forked from wazuh/wazuh-docker
Compare commits
49
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
056c9fec0e | ||
|
|
579672a783 | ||
|
|
f506a5e20d | ||
|
|
f215dae68e | ||
|
|
758ccaf309 | ||
|
|
6852ecae39 | ||
|
|
db24a0ea2d | ||
|
|
01c0d4c7c2 | ||
|
|
544fd8e111 | ||
|
|
3c53858c5a | ||
|
|
355a1a4a90 | ||
|
|
f7f2248185 | ||
|
|
4f51bef735 | ||
|
|
68f81a6f6f | ||
|
|
fc0e170315 | ||
|
|
04a4cdbd1e | ||
|
|
513f4d71ad | ||
|
|
2a8d2d963d | ||
|
|
14fc1019e8 | ||
|
|
d2971cb198 | ||
|
|
fb20a0d1ba | ||
|
|
76be72bc08 | ||
|
|
adcc5b57d2 | ||
|
|
ecea95427b | ||
|
|
d83dfe5cfd | ||
|
|
031c66c671 | ||
|
|
6edf9cf598 | ||
|
|
82ada64e37 | ||
|
|
a6558e8f4a | ||
|
|
b92438499b | ||
|
|
af31c08f70 | ||
|
|
1822f025af | ||
|
|
daa919db58 | ||
|
|
d8087b2238 | ||
|
|
495b67251e | ||
|
|
80807a1cf9 | ||
|
|
1c8583f366 | ||
|
|
63b8af98d3 | ||
|
|
3f2ebfac37 | ||
|
|
8357d2c3ad | ||
|
|
577f2e0af7 | ||
|
|
d5dddfbbd8 | ||
|
|
e153333402 | ||
|
|
ffd39b0191 | ||
|
|
1f2b777866 | ||
|
|
4d9cfab272 | ||
|
|
fb0110a1c3 | ||
|
|
b2a559d081 | ||
|
|
b8368a207a |
@@ -6,7 +6,7 @@ on:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: '4.14.7'
|
||||
default: '4.14.8'
|
||||
required: true
|
||||
docker_reference:
|
||||
description: 'wazuh-docker reference'
|
||||
@@ -38,7 +38,7 @@ on:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: '4.14.7'
|
||||
default: '4.14.8'
|
||||
required: true
|
||||
type: string
|
||||
docker_reference:
|
||||
|
||||
@@ -110,13 +110,21 @@ jobs:
|
||||
bash ${{ env.BUMP_SCRIPT_PATH }} ${{ steps.vars.outputs.script_params }}
|
||||
|
||||
- name: Commit and push changes
|
||||
id: bump_commit
|
||||
run: |
|
||||
git add .
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
git push origin ${{ steps.vars.outputs.branch_name }}
|
||||
if git diff --staged --quiet; then
|
||||
echo "Nothing to bump: the repository is already at the requested version/stage. Skipping commit."
|
||||
echo "has_changes=false" >> $GITHUB_OUTPUT
|
||||
else
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
git push origin ${{ steps.vars.outputs.branch_name }}
|
||||
echo "has_changes=true" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Create pull request
|
||||
id: create_pr
|
||||
if: steps.bump_commit.outputs.has_changes == 'true'
|
||||
run: |
|
||||
gh auth setup-git
|
||||
PR_URL=$(gh pr create \
|
||||
@@ -129,14 +137,19 @@ jobs:
|
||||
echo "pull_request_url=${PR_URL}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Merge pull request
|
||||
if: steps.bump_commit.outputs.has_changes == 'true'
|
||||
run: |
|
||||
# Any checks for the PR are bypassed since the branch is expected to be functional (i.e. the bump process does not introduce any bugs)
|
||||
gh pr merge "${{ steps.create_pr.outputs.pull_request_url }}" --merge --admin
|
||||
|
||||
- name: Show logs
|
||||
run: |
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
if [[ "${{ steps.bump_commit.outputs.has_changes }}" == "true" ]]; then
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
else
|
||||
echo "Bump skipped: the repository is already at the requested version/stage."
|
||||
fi
|
||||
echo "Bumper scripts logs:"
|
||||
cat ${BUMP_LOG_PATH}/repository_bumper*log
|
||||
@@ -6,7 +6,7 @@ on:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: 'v5.0.0-beta3'
|
||||
default: '5.0.0'
|
||||
required: true
|
||||
docker_reference:
|
||||
description: 'wazuh-docker reference'
|
||||
@@ -14,7 +14,7 @@ on:
|
||||
wazuh_automation_reference:
|
||||
description: 'Branch or tag of the wazuh-automation repository'
|
||||
required: false
|
||||
default: 'v5.0.0-beta3'
|
||||
default: '5.0.0'
|
||||
products:
|
||||
description: 'Comma-separated list of the image names to build and push'
|
||||
default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent'
|
||||
@@ -42,7 +42,7 @@ on:
|
||||
inputs:
|
||||
image_tag:
|
||||
description: 'Docker image tag'
|
||||
default: 'v5.0.0-beta3'
|
||||
default: '5.0.0'
|
||||
required: true
|
||||
type: string
|
||||
docker_reference:
|
||||
@@ -52,7 +52,7 @@ on:
|
||||
wazuh_automation_reference:
|
||||
description: 'Branch or tag of the wazuh-automation repository'
|
||||
required: false
|
||||
default: 'v5.0.0-beta3'
|
||||
default: '5.0.0'
|
||||
type: string
|
||||
products:
|
||||
description: 'Comma-separated list of the image names to build and push'
|
||||
|
||||
@@ -144,10 +144,17 @@ jobs:
|
||||
bash ${{ env.BUMP_SCRIPT_PATH }} ${{ steps.vars.outputs.script_params }}
|
||||
|
||||
- name: Commit changes (Bump)
|
||||
id: bump_commit
|
||||
if: inputs.revert != true
|
||||
run: |
|
||||
git add .
