run-name: Launch Push Docker Images - ${{ inputs.id }} name: Push Docker Images on: workflow_dispatch: inputs: image_tag: description: 'Docker image tag' default: '5.0.0' required: true docker_reference: description: 'wazuh-docker reference' required: true products: description: 'Comma-separated list of the image names to build and push' default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' required: false revision: description: 'Package revision' default: '1' required: true reference: description: 'Dev reference' type: string default: latest id: description: "ID used to identify the workflow uniquely." type: string required: false dev: description: "Add tag suffix '-dev' to the image tag ?" type: boolean default: true required: false workflow_call: inputs: image_tag: description: 'Docker image tag' default: '5.0.0' required: true type: string docker_reference: description: 'wazuh-docker reference' required: false type: string products: description: 'Comma-separated list of the image names to build and push' default: 'wazuh-manager,wazuh-dashboard,wazuh-indexer,wazuh-agent' required: false type: string revision: description: 'Package revision' default: '1' required: true type: string reference: description: 'Dev reference' type: string default: latest id: description: "ID used to identify the workflow uniquely." type: string required: false dev: description: "Add tag suffix '-dev' to the image tag ?" type: boolean default: false required: false jobs: setup: runs-on: ubuntu-22.04 permissions: id-token: write contents: read outputs: WAZUH_COMPONENTS: ${{ steps.compute-outputs.outputs.WAZUH_COMPONENTS }} steps: - name: Print inputs run: | echo "---------------------------------------------" echo "Running Procedure_push_docker_images workflow" echo "---------------------------------------------" echo "* BRANCH: ${{ github.ref }}" echo "* COMMIT: ${{ github.sha }}" echo "---------------------------------------------" echo "Inputs provided:" echo "---------------------------------------------" echo "* id: ${{ inputs.id }}" echo "* image_tag: ${{ inputs.image_tag }}" echo "* docker_reference: ${{ inputs.docker_reference }}" echo "* products: ${{ inputs.products }}" echo "* revision: ${{ inputs.revision }}" echo "* dev: ${{ inputs.dev }}" echo "* dev reference: ${{ inputs.reference }}" echo "---------------------------------------------" - name: Set up variables id: compute-outputs run: | if [[ "${{ inputs.products }}" != "null" && "${{ inputs.products }}" != "" ]]; then # Convert comma-separated list to JSON array format IFS=',' read -ra COMPONENTS <<< "${{ inputs.products }}" JSON_ARRAY="[" for i in "${!COMPONENTS[@]}"; do if [ $i -gt 0 ]; then JSON_ARRAY+="," fi JSON_ARRAY+="\"${COMPONENTS[$i]}\"" done JSON_ARRAY+="]" echo "WAZUH_COMPONENTS=$JSON_ARRAY" >> $GITHUB_OUTPUT else echo "WAZUH_COMPONENTS=[\"wazuh-manager\",\"wazuh-dashboard\",\"wazuh-indexer\",\"wazuh-agent\"]" >> $GITHUB_OUTPUT fi build-and-push: runs-on: ubuntu-22.04 permissions: id-token: write contents: read needs: - setup strategy: fail-fast: false # all jobs will run even if one fails matrix: wazuh_component: ${{ fromJson(needs.setup.outputs.WAZUH_COMPONENTS) }} env: IMAGE_REGISTRY: ${{ inputs.dev && vars.IMAGE_REGISTRY_DEV || vars.IMAGE_REGISTRY_PROD }} IMAGE_TAG: ${{ inputs.image_tag }} REVISION: ${{ inputs.revision }} steps: - name: Checkout repository uses: actions/checkout@v4 with: ref: ${{ inputs.docker_reference }} - name: free disk space uses: ./.github/free-disk-space - name: Set up QEMU uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Configure aws credentials if: ${{ inputs.dev == true }} uses: aws-actions/configure-aws-credentials@v4 with: role-to-assume: ${{ secrets.AWS_IAM_DOCKER_ROLE }} aws-region: "${{ secrets.AWS_REGION }}" - name: Log in to Amazon ECR if: ${{ inputs.dev == true }} uses: aws-actions/amazon-ecr-login@v2 - name: Log