ env.PRESIGNED_URLS_SCRIPT_PROCESS }} \
|
||||
--wazuh-version ${{ env.WAZUH_VERSION }} \
|
||||
--aws-s3-bucket-dev ${{ env.LOCAL_AWS_S3_BUCKET_DEV }} \
|
||||
source "$WORKFLOW_VENV/bin/activate"
|
||||
SCRIPT_PARAMS="--process $PRESIGNED_URLS_SCRIPT_PROCESS \
|
||||
--wazuh-version $WAZUH_VERSION \
|
||||
--aws-s3-bucket-dev $LOCAL_AWS_S3_BUCKET_DEV \
|
||||
--assistant-revision $ASSISTANT_REVISION "
|
||||
|
||||
|
||||
@@ -270,19 +280,17 @@ jobs:
|
||||
esac
|
||||
done
|
||||
|
||||
python ${{ env.GENERATE_PRESIGNED_URLS_SCRIPT_PATH }} \
|
||||
python "$GENERATE_PRESIGNED_URLS_SCRIPT_PATH" \
|
||||
$SCRIPT_PARAMS
|
||||
|
||||
- name: Save presigned URLs file to artifact
|
||||
if: ${{ inputs.dev == true }}
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: presigned-artifact-urls-${{ github.run_id }}
|
||||
path: ${{ env.LOCAL_ARTIFACT_URLS_FILEPATH }}
|
||||
run: |
|
||||
echo "Uploading presigned URLs artifact..."
|
||||
aws s3 cp "${{ env.LOCAL_ARTIFACT_URLS_FILEPATH }}" "s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/5_build_and_push_images/${{ github.run_id }}/${{ vars.ARTIFACT_URL_FILE_NAME }}"
|
||||
|
||||
build-and-push:
|
||||
runs-on:
|
||||
group: wz-linux-amd64
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
|
||||
needs:
|
||||
- setup
|
||||
@@ -302,6 +310,13 @@ jobs:
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: ${{ inputs.docker_reference }}
|
||||
persist-credentials: false
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v4
|
||||
@@ -320,27 +335,20 @@ jobs:
|
||||
if: ${{ inputs.dev == true }}
|
||||
uses: aws-actions/amazon-ecr-login@v2
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
if: ${{ inputs.dev == false }}
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||
|
||||
- name: Download artifact_urls.yaml (dev)
|
||||
if: ${{ inputs.dev == true }}
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: presigned-artifact-urls-${{ github.run_id }}
|
||||
path: ./build-docker-images
|
||||
run: |
|
||||
echo "Downloading presigned URLs artifact..."
|
||||
aws s3 cp "s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/5_build_and_push_images/${{ github.run_id }}/${{ vars.ARTIFACT_URL_FILE_NAME }}" "${{ env.LOCAL_ARTIFACT_URLS_FILEPATH }}"
|
||||
mv "${{ env.LOCAL_ARTIFACT_URLS_FILEPATH }}" ./build-docker-images/${{ vars.ARTIFACT_URL_FILE_NAME }}
|
||||
|
||||
- name: Compute component reference (dev)
|
||||
if: ${{ inputs.dev == true }}
|
||||
env:
|
||||
COMPONENT: ${{ matrix.wazuh_component }}
|
||||
WAZUH_COMPONENTS: ${{ needs.setup.outputs.WAZUH_COMPONENTS }}
|
||||
COMMIT_LIST: ${{ needs.setup.outputs.COMMIT_LIST }}
|
||||
run: |
|
||||
COMPONENT='${{ matrix.wazuh_component }}'
|
||||
WAZUH_COMPONENTS='${{ needs.setup.outputs.WAZUH_COMPONENTS }}'
|
||||
COMMIT_LIST='${{ needs.setup.outputs.COMMIT_LIST }}'
|
||||
|
||||
idx=$(jq -r --arg c "$COMPONENT" 'index($c)' <<<"$WAZUH_COMPONENTS")
|
||||
ref=$(jq -r --argjson i "$idx" '.[ $i ]' <<<"$COMMIT_LIST")
|
||||
|
||||
@@ -348,6 +356,9 @@ jobs:
|
||||
echo "Using component ref for $COMPONENT: $ref"
|
||||
|
||||
- name: Build Wazuh images
|
||||
env:
|
||||
DEV: ${{ inputs.dev }}
|
||||
WAZUH_COMPONENT: ${{ matrix.wazuh_component }}
|
||||
run: |
|
||||
if [[ "$IMAGE_TAG" == *"-"* ]]; then
|
||||
IFS='-' read -r -a tokens <<< "$IMAGE_TAG"
|
||||
@@ -357,7 +368,7 @@ jobs:
|
||||
fi
|
||||
DEV_STAGE=${tokens[1]}
|
||||
WAZUH_VER=${tokens[0]}
|
||||
if [ "${{ inputs.dev }}" = true ]; then
|
||||
if [ "$DEV" = true ]; then
|
||||
./build-images.sh \
|
||||
-v $WAZUH_VER \
|
||||
-d $DEV_STAGE \
|
||||
@@ -365,30 +376,30 @@ jobs:
|
||||
-m \
|
||||
--dev \
|
||||
-refs "$COMPONENT_REFS_JSON" \
|
||||
-c ${{ matrix.wazuh_component }}
|
||||
-c $WAZUH_COMPONENT
|
||||
else
|
||||
./build-images.sh \
|
||||
-v $WAZUH_VER \
|
||||
-d $DEV_STAGE \
|
||||
-rg $IMAGE_REGISTRY \
|
||||
-m \
|
||||
-c ${{ matrix.wazuh_component }}
|
||||
-c $WAZUH_COMPONENT
|
||||
fi
|
||||
else
|
||||
if [ "${{ inputs.dev }}" = true ]; then
|
||||
if [ "$DEV" = true ]; then
|
||||
./build-images.sh \
|
||||
-v $IMAGE_TAG \
|
||||
-rg $IMAGE_REGISTRY \
|
||||
-m \
|
||||
--dev \
|
||||
-refs "$COMPONENT_REFS_JSON" \
|
||||
-c ${{ matrix.wazuh_component }}
|
||||
-c $WAZUH_COMPONENT
|
||||
else
|
||||
./build-images.sh \
|
||||
-v $IMAGE_TAG \
|
||||
-rg $IMAGE_REGISTRY \
|
||||
-m \
|
||||
-c ${{ matrix.wazuh_component }}
|
||||
-c $WAZUH_COMPONENT
|
||||
fi
|
||||
fi
|
||||
# Save .env file (generated by build-images.sh) contents to $GITHUB_ENV
|
||||
@@ -406,7 +417,7 @@ jobs:
|
||||
|
||||
|
||||
notify:
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
needs: [setup, build-and-push]
|
||||
# Only run if NOT dev AND all products were selected
|
||||
if: ${{ inputs.dev == false && needs.setup.outputs.ALL_PRODUCTS_SELECTED == 'true' }}
|
||||
@@ -414,9 +425,10 @@ jobs:
|
||||
steps:
|
||||
- name: Image exists validation
|
||||
id: validation
|
||||
env:
|
||||
IMAGE_TAG: ${{ inputs.image_tag }}
|
||||
IMAGE_REGISTRY: ${{ vars.IMAGE_REGISTRY_PROD }}
|
||||
run: |
|
||||
IMAGE_TAG=${{ inputs.image_tag }}
|
||||
IMAGE_REGISTRY="${{ vars.IMAGE_REGISTRY_PROD }}"
|
||||
PURPOSE=""
|
||||
|
||||
if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||
@@ -441,9 +453,9 @@ jobs:
|
||||
if: ${{ steps.validation.outputs.purpose != '' }}
|
||||
env:
|
||||
GH_TOKEN: ${{ secrets.NOTIFICATION_GH_ARTIFACT_TOKEN }}
|
||||
IMAGE_TAG: ${{ inputs.image_tag }}
|
||||
PURPOSE: ${{ steps.validation.outputs.purpose }}
|
||||
run: |
|
||||
IMAGE_TAG=${{ inputs.image_tag }}
|
||||
PURPOSE="${{ steps.validation.outputs.purpose }}"
|
||||
|
||||
GH_TITLE=""
|
||||
GH_MESSAGE=""
|
||||
@@ -1,4 +1,4 @@
|
||||
name: Repository bumper 5.x
|
||||
name: (5.x) Repository bumper
|
||||
run-name: Bump ${{ github.ref_name }} (${{ inputs.id }})
|
||||
|
||||
on:
|
||||
@@ -37,10 +37,15 @@ on:
|
||||
default: false
|
||||
required: false
|
||||
type: boolean
|
||||
bump-issue-link:
|
||||
description: 'Issue link used in the original bump (required for revert if different from issue-link)'
|
||||
required: false
|
||||
type: string
|
||||
|
||||
jobs:
|
||||
bump:
|
||||
name: Repository bumper 5.x
|
||||
runs-on: ubuntu-24.04
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
permissions:
|
||||
contents: write
|
||||
pull-requests: write
|
||||
@@ -96,18 +101,24 @@ jobs:
|
||||
version=${{ env.VERSION }}
|
||||
stage=${{ env.STAGE }}
|
||||
tag=${{ env.TAG }}
|
||||
|
||||
set_as_main=${{ inputs.set_as_main }}
|
||||
|
||||
if [[ "$set_as_main" == "true" ]]; then
|
||||
script_params="--set-as-main"
|
||||
if [[ -n "$version" && -n "$stage" && "$tag" != "true" ]]; then
|
||||
script_params="--version ${version} --stage ${stage}"
|
||||
elif [[ -n "$version" && -n "$stage" && "$tag" == "true" ]]; then
|
||||
script_params="--version ${version} --stage ${stage} --tag"
|
||||
elif [[ -z "$version" && -n "$stage" && "$tag" == "true" ]]; then
|
||||
script_params="--stage ${stage} --tag"
|
||||
elif [[ -z "$version" && -z "$stage" && "$tag" == "true" ]]; then
|
||||
script_params="--tag"
|
||||
fi
|
||||
|
||||
# Both version and stage provided
|
||||
if [[ -n "$version" && -n "$stage" && "$tag" != "true" ]]; then
|
||||
script_params+=" --version ${version} --stage ${stage}"
|
||||
elif [[ -n "$version" && -n "$stage" && "$tag" == "true" ]]; then
|
||||
script_params+=" --version ${version} --stage ${stage} --tag ${tag}"
|
||||
if [[ "$set_as_main" == "true" ]]; then
|
||||
if [[ -z "$version" || -z "$stage" ]]; then
|
||||
echo "Error: set_as_main requires both version and stage inputs."
|
||||
exit 1
|
||||
fi
|
||||
script_params="${script_params} --set-as-main"
|
||||
fi
|
||||
|
||||
issue_number=$(echo "${{ inputs.issue-link }}" | awk -F'/' '{print $NF}')
|
||||
@@ -133,10 +144,17 @@ jobs:
|
||||
bash ${{ env.BUMP_SCRIPT_PATH }} ${{ steps.vars.outputs.script_params }}
|
||||
|
||||
- name: Commit changes (Bump)
|
||||
id: bump_commit
|
||||
if: inputs.revert != true
|
||||
run: |
|
||||
git add .
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
if git diff --staged --quiet; then
|
||||
echo "Nothing to bump: the repository is already at the requested version/stage. Skipping commit."
|
||||
echo "has_changes=false" >> $GITHUB_OUTPUT
|
||||
else
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
echo "has_changes=true" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Fetch full history (Revert)
|
||||
if: inputs.revert == true
|
||||
@@ -146,9 +164,18 @@ jobs:
|
||||
id: revert_step
|
||||
if: inputs.revert == true
|
||||
run: |
|
||||
# 1. Get the current issue number (for the new revert branch/PR)
|
||||
ISSUE_NUMBER=$(echo "${{ inputs.issue-link }}" | awk -F'/' '{print $NF}')
|
||||
|
||||
BUMP_BRANCH="enhancement/wqa${ISSUE_NUMBER}-bump-${{ github.ref_name }}"
|
||||
# 2. Get the issue number from the original bump (if provided; otherwise, defaults to the current one)
|
||||
if [ -n "${{ inputs.bump-issue-link }}" ]; then
|
||||
BUMP_ISSUE_NUMBER=$(echo "${{ inputs.bump-issue-link }}" | awk -F'/' '{print $NF}')
|
||||
else
|
||||
BUMP_ISSUE_NUMBER=$ISSUE_NUMBER
|
||||
fi
|
||||
|
||||
# 3. Search for the original bump branch using the obtained BUMP ISSUE number
|
||||
BUMP_BRANCH="enhancement/wqa${BUMP_ISSUE_NUMBER}-bump-${{ github.ref_name }}"
|
||||
|
||||
PR_NUMBER=$(gh pr list --head "$BUMP_BRANCH" --base "${{ github.ref_name }}" --state merged --json number --jq '.[0].number')
|
||||
|
||||
@@ -167,7 +194,7 @@ jobs:
|
||||
# Remove the files to prevent them from being included in the revert commit
|
||||
git checkout HEAD -- VERSION.json 2>/dev/null || true
|
||||
git checkout HEAD -- CHANGELOG.md 2>/dev/null || true
|
||||
# Add any other repository-specific version files here
|
||||
# [!] ADD ANY OTHER REPOSITORY-SPECIFIC VERSION FILES HERE [!]
|
||||
|
||||
if git diff --staged --quiet; then
|
||||
echo "No references to revert. Skipping commit."
|
||||
@@ -178,13 +205,13 @@ jobs:
|
||||
fi
|
||||
|
||||
- name: Push changes
|
||||
if: inputs.revert != true || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
if: (inputs.revert != true && steps.bump_commit.outputs.has_changes == 'true') || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
run: |
|
||||
git push origin ${{ steps.vars.outputs.branch_name }}
|
||||
|
||||
- name: Create pull request
|
||||
id: create_pr
|
||||
if: inputs.revert != true || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
if: (inputs.revert != true && steps.bump_commit.outputs.has_changes == 'true') || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
run: |
|
||||
gh auth setup-git
|
||||
PR_URL=$(gh pr create \
|
||||
@@ -197,7 +224,7 @@ jobs:
|
||||
echo "pull_request_url=${PR_URL}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Merge pull request
|
||||
if: inputs.revert != true || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
if: (inputs.revert != true && steps.bump_commit.outputs.has_changes == 'true') || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
run: |
|
||||
# Any checks for the PR are bypassed since the branch is expected to be functional
|
||||
gh pr merge "${{ steps.create_pr.outputs.pull_request_url }}" --merge --admin
|
||||
@@ -205,9 +232,13 @@ jobs:
|
||||
- name: Show logs
|
||||
if: inputs.revert != true
|
||||
run: |
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
if [[ "${{ steps.bump_commit.outputs.has_changes }}" == "true" ]]; then
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
else
|
||||
echo "Bump skipped: the repository is already at the requested version/stage."
|
||||
fi
|
||||
echo "Bumper scripts logs:"
|
||||
cat ${BUMP_LOG_PATH}/repository_bumper*log
|
||||
|
||||
|
||||
@@ -0,0 +1,62 @@
|
||||
name: 5.x Changelog check
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize, reopened, ready_for_review, labeled, unlabeled]
|
||||
|
||||
jobs:
|
||||
changelog_check:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
if: ${{ github.event_name == 'pull_request' && !github.event.pull_request.draft && !contains(github.event.pull_request.labels.*.name, 'no-changelog') }}
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Validate CHANGELOG.md changes
|
||||
env:
|
||||
BASE_REF: ${{ github.base_ref }}
|
||||
run: |
|
||||
UPDATED="✅" FORMAT="—" INVALID=""
|
||||
|
||||
ADDED=$(git diff -U0 "origin/${BASE_REF}...HEAD" -- CHANGELOG.md | grep -E '^\+[^+]' | sed 's/^+//' || true)
|
||||
if [ -z "$ADDED" ]; then
|
||||
UPDATED="❌"
|
||||
echo "::error::CHANGELOG.md was not updated with new entries. Add one or add the 'no-changelog' label to skip this check."
|
||||
else
|
||||
FORMAT="✅"
|
||||
|
||||
ENTRY_REGEX='^- .+ \(\[#[0-9]+\]\(https://github\.com/[^)]+/(issues|pull)/[0-9]+\)\)$'
|
||||
INVALID=$(echo "$ADDED" | grep -E '^- ' | grep -vx -- '- None' | grep -vE "$ENTRY_REGEX" || true)
|
||||
if [ -n "$INVALID" ]; then
|
||||
FORMAT="❌"
|
||||
echo "::error::Invalid CHANGELOG.md entries. Expected format: '- Description ([#123](https://github.com/<org>/<repo>/issues/123))'. Offending lines:"
|
||||
echo "$INVALID"
|
||||
fi
|
||||
fi
|
||||
|
||||
{
|
||||
echo "## Changelog check"
|
||||
echo ""
|
||||
echo "| Check | Result |"
|
||||
echo "|---|---|"
|
||||
echo "| CHANGELOG.md has new entries | $UPDATED |"
|
||||
echo "| Entry format | $FORMAT |"
|
||||
if [ -n "$INVALID" ]; then
|
||||
echo ""
|
||||
echo "Offending lines:"
|
||||
echo '```'
|
||||
echo "$INVALID"
|
||||
echo '```'
|
||||
fi
|
||||
} >> "$GITHUB_STEP_SUMMARY"
|
||||
|
||||
if [ "$UPDATED" != "✅" ] || [ "$FORMAT" != "✅" ]; then
|
||||
exit 1
|
||||
fi
|
||||
echo "CHANGELOG.md update is valid."
|
||||
@@ -0,0 +1,890 @@
|
||||
run-name: >-
|
||||
${{ github.event_name == 'workflow_dispatch'
|
||||
&& format('Docker Integration Test - Manual {0} on {1}', inputs.deployment_type, inputs.pr_head_ref)
|
||||
|| format('Docker Integration Test - #{0} {1}', github.event.issue.number, github.event.issue.title) }}
|
||||
name: (5.x) PR Check - Docker Integration Tests
|
||||
|
||||
on:
|
||||
issue_comment:
|
||||
types: [created]
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
pr_head_ref:
|
||||
description: 'Branch of wazuh-docker to test'
|
||||
required: true
|
||||
type: string
|
||||
automation_reference:
|
||||
description: 'Branch of wazuh-automation to use'
|
||||
required: false
|
||||
default: 'main'
|
||||
type: string
|
||||
deployment_type:
|
||||
description: 'Deployment type to test'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- single-node
|
||||
- multi-node
|
||||
- both
|
||||
version:
|
||||
description: 'Image version to test (e.g. 5.1.0).'
|
||||
required: false
|
||||
type: string
|
||||
stage:
|
||||
description: 'Image stage suffix (e.g. beta1, beta2-latest, beta2-<commit>). Required when version is set.'
|
||||
required: false
|
||||
type: string
|
||||
registry:
|
||||
description: 'Docker registry. ECR for dev versions, DockerHub for prod versions.'