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
if git diff --staged --quiet; then
|
||||
echo "Nothing to bump: the repository is already at the requested version/stage. Skipping commit."
|
||||
echo "has_changes=false" >> $GITHUB_OUTPUT
|
||||
else
|
||||
git commit -m "feat: bump ${{ github.ref_name }}"
|
||||
echo "has_changes=true" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Fetch full history (Revert)
|
||||
if: inputs.revert == true
|
||||
@@ -198,13 +205,13 @@ jobs:
|
||||
fi
|
||||
|
||||
- name: Push changes
|
||||
if: inputs.revert != true || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
if: (inputs.revert != true && steps.bump_commit.outputs.has_changes == 'true') || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
run: |
|
||||
git push origin ${{ steps.vars.outputs.branch_name }}
|
||||
|
||||
- name: Create pull request
|
||||
id: create_pr
|
||||
if: inputs.revert != true || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
if: (inputs.revert != true && steps.bump_commit.outputs.has_changes == 'true') || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
run: |
|
||||
gh auth setup-git
|
||||
PR_URL=$(gh pr create \
|
||||
@@ -217,7 +224,7 @@ jobs:
|
||||
echo "pull_request_url=${PR_URL}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Merge pull request
|
||||
if: inputs.revert != true || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
if: (inputs.revert != true && steps.bump_commit.outputs.has_changes == 'true') || (inputs.revert == true && steps.revert_step.outputs.has_changes == 'true')
|
||||
run: |
|
||||
# Any checks for the PR are bypassed since the branch is expected to be functional
|
||||
gh pr merge "${{ steps.create_pr.outputs.pull_request_url }}" --merge --admin
|
||||
@@ -225,9 +232,13 @@ jobs:
|
||||
- name: Show logs
|
||||
if: inputs.revert != true
|
||||
run: |
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
if [[ "${{ steps.bump_commit.outputs.has_changes }}" == "true" ]]; then
|
||||
echo "Bump complete."
|
||||
echo "Branch: ${{ steps.vars.outputs.branch_name }}"
|
||||
echo "PR: ${{ steps.create_pr.outputs.pull_request_url }}"
|
||||
else
|
||||
echo "Bump skipped: the repository is already at the requested version/stage."
|
||||
fi
|
||||
echo "Bumper scripts logs:"
|
||||
cat ${BUMP_LOG_PATH}/repository_bumper*log
|
||||
|
||||
|
||||
@@ -0,0 +1,64 @@
|
||||
name: 5.x Changelog check
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize, reopened, ready_for_review, labeled, unlabeled]
|
||||
|
||||
jobs:
|
||||
changelog_check:
|
||||
runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }}
|
||||
if: ${{ github.event_name == 'pull_request' && !github.event.pull_request.draft && !contains(github.event.pull_request.labels.*.name, 'no-changelog') }}
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Validate CHANGELOG.md changes
|
||||
env:
|
||||
BASE_REF: ${{ github.base_ref }}
|
||||
run: |
|
||||
UPDATED="✅" FORMAT="—" INVALID=""
|
||||
|
||||
ADDED=$(git diff -U0 "origin/${BASE_REF}...HEAD" -- CHANGELOG.md | grep -E '^\+[^+]' | sed 's/^+//' || true)
|
||||
if [ -z "$ADDED" ]; then
|
||||
UPDATED="❌"
|
||||
echo "::error::CHANGELOG.md was not updated with new entries. Add one or add the 'no-changelog' label to skip this check."
|
||||
else
|
||||
FORMAT="✅"
|
||||
|
||||
TABLE_ENTRY_REGEX='^\| \[#[0-9]+\]\(https://github\.com/[^)]+/(issues|pull)/[0-9]+\) \| .+ \|$'
|
||||
TABLE_HEADER_REGEX='^\| Issue \| Comment \|$|^\| - \| - \|$'
|
||||
PRIOR_VERSION_REGEX='^- \[v?[0-9]+\.[0-9]+\.[0-9]+\]\(https://github\.com/[^)]+/blob/[^)]+/CHANGELOG\.md\)$|^- \[\]\(\)$'
|
||||
INVALID=$(echo "$ADDED" | grep -E '^(\||-)' | grep -vx -- '- None' | grep -vE "$TABLE_HEADER_REGEX" | grep -vE "$TABLE_ENTRY_REGEX" | grep -vE "$PRIOR_VERSION_REGEX" || true)
|
||||
if [ -n "$INVALID" ]; then
|
||||
FORMAT="❌"
|
||||
echo "::error::Invalid CHANGELOG.md entries. Expected format: '- Description ([#123](https://github.com/<org>/<repo>/issues/123))' or, for the Prior versions section, '- [vX.X.X](https://github.com/<org>/<repo>/blob/vX.X.X/CHANGELOG.md)'. Offending lines:"
|
||||
echo "$INVALID"
|
||||
fi
|
||||
fi
|
||||
|
||||
{
|
||||
echo "## Changelog check"
|
||||
echo ""
|
||||
echo "| Check | Result |"
|
||||
echo "|---|---|"
|
||||
echo "| CHANGELOG.md has new entries | $UPDATED |"
|
||||
echo "| Entry format | $FORMAT |"
|
||||
if [ -n "$INVALID" ]; then
|
||||
echo ""
|
||||
echo "Offending lines:"
|
||||
echo '```'
|
||||
echo "$INVALID"
|
||||
echo '```'
|
||||
fi
|
||||
} >> "$GITHUB_STEP_SUMMARY"
|
||||
|
||||
if [ "$UPDATED" != "✅" ] || [ "$FORMAT" != "✅" ]; then
|
||||
exit 1
|
||||
fi
|
||||
echo "CHANGELOG.md update is valid."
|
||||
@@ -16,7 +16,7 @@ on:
|
||||
automation_reference:
|
||||
description: 'Branch of wazuh-automation to use'
|
||||
required: false
|
||||
default: 'v5.0.0-beta3'
|
||||
default: '5.0.0'
|
||||
type: string
|
||||
deployment_type:
|
||||
description: 'Deployment type to test'
|
||||
|
||||
+77
-64
@@ -1,78 +1,91 @@
|
||||
# Change Log
|
||||
All notable changes to this project will be documented in this file.
