mirror of
https://github.com/wazuh/wazuh-docker.git
synced 2025-11-03 21:43:15 +00:00
Compare commits
4 Commits
v4.14.1-rc
...
2693-delet
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ade0b30f2e | ||
|
|
731fb5a899 | ||
|
|
b2de947ee9 | ||
|
|
0c8a36fe06 |
2
.env
2
.env
@@ -1,6 +1,6 @@
|
|||||||
WAZUH_VERSION=4.14.0
|
WAZUH_VERSION=4.14.0
|
||||||
WAZUH_IMAGE_VERSION=4.14.0
|
WAZUH_IMAGE_VERSION=4.14.0
|
||||||
WAZUH_TAG_REVISION=1
|
WAZUH_TAG_REVISION=1
|
||||||
FILEBEAT_TEMPLATE_BRANCH=4.14.0
|
FILEBEAT_TEMPLATE_BRANCH=v4.14.0
|
||||||
WAZUH_FILEBEAT_MODULE=wazuh-filebeat-0.4.tar.gz
|
WAZUH_FILEBEAT_MODULE=wazuh-filebeat-0.4.tar.gz
|
||||||
WAZUH_UI_REVISION=1
|
WAZUH_UI_REVISION=1
|
||||||
|
|||||||
@@ -20,13 +20,11 @@ RUN yum install wazuh-dashboard-${WAZUH_VERSION}-${WAZUH_TAG_REVISION} -y && \
|
|||||||
RUN mkdir -p $INSTALL_DIR/data/wazuh && chmod -R 775 $INSTALL_DIR/data/wazuh
|
RUN mkdir -p $INSTALL_DIR/data/wazuh && chmod -R 775 $INSTALL_DIR/data/wazuh
|
||||||
RUN mkdir -p $INSTALL_DIR/data/wazuh/config && chmod -R 775 $INSTALL_DIR/data/wazuh/config
|
RUN mkdir -p $INSTALL_DIR/data/wazuh/config && chmod -R 775 $INSTALL_DIR/data/wazuh/config
|
||||||
RUN mkdir -p $INSTALL_DIR/data/wazuh/logs && chmod -R 775 $INSTALL_DIR/data/wazuh/logs
|
RUN mkdir -p $INSTALL_DIR/data/wazuh/logs && chmod -R 775 $INSTALL_DIR/data/wazuh/logs
|
||||||
COPY config/wazuh.yml $INSTALL_DIR/data/wazuh/config/
|
|
||||||
RUN setcap 'cap_net_bind_service=-ep' /usr/share/wazuh-dashboard/node/bin/node
|
RUN setcap 'cap_net_bind_service=-ep' /usr/share/wazuh-dashboard/node/bin/node
|
||||||
RUN setcap 'cap_net_bind_service=-ep' /usr/share/wazuh-dashboard/node/fallback/bin/node
|
RUN setcap 'cap_net_bind_service=-ep' /usr/share/wazuh-dashboard/node/fallback/bin/node
|
||||||
|
|
||||||
# Generate certificates
|
# Generate certificates
|
||||||
COPY config/config.sh .
|
COPY config/config.sh .