|
||||
required: false
|
||||
type: choice
|
||||
options:
|
||||
- ECR
|
||||
- DockerHub
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
pull-requests: write
|
||||
issues: write
|
||||
checks: write
|
||||
|
||||
env:
|
||||
AUTOMATION_REFERENCE: ${{ inputs.automation_reference || 'main' }}
|
||||
ALLOCATOR_PATH: /tmp/allocator_instance
|
||||
REGION: us-east-1
|
||||
LOGS_ARTIFACT_ZIP_FILE: "docker_logs_artifacts_${{ github.run_id }}.zip"
|
||||
|
||||
jobs:
|
||||
# -------------------------------------------------------------------------
|
||||
# Job 1: Parse PR info and determine which deployment(s) to test
|
||||
#
|
||||
# Available commands:
|
||||
# /test-docker-single — test single-node deployment
|
||||
# /test-docker-multi — test multi-node deployment
|
||||
# /test-docker — test both single-node and multi-node
|
||||
# -------------------------------------------------------------------------
|
||||
get_pr_info:
|
||||
if: |
|
||||
github.event_name == 'issue_comment' &&
|
||||
github.event.issue.pull_request &&
|
||||
github.event.issue.state == 'open' &&
|
||||
!github.event.issue.draft &&
|
||||
(contains(github.event.comment.body, '/test-docker-single') ||
|
||||
contains(github.event.comment.body, '/test-docker-multi') ||
|
||||
contains(github.event.comment.body, '/test-docker'))
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
outputs:
|
||||
pr_number: ${{ steps.pr_data.outputs.pr_number }}
|
||||
pr_head_ref: ${{ steps.pr_data.outputs.pr_head_ref }}
|
||||
pr_head_sha: ${{ steps.pr_data.outputs.pr_head_sha }}
|
||||
check_run_id: ${{ steps.create_check.outputs.result }}
|
||||
deployment_matrix: ${{ steps.parse_command.outputs.deployment_matrix }}
|
||||
check_name: ${{ steps.parse_command.outputs.check_name }}
|
||||
|
||||
steps:
|
||||
- name: React to comment
|
||||
uses: actions/github-script@v7
|
||||
with:
|
||||
script: |
|
||||
await github.rest.reactions.createForIssueComment({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
comment_id: context.payload.comment.id,
|
||||
content: 'rocket'
|
||||
});
|
||||
|
||||
- name: Extract PR data
|
||||
id: pr_data
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
PR_NUMBER="${{ github.event.issue.number }}"
|
||||
PR_DATA=$(gh api repos/${{ github.repository }}/pulls/${PR_NUMBER})
|
||||
PR_HEAD_REF=$(echo "$PR_DATA" | jq -r '.head.ref')
|
||||
PR_HEAD_SHA=$(echo "$PR_DATA" | jq -r '.head.sha')
|
||||
echo "pr_number=${PR_NUMBER}" >> $GITHUB_OUTPUT
|
||||
echo "pr_head_ref=${PR_HEAD_REF}" >> $GITHUB_OUTPUT
|
||||
echo "pr_head_sha=${PR_HEAD_SHA}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Parse command and set deployment metadata
|
||||
id: parse_command
|
||||
env:
|
||||
COMMENT_BODY: ${{ github.event.comment.body }}
|
||||
run: |
|
||||
if echo "$COMMENT_BODY" | grep -q '/test-docker-single'; then
|
||||
echo 'deployment_matrix=["single-node"]' >> $GITHUB_OUTPUT
|
||||
echo 'check_name=Docker Integration Check (Single-Node)' >> $GITHUB_OUTPUT
|
||||
elif echo "$COMMENT_BODY" | grep -q '/test-docker-multi'; then
|
||||
echo 'deployment_matrix=["multi-node"]' >> $GITHUB_OUTPUT
|
||||
echo 'check_name=Docker Integration Check (Multi-Node)' >> $GITHUB_OUTPUT
|
||||
elif echo "$COMMENT_BODY" | grep -q '/test-docker'; then
|
||||
echo 'deployment_matrix=["single-node","multi-node"]' >> $GITHUB_OUTPUT
|
||||
echo 'check_name=Docker Integration Check' >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Create check run
|
||||
id: create_check
|
||||
uses: actions/github-script@v7
|
||||
env:
|
||||
HEAD_SHA: ${{ steps.pr_data.outputs.pr_head_sha }}
|
||||
CHECK_NAME: ${{ steps.parse_command.outputs.check_name }}
|
||||
COMMENT_BODY: ${{ github.event.comment.body }}
|
||||
with:
|
||||
script: |
|
||||
const { data: check } = await github.rest.checks.create({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
name: process.env.CHECK_NAME,
|
||||
head_sha: process.env.HEAD_SHA,
|
||||
status: 'in_progress',
|
||||
started_at: new Date().toISOString(),
|
||||
details_url: `https://github.com/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`,
|
||||
output: {
|
||||
title: `🔨 Running ${process.env.CHECK_NAME}...`,
|
||||
summary: `Triggered by comment: \`${process.env.COMMENT_BODY}\``,
|
||||
text: 'Allocating instance and running Docker integration tests'
|
||||
}
|
||||
});
|
||||
console.log('Check run created:', check.id);
|
||||
return check.id;
|
||||
|
||||
# -------------------------------------------------------------------------
|
||||
# Job 2: Prepare context (pr_head_ref + deployment matrix) for both triggers.
|
||||
# -------------------------------------------------------------------------
|
||||
prepare:
|
||||
needs: [get_pr_info]
|
||||
if: |
|
||||
always() &&
|
||||
(needs.get_pr_info.result == 'success' || github.event_name == 'workflow_dispatch')
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
outputs:
|
||||
pr_head_ref: ${{ steps.ctx.outputs.pr_head_ref }}
|
||||
deployment_matrix: ${{ steps.ctx.outputs.deployment_matrix }}
|
||||
wazuh_version: ${{ steps.version.outputs.wazuh_version }}
|
||||
wazuh_stage: ${{ steps.version.outputs.wazuh_stage }}
|
||||
|
||||
steps:
|
||||
- name: Resolve context
|
||||
id: ctx
|
||||
run: |
|
||||
if [ "${{ github.event_name }}" = "workflow_dispatch" ]; then
|
||||
echo "pr_head_ref=${{ inputs.pr_head_ref }}" >> $GITHUB_OUTPUT
|
||||
DEPLOY_TYPE="${{ inputs.deployment_type }}"
|
||||
if [ "$DEPLOY_TYPE" = "both" ]; then
|
||||
echo 'deployment_matrix=["single-node","multi-node"]' >> $GITHUB_OUTPUT
|
||||
else
|
||||
echo "deployment_matrix=[\"${DEPLOY_TYPE}\"]" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
else
|
||||
echo 'pr_head_ref=${{ needs.get_pr_info.outputs.pr_head_ref }}' >> $GITHUB_OUTPUT
|
||||
echo 'deployment_matrix=${{ needs.get_pr_info.outputs.deployment_matrix }}' >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Checkout wazuh-docker PR branch (VERSION.json only)
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ steps.ctx.outputs.pr_head_ref }}
|
||||
sparse-checkout: |
|
||||
VERSION.json
|
||||
sparse-checkout-cone-mode: false
|
||||
|
||||
- name: Read version info from VERSION.json
|
||||
id: version
|
||||
run: |
|
||||
VERSION=$(python3 -c "import json; d=json.load(open('VERSION.json')); print(d['version'])")
|
||||
STAGE=$(python3 -c "import json; d=json.load(open('VERSION.json')); print(d.get('stage',''))")
|
||||
echo "wazuh_version=${VERSION}" >> $GITHUB_OUTPUT
|
||||
echo "wazuh_stage=${STAGE}" >> $GITHUB_OUTPUT
|
||||
echo "Version: ${VERSION} Stage: ${STAGE:-<release>}"
|
||||
|
||||
- name: Show test plan
|
||||
run: |
|
||||
WAZUH_VERSION="${{ steps.version.outputs.wazuh_version }}"
|
||||
WAZUH_STAGE="${{ steps.version.outputs.wazuh_stage }}"
|
||||
INPUT_VERSION="${{ inputs.version }}"
|
||||
INPUT_STAGE="${{ inputs.stage }}"
|
||||
INPUT_REGISTRY="${{ inputs.registry }}"
|
||||
|
||||
# Determine effective case
|
||||
if [ -z "$INPUT_VERSION" ] && [ -z "$INPUT_STAGE" ]; then
|
||||
DOCKER_VERSION="$WAZUH_VERSION"
|
||||
DOCKER_STAGE_DISPLAY="${WAZUH_STAGE}"
|
||||
if [ "$INPUT_REGISTRY" = "ECR" ] || [ "${{ github.event_name }}" = "issue_comment" ]; then
|
||||
CASE="a.1 — No version/stage → BUILD images from PR → push to ECR"
|
||||
ACTION="BUILD + push to ECR"
|
||||
EFFECTIVE_TAG="${DOCKER_VERSION}${DOCKER_STAGE_DISPLAY:+-${DOCKER_STAGE_DISPLAY}}-latest"
|
||||
EFFECTIVE_REGISTRY="ECR (${{ vars.IMAGE_REGISTRY_DEV }})"
|
||||
else
|
||||
CASE="a.2 — No version/stage → PULL from DockerHub"
|
||||
ACTION="PULL (no build)"
|
||||
EFFECTIVE_TAG="${DOCKER_VERSION}${DOCKER_STAGE_DISPLAY:+-${DOCKER_STAGE_DISPLAY}}"
|
||||
EFFECTIVE_REGISTRY="DockerHub (${{ vars.IMAGE_REGISTRY_PROD }})"
|
||||
fi
|
||||
elif [ -n "$INPUT_VERSION" ] && [ -z "$INPUT_STAGE" ]; then
|
||||
DOCKER_VERSION="$INPUT_VERSION"
|
||||
ACTION="PULL (no build)"
|
||||
if [ "$INPUT_REGISTRY" = "ECR" ]; then
|
||||
CASE="b.1 — Version only, ECR → tag = version-latest"
|
||||
EFFECTIVE_TAG="${DOCKER_VERSION}-latest"
|
||||
EFFECTIVE_REGISTRY="ECR (${{ vars.IMAGE_REGISTRY_DEV }})"
|
||||
else
|
||||
CASE="b.2 — Version only, DockerHub → tag = version"
|
||||
EFFECTIVE_TAG="${DOCKER_VERSION}"
|
||||
EFFECTIVE_REGISTRY="DockerHub (${{ vars.IMAGE_REGISTRY_PROD }})"
|
||||
fi
|
||||
else
|
||||
CASE="c — Version + stage provided as-is (no -latest appended)"
|
||||
ACTION="PULL (no build)"
|
||||
DOCKER_VERSION="${INPUT_VERSION:-${WAZUH_VERSION}}"
|
||||
EFFECTIVE_TAG="${DOCKER_VERSION}-${INPUT_STAGE}"
|
||||
if [ "$INPUT_REGISTRY" = "ECR" ]; then
|
||||
EFFECTIVE_REGISTRY="ECR (${{ vars.IMAGE_REGISTRY_DEV }})"
|
||||
else
|
||||
EFFECTIVE_REGISTRY="DockerHub (${{ vars.IMAGE_REGISTRY_PROD }})"
|
||||
fi
|
||||
fi
|
||||
|
||||
# Log to stdout
|
||||
echo "============================================="
|
||||
echo " DOCKER INTEGRATION TEST PLAN"
|
||||
echo "============================================="
|
||||
echo "Branch: ${{ steps.ctx.outputs.pr_head_ref }}"
|
||||
echo "Trigger: ${{ github.event_name }}"
|
||||
echo "Deployments: ${{ steps.ctx.outputs.deployment_matrix }}"
|
||||
echo "Case: ${CASE}"
|
||||
echo "Action: ${ACTION}"
|
||||
echo "Registry: ${EFFECTIVE_REGISTRY}"
|
||||
echo "Image tag: ${EFFECTIVE_TAG}"
|
||||
echo "Example: wazuh/wazuh-manager:${EFFECTIVE_TAG}"
|
||||
echo "============================================="
|
||||
|
||||
# Write to step summary
|
||||
{
|
||||
echo "## Docker Integration Test Plan"
|
||||
echo ""
|
||||
echo "| | |"
|
||||
echo "|---|---|"
|
||||
echo "| **Branch** | \`${{ steps.ctx.outputs.pr_head_ref }}\` |"
|
||||
echo "| **Trigger** | \`${{ github.event_name }}\` |"
|
||||
echo "| **Deployments** | \`${{ steps.ctx.outputs.deployment_matrix }}\` |"
|
||||
echo "| **Case** | ${CASE} |"
|
||||
echo "| **Action** | ${ACTION} |"
|
||||
echo ""
|
||||
echo "### Image configuration"
|
||||
echo ""
|
||||
echo "| | |"
|
||||
echo "|---|---|"
|
||||
echo "| **Registry** | ${EFFECTIVE_REGISTRY} |"
|
||||
echo "| **Tag** | \`${EFFECTIVE_TAG}\` |"
|
||||
echo "| **Example image** | \`wazuh/wazuh-manager:${EFFECTIVE_TAG}\` |"
|
||||
echo ""
|
||||
echo "### Parameters"
|
||||
echo ""
|
||||
echo "| | |"
|
||||
echo "|---|---|"
|
||||
echo "| **VERSION.json version** | \`${WAZUH_VERSION}\` |"
|
||||
echo "| **VERSION.json stage** | \`${WAZUH_STAGE:-<release>}\` |"
|
||||
echo "| **Input version** | \`${INPUT_VERSION:-<not set>}\` |"
|
||||
echo "| **Input stage** | \`${INPUT_STAGE:-<not set>}\` |"
|
||||
echo "| **Input registry** | \`${INPUT_REGISTRY:-<not set>}\` |"
|
||||
} >> "$GITHUB_STEP_SUMMARY"
|
||||
|
||||
# -------------------------------------------------------------------------
|
||||
# Job 3: Build Docker images (only for ECR, when no explicit version/stage provided).
|
||||
# Calls 5_build_and_push_images.yml and pushes to the dev registry.
|
||||
# -------------------------------------------------------------------------
|
||||
build_images:
|
||||
name: Build Docker images
|
||||
needs: [prepare]
|
||||
if: |
|
||||
always() &&
|
||||
needs.prepare.result == 'success' &&
|
||||
inputs.version == '' &&
|
||||
inputs.stage == '' &&
|
||||
(inputs.registry == 'ECR' || github.event_name == 'issue_comment')
|
||||
uses: ./.github/workflows/5_build_and_push_images.yml
|
||||
with:
|
||||
image_tag: "${{ needs.prepare.outputs.wazuh_version }}-${{ needs.prepare.outputs.wazuh_stage }}"
|
||||
docker_reference: ${{ needs.prepare.outputs.pr_head_ref }}
|
||||
wazuh_automation_reference: ${{ inputs.automation_reference || 'main' }}
|
||||
products: "wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent"
|
||||
dev: true
|
||||
id: "docker-integration-${{ github.run_id }}"
