name: Wazuh Docker pipeline on: [pull_request] env: ARTIFACTS_LOCAL_DIR: /home/runner/work/wazuh-docker/wazuh-docker/docker-images ARTIFACT_NAMES: | wazuh-manager.tar wazuh-indexer.tar wazuh-dashboard.tar wazuh-agent.tar jobs: build-docker-images: runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }} steps: - name: Check out code uses: actions/checkout@v6 - name: Log in to Docker Hub uses: docker/login-action@v4 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_PASSWORD }} - name: Build Wazuh images run: ./build-images.sh working-directory: ./build-docker-images - name: Create enviroment variables run: cat .env > $GITHUB_ENV - name: Create backup Docker images run: | mkdir -p /home/runner/work/wazuh-docker/wazuh-docker/docker-images/ docker save wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-manager.tar docker save wazuh/wazuh-indexer:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-indexer.tar docker save wazuh/wazuh-dashboard:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-dashboard.tar docker save wazuh/wazuh-agent:${{env.WAZUH_IMAGE_VERSION}} -o /home/runner/work/wazuh-docker/wazuh-docker/docker-images/wazuh-agent.tar - name: Temporarily save Wazuh Docker images env: S3_ARTIFACTS_PATH: s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/4_pr_check/${{ github.run_id }} run: | echo "Uploading Docker image artifacts to S3..." while IFS= read -r artifact; do [ -z "$artifact" ] && continue echo " Uploading: $artifact" aws s3 cp "${ARTIFACTS_LOCAL_DIR}/${artifact}" "${S3_ARTIFACTS_PATH}/${artifact}" done <<< "$ARTIFACT_NAMES" echo "All artifacts uploaded successfully." check-single-node: runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }} needs: build-docker-images steps: - name: Check out code uses: actions/checkout@v6 - name: Create enviroment variables run: cat .env > $GITHUB_ENV - name: Log in to Docker Hub uses: docker/login-action@v4 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_PASSWORD }} - name: Retrieve saved Wazuh Docker images and load them into Docker env: S3_ARTIFACTS_PATH: s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/4_pr_check/${{ github.run_id }} ARTIFACTS_LOCAL_DIR: /home/runner/work/wazuh-docker/wazuh-docker/docker-images run: | mkdir -p "${ARTIFACTS_LOCAL_DIR}" echo "Downloading and loading Docker image artifacts from S3..." while IFS= read -r artifact; do [ -z "$artifact" ] && continue echo " Downloading: $artifact" aws s3 cp "${S3_ARTIFACTS_PATH}/${artifact}" "${ARTIFACTS_LOCAL_DIR}/${artifact}" echo " Loading into Docker: $artifact" docker load -i "${ARTIFACTS_LOCAL_DIR}/${artifact}" done <<< "$ARTIFACT_NAMES" echo "All artifacts downloaded and loaded successfully." - name: Create single node certficates run: docker compose -f single-node/generate-indexer-certs.yml run --rm generator - name: Start single node stack run: docker compose -f single-node/docker-compose.yml up -d - name: Check Wazuh indexer start run: | sleep 60 timeout 600 bash -c 'until curl -XGET "https://localhost:9200/_cluster/health" -u admin:SecretPassword -k -s | grep "green"; do sleep 5; done' if [ $? -ne 0 ]; then docker ps -a exit 1 fi status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`" if [[ $status_green -eq 1 ]]; then curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s else curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s exit 1 fi status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`" status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep "green" | wc -l`" timeout 120 bash -c 'until [ $status_index_green -eq $status_index ]; do sleep 5; done' if [[ $status_index_green -eq $status_index ]]; then curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s else curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s exit 1 fi - name: Check Wazuh indexer nodes run: | nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`" if [[ $nodes -eq 1 ]]; then echo "Wazuh indexer nodes: ${nodes}" else echo "Wazuh indexer nodes: ${nodes}" exit 1 fi - name: Check Wazuh templates run: | timeout 120 bash -c 'until [ $(curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh" | wc -l) -eq 3 ]; do sleep 5; done' qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics" | wc -l`" templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep -P "wazuh|wazuh-agent|wazuh-statistics"`" if [[ $qty_templates -gt 3 ]]; then echo "wazuh templates:" echo "${templates}" else echo "wazuh templates:" echo "${templates}" exit 1 fi - name: Check Wazuh manager start run: | services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`" if [[ $services -gt 9 ]]; then echo "Wazuh Manager Services: ${services}" echo "OK" else echo "Wazuh indexer nodes: ${nodes}" curl -k -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items exit 1 fi env: TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - name: Check filebeat output run: ./.github/single-node-filebeat-check.sh - name: Check Wazuh dashboard service URL run: | status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I -s | grep -E "^HTTP" | awk '{print $2}') if [[ $status -eq 200 ]]; then echo "Wazuh dashboard status: ${status}" else echo "Wazuh dashboard status: ${status}" exit 1 fi - name: Modify Docker endpoint into Wazuh agent docker-compose.yml file run: sed -i "s//$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml - name: Start Wazuh agent run: docker compose -f wazuh-agent/docker-compose.yml up -d - name: Check Wazuh agent enrollment run: | sleep 20 curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" env: TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - name: Check documents into wazuh-alerts index run: | sleep 