|
||||
|
||||
## [v5.0.0]
|
||||
|
||||
### Added
|
||||
|
||||
- Added bump-issue-link support for Revert Stage Bump. ([#2505](https://github.com/wazuh/wazuh-docker/pull/2505))
|
||||
- Add integration test module docs ([#2491](https://github.com/wazuh/wazuh-docker/pull/2491))
|
||||
- Implement the wazuh-docker integration testing module ([#2188](https://github.com/wazuh/wazuh-docker/issues/2188))
|
||||
- Support Revert bump functionality in wazuh-docker ([#2320](https://github.com/wazuh/wazuh-docker/issues/2320))
|
||||
- Docker and AMI workflows failing during stage release (v5.0.0-beta1) ([#35457](https://github.com/wazuh/wazuh/issues/35457))
|
||||
- Add `--set-as-main` flag support to repository bumper — `wazuh-docker` ([#2276](https://github.com/wazuh/wazuh-docker/issues/2276))
|
||||
|
||||
| Issue | Comment |
|
||||
| - | - |
|
||||
| [#2524](https://github.com/wazuh/wazuh-docker/issues/2524) | Set authd password in agents installation. |
|
||||
| [#2505](https://github.com/wazuh/wazuh-docker/pull/2505) | Added bump-issue-link support for Revert Stage Bump. |
|
||||
| [#2491](https://github.com/wazuh/wazuh-docker/pull/2491) | Add integration test module docs |
|
||||
| [#2188](https://github.com/wazuh/wazuh-docker/issues/2188) | Implement the wazuh-docker integration testing module |
|
||||
| [#2320](https://github.com/wazuh/wazuh-docker/issues/2320) | Support Revert bump functionality in wazuh-docker |
|
||||
| [#35457](https://github.com/wazuh/wazuh/issues/35457) | Docker and AMI workflows failing during stage release (v5.0.0-beta1) |
|
||||
| [#2276](https://github.com/wazuh/wazuh-docker/issues/2276) | Add `--set-as-main` flag support to repository bumper — `wazuh-docker` |
|
||||
|
||||
### Changed
|
||||
|
||||
- Change artifact upload and download ([#2502](https://github.com/wazuh/wazuh-docker/issues/2502))
|
||||
- Change runners on repository workflows 5.x ([#2471](https://github.com/wazuh/wazuh-docker/issues/2471))
|
||||
- PR revamp modifications 5.x ([#2446](https://github.com/wazuh/wazuh-docker/issues/2446))
|
||||
- Forbid pr_check workflow execution in draft PRs ([#2399](https://github.com/wazuh/wazuh-docker/issues/2399))
|
||||
- Unification of user UID and GID ([#2375](https://github.com/wazuh/wazuh-docker/issues/2375))
|
||||
- Wazuh indexer engine requirements ([#2392](https://github.com/wazuh/wazuh-docker/issues/2392))
|
||||
- Image build process update ([#2356](https://github.com/wazuh/wazuh-docker/issues/2356))
|
||||
- Add new path on artifact_urls file ([#2344](https://github.com/wazuh/wazuh-docker/issues/2344))
|
||||
- Unable to generate single component in `Procedure_push_docker_images` ([#2341](https://github.com/wazuh/wazuh-docker/issues/2341))
|
||||
- Adapt bumper workflows to change main branch ([#2294](https://github.com/wazuh/wazuh-docker/issues/2294))
|
||||
- Ensure default values are used for variables and passwords ([#2288](https://github.com/wazuh/wazuh-docker/issues/2288))
|
||||
- Docker - Ensure correct Wazuh manager certificates ownership ([#2283](https://github.com/wazuh/wazuh-docker/issues/2283))
|
||||
- Docker - Standarize Artifact URL keys ([#2278](https://github.com/wazuh/wazuh-docker/issues/2278))
|
||||
- Modify artifact URLs file name. ([#2266](https://github.com/wazuh/wazuh-docker/issues/2266))
|
||||
- URL presigned file - Update the Wazuh Docker image creation workflow ([#2218](https://github.com/wazuh/wazuh-docker/issues/2218))
|
||||
- Updated wazuh-docker documentation config and tooling versions to meet new standards. ([#2264](https://github.com/wazuh/wazuh-docker/issues/2264))
|
||||
- Align cert generation steps with current cert-tool ip validation ([#2250](https://github.com/wazuh/wazuh-docker/issues/2250))
|
||||
- Modify Healthchecks ([#2252](https://github.com/wazuh/wazuh-docker/issues/2252))
|
||||
- Add deployment healthchecks ([#2251](https://github.com/wazuh/wazuh-docker/issues/2251))
|
||||
- Update artifact generation jobs to use wz-linux dedicated runner group ([#2242](https://github.com/wazuh/wazuh-docker/issues/2242))
|
||||
- Error during Wazuh manager entrypoint ([#2237](https://github.com/wazuh/wazuh-docker/issues/2237))
|
||||
- Adapt PR test for workflow_dispatch option ([#2230](https://github.com/wazuh/wazuh-docker/issues/2230))
|
||||
- Wazuh Manager/agent Separation - Breaking changes summary ([#2227](https://github.com/wazuh/wazuh-docker/issues/2227))
|
||||
- Errors in wazuh-docker PR Test ([#2222](https://github.com/wazuh/wazuh-docker/issues/2222))
|
||||
- Development - Separate Agent/Manager - Docker - Adapt image build process ([#2206](https://github.com/wazuh/wazuh-docker/issues/2206))
|
||||
- Remove revision input ([#2217](https://github.com/wazuh/wazuh-docker/issues/2217))
|
||||
- Build images script improvement ([#2196](https://github.com/wazuh/wazuh-docker/issues/2196))
|
||||
- Missing documentation in the wazuh-docker repository ([#2197](https://github.com/wazuh/wazuh-docker/issues/2197))
|
||||
- Add Wazuh version and revision into wazuh-certs-tool and config file ([#2195](https://github.com/wazuh/wazuh-docker/issues/2195))
|