in to Docker Hub if: ${{ inputs.dev == false }} uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_PASSWORD }} - name: Create artifact_urls.yml file if : ${{ inputs.dev == true }} run: | cat << EOF > artifact_urls.yml wazuh_manager_url_amd64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-manager_5.0.0-${{ inputs.reference }}_amd64.deb --expires-in 3600 --region us-west-1)" wazuh_manager_url_arm64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-manager_5.0.0-${{ inputs.reference }}_arm64.deb --expires-in 3600 --region us-west-1)" wazuh_manager_url_x86_64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-manager-5.0.0-${{ inputs.reference }}.x86_64.rpm --expires-in 3600 --region us-west-1)" wazuh_manager_url_aarch64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-manager-5.0.0-${{ inputs.reference }}.aarch64.rpm --expires-in 3600 --region us-west-1)" wazuh_indexer_url_amd64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-indexer_5.0.0-${{ inputs.reference }}_amd64.deb --expires-in 3600 --region us-west-1)" wazuh_indexer_url_arm64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-indexer_5.0.0-${{ inputs.reference }}_arm64.deb --expires-in 3600 --region us-west-1)" wazuh_indexer_url_x86_64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-indexer-5.0.0-${{ inputs.reference }}.x86_64.rpm --expires-in 3600 --region us-west-1)" wazuh_indexer_url_aarch64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-indexer-5.0.0-${{ inputs.reference }}.aarch64.rpm --expires-in 3600 --region us-west-1)" wazuh_dashboard_url_amd64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-dashboard_5.0.0-${{ inputs.reference }}_amd64.deb --expires-in 3600 --region us-west-1)" wazuh_dashboard_url_arm64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-dashboard_5.0.0-${{ inputs.reference }}_arm64.deb --expires-in 3600 --region us-west-1)" wazuh_dashboard_url_x86_64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-dashboard-5.0.0-${{ inputs.reference }}.x86_64.rpm --expires-in 3600 --region us-west-1)" wazuh_dashboard_url_aarch64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-dashboard-5.0.0-${{ inputs.reference }}.aarch64.rpm --expires-in 3600 --region us-west-1)" wazuh_agent_url_amd64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-agent_5.0.0-${{ inputs.reference }}_amd64.deb --expires-in 3600 --region us-west-1)" wazuh_agent_url_arm64_deb: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-agent_5.0.0-${{ inputs.reference }}_arm64.deb --expires-in 3600 --region us-west-1)" wazuh_agent_url_x86_64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-agent-5.0.0-${{ inputs.reference }}.x86_64.rpm --expires-in 3600 --region us-west-1)" wazuh_agent_url_aarch64_rpm: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-agent-5.0.0-${{ inputs.reference }}.aarch64.rpm --expires-in 3600 --region us-west-1)" wazuh_agent_url_i386_msi: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-agent-5.0.0-${{ inputs.reference }}.i386.msi --expires-in 3600 --region us-west-1)" wazuh_agent_url_intel64_pkg: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-agent-5.0.0-${{ inputs.reference }}.intel64.pkg --expires-in 3600 --region us-west-1)" wazuh_agent_url_arm64_pkg: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/main/packages/wazuh-agent-5.0.0-${{ inputs.reference }}.arm64.pkg --expires-in 3600 --region us-west-1)" wazuh_certs_tool: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/secondary/installation-assistant/5.0.0/wazuh-certs-tool.sh --expires-in 3600 --region us-west-1)" wazuh_config_yml: "$(aws s3 presign s3://${{ vars.AWS_S3_BUCKET_DEV }}/development/wazuh/5.x/secondary/installation-assistant/5.0.0/config.yml --expires-in 3600 --region us-west-1)" EOF working-directory: ./build-docker-images - name: Build Wazuh images run: | if [[ "$IMAGE_TAG" == *"-"* ]]; then IFS='-' read -r -a tokens <<< "$IMAGE_TAG" if [ -z "${tokens[1]}" ]; then echo "Invalid image tag: $IMAGE_TAG" exit 1 fi DEV_STAGE=${tokens[1]} WAZUH_VER=${tokens[0]} if [ "${{ inputs.dev }}" = true ]; then ./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -rg $IMAGE_REGISTRY -m -ref ${{ inputs.reference }} -c ${{ matrix.wazuh_component }} else ./build-images.sh -v $WAZUH_VER -r $REVISION -d $DEV_STAGE -rg $IMAGE_REGISTRY -m -c ${{ matrix.wazuh_component }} fi else if [ "${{ inputs.dev }}" = true ]; then ./build-images.sh -v $IMAGE_TAG -r $REVISION -rg $IMAGE_REGISTRY -m -ref ${{ inputs.reference }} -c ${{ matrix.wazuh_component }} else ./build-images.sh -v $IMAGE_TAG -r $REVISION -rg $IMAGE_REGISTRY -m -c ${{ matrix.wazuh_component }} fi fi # Save .env file (generated by build-images.sh) contents to $GITHUB_ENV ENV_FILE_PATH="../.env" if [ -f $ENV_FILE_PATH ]; then while IFS= read -r line || [ -n "$line" ]; do echo "$line" >> $GITHUB_ENV done < $ENV_FILE_PATH else echo "The environment file $ENV_FILE_PATH does not exist!" exit 1 fi working-directory: ./build-docker-images - name: Image exists validation if: ${{ inputs.dev == false }} id: validation run: | IMAGE_TAG=${{ inputs.image_tag }} PURPOSE="" if [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then if docker manifest inspect $IMAGE_REGISTRY/wazuh/wazuh-manager:$IMAGE_TAG > /dev/null 2>&1; then PURPOSE="regeneration" echo "Image wazuh/wazuh-manager:$IMAGE_TAG exists. Setting PURPOSE to 'regeneration'" else PURPOSE="new release" echo "Image wazuh/wazuh-manager:$IMAGE_TAG does NOT exist. Setting PURPOSE to 'new release'" fi echo "✅ Release tag: '$IMAGE_TAG'" elif [[ "$IMAGE_TAG" =~ ^[0-9]+\.[0-9]+\.[0-9]+-(alpha|beta|rc)[0-9]+$ ]]; then PURPOSE="new stage" echo "✅ Stage tag: '$IMAGE_TAG'. Setting PURPOSE to 'new stage'" else echo "❌ No release or stage tag ('$IMAGE_TAG'), the GH issue will not be created" fi echo "purpose=$PURPOSE" >> $GITHUB_OUTPUT - name: GH issue notification if: ${{ inputs.dev == false && steps.validation.outputs.purpose != '' }} run: | IMAGE_TAG=${{ inputs.image_tag }} GH_TITLE="" GH_MESSAGE="" PURPOSE="${{ steps.validation.outputs.purpose }}" ## Setting GH issue title GH_TITLE="Artifactory vulnerabilities update \`v$IMAGE_TAG\`" ## Setting GH issue body GH_MESSAGE=$(cat <<- EOF | tr -d '\r' | sed 's/^[[:space:]]*//' ### Description - [ ] Update the [Artifactory vulnerabilities](${{ secrets.NOTIFICATION_SHEET_URL }}) sheet with the \`v$IMAGE_TAG\` vulnerabilities. **Purpose**: $PURPOSE >[!NOTE] >To update the \`Tentative Release\` column, follow these steps: https://github.com/wazuh/${{ secrets.NOTIFICATION_REPO }}/issues/2049#issuecomment-2671590268 EOF ) # Print the GH Variables content echo "--- Variable Content ---" echo "$GH_TITLE" echo "------------------------" echo "--- Variable Content ---" echo "$GH_MESSAGE" echo "------------------------" ## GH issue creation ISSUE_URL=$(gh issue create \ -R wazuh/${{ secrets.NOTIFICATION_REPO }} \ --title "$GH_TITLE" \ --body "$GH_MESSAGE" \ --label "level/task" \ --label "type/maintenance" \ --label "request/operational") ## Adding the issue to the team project PROJECT_ITEM_ID=$(gh project item-add \ ${{ secrets.NOTIFICATION_PROJECT_NUMBER }} \ --url $ISSUE_URL \ --owner wazuh \ --format json \ | jq -r '.id') ## Setting Objective gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_OBJECTIVE_ID }} --text "Security scans" ## Setting Priority gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_PRIORITY_OPTION_ID }} ## Setting Size gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SIZE_OPTION_ID }} ## Setting Subteam gh project item-edit --id $PROJECT_ITEM_ID --project-id ${{ secrets.NOTIFICATION_PROJECT_ID }} --field-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_ID }} --single-select-option-id ${{ secrets.NOTIFICATION_PROJECT_SUBTEAM_OPTION_ID }} env: GH_TOKEN: ${{ secrets.NOTIFICATION_GH_ARTIFACT_TOKEN }}