120 docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`" if [[ $docs -gt 0 ]]; then echo "wazuh-alerts index documents: ${docs}" else echo "wazuh-alerts index documents: ${docs}" exit 1 fi - name: Check errors in ossec.log for Wazuh manager run: ./.github/single-node-log-check.sh check-multi-node: runs-on: codebuild-github-actions-codebuild-runner-devops-amd-${{ github.run_id }}-${{ github.run_attempt }} needs: build-docker-images steps: - name: Check out code uses: actions/checkout@v6 - name: Create enviroment variables run: cat .env > $GITHUB_ENV - name: Log in to Docker Hub uses: docker/login-action@v4 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_PASSWORD }} - name: Set vm.max_map_count run: sysctl -w vm.max_map_count=262144 - name: Retrieve saved Wazuh Docker images and load them into Docker env: S3_ARTIFACTS_PATH: s3://${{ secrets.CI_DEV_INTERNAL_S3_BUCKET }}/wazuh-docker/4_pr_check/${{ github.run_id }} ARTIFACTS_LOCAL_DIR: /home/runner/work/wazuh-docker/wazuh-docker/docker-images run: | mkdir -p "${ARTIFACTS_LOCAL_DIR}" echo "Downloading and loading Docker image artifacts from S3..." while IFS= read -r artifact; do [ -z "$artifact" ] && continue echo " Downloading: $artifact" aws s3 cp "${S3_ARTIFACTS_PATH}/${artifact}" "${ARTIFACTS_LOCAL_DIR}/${artifact}" echo " Loading into Docker: $artifact" docker load -i "${ARTIFACTS_LOCAL_DIR}/${artifact}" done <<< "$ARTIFACT_NAMES" echo "All artifacts downloaded and loaded successfully." - name: Create multi node certficates run: docker compose -f multi-node/generate-indexer-certs.yml run --rm generator - name: Start multi node stack run: docker compose -f multi-node/docker-compose.yml up -d - name: Check Wazuh indexer start run: | sleep 120 timeout 600 bash -c 'until curl -XGET "https://localhost:9200/_cluster/health" -u admin:SecretPassword -k -s | grep -v "yellow"; do sleep 5; done' if [ $? -ne 0 ]; then docker ps -a exit 1 fi status_green="`curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s | grep green | wc -l`" if [[ $status_green -eq 1 ]]; then curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s else curl -XGET "https://0.0.0.0:9200/_cluster/health" -u admin:SecretPassword -k -s exit 1 fi status_index="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | wc -l`" status_index_green="`curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s | grep "green" | wc -l`" timeout 120 bash -c 'until [ $status_index_green -eq $status_index ]; do sleep 5; done' if [[ $status_index_green -eq $status_index ]]; then curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s else curl -XGET "https://0.0.0.0:9200/_cat/indices" -u admin:SecretPassword -k -s exit 1 fi - name: Check Wazuh indexer nodes run: | nodes="`curl -XGET "https://0.0.0.0:9200/_cat/nodes" -u admin:SecretPassword -k -s | grep -E "indexer" | wc -l`" if [[ $nodes -eq 3 ]]; then echo "Wazuh indexer nodes: ${nodes}" else echo "Wazuh indexer nodes: ${nodes}" exit 1 fi - name: Check Wazuh templates run: | timeout 120 bash -c 'until [ $(curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh" | wc -l) -eq 3 ]; do sleep 5; done' qty_templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh" | wc -l`" templates="`curl -XGET "https://0.0.0.0:9200/_cat/templates" -u admin:SecretPassword -k -s | grep "wazuh"`" if [[ $qty_templates -gt 3 ]]; then echo "wazuh templates:" echo "${templates}" else echo "wazuh templates:" echo "${templates}" exit 1 fi - name: Check Wazuh manager start run: | services="`curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items | grep running | wc -l`" if [[ $services -gt 10 ]]; then echo "Wazuh Manager Services: ${services}" echo "OK" else echo "Wazuh Manager Services: ${services}" curl -k -s -X GET "https://0.0.0.0:55000/manager/status?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r .data.affected_items exit 1 fi nodes=$(curl -k -s -X GET "https://0.0.0.0:55000/cluster/nodes" -H "Authorization: Bearer ${{env.TOKEN}}" | jq -r ".data.affected_items[].name" | wc -l) if [[ $nodes -eq 2 ]]; then echo "Wazuh manager nodes: ${nodes}" else echo "Wazuh manager nodes: ${nodes}" exit 1 fi env: TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - name: Check filebeat output run: ./.github/multi-node-filebeat-check.sh - name: Check Wazuh dashboard service URL run: | status=$(curl -XGET --silent https://0.0.0.0:443/app/status -k -u admin:SecretPassword -I | grep -E "^HTTP" | awk '{print $2}') if [[ $status -eq 200 ]]; then echo "Wazuh dashboard status: ${status}" else echo "Wazuh dashboard status: ${status}" exit 1 fi - name: Modify Docker endpoint into Wazuh agent docker-compose.yml file run: sed -i "s//$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d'/' -f1)/g" wazuh-agent/docker-compose.yml - name: Start Wazuh agent run: docker compose -f wazuh-agent/docker-compose.yml up -d - name: Check Wazuh agent enrollment run: | sleep 20 curl -k -s -X GET "https://localhost:55000/agents?pretty=true" -H "Authorization: Bearer ${{env.TOKEN}}" env: TOKEN: $(curl -s -u wazuh-wui:MyS3cr37P450r.*- -k -X GET "https://0.0.0.0:55000/security/user/authenticate?raw=true") - name: Check documents into wazuh-alerts index run: | until [[ $(``curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"``) -gt 0 ]] do echo 'Waiting for Wazuh indexer events' free -m df -h sleep 10 done docs="`curl -XGET "https://0.0.0.0:9200/wazuh-alerts*/_count" -u admin:SecretPassword -k -s | jq -r ".count"`" if [[ $docs -gt 0 ]]; then echo "wazuh-alerts index documents: ${docs}" else echo "wazuh-alerts index documents: ${docs}" exit 1 fi - name: Check errors in ossec.log for Wazuh manager run: ./.github/multi-node-log-check.sh