||||
- Improve S3 artifact URLs handling ([#2172](https://github.com/wazuh/wazuh-docker/issues/2172))
|
||||
- Allow building separate targets ([#2164](https://github.com/wazuh/wazuh-docker/issues/2164))
|
||||
- Add developement option when tag name is only version without stage ([#2179](https://github.com/wazuh/wazuh-docker/issues/2179))
|
||||
- Add IMAGE_TAG stage reference ([#2178](https://github.com/wazuh/wazuh-docker/issues/2178))
|
||||
- Remove Wazuh agent configuration template ([#2171](https://github.com/wazuh/wazuh-docker/issues/2171))
|
||||
- Docker - Ensure `run_as` set to true for every deployment alternative ([#2156](https://github.com/wazuh/wazuh-docker/issues/2156))
|
||||
- Change macOS and Windows deployment documentation ([#2150](https://github.com/wazuh/wazuh-docker/issues/2150))
|
||||
- Modify docker build image process ([#2131](https://github.com/wazuh/wazuh-docker/issues/2131))
|
||||
- Update documentation for Wazuh Docker image builder and workflow usage ([#2136](https://github.com/wazuh/wazuh-docker/issues/2136))
|
||||
- Configure deployment with environment variables ([#2081](https://github.com/wazuh/wazuh-docker/issues/2081))
|
||||
- Modify Wazuh components install method ([#2058](https://github.com/wazuh/wazuh-docker/issues/2058))
|
||||
- Image builder Workflow Rebuild ([#2054](https://github.com/wazuh/wazuh-docker/issues/2054))
|
||||
- Remove Wazuh Manager deprecated daemons and CLI tools ([#1933](https://github.com/wazuh/wazuh-docker/issues/1933))
|
||||
- DevOps - Docker - OpenSearch 3.0 deprecated settings ([#1891](https://github.com/wazuh/wazuh-docker/issues/1891))
|
||||
|
||||
| Issue | Comment |
|
||||
| - | - |
|
||||
| [#2537](https://github.com/wazuh/wazuh-docker/issues/2537) | Update deployment for Wazuh Indexer 5.0.0 RBAC |
|
||||
| [#2539](https://github.com/wazuh/wazuh-docker/pull/2539) | Add new WF for changelog check |
|
||||
| [#2502](https://github.com/wazuh/wazuh-docker/issues/2502) | Change artifact upload and download |
|
||||
| [#2471](https://github.com/wazuh/wazuh-docker/issues/2471) | Change runners on repository workflows 5.x |
|
||||
| [#2446](https://github.com/wazuh/wazuh-docker/issues/2446) | PR revamp modifications 5.x |
|
||||
| [#2399](https://github.com/wazuh/wazuh-docker/issues/2399) | Forbid pr_check workflow execution in draft PRs |
|
||||
| [#2375](https://github.com/wazuh/wazuh-docker/issues/2375) | Unification of user UID and GID |
|
||||
| [#2392](https://github.com/wazuh/wazuh-docker/issues/2392) | Wazuh indexer engine requirements |
|
||||
| [#2356](https://github.com/wazuh/wazuh-docker/issues/2356) | Image build process update |
|
||||
| [#2344](https://github.com/wazuh/wazuh-docker/issues/2344) | Add new path on artifact_urls file |
|
||||
| [#2341](https://github.com/wazuh/wazuh-docker/issues/2341) | Unable to generate single component in `Procedure_push_docker_images` |
|
||||
| [#2294](https://github.com/wazuh/wazuh-docker/issues/2294) | Adapt bumper workflows to change main branch |
|
||||
| [#2288](https://github.com/wazuh/wazuh-docker/issues/2288) | Ensure default values are used for variables and passwords |
|
||||
| [#2283](https://github.com/wazuh/wazuh-docker/issues/2283) | Docker - Ensure correct Wazuh manager certificates ownership |
|
||||
| [#2278](https://github.com/wazuh/wazuh-docker/issues/2278) | Docker - Standarize Artifact URL keys |
|
||||
| [#2266](https://github.com/wazuh/wazuh-docker/issues/2266) | Modify artifact URLs file name. |
|
||||
| [#2218](https://github.com/wazuh/wazuh-docker/issues/2218) | URL presigned file - Update the Wazuh Docker image creation workflow |
|
||||
| [#2264](https://github.com/wazuh/wazuh-docker/issues/2264) | Updated wazuh-docker documentation config and tooling versions to meet new standards. |
|
||||
| [#2250](https://github.com/wazuh/wazuh-docker/issues/2250) | Align cert generation steps with current cert-tool ip validation |
|
||||
| [#2252](https://github.com/wazuh/wazuh-docker/issues/2252) | Modify Healthchecks |
|
||||
| [#2251](https://github.com/wazuh/wazuh-docker/issues/2251) | Add deployment healthchecks |
|
||||
| [#2242](https://github.com/wazuh/wazuh-docker/issues/2242) | Update artifact generation jobs to use wz-linux dedicated runner group |
|
||||
| [#2237](https://github.com/wazuh/wazuh-docker/issues/2237) | Error during Wazuh manager entrypoint |
|
||||
| [#2230](https://github.com/wazuh/wazuh-docker/issues/2230) | Adapt PR test for workflow_dispatch option |
|
||||
| [#2227](https://github.com/wazuh/wazuh-docker/issues/2227) | Wazuh Manager/agent Separation - Breaking changes summary |
|
||||
| [#2222](https://github.com/wazuh/wazuh-docker/issues/2222) | Errors in wazuh-docker PR Test |
|
||||
| [#2206](https://github.com/wazuh/wazuh-docker/issues/2206) | Development - Separate Agent/Manager - Docker - Adapt image build process |
|
||||
| [#2217](https://github.com/wazuh/wazuh-docker/issues/2217) | Remove revision input |
|
||||
| [#2196](https://github.com/wazuh/wazuh-docker/issues/2196) | Build images script improvement |
|
||||