|
||||
secrets: inherit
|
||||
|
||||
# -------------------------------------------------------------------------
|
||||
# Job 4: For each deployment type — provision VM, deploy Docker stack, test,
|
||||
# collect results, and clean up.
|
||||
# -------------------------------------------------------------------------
|
||||
docker_test:
|
||||
needs: [get_pr_info, prepare, build_images]
|
||||
if: |
|
||||
always() &&
|
||||
needs.prepare.result == 'success' &&
|
||||
(needs.build_images.result == 'success' || needs.build_images.result == 'skipped')
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
deployment_type: ${{ fromJSON(needs.prepare.outputs.deployment_matrix) }}
|
||||
|
||||
steps:
|
||||
# -----------------------------------------------------------------------
|
||||
# Setup
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Checkout wazuh-automation
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
repository: wazuh/wazuh-automation
|
||||
ref: ${{ env.AUTOMATION_REFERENCE }}
|
||||
token: ${{ secrets.GH_CLONE_TOKEN }}
|
||||
path: wazuh-automation
|
||||
|
||||
- name: Checkout wazuh-docker PR branch
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: ${{ needs.prepare.outputs.pr_head_ref }}
|
||||
path: wazuh-docker
|
||||
|
||||
- name: Resolve image configuration
|
||||
run: |
|
||||
WAZUH_VERSION="${{ needs.prepare.outputs.wazuh_version }}"
|
||||
WAZUH_STAGE="${{ needs.prepare.outputs.wazuh_stage }}"
|
||||
INPUT_VERSION="${{ inputs.version }}"
|
||||
INPUT_STAGE="${{ inputs.stage }}"
|
||||
|
||||
# Map registry choice to actual URL (defined once)
|
||||
if [ "${{ inputs.registry }}" = "ECR" ]; then
|
||||
SELECTED_REGISTRY="${{ vars.IMAGE_REGISTRY_DEV }}"
|
||||
else
|
||||
SELECTED_REGISTRY="${{ vars.IMAGE_REGISTRY_PROD }}"
|
||||
fi
|
||||
|
||||
if [ -z "$INPUT_VERSION" ] && [ -z "$INPUT_STAGE" ]; then
|
||||
DOCKER_VERSION="$WAZUH_VERSION"
|
||||
DOCKER_STAGE="$WAZUH_STAGE"
|
||||
if [ "${{ inputs.registry }}" = "ECR" ] || [ "${{ github.event_name }}" = "issue_comment" ]; then
|
||||
# Case a.1: ECR / PR comment — images were built by build_images job → tag = version-stage-latest
|
||||
DOCKER_REGISTRY="${{ vars.IMAGE_REGISTRY_DEV }}"
|
||||
DOCKER_TAG="${DOCKER_VERSION}${DOCKER_STAGE:+-${DOCKER_STAGE}}-latest"
|
||||
else
|
||||
DOCKER_REGISTRY="${{ vars.IMAGE_REGISTRY_PROD }}"
|
||||
DOCKER_TAG="${DOCKER_VERSION}${DOCKER_STAGE:+-${DOCKER_STAGE}}"
|
||||
fi
|
||||
elif [ -n "$INPUT_VERSION" ] && [ -z "$INPUT_STAGE" ]; then
|
||||
DOCKER_VERSION="$INPUT_VERSION"
|
||||
DOCKER_STAGE=""
|
||||
DOCKER_REGISTRY="$SELECTED_REGISTRY"
|
||||
if [ "${{ inputs.registry }}" = "ECR" ]; then
|
||||
DOCKER_TAG="${DOCKER_VERSION}-latest"
|
||||
else
|
||||
DOCKER_TAG="${DOCKER_VERSION}"
|
||||
fi
|
||||
else
|
||||
DOCKER_VERSION="${INPUT_VERSION:-${WAZUH_VERSION}}"
|
||||
DOCKER_STAGE="$INPUT_STAGE"
|
||||
DOCKER_REGISTRY="$SELECTED_REGISTRY"
|
||||
DOCKER_TAG="${DOCKER_VERSION}-${DOCKER_STAGE}"
|
||||
fi
|
||||
|
||||
echo "WAZUH_VERSION=${WAZUH_VERSION}" >> $GITHUB_ENV
|
||||
echo "WAZUH_STAGE=${WAZUH_STAGE}" >> $GITHUB_ENV
|
||||
echo "DOCKER_VERSION=${DOCKER_VERSION}" >> $GITHUB_ENV
|
||||
echo "DOCKER_STAGE=${DOCKER_STAGE}" >> $GITHUB_ENV
|
||||
echo "DOCKER_REGISTRY=${DOCKER_REGISTRY}" >> $GITHUB_ENV
|
||||
echo "DOCKER_TAG=${DOCKER_TAG}" >> $GITHUB_ENV
|
||||
|
||||
echo "=== Resolved image configuration ==="
|
||||
echo "Registry: ${DOCKER_REGISTRY}"
|
||||
echo "Tag: ${DOCKER_TAG}"
|
||||
echo "Example: wazuh/wazuh-manager:${DOCKER_TAG}"
|
||||
|
||||
- name: Set up Python 3.12
|
||||
uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
- name: Install requirements
|
||||
run: |
|
||||
pip install -r wazuh-automation/deployability/deps/requirements.txt
|
||||
pip install -r wazuh-automation/integration-test-module/requirements.txt
|
||||
pip install -e wazuh-automation/integration-test-module/
|
||||
pip install pyyaml
|
||||
|
||||
- name: Configure AWS credentials
|
||||
uses: aws-actions/configure-aws-credentials@v4
|
||||
with:
|
||||
role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
|
||||
role-session-name: docker-test-${{ github.run_id }}-${{ matrix.deployment_type }}
|
||||
aws-region: ${{ env.REGION }}
|
||||
|
||||
- name: Generate presigned cert tool URL
|
||||
run: |
|
||||
python wazuh-automation/tools/sign_urls/generate_presigned_dev_urls.py \
|
||||
--process build_docker \
|
||||
--wazuh-version "${{ env.DOCKER_VERSION }}" \
|
||||
--aws-s3-bucket-dev "${{ vars.AWS_S3_BUCKET_DEV }}"
|
||||
|
||||
python3 -c "
|
||||
import yaml
|
||||
data = yaml.safe_load(open('/tmp/artifact_urls.yaml'))
|
||||
print(f'wazuh_certs_tool={data[\"wazuh_certs_tool\"]}')
|
||||
" >> "$GITHUB_ENV"
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Provision: allocate VM and extract SSH credentials
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Allocate instance
|
||||
id: allocate
|
||||
run: |
|
||||
mkdir -p ${{ env.ALLOCATOR_PATH }}
|
||||
python3 wazuh-automation/deployability/modules/allocation/main.py \
|
||||
--action create \
|
||||
--provider aws \
|
||||
--size large \
|
||||
--composite-name ubuntu-24-amd64 \
|
||||
--working-dir ${{ env.ALLOCATOR_PATH }} \
|
||||
--track-output ${{ env.ALLOCATOR_PATH }}/track.yml \
|
||||
--inventory-output ${{ env.ALLOCATOR_PATH }}/inventory.yml \
|
||||
--instance-name gha_${{ github.run_id }}_docker_${{ matrix.deployment_type }} \
|
||||
--label-team devops \
|
||||
--label-termination-date 1d
|
||||
|
||||
sed -n '/hosts:/,/^[^ ]/p' ${{ env.ALLOCATOR_PATH }}/inventory.yml \
|
||||
| grep "ansible_" \
|
||||
| sed 's/^[ ]*//g' \
|
||||
> ${{ env.ALLOCATOR_PATH }}/inventory_vars_raw.yml
|
||||
sed 's/: */=/g' ${{ env.ALLOCATOR_PATH }}/inventory_vars_raw.yml \
|
||||
> ${{ env.ALLOCATOR_PATH }}/inventory_vars.yml
|
||||
sed -i 's/-o StrictHostKeyChecking=no/"-o StrictHostKeyChecking=no"/g' \
|
||||
${{ env.ALLOCATOR_PATH }}/inventory_vars.yml
|
||||
|
||||
- name: Set SSH credentials from inventory
|
||||
run: |
|
||||
find ${{ env.ALLOCATOR_PATH }} -name '*-key-*' -exec chmod 600 {} \;
|
||||
source ${{ env.ALLOCATOR_PATH }}/inventory_vars.yml
|
||||
echo "SSH_HOST=$ansible_host" >> $GITHUB_ENV
|
||||
echo "SSH_PORT=$ansible_port" >> $GITHUB_ENV
|
||||
echo "SSH_USER=$ansible_user" >> $GITHUB_ENV
|
||||
echo "SSH_KEY=$ansible_ssh_private_key_file" >> $GITHUB_ENV
|
||||
|
||||
- name: Set SSH/SCP helper env vars
|
||||
run: |
|
||||
echo "SSH_OPTS=-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=20 -p ${{ env.SSH_PORT }} -i ${{ env.SSH_KEY }}" >> $GITHUB_ENV
|
||||
echo "SCP_OPTS=-o StrictHostKeyChecking=no -P ${{ env.SSH_PORT }} -i ${{ env.SSH_KEY }}" >> $GITHUB_ENV
|
||||
echo "REMOTE=${{ env.SSH_USER }}@${{ env.SSH_HOST }}" >> $GITHUB_ENV
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Install Docker CE on the remote VM
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Install Docker CE
|
||||
run: |
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
curl -fsSL https://get.docker.com | sudo sh
|
||||
sudo systemctl enable --now docker
|
||||
"
|
||||
|
||||
- name: Login VM to ECR registry
|
||||
if: inputs.registry == 'ECR' || github.event_name == 'issue_comment'
|
||||
run: |
|
||||
ECR_REGISTRY="${{ env.DOCKER_REGISTRY }}"
|
||||
ECR_REGION=$(echo "$ECR_REGISTRY" | cut -d. -f4)
|
||||
ECR_PASS=$(aws ecr get-login-password --region "$ECR_REGION")
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" \
|
||||
"echo '${ECR_PASS}' | sudo docker login --username AWS --password-stdin ${ECR_REGISTRY}"
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Deploy: patch image tags, copy wazuh-docker and start the stack
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Patch image tags
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
COMPOSE="wazuh-docker/${DEPLOYMENT}/docker-compose.yml"
|
||||
TAG="${{ env.DOCKER_TAG }}"
|
||||
REGISTRY="${{ env.DOCKER_REGISTRY }}"
|
||||
|
||||
if [ "$REGISTRY" = "${{ vars.IMAGE_REGISTRY_PROD }}" ] || [ -z "$REGISTRY" ]; then
|
||||
echo "Patching ${COMPOSE}: wazuh/wazuh-*:${TAG} (DockerHub, no registry prefix)"
|
||||
sed -i -E "s|(image: wazuh/wazuh-[^:]+:)[^ ]+|\1${TAG}|g" "$COMPOSE"
|
||||
else
|
||||
echo "Patching ${COMPOSE}: ${REGISTRY}/wazuh/wazuh-*:${TAG}"
|
||||
sed -i -E "s|image: (wazuh/wazuh-[^:]+):[^ ]+|image: ${REGISTRY}/\1:${TAG}|g" "$COMPOSE"
|
||||
fi
|
||||
echo "=== Patched image lines ==="
|
||||
grep 'image:' "$COMPOSE"
|
||||
|
||||
- name: Prepare cert tool and config
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
|
||||
echo "Cert tool: ${{ env.wazuh_certs_tool }} Docker image: ${{ env.DOCKER_TAG }}"
|
||||
|
||||
curl --output "wazuh-docker/${DEPLOYMENT}/wazuh-certs-tool.sh" "${{ env.wazuh_certs_tool }}"
|
||||
chmod +x "wazuh-docker/${DEPLOYMENT}/wazuh-certs-tool.sh"
|
||||
echo "Downloaded OK"
|
||||
|
||||
# Write config.yml directly into the deployment directory
|
||||
if [ "$DEPLOYMENT" = "single-node" ]; then
|
||||
printf '%s\n' \
|
||||
'nodes:' \
|
||||
' indexer:' \
|
||||
' - name: wazuh.indexer' \
|
||||
' dns: wazuh.indexer' \
|
||||
' manager:' \
|
||||
' - name: wazuh.manager' \
|
||||
' dns: wazuh.manager' \
|
||||
' dashboard:' \
|
||||
' - name: wazuh.dashboard' \
|
||||
' dns: wazuh.dashboard' \
|
||||
> "wazuh-docker/${DEPLOYMENT}/config.yml"
|
||||
else
|
||||
printf '%s\n' \
|
||||
'nodes:' \
|
||||
' indexer:' \
|
||||
' - name: wazuh1.indexer' \
|
||||
' dns: wazuh1.indexer' \
|
||||
' - name: wazuh2.indexer' \
|
||||
' dns: wazuh2.indexer' \
|
||||
' - name: wazuh3.indexer' \
|
||||
' dns: wazuh3.indexer' \
|
||||
' manager:' \
|
||||
' - name: wazuh.master' \
|
||||
' dns: wazuh.master' \
|
||||
' node_type: master' \
|
||||
' - name: wazuh.worker' \
|
||||
' dns: wazuh.worker' \
|
||||
' node_type: worker' \
|
||||
' dashboard:' \
|
||||
' - name: wazuh.dashboard' \
|
||||
' dns: wazuh.dashboard' \
|
||||
> "wazuh-docker/${DEPLOYMENT}/config.yml"
|
||||
fi
|
||||
echo "=== config.yml ==="
|
||||
cat "wazuh-docker/${DEPLOYMENT}/config.yml"
|
||||
echo "=== Files ready to copy ==="
|
||||
ls -la "wazuh-docker/${DEPLOYMENT}/"
|
||||
|
||||
- name: Copy wazuh-docker to VM
|
||||
run: |
|
||||
scp ${{ env.SCP_OPTS }} -r wazuh-docker "${{ env.REMOTE }}:/tmp/wazuh-docker"
|
||||
|
||||
- name: Show deployment config
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
echo '=== Files in deployment directory ==='
|
||||
ls -la /tmp/wazuh-docker/${DEPLOYMENT}/
|
||||
echo ''
|
||||
echo '=== Images referenced in docker-compose.yml ==='
|
||||
grep 'image:' /tmp/wazuh-docker/${DEPLOYMENT}/docker-compose.yml || echo '(none found)'
|
||||
echo ''
|
||||
echo '=== Docker version ==='
|
||||
sudo docker version --format 'Client: {{.Client.Version}} Server: {{.Server.Version}}'
|
||||
"
|
||||
|
||||
- name: Configure VM for Wazuh Indexer
|
||||
run: |
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
sudo sysctl -w vm.max_map_count=262144
|
||||
echo 'vm.max_map_count = '\$(cat /proc/sys/vm/max_map_count)
|
||||
"
|
||||
|
||||
- name: Generate SSL certificates
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
set -e
|
||||
cd /tmp/wazuh-docker/${DEPLOYMENT}
|
||||
echo '=== Running certificate generation ==='
|
||||
sudo bash /tmp/wazuh-docker/tools/utils/deployment/certificates-conf.sh --cert --copy
|
||||
echo ''
|
||||
echo '=== Generated certificate files ==='
|
||||
find ./config -name '*.pem' | sort
|
||||
echo ''
|
||||
echo '=== Certificate subjects ==='
|
||||
for pem in \$(find ./config -name '*.pem' ! -name '*-key.pem' | sort); do
|
||||
echo -n \"\$pem: \"
|
||||
sudo openssl x509 -in \"\$pem\" -noout -subject -issuer 2>/dev/null || echo '(not a cert / key file)'
|
||||
done
|
||||
"
|
||||
|
||||
- name: Start Docker Compose
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
set -eo pipefail
|
||||
cd /tmp/wazuh-docker/${DEPLOYMENT}
|
||||
sudo docker compose up -d 2>&1 | tee /tmp/docker-compose-up.log
|
||||
echo ''
|
||||
echo '=== Initial container status ==='
|
||||
sudo docker compose ps
|
||||
"
|
||||
|
||||
- name: Show indexer logs on failure
|
||||
if: failure()
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
cd /tmp/wazuh-docker/${DEPLOYMENT}
|
||||
echo '=== docker compose ps ==='
|
||||
sudo docker compose ps
|
||||
echo ''
|
||||
echo '=== wazuh.indexer logs ==='
|
||||
sudo docker compose logs wazuh.indexer 2>&1
|
||||
" || true
|
||||
|
||||
- name: Wait for containers healthy
|
||||
timeout-minutes: 15
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
cd /tmp/wazuh-docker/${DEPLOYMENT}
|
||||
|
||||
echo '=== Verifying containers started ==='
|
||||
TOTAL=\$(sudo docker compose ps 2>/dev/null | tail -n +2 | wc -l | tr -d ' ')
|
||||
if [ \"\$TOTAL\" -eq 0 ]; then
|
||||
echo 'ERROR: No containers are running — docker compose up may have failed'
|
||||
sudo docker compose ps
|
||||
sudo docker compose logs --no-color 2>&1 | tail -50
|
||||
exit 1
|
||||
fi
|
||||
echo \"Found \$TOTAL container(s), waiting for healthy status...\"
|
||||
echo ''
|
||||
|
||||
for i in \$(seq 1 90); do
|
||||
NOT_HEALTHY=\$(sudo docker compose ps 2>/dev/null \
|
||||
| tail -n +2 \
|
||||
| grep -v 'nginx' \
|
||||
| grep -vcE '(healthy|\(healthy\))')
|
||||
if [ \"\$NOT_HEALTHY\" -eq 0 ]; then
|
||||
echo \"All containers healthy after \${i} x 10s attempts\"
|
||||
sudo docker compose ps
|
||||
exit 0
|
||||
fi
|
||||
echo \" attempt \$i/90: \$NOT_HEALTHY container(s) not yet healthy\"
|
||||
if [ \"\$(( i % 6 ))\" -eq 0 ]; then
|
||||
echo ' --- current status ---'
|
||||
sudo docker compose ps
|
||||
fi
|
||||
sleep 10
|
||||
done
|
||||
echo 'ERROR: containers not healthy after 15 minutes'
|
||||
sudo docker compose ps
|
||||
sudo docker compose logs --no-color 2>&1 | tail -100
|
||||
exit 1
|
||||
"
|
||||
|
||||
- name: Cluster warm-up wait
|
||||
run: |
|
||||
if [ "${{ matrix.deployment_type }}" = "multi-node" ]; then
|
||||
WAIT=90
|
||||
else
|
||||
WAIT=60
|
||||
fi
|
||||
echo "Waiting ${WAIT}s for services to reach steady state..."
|
||||
sleep $WAIT
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
cd /tmp/wazuh-docker/${DEPLOYMENT}
|
||||
echo '=== Container status after warm-up ==='
|
||||
sudo docker compose ps
|
||||
"
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Run integration tests
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Run tests
|
||||
id: run_tests
|
||||
continue-on-error: true
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
test_runner \
|
||||
--test-type "docker-${DEPLOYMENT}" \
|
||||
--deployment-type "docker-${DEPLOYMENT}" \
|
||||
--ssh-host "${{ env.SSH_HOST }}" \
|
||||
--ssh-port "${{ env.SSH_PORT }}" \
|
||||
--ssh-key-path "${{ env.SSH_KEY }}" \
|
||||
--ssh-username "${{ env.SSH_USER }}" \
|
||||
--version "${{ env.DOCKER_VERSION }}" \
|
||||
--log-level INFO \
|
||||
--output github \
|
||||
--output-file "test-results-docker-${DEPLOYMENT}.github"
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Collect logs on failure
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Show test outcome
|
||||
if: always()
|
||||
run: |
|
||||
echo "Run tests outcome: ${{ steps.run_tests.outcome }}"
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
if [ -f "test-results-docker-${DEPLOYMENT}.github" ]; then
|
||||
echo "=== Test results file ==="
|
||||
cat "test-results-docker-${DEPLOYMENT}.github"
|
||||
else
|
||||
echo "WARNING: no test results file found (test_runner may have failed before writing output)"
|
||||
fi
|
||||
|
||||
- name: Collect Docker logs on failure
|
||||
if: failure() || steps.run_tests.outcome == 'failure'
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
cd /tmp/wazuh-docker/${DEPLOYMENT}
|
||||
sudo docker compose logs --no-color 2>&1
|
||||
" > docker-logs-${DEPLOYMENT}.txt || true
|
||||
|
||||
- name: Upload Docker logs
|
||||
if: failure() || steps.run_tests.outcome == 'failure'
|
||||
run: |
|
||||
echo "Uploading Docker logs artifact..."
|
||||
zip "${{ env.LOGS_ARTIFACT_ZIP_FILE }}" docker-logs-*.txt
|
||||
aws s3 cp "${{ env.LOGS_ARTIFACT_ZIP_FILE }}" "s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/5_check_integration_tools/${{ github.run_id }}/${{ env.LOGS_ARTIFACT_ZIP_FILE }}"
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Reporting
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Create step summary
|
||||
if: always()
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
echo "## Docker Integration Test Results — ${DEPLOYMENT}" >> $GITHUB_STEP_SUMMARY
|
||||
echo "" >> $GITHUB_STEP_SUMMARY
|
||||
if [ -f "test-results-docker-${DEPLOYMENT}.github" ]; then
|
||||
cat "test-results-docker-${DEPLOYMENT}.github" >> $GITHUB_STEP_SUMMARY
|
||||
else
|
||||
echo "No test results file found." >> $GITHUB_STEP_SUMMARY
|
||||
fi
|
||||
|
||||
- name: Post PR comment with results
|
||||
if: always() && github.event_name == 'issue_comment'
|
||||
uses: actions/github-script@v7
|
||||
env:
|
||||
DEPLOYMENT: ${{ matrix.deployment_type }}
|
||||
RUN_OUTCOME: ${{ steps.run_tests.outcome }}
|
||||
with:
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
script: |
|
||||
const fs = require('fs');
|
||||
const deployment = process.env.DEPLOYMENT;
|
||||
const outcome = process.env.RUN_OUTCOME;
|
||||
const marker = `<!-- docker-integration-check-${deployment} -->`;
|
||||
|
||||
let body = `${marker}\n## Docker Integration Tests — \`${deployment}\`\n\n`;
|
||||
body += outcome === 'success'
|
||||
? '✅ **All tests passed!**\n\n'
|
||||
: '❌ **Some tests failed**\n\n';
|
||||
|
||||
const resultsFile = `test-results-docker-${deployment}.github`;
|
||||
try {
|
||||
if (fs.existsSync(resultsFile)) {
|
||||
body += '### Results\n\n' + fs.readFileSync(resultsFile, 'utf8') + '\n\n';
|
||||
}
|
||||
} catch (e) {
|
||||
console.log('Could not read results file:', e.message);
|
||||
}
|
||||
body += `- **Workflow:** [View Details](${context.payload.repository.html_url}/actions/runs/${context.runId})\n`;
|
||||
|
||||
const { data: comments } = await github.rest.issues.listComments({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
issue_number: context.issue.number,
|
||||
});
|
||||
|
||||
const existing = comments.find(c =>
|
||||
c.user.type === 'Bot' && c.body.includes(marker)
|
||||
);
|
||||
|
||||
if (existing) {
|
||||
await github.rest.issues.updateComment({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
comment_id: existing.id,
|
||||
body: body,
|
||||
});
|
||||
} else {
|
||||
await github.rest.issues.createComment({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
issue_number: context.issue.number,
|
||||
body: body,
|
||||
});
|
||||
}
|
||||
|
||||
- name: Upload test results
|
||||
if: always()
|
||||
env:
|
||||
S3_ARTIFACTS_PATH: s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/5_check_integration_tools/${{ github.run_id }}
|
||||
LOCAL_RESULTS_PATH: test-results-docker-${{ matrix.deployment_type }}.github
|
||||
run: |
|
||||
if [ -f "${LOCAL_RESULTS_PATH}" ]; then
|
||||
echo "Uploading test results to S3..."
|
||||
aws s3 cp "${LOCAL_RESULTS_PATH}" "${S3_ARTIFACTS_PATH}/test-results-docker-${{ matrix.deployment_type }}/"
|
||||
else
|
||||
echo "::warning::No test results file found - skipping upload (an earlier step likely failed before test_runner produced output)."