|
||||||
COPY config/config.yml /
|
|
||||||
RUN bash config.sh
|
RUN bash config.sh
|
||||||
|
|
||||||
################################################################################
|
################################################################################
|
||||||
@@ -42,10 +40,8 @@ FROM amazonlinux:2023
|
|||||||
ENV USER="wazuh-dashboard" \
|
ENV USER="wazuh-dashboard" \
|
||||||
GROUP="wazuh-dashboard" \
|
GROUP="wazuh-dashboard" \
|
||||||
NAME="wazuh-dashboard" \
|
NAME="wazuh-dashboard" \
|
||||||
INSTALL_DIR="/usr/share/wazuh-dashboard"
|
INSTALL_DIR="/usr/share/wazuh-dashboard" \
|
||||||
|
PATTERN="" \
|
||||||
# Set Wazuh app variables
|
|
||||||
ENV PATTERN="" \
|
|
||||||
CHECKS_PATTERN="" \
|
CHECKS_PATTERN="" \
|
||||||
CHECKS_TEMPLATE="" \
|
CHECKS_TEMPLATE="" \
|
||||||
CHECKS_API="" \
|
CHECKS_API="" \
|
||||||
@@ -59,34 +55,32 @@ ENV PATTERN="" \
|
|||||||
WAZUH_MONITORING_SHARDS="" \
|
WAZUH_MONITORING_SHARDS="" \
|
||||||
WAZUH_MONITORING_REPLICAS=""
|
WAZUH_MONITORING_REPLICAS=""
|
||||||
|
|
||||||
# Update and install dependencies
|
# Copy and set permissions to scripts
|
||||||
RUN yum install shadow-utils -y
|
COPY config/entrypoint.sh /
|
||||||
|
COPY config/wazuh_app_config.sh /
|
||||||
|
|
||||||
# Create wazuh-dashboard user and group
|
# Update and install dependencies
|
||||||
RUN getent group $GROUP || groupadd -r -g 1000 $GROUP
|
RUN yum install shadow-utils -y && \
|
||||||
RUN useradd --system \
|
yum clean all && \
|
||||||
|
getent group $GROUP || groupadd -r -g 1000 $GROUP && \
|
||||||
|
useradd --system \
|
||||||
--uid 1000 \
|
--uid 1000 \
|
||||||
--no-create-home \
|
--no-create-home \
|
||||||
--home-dir $INSTALL_DIR \
|
--home-dir $INSTALL_DIR \
|
||||||
--gid $GROUP \
|
--gid $GROUP \
|
||||||
--shell /sbin/nologin \
|
--shell /sbin/nologin \
|
||||||
--comment "$USER user" \
|
--comment "$USER user" \
|
||||||
$USER
|
$USER && \
|
||||||
|
chmod 700 /entrypoint.sh && \
|
||||||
# Copy and set permissions to scripts
|
chmod 700 /wazuh_app_config.sh && \
|
||||||
COPY config/entrypoint.sh /
|
mkdir -p $INSTALL_DIR && \
|
||||||
COPY config/wazuh_app_config.sh /
|
chown 1000:1000 $INSTALL_DIR && \
|
||||||
RUN chmod 700 /entrypoint.sh
|
chown 1000:1000 /*.sh && \
|
||||||
RUN chmod 700 /wazuh_app_config.sh
|
mkdir -p /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom
|
||||||
RUN chown 1000:1000 /*.sh
|
|
||||||
|
|
||||||
# Copy Install dir from builder to current image
|
# Copy Install dir from builder to current image
|
||||||
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR
|
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR
|
||||||
|
|
||||||
# Create custom directory
|
|
||||||
RUN mkdir -p /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom
|
|
||||||
RUN chown 1000:1000 /usr/share/wazuh-dashboard/plugins/wazuh/public/assets/custom
|
|
||||||
|
|
||||||
# Set workdir and user
|
# Set workdir and user
|
||||||
WORKDIR $INSTALL_DIR
|
WORKDIR $INSTALL_DIR
|
||||||
USER wazuh-dashboard
|
USER wazuh-dashboard
|
||||||
|
|||||||
@@ -9,34 +9,71 @@ export CONFIG_DIR=${INSTALLATION_DIR}/config
|
|||||||
|
|
||||||
## Variables
|
## Variables
|
||||||
CERT_TOOL=wazuh-certs-tool.sh
|
CERT_TOOL=wazuh-certs-tool.sh
|
||||||
PACKAGES_URL=https://packages.wazuh.com/4.14/
|
CERT_CONFIG_FILE=config.yml
|
||||||
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.14/
|
CERT_TOOL_VERSION="${WAZUH_VERSION%.*}"
|
||||||
|
PACKAGES_URL=https://packages.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
|
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
|
|
||||||
## Check if the cert tool exists in S3 buckets
|
download_package() {
|
||||||
CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}')
|
local url=$1
|
||||||
CERT_TOOL_PACKAGES_DEV=$(curl --silent -I $PACKAGES_DEV_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}')
|
local package=$2
|
||||||
|
local output=$2
|
||||||
|
echo "Checking $url$package ..."
|
||||||
|
if curl -fsL "$url$package" -o "$output"; then
|
||||||
|
echo "Downloaded $package from $url"
|
||||||
|
return 0
|
||||||
|
else
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
## If cert tool exists in some bucket, download it, if not exit 1
|
# Download the tool to create the certificates
|
||||||
if [ "$CERT_TOOL_PACKAGES" = "200" ]; then
|
echo "Downloading the tool to create the certificates..."