| [#2197](https://github.com/wazuh/wazuh-docker/issues/2197) | Missing documentation in the wazuh-docker repository |
|
||||
| [#2195](https://github.com/wazuh/wazuh-docker/issues/2195) | Add Wazuh version and revision into wazuh-certs-tool and config file |
|
||||
| [#2172](https://github.com/wazuh/wazuh-docker/issues/2172) | Improve S3 artifact URLs handling |
|
||||
| [#2164](https://github.com/wazuh/wazuh-docker/issues/2164) | Allow building separate targets |
|
||||
| [#2179](https://github.com/wazuh/wazuh-docker/issues/2179) | Add developement option when tag name is only version without stage |
|
||||
| [#2178](https://github.com/wazuh/wazuh-docker/issues/2178) | Add IMAGE_TAG stage reference |
|
||||
| [#2171](https://github.com/wazuh/wazuh-docker/issues/2171) | Remove Wazuh agent configuration template |
|
||||
| [#2156](https://github.com/wazuh/wazuh-docker/issues/2156) | Docker - Ensure `run_as` set to true for every deployment alternative |
|
||||
| [#2150](https://github.com/wazuh/wazuh-docker/issues/2150) | Change macOS and Windows deployment documentation |
|
||||
| [#2131](https://github.com/wazuh/wazuh-docker/issues/2131) | Modify docker build image process |
|
||||
| [#2136](https://github.com/wazuh/wazuh-docker/issues/2136) | Update documentation for Wazuh Docker image builder and workflow usage |
|
||||
| [#2081](https://github.com/wazuh/wazuh-docker/issues/2081) | Configure deployment with environment variables |
|
||||
| [#2058](https://github.com/wazuh/wazuh-docker/issues/2058) | Modify Wazuh components install method |
|
||||
| [#2054](https://github.com/wazuh/wazuh-docker/issues/2054) | Image builder Workflow Rebuild |
|
||||
| [#1933](https://github.com/wazuh/wazuh-docker/issues/1933) | Remove Wazuh Manager deprecated daemons and CLI tools |
|
||||
| [#1891](https://github.com/wazuh/wazuh-docker/issues/1891) | DevOps - Docker - OpenSearch 3.0 deprecated settings |
|
||||
|
||||
### Removed
|
||||
|
||||
- None
|
||||
| Issue | Comment |
|
||||
| - | - |
|
||||
|
||||
### Fixed
|
||||
|
||||
- Bumper script issue when the tag is set to false ([#2477](https://github.com/wazuh/wazuh-docker/issues/2477))
|
||||
- Fix reported WF vulnerabilities ([#2443](https://github.com/wazuh/wazuh-docker/issues/2443))
|
||||
- Adapt Wazuh manager healthcheck with local binaries ([#2422](https://github.com/wazuh/wazuh-docker/issues/2422))
|
||||
- The Wazuh Docker image cannot be built during the Nightly ([#2337](https://github.com/wazuh/wazuh-docker/issues/2337))
|
||||
- Docker and AMI workflows failing during stage release (v5.0.0-beta1) ([#35457](https://github.com/wazuh/wazuh/issues/35457))
|
||||
- PR check issues ([#2274](https://github.com/wazuh/wazuh-docker/issues/2274))
|
||||
- Wazuh manager Healthcheck ([#2271](https://github.com/wazuh/wazuh-docker/issues/2271))
|
||||
- Delete WAZUH_AGENT_GROUPS of Wazuh 5.0.0 images build ([#2258](https://github.com/wazuh/wazuh-docker/issues/2258))
|
||||
- Development - DevOps 5.0 adaptation - Docker - Delete lists directory references ([#2128](https://github.com/wazuh/wazuh-docker/issues/2128))
|
||||
|
||||
## Prior version
|
||||
- []()
|
||||
| Issue | Comment |
|
||||
| - | - |
|
||||
| [#9999](https://github.com/wazuh/wazuh-docker/issues/9999) | Test entry to validate changelog check regex (standard entry) |
|
||||
| [#2563](https://github.com/wazuh/wazuh-docker/issues/2563) | Fixed changelog check workflow to accept Prior versions entries |
|
||||
| [#2533](https://github.com/wazuh/wazuh-docker/pull/2533) | Fix bumper workflow failure when bump produces no changes |
|
||||
| [#2477](https://github.com/wazuh/wazuh-docker/issues/2477) | Bumper script issue when the tag is set to false |
|
||||
| [#2443](https://github.com/wazuh/wazuh-docker/issues/2443) | Fix reported WF vulnerabilities |
|
||||
| [#2422](https://github.com/wazuh/wazuh-docker/issues/2422) | Adapt Wazuh manager healthcheck with local binaries |
|
||||
| [#2337](https://github.com/wazuh/wazuh-docker/issues/2337) | The Wazuh Docker image cannot be built during the Nightly |
|
||||
| [#35457](https://github.com/wazuh/wazuh/issues/35457) | Docker and AMI workflows failing during stage release (v5.0.0-beta1) |
|
||||
| [#2274](https://github.com/wazuh/wazuh-docker/issues/2274) | PR check issues |
|
||||
| [#2271](https://github.com/wazuh/wazuh-docker/issues/2271) | Wazuh manager Healthcheck |
|
||||
| [#2258](https://github.com/wazuh/wazuh-docker/issues/2258) | Delete WAZUH_AGENT_GROUPS of Wazuh 5.0.0 images build |
|
||||
| [#2128](https://github.com/wazuh/wazuh-docker/issues/2128) | Development - DevOps 5.0 adaptation - Docker - Delete lists directory references |
|
||||
|
||||
## Prior versions
|
||||
- []()
|
||||
|
||||
+19
-8
@@ -1,6 +1,6 @@
|
||||
# Wazuh Open Source Project Security Policy
|
||||
|
||||
Version: 2023-06-12
|
||||
Version: 2026-07-06
|
||||
|
||||
## Introduction
|
||||
This document outlines the Security Policy for Wazuh's open source projects. It emphasizes our commitment to maintain a secure environment for our users and contributors, and reflects our belief in the power of collaboration to identify and resolve security vulnerabilities.