|
||||
fi
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Cleanup: always stop stack and deallocate VM
|
||||
# -----------------------------------------------------------------------
|
||||
- name: Stop Docker Compose
|
||||
if: always()
|
||||
run: |
|
||||
DEPLOYMENT="${{ matrix.deployment_type }}"
|
||||
ssh ${{ env.SSH_OPTS }} "${{ env.REMOTE }}" "
|
||||
cd /tmp/wazuh-docker/${DEPLOYMENT} && sudo docker compose down -v || true
|
||||
" || true
|
||||
|
||||
- name: Configure AWS credentials for cleanup
|
||||
if: always()
|
||||
uses: aws-actions/configure-aws-credentials@v4
|
||||
with:
|
||||
role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
|
||||
role-session-name: docker-cleanup-${{ github.run_id }}-${{ matrix.deployment_type }}
|
||||
aws-region: ${{ env.REGION }}
|
||||
|
||||
- name: Deallocate instance
|
||||
if: always()
|
||||
run: |
|
||||
python3 wazuh-automation/deployability/modules/allocation/main.py \
|
||||
--action delete \
|
||||
--track-output ${{ env.ALLOCATOR_PATH }}/track.yml
|
||||
|
||||
# -------------------------------------------------------------------------
|
||||
# Job 4: Update the GitHub check run (issue_comment trigger only)
|
||||
# -------------------------------------------------------------------------
|
||||
update_check:
|
||||
needs: [get_pr_info, prepare, build_images, docker_test]
|
||||
if: always() && github.event_name == 'issue_comment' && needs.get_pr_info.result == 'success'
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
steps:
|
||||
- name: Update check run
|
||||
uses: actions/github-script@v7
|
||||
env:
|
||||
DOCKER_RESULT: ${{ needs.docker_test.result }}
|
||||
CHECK_NAME: ${{ needs.get_pr_info.outputs.check_name }}
|
||||
CHECK_RUN_ID: ${{ needs.get_pr_info.outputs.check_run_id }}
|
||||
with:
|
||||
script: |
|
||||
const result = process.env.DOCKER_RESULT;
|
||||
const conclusionMap = {
|
||||
success: { conclusion: 'success', icon: '✅', summary: 'All Docker integration tests passed.' },
|
||||
failure: { conclusion: 'failure', icon: '❌', summary: 'One or more Docker integration tests failed.' },
|
||||
cancelled: { conclusion: 'cancelled', icon: '⏹️', summary: 'Workflow was cancelled.' },
|
||||
};
|
||||
const { conclusion, icon, summary } = conclusionMap[result] ?? conclusionMap.failure;
|
||||
const label = conclusion.charAt(0).toUpperCase() + conclusion.slice(1);
|
||||
await github.rest.checks.update({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
check_run_id: parseInt(process.env.CHECK_RUN_ID),
|
||||
status: 'completed',
|
||||
conclusion,
|
||||
completed_at: new Date().toISOString(),
|
||||
output: {
|
||||
title: `${icon} ${process.env.CHECK_NAME} — ${label}`,
|
||||
summary,
|
||||
text: `[View workflow run](https://github.com/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId})`
|
||||
}
|
||||
});
|
||||
@@ -1,649 +0,0 @@
|
||||
name: Wazuh Docker pipeline
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize, reopened, ready_for_review]
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
docker_reference:
|
||||
description: 'Branch or tag to build from'
|
||||
required: true
|
||||
type: string
|
||||
|
||||
jobs:
|
||||
|
||||
prepare-variables:
|
||||
if: ${{ !github.event.pull_request.draft }}
|
||||
runs-on: ubuntu-latest
|
||||
outputs:
|
||||
WAZUH_VERSION: ${{ steps.dotenv.outputs.WAZUH_VERSION }}
|
||||
WAZUH_IMAGE_VERSION: ${{ steps.dotenv.outputs.WAZUH_IMAGE_VERSION }}
|
||||
WAZUH_REGISTRY: ${{ vars.IMAGE_REGISTRY_DEV }}
|
||||
IMAGE_TAG: ${{ steps.dotenv.outputs.IMAGE_TAG }}
|
||||
WAZUH_MINOR_VERSION: ${{ steps.dotenv.outputs.WAZUH_MINOR_VERSION }}
|
||||
steps:
|
||||
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Export .env variables
|
||||
id: dotenv
|
||||
shell: bash
|
||||
run: |
|
||||
if [ ! -f .env ]; then echo "::error::.env missing"; exit 1; fi
|
||||
grep -v '^#' .env | grep -v '^\s*$' >> "$GITHUB_OUTPUT"
|
||||
FULL_VERSION=$(grep "^WAZUH_VERSION=" .env | cut -d'=' -f2)
|
||||
MINOR_VERSION=$(echo "$FULL_VERSION" | cut -d'.' -f1,2)
|
||||
echo "WAZUH_MINOR_VERSION=$MINOR_VERSION" >> "$GITHUB_OUTPUT"
|
||||
|
||||
|
||||
build-images:
|
||||
needs: prepare-variables
|
||||
uses: ./.github/workflows/Procedure_push_docker_images.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
image_tag: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }}
|
||||
docker_reference: ${{ github.head_ref || inputs.docker_reference }}
|
||||
wazuh_automation_reference: 'v5.0.0-beta2'
|
||||
commit_list: '["latest", "latest", "latest", "latest"]'
|
||||
assistant_revision: 'latest'
|
||||
id: ${{ github.run_id }}
|
||||
dev: true
|
||||
|
||||
Execute-Goss-tests:
|
||||
needs: [prepare-variables, build-images]
|
||||
runs-on: ubuntu-22.04
|
||||
env:
|
||||
WAZUH_IMAGE_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }}
|
||||
WAZUH_REGISTRY: ${{ needs.prepare-variables.outputs.WAZUH_REGISTRY }}
|
||||
steps:
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install Goss
|
||||
uses: e1himself/goss-installation-action@v1.0.3
|
||||
with:
|
||||
version: 'v0.4.4'
|
||||
|
||||
- name: Configure aws credentials
|
||||
uses: aws-actions/configure-aws-credentials@v4
|
||||
with:
|
||||
role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
|
||||
aws-region: "${{ secrets.AWS_REGION }}"
|
||||
|
||||
- name: Log in to Amazon ECR
|
||||
uses: aws-actions/amazon-ecr-login@v2
|
||||
|
||||
- name: Execute Goss tests (wazuh-manager)
|
||||
run: dgoss run ${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-manager:${{ env.WAZUH_IMAGE_VERSION }}-latest
|
||||
env:
|
||||
GOSS_SLEEP: 30
|
||||
GOSS_FILE: .github/.goss.yaml
|
||||
|
||||
check-single-node:
|
||||
name: Check single node on ${{ matrix.os }}
|
||||
runs-on: ${{ matrix.os }}
|
||||
strategy:
|
||||
matrix:
|
||||
os: [ubuntu-22.04, ubuntu-22.04-arm]
|
||||
fail-fast: false
|
||||
needs: [prepare-variables, Execute-Goss-tests]
|
||||
env:
|
||||
WAZUH_IMAGE_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }}
|
||||
WAZUH_MINOR_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_MINOR_VERSION }}
|
||||
WAZUH_REGISTRY: ${{ needs.prepare-variables.outputs.WAZUH_REGISTRY }}
|
||||
INDEXER_USERNAME: admin
|
||||
INDEXER_PASSWORD: admin
|
||||
MANAGER_NODES: "manager"
|
||||
API_USERNAME: wazuh-wui
|
||||
API_PASSWORD: wazuh-wui
|
||||
steps:
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: free disk space
|
||||
uses: ./.github/free-disk-space
|
||||
|
||||
- name: Configure aws credentials
|
||||
uses: aws-actions/configure-aws-credentials@v4
|
||||
with:
|
||||
role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
|
||||
aws-region: "${{ secrets.AWS_REGION }}"
|
||||
|
||||
- name: Log in to Amazon ECR
|
||||
uses: aws-actions/amazon-ecr-login@v2
|
||||
|
||||
- name: Download artifact_urls.yaml
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: presigned-artifact-urls-${{ github.run_id }}
|
||||
path: ./single-node/
|
||||
|
||||
- name: Add environment variables into GITHUB_ENV
|
||||
run: |
|
||||
# Export variables to the environment
|
||||
awk -F':' '!/^#/ && NF>1 {name=$1; val=substr($0,length(name)+3); gsub(/[-.]/,"_",name); print name "=" val}' ${{ vars.ARTIFACT_URL_FILE_NAME }} >> "$GITHUB_ENV"
|
||||
working-directory: ./single-node/
|
||||
|
||||
- name: Create single node certficates
|
||||
run: |
|
||||
curl --output ./wazuh-certs-tool.sh "${{ env.wazuh_certs_tool }}"
|
||||
cat > config.yml <<EOF
|
||||
nodes:
|
||||
# Wazuh indexer server nodes
|
||||
indexer:
|
||||
- name: wazuh.indexer
|
||||
dns: "wazuh.indexer"
|
||||
|
||||
# Wazuh manager nodes
|
||||
# Use node_type only with more than one Wazuh manager
|
||||
manager:
|
||||
- name: wazuh.manager
|
||||
dns: "wazuh.manager"
|
||||
|
||||
# Wazuh dashboard node
|
||||
dashboard:
|
||||
- name: wazuh.dashboard
|
||||
dns: "wazuh.dashboard"
|
||||
EOF
|
||||
cat config.yml
|
||||
sudo bash ../tools/utils/deployment/certificates-conf.sh --cert --copy --priv
|
||||
sudo sysctl -w vm.max_map_count=262144
|
||||
working-directory: ./single-node
|
||||
|
||||
- name: Edit single node docker-compose file
|
||||
shell: bash
|
||||
env:
|
||||
WAZUH_REGISTRY: ${{ env.WAZUH_REGISTRY }}
|
||||
run: |
|
||||
TARGET_FILE="single-node/docker-compose.yml"
|
||||
if [ -f "$TARGET_FILE" ]; then
|
||||
echo "Updating registry in $TARGET_FILE to: ${{ env.WAZUH_REGISTRY }}"
|
||||
sed -i "s|wazuh/wazuh-|${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-|g" "$TARGET_FILE"
|
||||
sed -i "s/\(.*wazuh\/wazuh-.*:\)${{ env.WAZUH_IMAGE_VERSION }}/\1${{ env.WAZUH_IMAGE_VERSION }}-latest/g" "$TARGET_FILE"
|
||||
else
|
||||
echo "File $TARGET_FILE not found"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Start single node stack
|
||||
id: start_single_node_stack
|
||||
run: docker compose up -d
|
||||
working-directory: ./single-node
|
||||
|
||||
- name: Check Wazuh indexer start
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
for i in {1..20}; do
|
||||
echo "Checking Wazuh indexer health (Attempt $i/20)"
|
||||
RESPONSE=$(curl -XGET "https://127.0.0.1:9200/_cluster/health?pretty" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s --retry 2 || true)
|
||||
INDEXER_CONTAINERS=$(docker ps --format '{{.Names}}' | grep "indexer")
|
||||
if echo "$RESPONSE" | grep -qE "green|yellow"; then
|
||||
echo "Cluster Online"
|
||||
echo "$RESPONSE"
|
||||
exit 0
|
||||
fi
|
||||
echo "Waiting for cluster to be online"
|
||||
for CONTAINER_NAME in $INDEXER_CONTAINERS; do
|
||||
echo ""
|
||||
echo "========================================================="
|
||||
echo "Container logs for $CONTAINER_NAME"
|
||||
echo "========================================================="
|
||||
docker logs --tail 30 "$CONTAINER_NAME"
|
||||
echo "---------------------------------------------------------"
|
||||
done
|
||||
[ $i -lt 20 ] && sleep 60
|
||||
done
|
||||
status_index="`curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | wc -l`"
|
||||
status_index_green="`curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep -E "green|yellow" | wc -l`"
|
||||
if [[ $status_index_green -eq $status_index ]]; then
|
||||
curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s
|
||||
else
|
||||
curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s
|
||||
exit 1
|
||||
fi
|
||||
|
||||
|
||||
- name: Check Wazuh indexer nodes
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
nodes="`curl -XGET "https://127.0.0.1:9200/_cat/nodes" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep -E "indexer" | wc -l`"
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
|
||||
- name: Check Wazuh templates
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
qty_templates="`curl -XGET "https://127.0.0.1:9200/_cat/templates" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics" | wc -l`"
|
||||
templates="`curl -XGET "https://127.0.0.1:9200/_cat/templates" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics"`"
|
||||
if [[ $qty_templates -gt 3 ]]; then
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
else
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh manager start
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
for NODE in "${{ env.MANAGER_NODES }}"; do
|
||||
ok=false
|
||||
for i in {1..20}; do
|
||||
TOKEN=$(curl -s -u ${{ env.API_USERNAME }}:${{ env.API_PASSWORD }} -k -X POST "https://127.0.0.1:55000/security/user/authenticate?raw=true")
|
||||
services="`curl -k -s -X GET "https://127.0.0.1:55000/cluster/$NODE/status?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items | grep running | wc -l`"
|
||||
if [[ $services -gt 7 ]]; then
|
||||
echo "Wazuh Manager $NODE Services: ${services}"
|
||||
echo "OK"
|
||||
ok=true
|
||||
break
|
||||
else
|
||||
curl -k -X GET "https://127.0.0.1:55000/cluster/$NODE/status?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items
|
||||
echo "Wazuh Manager $NODE Services: ${services}. Retrying in 30s"
|
||||
[ $i -lt 20 ] && sleep 30
|
||||
fi
|
||||
done
|
||||
if [[ "$ok" != "true" ]]; then
|
||||
echo "Error: Wazuh Manager $NODE did not reach expected running services threshold"
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
- name: Check Wazuh dashboard service URL
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
for i in {1..20}; do
|
||||
echo "Checking Wazuh dashboard (Attempt $i/20)"
|
||||
STATUS=$(curl -k -s -o /dev/null -w "%{http_code}" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} "https://127.0.0.1:443/app/status" || true)
|
||||
echo "Current status: $STATUS"
|
||||
if [[ "$STATUS" == "200" ]]; then
|
||||
echo "Wazuh dashboard is UP"
|
||||
exit 0
|
||||
elif [[ "$STATUS" == "429" || "$STATUS" == "503" ]]; then
|
||||
echo "Dashboard is busy or initializing (Status $STATUS). Retrying in 30s"
|
||||
else
|
||||
echo "Unexpected status $STATUS. Retrying in 30s"
|
||||
fi
|
||||
sleep 30
|
||||
done
|
||||
echo "Error: Dashboard did not reach 200 status in time."
|
||||
exit 1
|
||||
|
||||
- name: Modify Docker endpoint into Wazuh agent docker-compose.yml file
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: sed -i "s/<WAZUH_MANAGER_IP>/$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml
|
||||
|
||||
- name: Edit Wazuh agent docker-compose file
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
shell: bash
|
||||
env:
|
||||
WAZUH_REGISTRY: ${{ env.WAZUH_REGISTRY }}
|
||||
run: |
|
||||
TARGET_FILE="wazuh-agent/docker-compose.yml"
|
||||
if [ -f "$TARGET_FILE" ]; then
|
||||
echo "Updating registry in $TARGET_FILE to: ${{ env.WAZUH_REGISTRY }}"
|
||||
sed -i "s|wazuh/wazuh-|${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-|g" "$TARGET_FILE"
|
||||
sed -i "s/\(.*wazuh\/wazuh-.*:\)${{ env.WAZUH_IMAGE_VERSION }}/\1${{ env.WAZUH_IMAGE_VERSION }}-latest/g" "$TARGET_FILE"
|
||||
else
|
||||
echo "File $TARGET_FILE not found"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Start Wazuh agent
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: docker compose up -d
|
||||
working-directory: ./wazuh-agent
|
||||
|
||||
- name: Check Wazuh agent enrollment
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
enrolled=false
|
||||
for i in {1..5}; do
|
||||
TOKEN=$(curl -s -u ${{ env.API_USERNAME }}:${{ env.API_PASSWORD }} -k -X POST "https://127.0.0.1:55000/security/user/authenticate?raw=true")
|
||||
agents="`curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items | grep active | wc -l`"
|
||||
if [[ $agents -gt 0 ]]; then
|
||||
echo "Wazuh agents: ${agents}"
|
||||
echo "OK"
|
||||
enrolled=true
|
||||
break
|
||||
else
|
||||
curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}"
|
||||
echo "Wazuh agents: ${agents}. Retrying in 10s"
|
||||
[ $i -lt 5 ] && sleep 10
|
||||
fi
|
||||
done
|
||||
if [[ "$enrolled" != "true" ]]; then
|
||||
echo "Error: Wazuh agent enrollment did not reach expected active agents threshold"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check errors in wazuh-manager.log for Wazuh manager
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: ./.github/single-node-log-check.sh
|
||||
|
||||
- name: Check documents into wazuh-states index
|
||||
if: ${{ always() && steps.start_single_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
for i in {1..20}; do
|
||||
echo "Checking documents in wazuh-states (Attempt $i/20)..."
|
||||
RESPONSE=$(curl -XGET "https://127.0.0.1:9200/wazuh-states*/_count" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s || echo "{}")
|
||||
DOCS=$(echo "$RESPONSE" | jq -r '.count // 0')
|
||||
if [[ "$DOCS" -gt 0 ]]; then
|
||||
echo "wazuh-states index has documents: ${DOCS}"
|
||||
exit 0
|
||||
fi
|
||||
echo "The index is empty or does not exist yet (Count: $DOCS). Waiting 60s"
|
||||
[ $i -lt 20 ] && sleep 60
|
||||
done
|
||||
echo "Error: No documents found in wazuh-states after 20 attempts."