|
||||||
curl -o $CERT_TOOL $PACKAGES_URL$CERT_TOOL
|
# Try first the prod URL, if it fails try the dev URL
|
||||||
echo "Cert tool exists in Packages bucket"
|
if download_package "$PACKAGES_URL" "$CERT_TOOL"; then
|
||||||
elif [ "$CERT_TOOL_PACKAGES_DEV" = "200" ]; then
|
:
|
||||||
curl -o $CERT_TOOL $PACKAGES_DEV_URL$CERT_TOOL
|
elif download_package "$PACKAGES_DEV_URL" "$CERT_TOOL"; then
|
||||||
echo "Cert tool exists in Packages-dev bucket"
|
:
|
||||||
else
|
else
|
||||||
echo "Cert tool does not exist in any bucket"
|
echo "The tool to create the certificates does not exist in any bucket"
|
||||||
exit 1
|
echo "ERROR: certificates were not created"
|
||||||
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
chmod 755 $CERT_TOOL && bash /$CERT_TOOL -A
|
# Download the config file for the certificate tool
|
||||||
|
echo "Downloading the config file for the certificate tool..."
|
||||||
|
# Try first the prod URL, if it fails try the dev URL
|
||||||
|
if download_package "$PACKAGES_URL" "$CERT_CONFIG_FILE"; then
|
||||||
|
:
|
||||||
|
elif download_package "$PACKAGES_DEV_URL" "$CERT_CONFIG_FILE"; then
|
||||||
|
:
|
||||||
|
else
|
||||||
|
echo "The config file for the certificate tool does not exist in any bucket"
|
||||||
|
echo "ERROR: certificates were not created"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Modify the config file to set the IP to localhost
|
||||||
|
sed -i 's/ ip:.*/ ip: "127.0.0.1"/' $CERT_CONFIG_FILE
|
||||||
|
|
||||||
|
chmod 700 "$CERT_CONFIG_FILE"
|
||||||
|
# Create the certificates
|
||||||
|
chmod 755 "$CERT_TOOL" && bash "$CERT_TOOL" -A
|
||||||
|
|
||||||
# Create certs directory
|
# Create certs directory
|
||||||
mkdir -p ${CONFIG_DIR}/certs
|
mkdir -p ${CONFIG_DIR}/certs
|
||||||
|
|
||||||
# Copy Wazuh dashboard certs to install config dir
|
# Copy Wazuh dashboard certs to install config dir
|
||||||
cp /wazuh-certificates/demo.dashboard.pem ${CONFIG_DIR}/certs/dashboard.pem
|
mv /etc/wazuh-dashboard/* ${CONFIG_DIR}/
|
||||||
cp /wazuh-certificates/demo.dashboard-key.pem ${CONFIG_DIR}/certs/dashboard-key.pem
|
cp -pr /wazuh-certificates/dashboard.pem ${CONFIG_DIR}/certs/dashboard.pem
|
||||||
cp /wazuh-certificates/root-ca.pem ${CONFIG_DIR}/certs/root-ca.pem
|
cp -pr /wazuh-certificates/dashboard-key.pem ${CONFIG_DIR}/certs/dashboard-key.pem
|
||||||
|
cp -pr /wazuh-certificates/root-ca.key ${CONFIG_DIR}/certs/root-ca.key
|
||||||
|
cp -pr /wazuh-certificates/root-ca.pem ${CONFIG_DIR}/certs/root-ca.pem
|
||||||
|
cp -pr /wazuh-certificates/admin.pem ${CONFIG_DIR}/certs/admin.pem
|
||||||
|
cp -pr /wazuh-certificates/admin-key.pem ${CONFIG_DIR}/certs/admin-key.pem
|
||||||
|
|
||||||
|
# Modify opensearch.yml config paths
|
||||||
|
sed -i "s|/etc/wazuh-dashboard|${CONFIG_DIR}|g" ${CONFIG_DIR}/opensearch_dashboards.yml
|
||||||
|
|
||||||
chmod -R 500 ${CONFIG_DIR}/certs
|
chmod -R 500 ${CONFIG_DIR}/certs
|
||||||
chmod -R 400 ${CONFIG_DIR}/certs/*
|
chmod -R 400 ${CONFIG_DIR}/certs/*
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
nodes:
|
|
||||||
# Wazuh dashboard server nodes
|
|
||||||
dashboard:
|
|
||||||
- name: demo.dashboard
|
|
||||||
ip: demo.dashboard
|
|
||||||
@@ -1,155 +0,0 @@
|
|||||||
---
|
|
||||||
#
|
|
||||||
# Wazuh app - App configuration file
|
|
||||||
# Copyright (C) 2017, Wazuh Inc.
|
|
||||||
#
|
|
||||||
# This program is free software; you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation; either version 2 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# Find more information about this on the LICENSE file.