|
||||
@@ -13,16 +13,27 @@ If you believe you've discovered a potential security vulnerability in one of ou
|
||||
|
||||
Please submit your findings as security advisories under the "Security" tab in the relevant GitHub repository. Alternatively, you may send the details of your findings to [security@wazuh.com](mailto:security@wazuh.com).
|
||||
|
||||
## Reporting Vulnerabilities in Non-GA Versions
|
||||
|
||||
Wazuh publishes pre-release versions (Alphas, Betas, and Release Candidates) of its open source projects ahead of General Availability (GA) to gather community feedback. If you discover a potential security vulnerability in one of these non-GA versions, please report it following the process described above.
|
||||
|
||||
Upon receiving such a report, we will determine whether the vulnerability:
|
||||
|
||||
- **Affects only non-GA version(s)**: We will manage the report privately by opening a GitHub Security Advisory (GHSA). Since the affected code has not been part of a GA release, the vulnerability is not eligible for a CVE ID, consistent with the [CNA Operational Rules](https://www.cve.org/ResourcesSupport/AllResources/CNARules). Once resolved, the GHSA will be converted into a public issue instead of a security advisory.
|
||||
- **Also affects a previously released GA version**: We will continue managing the report as a GHSA and evaluate requesting a CVE ID for the GA-affected versions, in accordance with the eligibility criteria in the CNA Operational Rules.
|
||||
|
||||
## Vulnerability Disclosure Policy
|
||||
Upon receiving a report of a potential vulnerability, our team will initiate an investigation. If the reported issue is confirmed as a vulnerability, we will take the following steps:
|
||||
|
||||
1. Acknowledgment: We will acknowledge the receipt of your vulnerability report and begin our investigation.
|
||||
2. Validation: We will validate the issue and work on reproducing it in our environment.
|
||||
3. Remediation: We will work on a fix and thoroughly test it
|
||||
4. Release & Disclosure: After 90 days from the discovery of the vulnerability, or as soon as a fix is ready and thoroughly tested (whichever comes first), we will release a security update for the affected project. We will also publicly disclose the vulnerability by publishing a CVE (Common Vulnerabilities and Exposures) and acknowledging the discovering party.
|
||||
5. Exceptions: In order to preserve the security of the Wazuh community at large, we might extend the disclosure period to allow users to patch their deployments.
|
||||
1. **Acknowledgment**: We will acknowledge the receipt of your vulnerability report and begin our investigation.
|
||||
2. **Validation**: We will validate the issue and work on reproducing it in our environment.
|
||||
3. **Remediation**: We will develop a fix, have it reviewed, and merge it once thoroughly tested.
|
||||
4. **Release**: We will publish a security release for the affected project that includes the fix.
|
||||
5. **Rollout**: We will confirm that the fix has been applied to environments managed by Wazuh before proceeding with disclosure.
|
||||
6. **Disclosure**: Once the fix has been released and confirmed in managed environments, we will publicly disclose the vulnerability by publishing a CVE (Common Vulnerabilities and Exposures), where applicable, and acknowledging the discovering party.
|
||||
7. **Exceptions**: In order to preserve the security of the Wazuh community at large, we might extend the disclosure period to allow users to patch their deployments.
|
||||
|
||||
This 90-day period allows for end-users to update their systems and minimizes the risk of widespread exploitation of the vulnerability.
|
||||
Steps 1 through 6 will be completed within 90 days from the report of the vulnerability. This period allows for end-users to update their systems and minimizes the risk of widespread exploitation of the vulnerability.
|
||||
|
||||
## Automatic Scanning
|
||||
We leverage GitHub Actions to perform automated scans of our supply chain. These scans assist us in identifying vulnerabilities and outdated dependencies in a proactive and timely manner.
|
||||
@@ -42,4 +53,4 @@ We ask that all users and contributors respect this policy and the security of o
|
||||
## Changes to this Security Policy
|
||||
This policy may be revised from time to time. Each version of the policy will be identified at the top of the page by its effective date.
|
||||
|
||||
If you have any questions about this Security Policy, please contact us at [security@wazuh.com](mailto:security@wazuh.com)
|
||||
If you have any questions about this Security Policy, please contact us at [security@wazuh.com](mailto:security@wazuh.com)
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
{
|
||||
"version": "5.0.0",
|
||||
"stage": "beta3"
|
||||
"stage": "rc1"
|
||||
}
|
||||
|
||||
@@ -36,8 +36,7 @@ RUN dnf install procps shadow-utils -y && \
|
||||
curl -o /wazuh-agent.rpm "${agent_url}" && \
|
||||
dnf install /wazuh-agent.rpm -y && \
|
||||
rm -rf /wazuh-agent.rpm && \
|
||||
dnf clean all && \
|
||||
sed -i '/<authorization_pass_path>/d' /var/ossec/etc/ossec.conf
|
||||
dnf clean all
|
||||
|
||||
# Download tini static binary (no external library dependencies)
|
||||
RUN curl --fail --silent -L \
|
||||
|
||||
@@ -62,6 +62,15 @@ set_manager_conn() {
|
||||
sed -i "s#<address>CHANGE_MANAGER_IP</address>#<address>$WAZUH_MANAGER_SERVER</address>#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf
|
||||
sed -i "s#<manager_address>CHANGE_ENROLL_IP</manager_address>#<manager_address>$WAZUH_REGISTRATION_SERVER</manager_address>#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf
|
||||
sed -i "s#<agent_name>CHANGE_AGENT_NAME</agent_name>#<agent_name>$WAZUH_AGENT_NAME</agent_name>#g" ${WAZUH_INSTALL_PATH}/etc/ossec.conf
|
||||
if [ -n "$WAZUH_REGISTRATION_PASSWORD" ]; then
|
||||
set +x
|
||||
cat << EOF > /var/ossec/etc/authd.pass
|
||||
$WAZUH_REGISTRATION_PASSWORD
|
||||
EOF
|
||||
set -x
|
||||
else
|
||||
echo "WAZUH_REGISTRATION_PASSWORD is not set; the authd.pass configuration is omitted."