|
||||
echo "Last response: $RESPONSE"
|
||||
exit 1
|
||||
|
||||
- name: Docker logs
|
||||
if: always()
|
||||
continue-on-error: true
|
||||
run: |
|
||||
INDEXER_CONTAINERS=$(docker ps --format '{{.Names}}')
|
||||
for CONTAINER_NAME in $INDEXER_CONTAINERS; do
|
||||
echo ""
|
||||
echo "========================================================="
|
||||
echo "Container logs for $CONTAINER_NAME"
|
||||
echo "========================================================="
|
||||
docker logs "$CONTAINER_NAME"
|
||||
echo "---------------------------------------------------------"
|
||||
done
|
||||
working-directory: ./single-node
|
||||
|
||||
check-multi-node:
|
||||
name: Check multi node on ${{ matrix.os }}
|
||||
runs-on: ${{ matrix.os }}
|
||||
strategy:
|
||||
matrix:
|
||||
os: [ubuntu-22.04, ubuntu-22.04-arm]
|
||||
fail-fast: false
|
||||
needs: [prepare-variables, Execute-Goss-tests]
|
||||
env:
|
||||
WAZUH_IMAGE_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_IMAGE_VERSION }}
|
||||
WAZUH_MINOR_VERSION: ${{ needs.prepare-variables.outputs.WAZUH_MINOR_VERSION }}
|
||||
WAZUH_REGISTRY: ${{ needs.prepare-variables.outputs.WAZUH_REGISTRY }}
|
||||
INDEXER_USERNAME: admin
|
||||
INDEXER_PASSWORD: admin
|
||||
MANAGER_NODES: "master,worker01"
|
||||
API_USERNAME: wazuh-wui
|
||||
API_PASSWORD: wazuh-wui
|
||||
steps:
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: free disk space
|
||||
uses: ./.github/free-disk-space
|
||||
|
||||
- name: Configure aws credentials
|
||||
uses: aws-actions/configure-aws-credentials@v4
|
||||
with:
|
||||
role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }}
|
||||
aws-region: "${{ secrets.AWS_REGION }}"
|
||||
|
||||
- name: Log in to Amazon ECR
|
||||
uses: aws-actions/amazon-ecr-login@v2
|
||||
|
||||
- name: Download artifact_urls.yaml
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: presigned-artifact-urls-${{ github.run_id }}
|
||||
path: ./multi-node/
|
||||
|
||||
- name: Add environment variables into GITHUB_ENV
|
||||
run: |
|
||||
# Export variables to the environment
|
||||
awk -F':' '!/^#/ && NF>1 {name=$1; val=substr($0,length(name)+3); gsub(/[-.]/,"_",name); print name "=" val}' ${{ vars.ARTIFACT_URL_FILE_NAME }} >> "$GITHUB_ENV"
|
||||
working-directory: ./multi-node/
|
||||
|
||||
- name: Create multi node certficates
|
||||
run: |
|
||||
curl --output ./wazuh-certs-tool.sh "${{ env.wazuh_certs_tool }}"
|
||||
cat > config.yml <<EOF
|
||||
nodes:
|
||||
# Wazuh indexer server nodes
|
||||
indexer:
|
||||
- name: wazuh1.indexer
|
||||
dns: "wazuh1.indexer"
|
||||
- name: wazuh2.indexer
|
||||
dns: "wazuh2.indexer"
|
||||
- name: wazuh3.indexer
|
||||
dns: "wazuh3.indexer"
|
||||
|
||||
# Wazuh manager nodes
|
||||
# Use node_type only with more than one Wazuh manager
|
||||
manager:
|
||||
- name: wazuh.master
|
||||
dns: "wazuh.master"
|
||||
node_type: master
|
||||
- name: wazuh.worker
|
||||
dns: "wazuh.worker"
|
||||
node_type: worker
|
||||
|
||||
# Wazuh dashboard node
|
||||
dashboard:
|
||||
- name: wazuh.dashboard
|
||||
dns: "wazuh.dashboard"
|
||||
EOF
|
||||
cat config.yml
|
||||
sudo bash ../tools/utils/deployment/certificates-conf.sh --cert --copy --priv
|
||||
sudo sysctl -w vm.max_map_count=262144
|
||||
working-directory: ./multi-node
|
||||
|
||||
- name: Edit multi node docker-compose file
|
||||
shell: bash
|
||||
run: |
|
||||
TARGET_FILE="multi-node/docker-compose.yml"
|
||||
if [ -f "$TARGET_FILE" ]; then
|
||||
echo "Updating registry in $TARGET_FILE to: ${{ env.WAZUH_REGISTRY }}"
|
||||
sed -i "s|wazuh/wazuh-|${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-|g" "$TARGET_FILE"
|
||||
sed -i "s/\(.*wazuh\/wazuh-.*:\)${{ env.WAZUH_IMAGE_VERSION }}/\1${{ env.WAZUH_IMAGE_VERSION }}-latest/g" "$TARGET_FILE"
|
||||
else
|
||||
echo "File $TARGET_FILE not found"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Start multi node stack
|
||||
id: start_multi_node_stack
|
||||
run: docker compose up -d
|
||||
working-directory: ./multi-node
|
||||
|
||||
- name: Check Wazuh indexer start
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
for i in {1..20}; do
|
||||
echo "Checking Wazuh indexer health (Attempt $i/20)"
|
||||
RESPONSE=$(curl -XGET "https://127.0.0.1:9200/_cluster/health?pretty" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s --retry 2 || true)
|
||||
INDEXER_CONTAINERS=$(docker ps --format '{{.Names}}' | grep "indexer")
|
||||
if echo "$RESPONSE" | grep -qE "green|yellow"; then
|
||||
echo "Cluster Online"
|
||||
echo "$RESPONSE"
|
||||
exit 0
|
||||
fi
|
||||
echo "Waiting for cluster to be online"
|
||||
for CONTAINER_NAME in $INDEXER_CONTAINERS; do
|
||||
echo ""
|
||||
echo "========================================================="
|
||||
echo "Container logs for $CONTAINER_NAME"
|
||||
echo "========================================================="
|
||||
docker logs --tail 30 "$CONTAINER_NAME"
|
||||
echo "---------------------------------------------------------"
|
||||
done
|
||||
[ $i -lt 20 ] && sleep 60
|
||||
done
|
||||
status_index="`curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | wc -l`"
|
||||
status_index_green="`curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep -E "green" | wc -l`"
|
||||
if [[ $status_index_green -eq $status_index ]]; then
|
||||
curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s
|
||||
else
|
||||
curl -XGET "https://127.0.0.1:9200/_cat/indices" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh indexer nodes
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
nodes="`curl -XGET "https://127.0.0.1:9200/_cat/nodes" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep -E "indexer" | wc -l`"
|
||||
if [[ $nodes -eq 3 ]]; then
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
else
|
||||
echo "Wazuh indexer nodes: ${nodes}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh templates
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
qty_templates="`curl -XGET "https://127.0.0.1:9200/_cat/templates" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep "wazuh" | wc -l`"
|
||||
templates="`curl -XGET "https://127.0.0.1:9200/_cat/templates" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s | grep "wazuh"`"
|
||||
if [[ $qty_templates -gt 3 ]]; then
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
else
|
||||
echo "wazuh templates:"
|
||||
echo "${templates}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check Wazuh manager start
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
IFS=',' read -r -a NODES <<< "${{ env.MANAGER_NODES }}"
|
||||
for NODE in "${NODES[@]}"; do
|
||||
if [[ "$NODE" == "master" ]]; then
|
||||
THRESHOLD=8
|
||||
else
|
||||
THRESHOLD=7
|
||||
fi
|
||||
ok=false
|
||||
for i in {1..20}; do
|
||||
TOKEN=$(curl -s -u ${{ env.API_USERNAME }}:${{ env.API_PASSWORD }} -k -X POST "https://127.0.0.1:55000/security/user/authenticate?raw=true")
|
||||
services="`curl -k -s -X GET "https://127.0.0.1:55000/cluster/$NODE/status?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items | grep running | wc -l`"
|
||||
if [[ $services -ge $THRESHOLD ]]; then
|
||||
echo "Wazuh Manager $NODE Services: ${services}"
|
||||
echo "OK"
|
||||
ok=true
|
||||
break
|
||||
else
|
||||
curl -k -X GET "https://127.0.0.1:55000/cluster/$NODE/status?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items
|
||||
echo "Wazuh Manager $NODE Services: ${services}. Retrying in 30s"
|
||||
[ $i -lt 20 ] && sleep 30
|
||||
fi
|
||||
done
|
||||
if [[ "$ok" != "true" ]]; then
|
||||
echo "Error: Wazuh Manager $NODE did not reach expected running services threshold"
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
- name: Check Wazuh dashboard service URL
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
for i in {1..20}; do
|
||||
echo "Checking Wazuh dashboard (Attempt $i/20)"
|
||||
STATUS=$(curl -k -s -o /dev/null -w "%{http_code}" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} "https://127.0.0.1:443/app/status" || true)
|
||||
echo "Current status: $STATUS"
|
||||
if [[ "$STATUS" == "200" ]]; then
|
||||
echo "Wazuh dashboard is UP"
|
||||
exit 0
|
||||
elif [[ "$STATUS" == "429" || "$STATUS" == "503" ]]; then
|
||||
echo "Dashboard is busy or initializing (Status $STATUS). Retrying in 30s"
|
||||
else
|
||||
echo "Unexpected status $STATUS. Retrying in 30s"
|
||||
fi
|
||||
sleep 30
|
||||
done
|
||||
echo "Error: Dashboard did not reach 200 status in time."
|
||||
exit 1
|
||||
|
||||
- name: Modify Docker endpoint into Wazuh agent docker-compose.yml file
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: sed -i "s/<WAZUH_MANAGER_IP>/$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml
|
||||
|
||||
- name: Edit Wazuh agent docker-compose file
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
shell: bash
|
||||
env:
|
||||
WAZUH_REGISTRY: ${{ env.WAZUH_REGISTRY }}
|
||||
run: |
|
||||
TARGET_FILE="wazuh-agent/docker-compose.yml"
|
||||
if [ -f "$TARGET_FILE" ]; then
|
||||
echo "Updating registry in $TARGET_FILE to: ${{ env.WAZUH_REGISTRY }}"
|
||||
sed -i "s|wazuh/wazuh-|${{ env.WAZUH_REGISTRY }}/wazuh/wazuh-|g" "$TARGET_FILE"
|
||||
sed -i "s/\(.*wazuh\/wazuh-.*:\)${{ env.WAZUH_IMAGE_VERSION }}/\1${{ env.WAZUH_IMAGE_VERSION }}-latest/g" "$TARGET_FILE"
|
||||
else
|
||||
echo "File $TARGET_FILE not found"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Start Wazuh agent
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: docker compose -f wazuh-agent/docker-compose.yml up -d
|
||||
|
||||
- name: Check Wazuh agent enrollment
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
enrolled=false
|
||||
for i in {1..5}; do
|
||||
TOKEN=$(curl -s -u ${{ env.API_USERNAME }}:${{ env.API_PASSWORD }} -k -X POST "https://127.0.0.1:55000/security/user/authenticate?raw=true")
|
||||
agents="`curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}" | jq -r .data.affected_items | grep active | wc -l`"
|
||||
if [[ $agents -gt 0 ]]; then
|
||||
echo "Wazuh agents: ${agents}"
|
||||
echo "OK"
|
||||
enrolled=true
|
||||
break
|
||||
else
|
||||
curl -k -s -X GET "https://127.0.0.1:55000/agents?pretty=true" -H "Authorization: Bearer ${TOKEN}"
|
||||
echo "Wazuh agents: ${agents}. Retrying in 10s"
|
||||
[ $i -lt 5 ] && sleep 10
|
||||
fi
|
||||
done
|
||||
if [[ "$enrolled" != "true" ]]; then
|
||||
echo "Error: Wazuh agent enrollment did not reach expected active agents threshold"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Check errors in wazuh-manager.log for Wazuh manager
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: ./.github/multi-node-log-check.sh
|
||||
|
||||
- name: Check documents into wazuh-states index
|
||||
if: ${{ always() && steps.start_multi_node_stack.outcome == 'success' }}
|
||||
run: |
|
||||
for i in {1..20}; do
|
||||
echo "Checking documents in wazuh-states (Attempt $i/20)..."
|
||||
RESPONSE=$(curl -XGET "https://127.0.0.1:9200/wazuh-states*/_count" -u ${{ env.INDEXER_USERNAME }}:${{ env.INDEXER_PASSWORD }} -k -s || echo "{}")
|
||||
DOCS=$(echo "$RESPONSE" | jq -r '.count // 0')
|
||||
if [[ "$DOCS" -gt 0 ]]; then
|
||||
echo "wazuh-states index has documents: ${DOCS}"
|
||||
exit 0
|
||||
fi
|
||||
echo "The index is empty or does not exist yet (Count: $DOCS). Waiting 60s"
|
||||
[ $i -lt 20 ] && sleep 60
|
||||
done
|
||||
echo "Error: No documents found in wazuh-states after 20 attempts."
|
||||
echo "Last response: $RESPONSE"
|
||||
exit 1
|
||||
|
||||
- name: Docker logs
|
||||
if: always()
|
||||
continue-on-error: true
|
||||
run: |
|
||||
INDEXER_CONTAINERS=$(docker ps --format '{{.Names}}')
|
||||
for CONTAINER_NAME in $INDEXER_CONTAINERS; do
|
||||
echo ""
|
||||
echo "========================================================="
|
||||
echo "Container logs for $CONTAINER_NAME"
|
||||
echo "========================================================="
|
||||
docker logs "$CONTAINER_NAME"
|
||||
echo "---------------------------------------------------------"
|
||||
done
|
||||
working-directory: ./multi-node
|
||||
@@ -1,32 +0,0 @@
|
||||
name: PR Check - Docker Integration Tests
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
pr_head_ref:
|
||||
description: 'Branch of wazuh-docker to test'
|
||||
required: true
|
||||
type: string
|
||||
automation_reference:
|
||||
description: 'Branch of wazuh-automation to use'
|
||||
required: false
|
||||
default: 'main'
|
||||
type: string
|
||||
deployment_type:
|
||||
description: 'Deployment type to test'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- single-node
|
||||
- multi-node
|
||||
- both
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
placeholder:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- run: echo "Workflow registered. Use workflow_dispatch selecting the feature branch."
|
||||
+13
-981
File diff suppressed because it is too large
Load Diff
@@ -18,7 +18,7 @@ The `wazuh/wazuh-docker` repository provides resources to deploy the Wazuh cyber
|
||||
## Branch Convention
|
||||
|
||||
- `main`: Developing and testing of new features.
|
||||
- `X.Y.Z`: Version-specific branches (e.g., `5.0.0`, `4.14.0`, etc.).
|
||||
- `X.Y.Z`: Version-specific branches (e.g., `5.1.0`, `4.14.0`, etc.).
|
||||
|
||||
## Documentation
|
||||
|
||||
|
||||
+19
-8
@@ -1,6 +1,6 @@
|
||||
# Wazuh Open Source Project Security Policy
|
||||
|
||||
Version: 2023-06-12
|
||||
Version: 2026-07-06
|
||||
|
||||
## Introduction
|
||||
This document outlines the Security Policy for Wazuh's open source projects. It emphasizes our commitment to maintain a secure environment for our users and contributors, and reflects our belief in the power of collaboration to identify and resolve security vulnerabilities.
|
||||
@@ -13,16 +13,27 @@ If you believe you've discovered a potential security vulnerability in one of ou
|
||||
|
||||
Please submit your findings as security advisories under the "Security" tab in the relevant GitHub repository. Alternatively, you may send the details of your findings to [security@wazuh.com](mailto:security@wazuh.com).
|
||||
|
||||
## Reporting Vulnerabilities in Non-GA Versions
|
||||
|
||||
Wazuh publishes pre-release versions (Alphas, Betas, and Release Candidates) of its open source projects ahead of General Availability (GA) to gather community feedback. If you discover a potential security vulnerability in one of these non-GA versions, please report it following the process described above.
|
||||
|
||||
Upon receiving such a report, we will determine whether the vulnerability:
|
||||
|
||||
- **Affects only non-GA version(s)**: We will manage the report privately by opening a GitHub Security Advisory (GHSA). Since the affected code has not been part of a GA release, the vulnerability is not eligible for a CVE ID, consistent with the [CNA Operational Rules](https://www.cve.org/ResourcesSupport/AllResources/CNARules). Once resolved, the GHSA will be converted into a public issue instead of a security advisory.
|
||||
- **Also affects a previously released GA version**: We will continue managing the report as a GHSA and evaluate requesting a CVE ID for the GA-affected versions, in accordance with the eligibility criteria in the CNA Operational Rules.
|
||||
|
||||
## Vulnerability Disclosure Policy
|
||||
Upon receiving a report of a potential vulnerability, our team will initiate an investigation. If the reported issue is confirmed as a vulnerability, we will take the following steps:
|
||||
|
||||
1. Acknowledgment: We will acknowledge the receipt of your vulnerability report and begin our investigation.
|
||||
2. Validation: We will validate the issue and work on reproducing it in our environment.
|
||||
3. Remediation: We will work on a fix and thoroughly test it
|
||||
4. Release & Disclosure: After 90 days from the discovery of the vulnerability, or as soon as a fix is ready and thoroughly tested (whichever comes first), we will release a security update for the affected project. We will also publicly disclose the vulnerability by publishing a CVE (Common Vulnerabilities and Exposures) and acknowledging the discovering party.
|
||||
5. Exceptions: In order to preserve the security of the Wazuh community at large, we might extend the disclosure period to allow users to patch their deployments.
|
||||
1. **Acknowledgment**: We will acknowledge the receipt of your vulnerability report and begin our investigation.
|
||||
2. **Validation**: We will validate the issue and work on reproducing it in our environment.
|
||||
3. **Remediation**: We will develop a fix, have it reviewed, and merge it once thoroughly tested.
|
||||
4. **Release**: We will publish a security release for the affected project that includes the fix.
|
||||
5. **Rollout**: We will confirm that the fix has been applied to environments managed by Wazuh before proceeding with disclosure.
|
||||
6. **Disclosure**: Once the fix has been released and confirmed in managed environments, we will publicly disclose the vulnerability by publishing a CVE (Common Vulnerabilities and Exposures), where applicable, and acknowledging the discovering party.
|
||||
7. **Exceptions**: In order to preserve the security of the Wazuh community at large, we might extend the disclosure period to allow users to patch their deployments.
|
||||
|
||||
This 90-day period allows for end-users to update their systems and minimizes the risk of widespread exploitation of the vulnerability.
|
||||
Steps 1 through 6 will be completed within 90 days from the report of the vulnerability. This period allows for end-users to update their systems and minimizes the risk of widespread exploitation of the vulnerability.
|
||||
|
||||
## Automatic Scanning
|
||||
We leverage GitHub Actions to perform automated scans of our supply chain. These scans assist us in identifying vulnerabilities and outdated dependencies in a proactive and timely manner.
|
||||
@@ -42,4 +53,4 @@ We ask that all users and contributors respect this policy and the security of o
|
||||
## Changes to this Security Policy
|
||||
This policy may be revised from time to time. Each version of the policy will be identified at the top of the page by its effective date.
|
||||
|
||||
If you have any questions about this Security Policy, please contact us at [security@wazuh.com](mailto:security@wazuh.com)
|
||||
If you have any questions about this Security Policy, please contact us at [security@wazuh.com](mailto:security@wazuh.com)
|
||||
+3
-3
@@ -1,4 +1,4 @@
|
||||
{
|
||||
"version": "5.0.0",
|
||||
"stage": "beta2"
|
||||
}
|
||||
"version": "5.1.0",
|
||||
"stage": "alpha0"
|
||||
}
|
||||
|
||||
@@ -8,13 +8,13 @@
|
||||
# License (version 2) as published by the FSF - Free Software
|
||||
# Foundation.
|
||||
|
||||
WAZUH_IMAGE_VERSION=5.0.0
|
||||
IMAGE_TAG=5.0.0
|
||||
WAZUH_IMAGE_VERSION=5.1.0
|
||||
IMAGE_TAG=5.1.0
|
||||
WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '["]tag_name["]:' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g')
|
||||
IMAGE_VERSION=${WAZUH_IMAGE_VERSION}
|
||||
WAZUH_REGISTRY=docker.io
|
||||
|
||||
WAZUH_IMAGE_VERSION="5.0.0"
|
||||
WAZUH_IMAGE_VERSION="5.1.0"
|
||||
WAZUH_DEV_STAGE=""
|
||||
WAZUH_COMPONENTS_COMMIT_LIST=''
|
||||
IS_DEV_BUILD=""
|
||||
@@ -38,11 +38,11 @@ ctrl_c() {
|
||||
|
||||
build() {
|
||||
|
||||
# WAZUH_MINOR_VERSION: Extracts major and minor version only (e.g., 5.0.0 -> 5.0)
|
||||
# WAZUH_MINOR_VERSION: Extracts major and minor version only (e.g., 5.1.0 -> 5.0)
|
||||
WAZUH_MINOR_VERSION="${WAZUH_IMAGE_VERSION%.*}"
|
||||
# WAZUH_MAJOR_VERSION: Extracts major version only (e.g., 5.0.0 -> 5)
|
||||
# WAZUH_MAJOR_VERSION: Extracts major version only (e.g., 5.1.0 -> 5)
|
||||
WAZUH_MAJOR_VERSION="${WAZUH_IMAGE_VERSION%%.*}"
|
||||
# WAZUH_STAGE: Extract the 'stage' (e.g., alpha0, beta2, rc2) from the local JSON metadata file.
|
||||
# WAZUH_STAGE: Extract the 'stage' (e.g., alpha0, beta1, rc2) from the local JSON metadata file.
|
||||
# Note: This is primarily used for pre-release package naming.
|
||||
WAZUH_STAGE=$(jq -r '.stage' ../VERSION.json)
|
||||
# ARTIFACT_URLS_FILE: The name of the artifact URLs file.
|
||||
@@ -192,10 +192,10 @@ build() {
|
||||
|
||||
# Generate per-component image tags.
|
||||
# The commit suffix is only appended when --dev is passed. This ensures:
|
||||
# dev=false, tag=5.0.0 → 5.0.0
|
||||
# dev=false, tag=5.0.0-beta2 → 5.0.0-beta2
|
||||
# dev=true, tag=5.0.0 → 5.0.0-latest
|
||||
# dev=true, tag=5.0.0-beta2 → 5.0.0-beta2-latest
|
||||
# dev=false, tag=5.1.0 → 5.1.0
|
||||
# dev=false, tag=5.1.0-beta1 → 5.1.0-beta1
|
||||
# dev=true, tag=5.1.0 → 5.1.0-latest
|
||||
# dev=true, tag=5.1.0-beta1 → 5.1.0-beta1-latest
|
||||
make_tag() {
|
||||
local commit=$1
|
||||
if [ -n "${IS_DEV_BUILD}" ]; then
|
||||
@@ -248,7 +248,7 @@ help() {
|
||||
echo
|
||||
echo "Usage: $0 [OPTIONS]"
|
||||
echo
|
||||
echo " -d, --dev-stage <ref> [Optional] Set the pre-release stage suffix (e.g. beta2, rc2). Not used by default."
|
||||
echo " -d, --dev-stage <ref> [Optional] Set the pre-release stage suffix (e.g. beta1, rc2). Not used by default."
|
||||
echo " --dev [Optional] Mark as a development build: appends the commit ref to the image tag. Controlled by inputs.dev in the workflow."
|
||||
echo " -refs, --references <refs> [Optional] [Only with --dev] JSON array of commit refs for components (indexer, manager, dashboard, agent) in order. Defaults to 'latest'."
|
||||
echo " -rg, --registry <reg> [Optional] Set the Docker registry to push the images."