|
||||
fi
|
||||
}
|
||||
|
||||
##############################################################################
|
||||
|
||||
@@ -46,8 +46,7 @@ RUN setcap 'cap_net_bind_service=-ep' /usr/share/wazuh-dashboard/node/bin/node
|
||||
|
||||
################################################################################
|
||||
# Build stage 1 (the current Wazuh dashboard image):
|
||||
#
|
||||
# Copy wazuh-dashboard from stage 0
|
||||
# Copy wazuh-dashboard from builder
|
||||
# Add entrypoint
|
||||
# Add wazuh_dashboard_config
|
||||
################################################################################
|
||||
|
||||
@@ -41,8 +41,7 @@ RUN yum install curl-minimal shadow-utils findutils hostname -y && \
|
||||
|
||||
################################################################################
|
||||
# Build stage 1 (the actual Wazuh indexer image):
|
||||
#
|
||||
# Copy wazuh-indexer from stage 0
|
||||
# Copy wazuh-indexer from builder
|
||||
# Add entrypoint
|
||||
################################################################################
|
||||
FROM amazonlinux:2023
|
||||
|
||||
@@ -252,9 +252,9 @@ configure_permissions() {
|
||||
##############################################################################
|
||||
|
||||
set_correct_permOwner() {
|
||||
find /var/wazuh-manager/ -group 997 -exec chown :101 {} +;
|
||||
find /var/wazuh-manager/ -group 999 -exec chown :101 {} +;
|
||||
find /var/wazuh-manager/ -user 999 -exec chown 101:{} +;
|
||||
find /var/wazuh-manager/ -group 997 -exec chown :101 {} +
|
||||
find /var/wazuh-manager/ -group 999 -exec chown :101 {} +
|
||||
find /var/wazuh-manager/ -user 999 -exec chown 101 {} +
|
||||
}
|
||||
|
||||
##############################################################################
|
||||
|
||||
@@ -21,8 +21,8 @@ The Wazuh Manager container accepts the following environment variables, which c
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=SecretPassword
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
- WAZUH_API_URL=https://wazuh.manager
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
@@ -30,7 +30,7 @@ environment:
|
||||
|
||||
**Variable Descriptions:**
|
||||
|
||||
- `INDEXER_USERNAME` / `INDEXER_PASSWORD`: Credentials for accessing the Wazuh Indexer with `admin` user or a user with the same permissions.
|
||||
- `INDEXER_USERNAME` / `INDEXER_PASSWORD`: Credentials for accessing the Wazuh Indexer with `wazuh-manager` user or a user with the same permissions.
|
||||
- `WAZUH_API_URL`: URL of the Wazuh API, used by other services for communication.
|
||||
- `DASHBOARD_USERNAME` / `DASHBOARD_PASSWORD`: Credentials for the Wazuh Dashboard to authenticate with the Indexer.
|
||||
|
||||
@@ -57,8 +57,8 @@ The Wazuh Dashboard container accepts the following environment variables, which
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=SecretPassword
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
- WAZUH_API_URL=https://wazuh.manager
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
|
||||
@@ -19,9 +19,11 @@ Follow these steps to deploy the Wazuh agent using Docker.
|
||||
# ...
|
||||
environment:
|
||||
- WAZUH_MANAGER_SERVER=<YOUR_WAZUH_MANAGER_IP_OR_HOSTNAME>
|
||||
- WAZUH_REGISTRATION_PASSWORD=<authd.pass-PASSWORD>
|
||||
# ...
|
||||
```
|
||||
**Note:** Replace `<YOUR_WAZUH_MANAGER_IP_OR_HOSTNAME>` with the actual IP address or hostname of your Wazuh manager.
|
||||
**Note:** Replaces `<YOUR_WAZUH_MANAGER_IP_OR_HOSTNAME>` with the actual IP address or hostname of your Wazuh manager.
|
||||
**Note:** Replaces `<authd.pass-PASSWORD>` with the password configured in the `/var/wazuh-manager/etc/authd.pass` file of the Wazuh manager server where you will connect.
|
||||
|
||||
3. Start the environment using `docker compose`:
|
||||
|
||||
|
||||
+9
-9
@@ -24,15 +24,15 @@ Below is a step-by-step example of how to perform this update:
|
||||
```yaml
|
||||
services:
|
||||
wazuh.manager:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta3
|
||||
image: wazuh/wazuh-manager:5.0.0
|
||||
...
|
||||
|
||||
wazuh.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
...
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta3
|
||||
image: wazuh/wazuh-dashboard:5.0.0
|
||||
...
|
||||
```
|
||||
|
||||
@@ -48,27 +48,27 @@ Below is a step-by-step example of how to perform this update:
|
||||
```yaml
|
||||
services:
|
||||
wazuh.master:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta3
|
||||
image: wazuh/wazuh-manager:5.0.0
|
||||
...
|
||||
|
||||
wazuh.worker:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta3
|
||||
image: wazuh/wazuh-manager:5.0.0
|
||||
...
|
||||
|
||||
wazuh1.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
...
|
||||
|
||||
wazuh2.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
...
|
||||
|
||||
wazuh3.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
...