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
|
||||
# ── Global variables ──────────────────────────────────────────────────────────
|
||||
|
||||
variable "WAZUH_VERSION" { default = "5.0.0" }
|
||||
variable "WAZUH_VERSION" { default = "5.1.0" }
|
||||
variable "WAZUH_REGISTRY" { default = "docker.io" }
|
||||
|
||||
# Set IMAGE_TAG externally to override; defaults to WAZUH_VERSION.
|
||||
@@ -23,7 +23,7 @@ variable "MULTIARCH" { default = "" }
|
||||
|
||||
# Per-component tags — all default to IMAGE_TAG.
|
||||
# In dev builds the shell script sets each one independently to append the
|
||||
# per-component commit ref (e.g. MANAGER_TAG=5.0.0-beta2-abc1234).
|
||||
# per-component commit ref (e.g. MANAGER_TAG=5.1.0-beta1-abc1234).
|
||||
variable "INDEXER_TAG" { default = IMAGE_TAG }
|
||||
variable "MANAGER_TAG" { default = IMAGE_TAG }
|
||||
variable "DASHBOARD_TAG" { default = IMAGE_TAG }
|
||||
|
||||
@@ -36,8 +36,7 @@ RUN dnf install procps shadow-utils -y && \
|
||||
curl -o /wazuh-agent.rpm "${agent_url}" && \
|
||||
dnf install /wazuh-agent.rpm -y && \
|
||||
rm -rf /wazuh-agent.rpm && \
|
||||
dnf clean all && \
|
||||
sed -i '/<authorization_pass_path>/d' /var/ossec/etc/ossec.conf
|
||||
dnf clean all
|
||||
|
||||
# Download tini static binary (no external library dependencies)
|
||||
RUN curl --fail --silent -L \
|
||||
|
||||
@@ -62,6 +62,15 @@ set_manager_conn() {
|
||||
sed -i "s#<address>CHANGE_MANAGER_IP</address>#<address>$WAZUH_MANAGER_SERVER</address>#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf
|
||||
sed -i "s#<manager_address>CHANGE_ENROLL_IP</manager_address>#<manager_address>$WAZUH_REGISTRATION_SERVER</manager_address>#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf
|
||||
sed -i "s#<agent_name>CHANGE_AGENT_NAME</agent_name>#<agent_name>$WAZUH_AGENT_NAME</agent_name>#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf
|
||||
if [ -n "$WAZUH_REGISTRATION_PASSWORD" ]; then
|
||||
set +x
|
||||
cat << EOF > /var/ossec/etc/authd.pass
|
||||
$WAZUH_REGISTRATION_PASSWORD
|
||||
EOF
|
||||
set -x
|
||||
else
|
||||
echo "WAZUH_REGISTRATION_PASSWORD is not set; the authd.pass configuration is omitted."
|
||||
fi
|
||||
}
|
||||
|
||||
##############################################################################
|
||||
|
||||
@@ -46,8 +46,7 @@ RUN setcap 'cap_net_bind_service=-ep' /usr/share/wazuh-dashboard/node/bin/node
|
||||
|
||||
################################################################################
|
||||
# Build stage 1 (the current Wazuh dashboard image):
|
||||
#
|
||||
# Copy wazuh-dashboard from stage 0
|
||||
# Copy wazuh-dashboard from builder
|
||||
# Add entrypoint
|
||||
# Add wazuh_dashboard_config
|
||||
################################################################################
|
||||
|
||||
@@ -41,8 +41,7 @@ RUN yum install curl-minimal shadow-utils findutils hostname -y && \
|
||||
|
||||
################################################################################
|
||||
# Build stage 1 (the actual Wazuh indexer image):
|
||||
#
|
||||
# Copy wazuh-indexer from stage 0
|
||||
# Copy wazuh-indexer from builder
|
||||
# Add entrypoint
|
||||
################################################################################
|
||||
FROM amazonlinux:2023
|
||||
|
||||
@@ -252,9 +252,9 @@ configure_permissions() {
|
||||
##############################################################################
|
||||
|
||||
set_correct_permOwner() {
|
||||
find /var/wazuh-manager/ -group 997 -exec chown :101 {} +;
|
||||
find /var/wazuh-manager/ -group 999 -exec chown :101 {} +;
|
||||
find /var/wazuh-manager/ -user 999 -exec chown 101:{} +;
|
||||
find /var/wazuh-manager/ -group 997 -exec chown :101 {} +
|
||||
find /var/wazuh-manager/ -group 999 -exec chown :101 {} +
|
||||
find /var/wazuh-manager/ -user 999 -exec chown 101 {} +
|
||||
}
|
||||
|
||||
##############################################################################
|
||||
|
||||
@@ -30,3 +30,9 @@
|
||||
- [Security](ref/security.md)
|
||||
- [Performance](ref/performance.md)
|
||||
- [Glossary](ref/glossary.md)
|
||||
|
||||
---
|
||||
|
||||
# Integration Tests
|
||||
|
||||
- [Docker Integration Tests](ref/integration_test/docker_integration_tests.md)
|
||||
|
||||
@@ -19,7 +19,7 @@ Then execute:
|
||||
The script also allows to build images from other versions of Wazuh by using the `-v` or `--version` argument:
|
||||
|
||||
```bash
|
||||
./build-images.sh -v 5.0.0
|
||||
./build-images.sh -v 5.1.0
|
||||
```
|
||||
|
||||
To get all the available script options use the `-h` or `--help` option:
|
||||
@@ -29,10 +29,10 @@ To get all the available script options use the `-h` or `--help` option:
|
||||
|
||||
Usage: build-images.sh [OPTIONS]
|
||||
|
||||
-d, --dev <ref> [Optional] Set the development stage you want to build, example rc2 or beta2, not used by default.
|
||||
-d, --dev <ref> [Optional] Set the development stage you want to build, example rc2 or beta1, not used by default.
|
||||
-refs, --references <ref> [Optional] Set each Wazuh component reference to be build (indexer, manager, dasboard and agent). By default, using the latest release: ['latest', 'latest', 'latest', 'latest']
|
||||
-rg, --registry <reg> [Optional] Set the Docker registry to push the images.
|
||||
-v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, 5.0.0.
|
||||
-v, --version <ver> [Optional] Set the Wazuh version should be builded. By default, 5.1.0.
|
||||
-m, --multiarch [Optional] Enable multi-architecture builds.
|
||||
-h, --help Show this help.
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Development Guide - Introduction
|
||||
|
||||
Welcome to the Development Guide for Wazuh-docker version 5.0.0 This guide is intended for developers, contributors, and advanced users who wish to understand the development aspects of the Wazuh-Docker project, build custom Docker images, or contribute to its development.
|
||||
Welcome to the Development Guide for Wazuh-docker version 5.1.0 This guide is intended for developers, contributors, and advanced users who wish to understand the development aspects of the Wazuh-Docker project, build custom Docker images, or contribute to its development.
|
||||
|
||||
## Purpose of This Guide
|
||||
|
||||
|
||||
+3
-3
@@ -1,6 +1,6 @@
|
||||
# Development Guide - Setup Environment
|
||||
|
||||
This section outlines the steps required to set up your local development environment for working with the Wazuh-Docker project (version 5.0.0). A proper setup is crucial for building images, running tests, and contributing effectively.
|
||||
This section outlines the steps required to set up your local development environment for working with the Wazuh-Docker project (version 5.1.0). A proper setup is crucial for building images, running tests, and contributing effectively.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
@@ -26,12 +26,12 @@ Before you begin, ensure your system meets the following requirements:
|
||||
Follow these steps to prepare your development environment:
|
||||
|
||||
1. **Clone the Repository**:
|
||||
Clone the `wazuh-docker` repository from GitHub. It's important to check out the specific branch you intend to work with, in this case, `5.0.0`.
|
||||
Clone the `wazuh-docker` repository from GitHub. It's important to check out the specific branch you intend to work with, in this case, `5.1.0`.
|
||||
|
||||
```bash
|
||||
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
||||
cd wazuh-docker
|
||||
git checkout v5.0.0
|
||||
git checkout v5.1.0
|
||||
```
|
||||
|
||||
2. **Verify Docker Installation**:
|
||||
|
||||
@@ -6,7 +6,7 @@ The Procedure_push_docker_images.yml workflow builds and pushes multi-architectu
|
||||
|
||||
| Parameter | Description | Default | Required |
|
||||
|-----------|-------------|---------|----------|
|
||||
| `image_tag` | Docker image version tag | `5.0.0` | Yes |
|
||||
| `image_tag` | Docker image version tag | `5.1.0` | Yes |
|
||||
| `docker_reference` | Branch/tag to build from | - | Yes |
|
||||
| `reference` | Dev reference (for pre-release builds) | `latest` | No |
|
||||
| `id` | Workflow run identifier | - | No |
|
||||
|
||||
@@ -2,5 +2,5 @@
|
||||
|
||||
For backup and restore, refer to the documentation for each component:
|
||||
|
||||
- [Wazuh manager](https://github.com/wazuh/wazuh/blob/v5.0.0/docs/ref/backup-restore.md)
|
||||
- [Wazuh agent](https://github.com/wazuh/wazuh-agent/blob/v5.0.0/docs/ref/backup-restore.md)
|
||||
- [Wazuh manager](https://github.com/wazuh/wazuh/blob/v5.1.0/docs/ref/backup-restore.md)
|
||||
- [Wazuh agent](https://github.com/wazuh/wazuh-agent/blob/v5.1.0/docs/ref/backup-restore.md)
|
||||
|
||||
@@ -28,7 +28,7 @@
|
||||
docker compose up -d
|
||||
```
|
||||
|
||||
Consult the official Wazuh documentation for version 5.0.0 for detailed information on all possible configuration parameters for each component.
|
||||
Consult the official Wazuh documentation for version 5.1.0 for detailed information on all possible configuration parameters for each component.
|
||||
|
||||
## Persistence configuration
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reference Manual - Configuration
|
||||
|
||||
This section details how to configure your Wazuh-Docker deployment (version 5.0.0). Proper configuration is key to tailoring the Wazuh stack to your specific needs, managing data persistence, and integrating with your environment.
|
||||
This section details how to configure your Wazuh-Docker deployment (version 5.1.0). Proper configuration is key to tailoring the Wazuh stack to your specific needs, managing data persistence, and integrating with your environment.
|
||||
|
||||
## Overview of Configuration Methods
|
||||
|
||||
|
||||
@@ -21,8 +21,8 @@ The Wazuh Manager container accepts the following environment variables, which c
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=SecretPassword
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
- WAZUH_API_URL=https://wazuh.manager
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
@@ -30,7 +30,7 @@ environment:
|
||||
|
||||
**Variable Descriptions:**
|
||||
|
||||
- `INDEXER_USERNAME` / `INDEXER_PASSWORD`: Credentials for accessing the Wazuh Indexer with `admin` user or a user with the same permissions.
|
||||
- `INDEXER_USERNAME` / `INDEXER_PASSWORD`: Credentials for accessing the Wazuh Indexer with `wazuh-manager` user or a user with the same permissions.
|
||||
- `WAZUH_API_URL`: URL of the Wazuh API, used by other services for communication.
|
||||
- `DASHBOARD_USERNAME` / `DASHBOARD_PASSWORD`: Credentials for the Wazuh Dashboard to authenticate with the Indexer.
|
||||
|
||||
@@ -57,8 +57,8 @@ The Wazuh Dashboard container accepts the following environment variables, which
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=SecretPassword
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
- WAZUH_API_URL=https://wazuh.manager
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reference Manual - Deployment
|
||||
|
||||
This section provides detailed instructions for deploying Wazuh-Docker (version 5.0.0) in various configurations. Choose the deployment model that best suits your needs, from simple single-node setups for testing to more robust multi-node configurations for production environments.
|
||||
This section provides detailed instructions for deploying Wazuh-Docker (version 5.1.0) in various configurations. Choose the deployment model that best suits your needs, from simple single-node setups for testing to more robust multi-node configurations for production environments.
|
||||
|
||||
## Overview of Deployment Options
|
||||
|
||||
@@ -24,11 +24,11 @@ Ensure you have:
|
||||
|
||||
- Met all the [System Requirements](../requirements.md).
|
||||
- Installed Docker and Docker Compose on your host(s).
|
||||
- Cloned the `wazuh-docker` repository (version `5.0.0`) or downloaded the necessary deployment files.
|
||||
- Cloned the `wazuh-docker` repository (version `5.1.0`) or downloaded the necessary deployment files.
|
||||
```bash
|
||||
git clone https://github.com/wazuh/wazuh-docker.git
|
||||
cd wazuh-docker
|
||||
git checkout v5.0.0
|
||||
git checkout v5.1.0
|
||||
```
|
||||
- Made a backup of any existing Wazuh data if you are migrating or upgrading.
|
||||
|
||||
|
||||
@@ -21,8 +21,8 @@ This deployment utilizes the `multi-node/docker-compose.yml` file, which defines
|
||||
3. Download the certificate creation script and config.yml file:
|
||||
|
||||
```bash
|
||||
curl -o wazuh-certs-tool.sh https://packages.wazuh.com/5.0/wazuh-certs-tool-5.0.0-1.sh
|
||||
curl -o config.yml https://packages.wazuh.com/5.0/config-5.0.0-1.yml
|
||||
curl -o wazuh-certs-tool.sh https://packages.wazuh.com/5.0/wazuh-certs-tool-5.1.0-1.sh
|
||||
curl -o config.yml https://packages.wazuh.com/5.0/config-5.1.0-1.yml
|
||||
```
|
||||
|
||||
4. Edit the `config.yml` file with the configuration of the Wazuh components to be deployed
|
||||
|
||||
@@ -21,8 +21,8 @@ This deployment uses the `single-node/docker-compose.yml` file, which defines a
|
||||
3. Download the certificate creation script and `config.yml` file:
|
||||
|
||||
```bash
|
||||
curl -o wazuh-certs-tool.sh https://packages.wazuh.com/5.0/wazuh-certs-tool-5.0.0-1.sh
|
||||
curl -o config.yml https://packages.wazuh.com/5.0/config-5.0.0-1.yml
|
||||
curl -o wazuh-certs-tool.sh https://packages.wazuh.com/5.0/wazuh-certs-tool-5.1.0-1.sh
|
||||
curl -o config.yml https://packages.wazuh.com/5.0/config-5.1.0-1.yml
|
||||
```
|
||||
|
||||
4. Edit the config.yml file with the configuration of the Wazuh components to be deployed
|
||||
|
||||
@@ -19,9 +19,11 @@ Follow these steps to deploy the Wazuh agent using Docker.
|
||||
# ...
|
||||
environment:
|
||||
- WAZUH_MANAGER_SERVER=<YOUR_WAZUH_MANAGER_IP_OR_HOSTNAME>
|
||||
- WAZUH_REGISTRATION_PASSWORD=<authd.pass-PASSWORD>
|
||||
# ...
|
||||
```
|
||||
**Note:** Replace `<YOUR_WAZUH_MANAGER_IP_OR_HOSTNAME>` with the actual IP address or hostname of your Wazuh manager.
|
||||
**Note:** Replaces `<YOUR_WAZUH_MANAGER_IP_OR_HOSTNAME>` with the actual IP address or hostname of your Wazuh manager.
|
||||
**Note:** Replaces `<authd.pass-PASSWORD>` with the password configured in the `/var/wazuh-manager/etc/authd.pass` file of the Wazuh manager server where you will connect.
|
||||
|
||||
3. Start the environment using `docker compose`:
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reference Manual - Getting Started
|
||||
|
||||
This section guides you through the initial steps to get your Wazuh-docker (version 5.0.0) environment up and running. We will cover the prerequisites and point you to the deployment instructions.
|
||||
This section guides you through the initial steps to get your Wazuh-docker (version 5.1.0) environment up and running. We will cover the prerequisites and point you to the deployment instructions.
|
||||
|
||||
## Overview
|
||||
|
||||
@@ -27,11 +27,11 @@ Before diving into the deployment, please ensure you have reviewed:
|
||||
Verify that your host system has sufficient RAM, CPU, and disk space. Ensure Docker and Docker Compose are installed and functioning correctly.
|
||||
|
||||
2. **Obtain Wazuh-docker Configuration**:
|
||||
You'll need the Docker Compose files and any associated configuration files from the `wazuh-docker` repository for version 5.0.0.
|
||||
You'll need the Docker Compose files and any associated configuration files from the `wazuh-docker` repository for version 5.1.0.
|
||||
```bash
|
||||
git clone [https://github.com/wazuh/wazuh-docker.git](https://github.com/wazuh/wazuh-docker.git)
|
||||
cd wazuh-docker
|
||||
git checkout v5.0.0
|
||||
git checkout v5.1.0
|
||||
# Navigate to the specific docker-compose directory, e.g., single-node or multi-node
|
||||
# cd docker-compose/single-node/ (example path)
|
||||
```
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reference Manual - Requirements
|
||||
|
||||
Before deploying Wazuh-Docker (version 5.0.0), it's essential to ensure your environment meets the necessary hardware and software requirements. Meeting these prerequisites will help ensure a stable and performant Wazuh deployment.
|
||||
Before deploying Wazuh-Docker (version 5.1.0), it's essential to ensure your environment meets the necessary hardware and software requirements. Meeting these prerequisites will help ensure a stable and performant Wazuh deployment.
|
||||
|
||||
## Host System Requirements
|
||||
|
||||
@@ -53,7 +53,7 @@ These are general recommendations. Actual needs may vary based on the number of
|
||||
* **Docker Desktop**
|
||||
* Install Docker Desktop by following the official instructions: [Install Docker Desktop](https://docs.docker.com/desktop/setup/install/windows-install/).
|
||||
* **WSL Linux distribution**
|
||||
* Install Ubuntu or other compatible Linux distribution (bash in Alpine is not compatible with wazuh-certs-tool-5.0.0-1.sh): [Install Ubuntu on WSL](https://documentation.ubuntu.com/wsl/stable/howto/install-ubuntu-wsl2/)
|
||||
* Install Ubuntu or other compatible Linux distribution (bash in Alpine is not compatible with wazuh-certs-tool-5.1.0-1.sh): [Install Ubuntu on WSL](https://documentation.ubuntu.com/wsl/stable/howto/install-ubuntu-wsl2/)
|
||||
* **Git Client**:
|
||||
* Required for cloning the `wazuh-docker` repository.
|
||||
* **Web Browser**:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reference Manual - Glossary
|
||||
|
||||
This glossary defines key terms and concepts related to Wazuh, Docker, and their use together in the Wazuh-Docker project (version 5.0.0).
|
||||
This glossary defines key terms and concepts related to Wazuh, Docker, and their use together in the Wazuh-Docker project (version 5.1.0).
|
||||
|
||||
---
|
||||
|
||||
@@ -22,7 +22,7 @@ This glossary defines key terms and concepts related to Wazuh, Docker, and their
|
||||
|
||||
**D**
|
||||
|
||||
- **Dashboard (Wazuh Dashboard / OpenSearch Dashboards / Kibana)**: A web-based visualization tool used to explore, analyze, and visualize data stored in the Wazuh Indexer. It provides dashboards, visualizations, and a query interface for security events and alerts. For Wazuh 5.0.0, this is typically OpenSearch Dashboards.