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta3
|
||||
image: wazuh/wazuh-dashboard:5.0.0
|
||||
...
|
||||
```
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||
services:
|
||||
wazuh.master:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta3
|
||||
image: wazuh/wazuh-manager:5.0.0
|
||||
hostname: wazuh.master
|
||||
container_name: multi-node-wazuh.master
|
||||
restart: always
|
||||
@@ -31,8 +31,8 @@ services:
|
||||
- WAZUH_NODE_TYPE=master
|
||||
- WAZUH_CLUSTER_BIND_ADDR=0.0.0.0
|
||||
- WAZUH_CLUSTER_NODES=wazuh.master
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
volumes:
|
||||
- master-wazuh-api-configuration:/var/wazuh-manager/api/configuration
|
||||
- master-wazuh-etc:/var/wazuh-manager/etc
|
||||
@@ -44,7 +44,7 @@ services:
|
||||
- ./config/wazuh_master/certs/wazuh.master-key.pem:/var/wazuh-manager/etc/certs/manager-key.pem
|
||||
|
||||
wazuh.worker:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta3
|
||||
image: wazuh/wazuh-manager:5.0.0
|
||||
hostname: wazuh.worker
|
||||
container_name: multi-node-wazuh.worker
|
||||
restart: always
|
||||
@@ -70,8 +70,8 @@ services:
|
||||
- WAZUH_NODE_TYPE=worker
|
||||
- WAZUH_CLUSTER_BIND_ADDR=0.0.0.0
|
||||
- WAZUH_CLUSTER_NODES=wazuh.master
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
volumes:
|
||||
- worker-wazuh-api-configuration:/var/wazuh-manager/api/configuration
|
||||
- worker-wazuh-etc:/var/wazuh-manager/etc
|
||||
@@ -83,7 +83,7 @@ services:
|
||||
- ./config/wazuh_worker/certs/wazuh.worker-key.pem:/var/wazuh-manager/etc/certs/manager-key.pem
|
||||
|
||||
wazuh1.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
hostname: wazuh1.indexer
|
||||
container_name: multi-node-wazuh1.indexer
|
||||
restart: always
|
||||
@@ -121,7 +121,7 @@ services:
|
||||
- ./config/wazuh1_indexer/certs/admin-key.pem:/usr/share/wazuh-indexer/config/certs/admin-key.pem
|
||||
|
||||
wazuh2.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
hostname: wazuh2.indexer
|
||||
container_name: multi-node-wazuh2.indexer
|
||||
restart: always
|
||||
@@ -159,7 +159,7 @@ services:
|
||||
- ./config/wazuh2_indexer/certs/wazuh2.indexer.pem:/usr/share/wazuh-indexer/config/certs/indexer.pem
|
||||
|
||||
wazuh3.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
hostname: wazuh3.indexer
|
||||
container_name: multi-node-wazuh3.indexer
|
||||
restart: always
|
||||
@@ -197,7 +197,7 @@ services:
|
||||
- ./config/wazuh3_indexer/certs/wazuh3.indexer.pem:/usr/share/wazuh-indexer/config/certs/indexer.pem
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta3
|
||||
image: wazuh/wazuh-dashboard:5.0.0
|
||||
hostname: wazuh.dashboard
|
||||
container_name: multi-node-wazuh.dashboard
|
||||
restart: always
|
||||
@@ -213,8 +213,6 @@ services:
|
||||
- SERVER_PORT=5601
|
||||
- SERVER_HOST=0.0.0.0
|
||||
- OPENSEARCH_HOSTS=["https://wazuh1.indexer:9200","https://wazuh2.indexer:9200","https://wazuh3.indexer:9200"]
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- WAZUH_API_URL=https://wazuh.master
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||
services:
|
||||
wazuh.manager:
|
||||
image: wazuh/wazuh-manager:5.0.0-beta3
|
||||
image: wazuh/wazuh-manager:5.0.0
|
||||
hostname: wazuh.manager
|
||||
container_name: single-node-wazuh.manager
|
||||
restart: always
|
||||
@@ -31,8 +31,8 @@ services:
|
||||
- WAZUH_NODE_NAME=manager
|
||||
- WAZUH_CLUSTER_NODES=wazuh.manager
|
||||
- WAZUH_CLUSTER_BIND_ADDR=wazuh.manager
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- INDEXER_USERNAME=wazuh-manager
|
||||
- INDEXER_PASSWORD=wazuh-manager
|
||||
volumes:
|
||||
- wazuh_api_configuration:/var/wazuh-manager/api/configuration
|
||||
- wazuh_etc:/var/wazuh-manager/etc
|
||||
@@ -44,7 +44,7 @@ services:
|
||||
- ./config/wazuh_manager/certs/wazuh.manager-key.pem:/var/wazuh-manager/etc/certs/manager-key.pem
|
||||
|
||||
wazuh.indexer:
|
||||
image: wazuh/wazuh-indexer:5.0.0-beta3
|
||||
image: wazuh/wazuh-indexer:5.0.0
|
||||
hostname: wazuh.indexer
|
||||
container_name: single-node-wazuh.indexer
|
||||
restart: always
|
||||
@@ -81,7 +81,7 @@ services:
|
||||
- ./config/wazuh_indexer/certs/admin-key.pem:/usr/share/wazuh-indexer/config/certs/admin-key.pem
|
||||
|
||||
wazuh.dashboard:
|
||||
image: wazuh/wazuh-dashboard:5.0.0-beta3
|
||||
image: wazuh/wazuh-dashboard:5.0.0
|
||||
hostname: wazuh.dashboard
|
||||
container_name: single-node-wazuh.dashboard
|
||||
restart: always
|
||||
@@ -97,8 +97,6 @@ services:
|
||||
- SERVER_PORT=5601
|
||||
- SERVER_HOST=0.0.0.0
|
||||
- OPENSEARCH_HOSTS=https://wazuh.indexer:9200
|
||||
- INDEXER_USERNAME=admin
|
||||
- INDEXER_PASSWORD=admin
|
||||
- WAZUH_API_URL=https://wazuh.manager
|
||||
- DASHBOARD_USERNAME=kibanaserver
|
||||
- DASHBOARD_PASSWORD=kibanaserver
|
||||
|
||||
@@ -1,7 +1,8 @@
|
||||
# Wazuh App Copyright (C) 2017, Wazuh Inc. (License GPLv2)
|
||||
services:
|
||||
wazuh.agent:
|
||||
image: wazuh/wazuh-agent:5.0.0-beta3
|
||||
image: wazuh/wazuh-agent:5.0.0
|
||||
restart: always
|
||||
environment:
|
||||
- WAZUH_MANAGER_SERVER=<WAZUH_MANAGER_IP>
|
||||
- WAZUH_REGISTRATION_PASSWORD=<authd.pass-PASSWORD>
|
||||
|
||||
Reference in New Issue
Block a user