|
||||
- **Dashboard (Wazuh Dashboard / OpenSearch Dashboards / Kibana)**: A web-based visualization tool used to explore, analyze, and visualize data stored in the Wazuh Indexer. It provides dashboards, visualizations, and a query interface for security events and alerts. For Wazuh 5.1.0, this is typically OpenSearch Dashboards.
|
||||
- **Decoder**: A component in the Wazuh Manager that parses and extracts relevant information (fields) from raw log messages or event data.
|
||||
- **Docker**: An open platform for developing, shipping, and running applications inside containers.
|
||||
- **Docker Compose**: A tool for defining and running multi-container Docker applications. It uses a YAML file (`docker-compose.yml`) to configure the application's services, networks, and volumes.
|
||||
@@ -42,7 +42,7 @@ This glossary defines key terms and concepts related to Wazuh, Docker, and their
|
||||
|
||||
**I**
|
||||
|
||||
- **Indexer (Wazuh Indexer / OpenSearch / Elasticsearch)**: The component responsible for storing, indexing, and making searchable the alerts and event data generated by the Wazuh Manager. For Wazuh 5.0.0, this is typically OpenSearch.
|
||||
- **Indexer (Wazuh Indexer / OpenSearch / Elasticsearch)**: The component responsible for storing, indexing, and making searchable the alerts and event data generated by the Wazuh Manager. For Wazuh 5.1.0, this is typically OpenSearch.
|
||||
|
||||
**L**
|
||||
|
||||
|
||||
@@ -0,0 +1,332 @@
|
||||
# Docker Integration Tests
|
||||
|
||||
Workflow file: `.github/workflows/5_check_integration_tools.yml`
|
||||
|
||||
This workflow optionally builds Docker images from the PR branch, provisions a dedicated AWS VM, deploys the Wazuh Docker stack (single-node or multi-node), and runs the integration test suite against it via SSH.
|
||||
|
||||
---
|
||||
|
||||
## Triggers
|
||||
|
||||
| Mode | Trigger | Who can trigger |
|
||||
|---|---|---|
|
||||
| PR comment | `issue_comment` on an open, non-draft PR | Any repo collaborator |
|
||||
| Manual | `workflow_dispatch` | Anyone with repo write access |
|
||||
|
||||
---
|
||||
|
||||
## Execution Flows
|
||||
|
||||
### issue_comment flow
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
A[PR comment posted] --> B{Recognized command\non open non-draft PR?}
|
||||
B -- No --> Z[Ignored]
|
||||
B -- Yes --> C[get_pr_info\nReact · Extract PR data\nParse command · Create Check Run]
|
||||
C --> D[prepare\nResolve branch · Read VERSION.json]
|
||||
D --> E[build_images\nBuild + push to ECR\nalways runs on PR comment]
|
||||
E --> F{deployment_matrix}
|
||||
F --> G[docker_test\nsingle-node]
|
||||
F --> H[docker_test\nmulti-node]
|
||||
G --> I[update_check]
|
||||
H --> I
|
||||
```
|
||||
|
||||
**Recognized commands:**
|
||||
|
||||
| Comment | Deployment matrix |
|
||||
|---|---|
|
||||
| `/test-docker` | `["single-node","multi-node"]` |
|
||||
| `/test-docker-single` | `["single-node"]` |
|
||||
| `/test-docker-multi` | `["multi-node"]` |
|
||||
|
||||
When triggered by PR comment, `build_images` **always** runs — images are always built from the PR branch and pushed to ECR.
|
||||
|
||||
### workflow_dispatch flow
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
A[Manual trigger] --> D[prepare\nResolve branch · Read VERSION.json]
|
||||
D --> E{Build needed?\nno version + no stage\n+ registry=ECR}
|
||||
E -- Yes --> F[build_images\nBuild + push to ECR]
|
||||
E -- No --> G{deployment_type input}
|
||||
F --> G
|
||||
G -- single-node --> H[docker_test\nsingle-node]
|
||||
G -- multi-node --> I[docker_test\nmulti-node]
|
||||
G -- both --> H & I
|
||||
```
|
||||
|
||||
`build_images` is **skipped** when either `version` or `stage` is provided, or when `registry = DockerHub`.
|
||||
|
||||
---
|
||||
|
||||
## Parameters
|
||||
|
||||
### workflow_dispatch inputs
|
||||
|
||||
| Input | Required | Default | Description |
|
||||
|---|---|---|---|
|
||||
| `pr_head_ref` | Yes | — | Branch of `wazuh-docker` to test |
|
||||
| `automation_reference` | No | `main` | Branch of `wazuh-automation` to use |
|
||||
| `deployment_type` | Yes | — | `single-node`, `multi-node`, or `both` |
|
||||
| `version` | No | — | Override image version (e.g. `5.1.0`). If empty, reads from `VERSION.json` |
|
||||
| `stage` | No | — | Image stage suffix (e.g. `beta1`, `beta2-latest`). Required when `version` is set |
|
||||
| `registry` | No | `ECR` | `ECR` (dev/built images) or `DockerHub` (released images) |
|
||||
|
||||
### issue_comment parameters
|
||||
|
||||
All parameters are derived automatically:
|
||||
|
||||
| Parameter | Source |
|
||||
|---|---|
|
||||
| `pr_head_ref` | PR head branch from GitHub API |
|
||||
| `deployment_matrix` | Parsed from comment command |
|
||||
| `version` / `stage` | Read from `VERSION.json` on the PR branch |
|
||||
| `registry` | Always ECR (images are always built) |
|
||||
| `automation_reference` | Always `main` |
|
||||
|
||||
---
|
||||
|
||||
## Image Resolution Scenarios
|
||||
|
||||
The workflow distinguishes five cases based on inputs:
|
||||
|
||||
| Case | `version` input | `stage` input | Registry | Action | Image tag |
|
||||
|---|---|---|---|---|---|
|
||||
| a.1 | empty | empty | ECR (or PR comment) | **BUILD** from PR → ECR | `{version}-{stage}-latest` |
|
||||
| a.2 | empty | empty | DockerHub | Pull (no build) | `{version}-{stage}` |
|
||||
| b.1 | set | empty | ECR | Pull (no build) | `{version}-latest` |
|
||||
| b.2 | set | empty | DockerHub | Pull (no build) | `{version}` |
|
||||
| c | set or empty | set | ECR or DockerHub | Pull (no build) | `{version}-{stage}` |
|
||||
|
||||
> When neither `version` nor `stage` is set, `version` and `stage` are read from `VERSION.json` on the target branch.
|
||||
|
||||
> Case a.1 always applies when triggered by PR comment, regardless of the `registry` input (which is not available in that trigger mode).
|
||||
|
||||
---
|
||||
|
||||
## Job Details
|
||||
|
||||
### Job 1 — `get_pr_info` (issue_comment only)
|
||||
|
||||
| Step | What it does |
|
||||
|---|---|
|
||||
| React to comment | Adds a 🚀 reaction to the triggering PR comment |
|
||||
| Extract PR data | Calls GitHub API to get PR `head_ref` and `head_sha` |
|
||||
| Parse command | Maps comment text → `deployment_matrix` JSON and `check_name` string |
|
||||
| Create Check Run | Creates a GitHub Check Run in `in_progress` state on the PR head SHA |
|
||||
|
||||
### Job 2 — `prepare` (both triggers)
|
||||
|
||||
| Step | What it does |
|
||||
|---|---|
|
||||
| Resolve context | Reads inputs (workflow_dispatch) or `get_pr_info` outputs (issue_comment) |
|
||||
| Checkout `VERSION.json` | Sparse-checks out only `VERSION.json` from the target branch |
|
||||
| Read version info | Extracts `version` and `stage` from `VERSION.json` |
|
||||
| Show test plan | Logs the resolved image case (a.1/a.2/b.1/b.2/c) and writes a summary table |
|
||||
|
||||
Outputs: `pr_head_ref`, `deployment_matrix`, `wazuh_version`, `wazuh_stage`.
|
||||
|
||||
### Job 3 — `build_images` (conditional)
|
||||
|
||||
Calls the reusable workflow `.github/workflows/5_build_and_push_images.yml`.
|
||||
|
||||
**Runs when:** `version == ''` AND `stage == ''` AND (`registry == 'ECR'` OR `github.event_name == 'issue_comment'`).
|
||||
|
||||
**Skipped when:** any explicit `version` or `stage` is provided, or `registry = DockerHub`.
|
||||
|
||||
| Parameter passed | Value |
|
||||
|---|---|
|
||||
| `image_tag` | `{wazuh_version}-{wazuh_stage}` |
|
||||
| `docker_reference` | `pr_head_ref` |
|
||||
| `wazuh_automation_reference` | `automation_reference` input |
|
||||
| `products` | `wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent` |
|
||||
| `dev` | `true` |
|
||||
| `id` | `docker-integration-{run_id}` |
|
||||
|
||||
### Job 4 — `docker_test` (matrix, both triggers)
|
||||
|
||||
Runs once per entry in `deployment_matrix`. Each instance provisions its own VM.
|
||||
|
||||
#### Setup
|
||||
|
||||
1. Checkout `wazuh-automation` at `automation_reference`
|
||||
2. Checkout `wazuh-docker` at `pr_head_ref`
|
||||
3. Resolve image configuration (see [Image Resolution Scenarios](#image-resolution-scenarios)) → sets `DOCKER_REGISTRY`, `DOCKER_TAG`, `DOCKER_VERSION`
|
||||
4. Set up Python 3.12 and install `test_runner`
|
||||
5. Configure AWS credentials via OIDC (`AWS_IAM_DOCKER_ROLE`)
|
||||
|
||||
#### Instance allocation
|
||||
|
||||
Provisions a dedicated AWS VM using the `deployability` allocator module:
|
||||
|
||||
```bash
|
||||
python3 wazuh-automation/deployability/modules/allocation/main.py \
|
||||
--action create \
|
||||
--provider aws \
|
||||
--size large \
|
||||
--composite-name ubuntu-24-amd64 \
|
||||
--instance-name gha_{run_id}_docker_{deployment_type} \
|
||||
--label-team devops \
|
||||
--label-termination-date 1d
|
||||
```
|
||||
|
||||
The allocator writes `inventory.yml` with the SSH connection details (`ansible_host`, `ansible_port`, `ansible_user`, `ansible_ssh_private_key_file`). These are extracted and exported as `SSH_HOST`, `SSH_PORT`, `SSH_USER`, `SSH_KEY` environment variables.
|
||||
|
||||
#### VM configuration and Docker install
|
||||
|
||||
All subsequent steps run on the remote VM over SSH:
|
||||
|
||||
1. **Install Docker CE**: `curl -fsSL https://get.docker.com | sudo sh`
|
||||
2. **Login to ECR** (when registry is ECR or trigger is issue_comment): authenticates the VM's Docker daemon to the dev registry
|
||||
3. **Set `vm.max_map_count=262144`**: required for OpenSearch/Wazuh Indexer
|
||||
|
||||
#### Certificate generation and config
|
||||
|
||||
Runs on the **runner** (not the VM):
|
||||
|
||||
1. **Download `wazuh-certs-tool.sh`** directly from the packages URL:
|
||||
- Pre-release: `packages-staging.xdrsiem.wazuh.info/pre-release/{major}.x/installation-assistant/wazuh-certs-tool-{version}-{stage}.sh`
|
||||
- Release: `packages.wazuh.com/{major}.{minor}/wazuh-certs-tool-{version}-1.sh`
|
||||
|
||||
2. **Generate `config.yml`** inline based on deployment type:
|
||||
|
||||
**single-node:**
|
||||
```yaml
|
||||
nodes:
|
||||
indexer: [{ name: wazuh.indexer, dns: wazuh.indexer }]
|
||||
manager: [{ name: wazuh.manager, dns: wazuh.manager }]
|
||||
dashboard:[{ name: wazuh.dashboard, dns: wazuh.dashboard }]
|
||||
```
|
||||
|
||||
**multi-node:**
|
||||
```yaml
|
||||
nodes:
|
||||
indexer:
|
||||
- { name: wazuh1.indexer, dns: wazuh1.indexer }
|
||||
- { name: wazuh2.indexer, dns: wazuh2.indexer }
|
||||
- { name: wazuh3.indexer, dns: wazuh3.indexer }
|
||||
manager:
|
||||
- { name: wazuh.master, dns: wazuh.master, node_type: master }
|
||||
- { name: wazuh.worker, dns: wazuh.worker, node_type: worker }
|
||||
dashboard: [{ name: wazuh.dashboard, dns: wazuh.dashboard }]
|
||||
```
|
||||
|
||||
3. **Copy `wazuh-docker/` to VM** via SCP: `scp -r wazuh-docker {remote}:/tmp/wazuh-docker`
|
||||
|
||||
4. **Generate certificates on VM**: runs `tools/utils/deployment/certificates-conf.sh --cert --copy` inside `/tmp/wazuh-docker/{deployment}/`
|
||||
|
||||
#### Deployment
|
||||
|
||||
```bash
|
||||
# On the VM
|
||||
cd /tmp/wazuh-docker/{deployment_type}
|
||||
sudo docker compose up -d
|
||||
```
|
||||
|
||||
Waits up to **15 minutes** polling every 10 seconds until all non-nginx containers report `healthy` status.
|
||||
|
||||
After containers are healthy, waits for steady state:
|
||||
- `single-node`: 60 seconds
|
||||
- `multi-node`: 90 seconds
|
||||
|
||||
#### Test execution
|
||||
|
||||
```bash
|
||||
test_runner \
|
||||
--test-type "docker-{deployment_type}" \
|
||||
--deployment-type "docker-{deployment_type}" \
|
||||
--ssh-host "{SSH_HOST}" \
|
||||
--ssh-port "{SSH_PORT}" \
|
||||
--ssh-key-path "{SSH_KEY}" \
|
||||
--ssh-username "{SSH_USER}" \
|
||||
--version "{DOCKER_VERSION}" \
|
||||
--log-level INFO \
|
||||
--output github \
|
||||
--output-file "test-results-docker-{deployment_type}.github"
|
||||
```
|
||||
|
||||
| Argument | Value | Notes |
|
||||
|---|---|---|
|
||||
| `--test-type` | `docker-single-node` or `docker-multi-node` | Selects the test module set |
|
||||
| `--deployment-type` | `docker-single-node` or `docker-multi-node` | Selects the deployment profile |
|
||||
| `--ssh-host/port/key/username` | From allocator inventory | Connects to the allocated VM |
|
||||
| `--version` | Resolved `DOCKER_VERSION` | Used for version assertion tests |
|
||||
| `--output github` | — | Emits GitHub Actions annotations |
|
||||
|
||||
For details on what `docker-single-node` and `docker-multi-node` test types validate, see the `Integration Test Module — Description` of the internal documentation.
|
||||
|
||||
#### Reporting
|
||||
|
||||
| Output | When | Content |
|
||||
|---|---|---|
|
||||
| Step summary | Always | Test results appended to `$GITHUB_STEP_SUMMARY` |
|
||||
| PR comment | `issue_comment` trigger only | Posts or updates a comment (marker: `<!-- docker-integration-check-{deployment} -->`) with ✅/❌ and results |
|
||||
| Artifact: `test-results-docker-{deployment}-{run_id}` | Always | Results file, retained 7 days |
|
||||
| Artifact: `docker-logs-{deployment}-{run_id}` | On failure only | Full `docker compose logs` output, retained 7 days |
|
||||
|
||||
#### Cleanup (always runs, even on failure)
|
||||
|
||||
1. `docker compose down -v` on the VM (stops containers and removes volumes)
|
||||
2. Deallocate the VM:
|
||||
```bash
|
||||
python3 wazuh-automation/deployability/modules/allocation/main.py \
|
||||
--action delete \
|
||||
--track-output {ALLOCATOR_PATH}/track.yml
|
||||
```
|
||||
|
||||
### Job 5 — `update_check` (issue_comment only)
|
||||
|
||||
Updates the GitHub Check Run created in Job 1:
|
||||
|
||||
| `docker_test` result | Check conclusion |
|
||||
|---|---|
|
||||
| `success` | `success` — ✅ All Docker integration tests passed |
|
||||
| `failure` | `failure` — ❌ One or more tests failed |
|
||||
| `cancelled` | `cancelled` |
|
||||
|
||||
---
|
||||
|
||||
## Required Secrets and Variables
|
||||
|
||||
### Secrets
|
||||
|
||||
| Secret | Used by |
|
||||
|---|---|
|
||||
| `AWS_IAM_DOCKER_ROLE` | OIDC role for AWS operations (allocator + ECR) |
|
||||
| `GH_CLONE_TOKEN` | Checkout `wazuh-automation` |
|
||||
| `GITHUB_TOKEN` | PR comments and Check Run updates (built-in) |
|
||||
|
||||
### Repository variables
|
||||
|
||||
| Variable | Used by |
|
||||
|---|---|
|
||||
| `IMAGE_REGISTRY_PROD` | DockerHub registry URL |
|
||||
| `IMAGE_REGISTRY_DEV` | ECR registry URL |
|
||||
|
||||
---
|
||||
|
||||
## Permissions
|
||||
|
||||
| Permission | Purpose |
|
||||
|---|---|
|
||||
| `id-token: write` | OIDC authentication to AWS |
|
||||
| `contents: read` | Checkout repository |
|
||||
| `pull-requests: write` | Post PR comments |
|
||||
| `issues: write` | Post comments via issues API |
|
||||
| `checks: write` | Create and update GitHub Check Runs |
|
||||
|
||||
---
|
||||
|
||||
## Instance Naming
|
||||
|
||||
Allocated VMs are named:
|
||||
|
||||
```
|
||||
gha_{github.run_id}_docker_{deployment_type}
|
||||
```
|
||||
|
||||
Example: `gha_12345678_docker_single-node`
|
||||
|
||||
VMs are tagged with `termination-date: 1d` — they are automatically terminated after 24 hours as a safety net, even if the cleanup step fails.
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reference Manual - Description
|
||||
|
||||
This section provides a detailed description of Wazuh-docker (version 5.0.0), its components, and its architecture when deployed using Docker containers. Understanding these aspects is key to effectively deploying and managing your Wazuh environment.
|
||||
This section provides a detailed description of Wazuh-docker (version 5.1.0), its components, and its architecture when deployed using Docker containers. Understanding these aspects is key to effectively deploying and managing your Wazuh environment.
|
||||
|
||||
## What is Wazuh?
|
||||
|
||||
@@ -18,7 +18,7 @@ Wazuh-docker is a project that provides Docker images and `docker compose` confi
|
||||
|
||||
## Core Components in Wazuh-Docker
|
||||
|
||||
The Wazuh-Docker project typically provides images for the following core Wazuh components, adapted for version 5.0.0:
|
||||
The Wazuh-Docker project typically provides images for the following core Wazuh components, adapted for version 5.1.0:
|
||||
|
||||
1. **Wazuh Manager**:
|
||||
- The central component that collects and analyzes data from deployed Wazuh agents.
|
||||
@@ -28,7 +28,7 @@ The Wazuh-Docker project typically provides images for the following core Wazuh
|
||||
2. **Wazuh Indexer**:
|
||||
- A highly scalable, full-text search and analytics engine.
|
||||
- Based on OpenSearch (or historically Elasticsearch), it stores and indexes alerts and monitoring data generated by the Wazuh manager.
|
||||
- The Wazuh indexer container provides the data persistence layer for Wazuh alerts and events. For version 5.0.0, this is typically an OpenSearch-based component.
|
||||
- The Wazuh indexer container provides the data persistence layer for Wazuh alerts and events. For version 5.1.0, this is typically an OpenSearch-based component.
|
||||
|
||||
3. **Wazuh Dashboard**:
|
||||
- A flexible visualization tool based on OpenSearch Dashboards (or historically Kibana).
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reference Manual - Introduction
|
||||
|
||||
Welcome to the Reference Manual for Wazuh-Docker, version 5.0.0. This manual provides comprehensive information about deploying, configuring, and managing your Wazuh environment using Docker.
|
||||
Welcome to the Reference Manual for Wazuh-Docker, version 5.1.0. This manual provides comprehensive information about deploying, configuring, and managing your Wazuh environment using Docker.
|
||||
|
||||
## Purpose of This Manual
|
||||
|
||||
@@ -44,4 +44,4 @@ This manual is structured to help you find information efficiently:
|
||||
- If you need to customize your deployment, refer to the [Configuration](configuration/configuration.md) section.
|
||||
- For specific terms or concepts, consult the [Glossary](glossary.md).
|
||||
|
||||
This manual refers to version 5.0.0 of Wazuh-Docker. Ensure you are using the documentation that corresponds to your deployed version.
|
||||
This manual refers to version 5.1.0 of Wazuh-Docker. Ensure you are using the documentation that corresponds to your deployed version.
|
||||
|
||||
+11
-11
@@ -19,20 +19,20 @@ Below is a step-by-step example of how to perform this update:
|
||||
- `wazuh.indexer`
|
||||
- `wazuh.dashboard`
|
||||
|
||||
Example (update to 5.0.0):
|
||||
Example (update to 5.1.0):
|
||||
|
||||
```yaml
|
||||
services:
|
||||
wazuh.manager:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta2
|
||||
image: wazuh/wazuh-manager:5.1.0
|
||||
...
|
||||
|
||||
wazuh.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
...
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta2
|
||||
image: wazuh/wazuh-dashboard:5.1.0
|
||||
...
|
||||
```
|
||||
|
||||
@@ -43,32 +43,32 @@ Below is a step-by-step example of how to perform this update:
|
||||
- `wazuh1.indexer`, `wazuh2.indexer`, and `wazuh3.indexer`
|
||||
- `wazuh.dashboard`
|
||||
|
||||
Example (update to 5.0.0):
|
||||
Example (update to 5.1.0):
|
||||
|
||||
```yaml
|
||||
services:
|
||||
wazuh.master:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta2
|
||||
image: wazuh/wazuh-manager:5.1.0
|
||||
...
|
||||
|
||||
wazuh.worker:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta2
|
||||
image: wazuh/wazuh-manager:5.1.0
|
||||
...
|
||||
|
||||
wazuh1.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
...
|
||||
|
||||
wazuh2.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
...
|
||||
|
||||
wazuh3.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
...
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta2
|
||||
image: wazuh/wazuh-dashboard:5.1.0
|
||||
...
|
||||
```
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||
services:
|
||||
wazuh.master:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta2
|
||||
image: wazuh/wazuh-manager:5.1.0
|
||||
hostname: wazuh.master
|
||||
container_name: multi-node-wazuh.master
|
||||
restart: always
|
||||
@@ -9,10 +9,11 @@ services:
|
||||
wazuh1.indexer:
|
||||
condition: service_healthy
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "curl -k -s -o /dev/null https://localhost:55000 || exit 1" ]
|
||||
test: [ "CMD-SHELL", "/var/wazuh-manager/bin/wazuh-manager-control status 2>/dev/null | grep -q 'not running' && exit 1 || exit 0" ]
|
||||
interval: 15s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
start_period: 60s
|
||||
ulimits:
|
||||
memlock:
|
||||
soft: -1
|
||||
@@ -30,8 +31,8 @@ services:
|
||||
- WAZUH_NODE_TYPE=master
|
||||
- WAZUH_CLUSTER_BIND_ADDR=0.0.0.0
|
||||
- WAZUH_CLUSTER_NODES=wazuh.master
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
volumes:
|
||||
- master-wazuh-api-configuration:/var/wazuh-manager/api/configuration
|
||||
- master-wazuh-etc:/var/wazuh-manager/etc
|
||||
@@ -43,16 +44,16 @@ services:
|
||||
- ./config/wazuh_master/certs/wazuh.master-key.pem:/var/wazuh-manager/etc/certs/manager-key.pem
|
||||
|
||||
wazuh.worker:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta2
|
||||
image: wazuh/wazuh-manager:5.1.0
|
||||
hostname: wazuh.worker
|
||||
container_name: multi-node-wazuh.worker
|
||||
restart: always
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "timeout 2 bash -c '</dev/tcp/localhost/1514' || exit 1" ]
|
||||
interval: 5s
|
||||
test: [ "CMD-SHELL", "/var/wazuh-manager/bin/wazuh-manager-control status 2>/dev/null | grep -v apid | grep -q 'not running' && exit 1 || exit 0" ]
|
||||
interval: 15s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
start_period: 30s
|
||||
retries: 5
|
||||
start_period: 60s
|
||||
ulimits:
|
||||
memlock:
|
||||
soft: -1
|
||||
@@ -69,8 +70,8 @@ services:
|
||||
- WAZUH_NODE_TYPE=worker
|
||||
- WAZUH_CLUSTER_BIND_ADDR=0.0.0.0
|
||||
- WAZUH_CLUSTER_NODES=wazuh.master
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
volumes:
|
||||
- worker-wazuh-api-configuration:/var/wazuh-manager/api/configuration
|
||||
- worker-wazuh-etc:/var/wazuh-manager/etc
|
||||
@@ -82,7 +83,7 @@ services:
|
||||
- ./config/wazuh_worker/certs/wazuh.worker-key.pem:/var/wazuh-manager/etc/certs/manager-key.pem
|
||||
|
||||
wazuh1.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
hostname: wazuh1.indexer
|
||||
container_name: multi-node-wazuh1.indexer
|
||||
restart: always
|
||||
@@ -120,7 +121,7 @@ services:
|
||||
- ./config/wazuh1_indexer/certs/admin-key.pem:/usr/share/wazuh-indexer/config/certs/admin-key.pem
|
||||
|
||||
wazuh2.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
hostname: wazuh2.indexer
|
||||
container_name: multi-node-wazuh2.indexer
|
||||
restart: always
|
||||
@@ -158,7 +159,7 @@ services:
|
||||
- ./config/wazuh2_indexer/certs/wazuh2.indexer.pem:/usr/share/wazuh-indexer/config/certs/indexer.pem
|
||||
|
||||
wazuh3.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
hostname: wazuh3.indexer
|
||||
container_name: multi-node-wazuh3.indexer
|
||||
restart: always
|
||||
@@ -196,7 +197,7 @@ services:
|
||||
- ./config/wazuh3_indexer/certs/wazuh3.indexer.pem:/usr/share/wazuh-indexer/config/certs/indexer.pem
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta2
|
||||
image: wazuh/wazuh-dashboard:5.1.0
|
||||
hostname: wazuh.dashboard
|
||||
container_name: multi-node-wazuh.dashboard
|
||||
restart: always
|
||||
@@ -212,8 +213,6 @@ services:
|
||||
- SERVER_PORT=5601
|
||||
- SERVER_HOST=0.0.0.0
|
||||
- OPENSEARCH_HOSTS=["https://wazuh1.indexer:9200","https://wazuh2.indexer:9200","https://wazuh3.indexer:9200"]
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- WAZUH_API_URL=https://wazuh.master
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||
services:
|
||||
wazuh.manager:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta2
|
||||
image: wazuh/wazuh-manager:5.1.0
|
||||
hostname: wazuh.manager
|
||||
container_name: single-node-wazuh.manager
|
||||
restart: always
|
||||
@@ -9,10 +9,11 @@ services:
|
||||
wazuh.indexer:
|
||||
condition: service_healthy
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "curl -k -s -o /dev/null https://localhost:55000 || exit 1" ]
|
||||
test: [ "CMD-SHELL", "/var/wazuh-manager/bin/wazuh-manager-control status 2>/dev/null | grep -q 'not running' && exit 1 || exit 0" ]
|
||||
interval: 15s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
start_period: 60s
|
||||
ulimits:
|
||||
memlock:
|
||||
soft: -1
|
||||
@@ -30,8 +31,8 @@ services:
|
||||
- WAZUH_NODE_NAME=manager
|
||||
- WAZUH_CLUSTER_NODES=wazuh.manager
|
||||
- WAZUH_CLUSTER_BIND_ADDR=wazuh.manager
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
volumes:
|
||||
- wazuh_api_configuration:/var/wazuh-manager/api/configuration
|
||||
- wazuh_etc:/var/wazuh-manager/etc
|
||||
@@ -43,7 +44,7 @@ services:
|
||||
- ./config/wazuh_manager/certs/wazuh.manager-key.pem:/var/wazuh-manager/etc/certs/manager-key.pem
|
||||
|
||||
wazuh.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta2
|
||||
image: wazuh/wazuh-indexer:5.1.0
|
||||
hostname: wazuh.indexer
|
||||
container_name: single-node-wazuh.indexer
|
||||
restart: always
|
||||
@@ -80,7 +81,7 @@ services:
|
||||
- ./config/wazuh_indexer/certs/admin-key.pem:/usr/share/wazuh-indexer/config/certs/admin-key.pem
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta2
|
||||
image: wazuh/wazuh-dashboard:5.1.0
|
||||
hostname: wazuh.dashboard
|
||||
container_name: single-node-wazuh.dashboard
|
||||
restart: always
|
||||
@@ -96,8 +97,6 @@ services:
|
||||
- SERVER_PORT=5601
|
||||
- SERVER_HOST=0.0.0.0
|
||||
- OPENSEARCH_HOSTS=https://wazuh.indexer:9200
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- WAZUH_API_URL=https://wazuh.manager
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
|
||||
+80
-56
@@ -9,6 +9,8 @@ DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
LOG_FILE="${DIR}/tools/repository_bumper_$(date +"%Y-%m-%d_%H-%M-%S-%3N").log"
|
||||
VERSION=""
|
||||
STAGE=""
|
||||
TAG=""
|
||||
REFERENCE=""
|
||||
FILES_EDITED=()
|
||||
FILES_EXCLUDED='--exclude="repository_bumper_*.log" --exclude="CHANGELOG.md" --exclude="repository_bumper.sh" --exclude="*_bumper_repository.yml" --exclude="mermaid-init.js" --exclude="mermaid.min.js"'
|
||||
|
||||
@@ -74,40 +76,44 @@ update_stage_in_files() {
|
||||
FILES_EDITED+=("${file}")
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
if [ $STAGE != "alpha0" ]; then
|
||||
version_tag_string=": 'v${VERSION}'"
|
||||
files_tag=( $(grep_command "${version_tag_string}" "${DIR}") )
|
||||
for file in "${files_tag[@]}"; do
|
||||
sed -i -E "s/(: )'v${VERSION}'/\1'v${VERSION}-${STAGE}'/g" "${file}"
|
||||
if [[ $(git diff --name-only "${file}") ]]; then
|
||||
FILES_EDITED+=("${file}")
|
||||
fi
|
||||
done
|
||||
|
||||
version_number_string=": '${VERSION}'"
|
||||
files_version=( $(grep -RlE ": '[0-9]\.[0-9]+\.[0-9]+'" "${DIR}") )
|
||||
for file in "${files_version[@]}"; do
|
||||
sed -i -E "s/(: )'${VERSION}'/\1'v${VERSION}-${STAGE}'/g" "${file}"
|
||||
if [[ $(git diff --name-only "${file}") ]]; then
|
||||
FILES_EDITED+=("${file}")
|
||||
fi
|
||||
done
|
||||
# Compute the value written into branch reference defaults ("<key>: '...'").
|
||||
# Without --tag, references stay branch-like (e.g. 5.0.0).
|
||||
# With --tag, references become tag-like (e.g. v5.0.0-beta3), or a plain release
|
||||
# tag (e.g. v5.0.0) when no stage is provided.
|
||||
build_reference() {
|
||||
if [[ -n "$TAG" ]]; then
|
||||
if [[ -z "$STAGE" ]]; then
|
||||
REFERENCE="v${VERSION}"
|
||||
else
|
||||
REFERENCE="v${VERSION}-${STAGE}"
|
||||
fi
|
||||
else
|
||||
REFERENCE="${VERSION}"
|
||||
fi
|
||||
}
|
||||
|
||||
# Tag mode only: normalize every reference to the current version
|
||||
# (branch-like "5.0.0", "v5.0.0" or "v5.0.0-<stage>") into ${REFERENCE}.
|
||||
# Matching is restricted to "<key>: '...'" entries so plain version strings
|
||||
# elsewhere in the repository are left untouched.
|
||||
update_tag_references() {
|
||||
local V_ESC="${VERSION//./\\.}"
|
||||
files=( $(grep_command "${VERSION}" "${DIR}") )
|
||||
for file in "${files[@]}"; do
|
||||
sed -Ei "s/(:[[:space:]]*')v?${V_ESC}(-[A-Za-z0-9]+)?(')/\1${REFERENCE}\3/g" "${file}"
|
||||
if [[ $(git diff --name-only "${file}") ]]; then
|
||||
FILES_EDITED+=("${file}")
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
update_main_in_files() {
|
||||
if [[ $STAGE == "alpha0" ]]; then
|
||||
bump_value="${VERSION}"
|
||||
else
|
||||
bump_value="v${VERSION}"
|
||||
fi
|
||||
main_string=": 'main'"
|
||||
local main_string=": 'main'"
|
||||
files=( $(grep_command "${main_string}" "${DIR}") )
|
||||
for file in "${files[@]}"; do
|
||||
if [[ "$skip_urls" != "yes" ]]; then
|
||||
sed -Ei "s/(:[[:space:]])'main'/\1'${bump_value}'/g" "${file}"
|
||||
fi
|
||||
sed -Ei "s/(:[[:space:]])'main'/\1'${REFERENCE}'/g" "${file}"
|
||||
if [[ $(git diff --name-only "${file}") ]]; then
|
||||
FILES_EDITED+=("${file}")
|
||||
fi
|
||||
@@ -141,8 +147,8 @@ main() {
|
||||
shift 2
|
||||
;;
|
||||
--tag)
|
||||
TAG="$2"
|
||||
shift 2
|
||||
TAG="yes"
|
||||
shift 1
|
||||
;;
|
||||
--set-as-main)
|
||||
set_as_main="yes"
|
||||
@@ -155,15 +161,33 @@ main() {
|
||||
esac
|
||||
done
|
||||
|
||||
# Validate arguments
|
||||
if [[ -z "${VERSION}" ]]; then
|
||||
echo "Error: --version argument is required." | tee -a "${LOG_FILE}"
|
||||
# --tag rewrites branch references into tag-like references (e.g. v5.0.0-beta3)
|
||||
# and re-tags the Docker images accordingly. It is mutually exclusive with
|
||||
# --set-as-main, which keeps references on main.
|
||||
if [[ -n "$TAG" && -n "$set_as_main" ]]; then
|
||||
echo "Error: --tag cannot be combined with --set-as-main." | tee -a "${LOG_FILE}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ -z "${STAGE}" ]]; then
|
||||
echo "Error: --stage argument is required." | tee -a "${LOG_FILE}"
|
||||
exit 1
|
||||
# Read the current version/stage early: tag scenarios may omit --version and/or
|
||||
# --stage and reuse the values already stored in VERSION.json.
|
||||
get_old_version_and_stage
|
||||
|
||||
# Resolve and validate arguments depending on the mode
|
||||
if [[ -n "$TAG" ]]; then
|
||||
# Tag mode: version defaults to the current one; stage is optional
|
||||
# (absent yields a release tag without a stage suffix).
|
||||
[[ -z "$VERSION" ]] && VERSION="$OLD_VERSION"
|
||||
else
|
||||
# Branch mode: a full version + stage bump is required
|
||||
if [[ -z "${VERSION}" ]]; then
|
||||
echo "Error: --version argument is required." | tee -a "${LOG_FILE}"
|
||||
exit 1
|
||||
fi
|
||||
if [[ -z "${STAGE}" ]]; then
|
||||
echo "Error: --stage argument is required." | tee -a "${LOG_FILE}"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Validate if version is in the correct format
|
||||
@@ -172,28 +196,25 @@ main() {
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Validate if stage is in the correct format
|
||||
STAGE=$(echo "${STAGE}" | tr '[:upper:]' '[:lower:]')
|
||||
if ! [[ "${STAGE}" =~ ^(alpha[0-9]*|beta[0-9]*|rc[0-9]*|stable)$ ]]; then
|
||||
echo "Error: Stage must be one of the following examples: alpha1, beta1, rc1, stable." | tee -a "${LOG_FILE}"
|
||||
exit 1
|
||||
# Validate if stage is in the correct format (when provided)
|
||||
if [[ -n "${STAGE}" ]]; then
|
||||
STAGE=$(echo "${STAGE}" | tr '[:upper:]' '[:lower:]')
|
||||
if ! [[ "${STAGE}" =~ ^(alpha[0-9]*|beta[0-9]*|rc[0-9]*|stable)$ ]]; then
|
||||
echo "Error: Stage must be one of the following examples: alpha1, beta1, rc1, stable." | tee -a "${LOG_FILE}"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Set skip_urls variable based on set_as_main flag
|
||||
# Compute the value written into branch reference defaults
|
||||
build_reference
|
||||
echo "Reference for branch defaults: ${REFERENCE}" | tee -a "${LOG_FILE}"
|
||||
|
||||
# Convert 'main' references unless they must keep pointing to main (set-as-main)
|
||||
if [[ -z "$set_as_main" ]]; then
|
||||
echo "Updating version from main to $VERSION" | tee -a "${LOG_FILE}"
|
||||
update_main_in_files "$VERSION" "$STAGE"
|
||||
echo "Updating 'main' references to ${REFERENCE}" | tee -a "${LOG_FILE}"
|
||||
update_main_in_files
|
||||
fi
|
||||
|
||||
# Validate if tag is true or false
|
||||
if [[ -n "${TAG}" && ! "${TAG}" =~ ^(true|false)$ ]]; then
|
||||
echo "Error: --tag must be either true or false." | tee -a "${LOG_FILE}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Get old version and stage
|
||||
get_old_version_and_stage
|
||||
|
||||
if [[ "${OLD_VERSION}" != "${VERSION}" ]]; then
|
||||
echo "Updating version from ${OLD_VERSION} to ${VERSION}" | tee -a "${LOG_FILE}"
|
||||
update_version_in_files "${VERSION}"
|
||||
@@ -203,10 +224,13 @@ main() {
|
||||
update_stage_in_files "$VERSION" "$STAGE"
|
||||
fi
|
||||
|
||||
# Update Docker images tag if tag is true
|
||||
if [[ "${TAG}" == "true" ]]; then
|
||||
echo "Updating Docker images tag to ${VERSION}-${STAGE}" | tee -a "${LOG_FILE}"
|
||||
update_docker_images_tag "${VERSION}-${STAGE}"
|
||||
# Tag mode: normalize remaining version references and re-tag the Docker images
|
||||
# (image tags carry no leading 'v', e.g. 5.0.0-beta3).
|
||||
if [[ -n "$TAG" ]]; then
|
||||
echo "Updating version references to tag reference ${REFERENCE}" | tee -a "${LOG_FILE}"
|
||||
update_tag_references
|
||||
echo "Updating Docker images tag to ${REFERENCE#v}" | tee -a "${LOG_FILE}"
|
||||
update_docker_images_tag "${REFERENCE#v}"
|
||||
fi
|
||||
|
||||
|
||||
|
||||
@@ -1,7 +1,8 @@
|
||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||
services:
|
||||
wazuh.agent:
|
||||
image: wazuh/wazuh-agent:5.0.0-beta2
|
||||
image: wazuh/wazuh-agent:5.1.0
|
||||
restart: always
|
||||
environment:
|
||||
- WAZUH_MANAGER_SERVER=<WAZUH_MANAGER_IP>
|
||||
- WAZUH_REGISTRATION_PASSWORD=<authd.pass-PASSWORD>
|
||||
|
||||
Reference in New Issue
Block a user