|
|
||||||
#
|
|
||||||
# ======================== Wazuh app configuration file ========================
|
|
||||||
#
|
|
||||||
# Please check the documentation for more information on configuration options:
|
|
||||||
# https://documentation.wazuh.com/current/installation-guide/index.html
|
|
||||||
#
|
|
||||||
# Also, you can check our repository:
|
|
||||||
# https://github.com/wazuh/wazuh-dashboard-plugins
|
|
||||||
#
|
|
||||||
# ------------------------------- Index patterns -------------------------------
|
|
||||||
#
|
|
||||||
# Default index pattern to use.
|
|
||||||
#pattern: wazuh-alerts-*
|
|
||||||
#
|
|
||||||
# ----------------------------------- Checks -----------------------------------
|
|
||||||
#
|
|
||||||
# Defines which checks must to be consider by the healthcheck
|
|
||||||
# step once the Wazuh app starts. Values must to be true or false.
|
|
||||||
#checks.pattern : true
|
|
||||||
#checks.template: true
|
|
||||||
#checks.api : true
|
|
||||||
#checks.setup : true
|
|
||||||
#checks.metaFields: true
|
|
||||||
#
|
|
||||||
# --------------------------------- Extensions ---------------------------------
|
|
||||||
#
|
|
||||||
# Defines which extensions should be activated when you add a new API entry.
|
|
||||||
# You can change them after Wazuh app starts.
|
|
||||||
# Values must to be true or false.
|
|
||||||
#extensions.pci : true
|
|
||||||
#extensions.gdpr : true
|
|
||||||
#extensions.hipaa : true
|
|
||||||
#extensions.nist : true
|
|
||||||
#extensions.tsc : true
|
|
||||||
#extensions.audit : true
|
|
||||||
#extensions.oscap : false
|
|
||||||
#extensions.ciscat : false
|
|
||||||
#extensions.aws : false
|
|
||||||
#extensions.gcp : false
|
|
||||||
#extensions.virustotal: false
|
|
||||||
#extensions.osquery : false
|
|
||||||
#extensions.docker : false
|
|
||||||
#
|
|
||||||
# ---------------------------------- Time out ----------------------------------
|
|
||||||
#
|
|
||||||
# Defines maximum timeout to be used on the Wazuh app requests.
|
|
||||||
# It will be ignored if it is bellow 1500.
|
|
||||||
# It means milliseconds before we consider a request as failed.
|
|
||||||
# Default: 20000
|
|
||||||
#timeout: 20000
|
|
||||||
#
|
|
||||||
# -------------------------------- API selector --------------------------------
|
|
||||||
#
|
|
||||||
# Defines if the user is allowed to change the selected
|
|
||||||
# API directly from the Wazuh app top menu.
|
|
||||||
# Default: true
|
|
||||||
#api.selector: true
|
|
||||||
#
|
|
||||||
# --------------------------- Index pattern selector ---------------------------
|
|
||||||
#
|
|
||||||
# Defines if the user is allowed to change the selected
|
|
||||||
# index pattern directly from the Wazuh app top menu.
|
|
||||||
# Default: true
|
|
||||||
#ip.selector: true
|
|
||||||
#
|
|
||||||
# List of index patterns to be ignored
|
|
||||||
#ip.ignore: []
|
|
||||||
#
|
|
||||||
# ------------------------------ wazuh-monitoring ------------------------------
|
|
||||||
#
|
|
||||||
# Custom setting to enable/disable wazuh-monitoring indices.
|
|
||||||
# Values: true, false, worker
|
|
||||||
# If worker is given as value, the app will show the Agents status
|
|
||||||
# visualization but won't insert data on wazuh-monitoring indices.
|
|
||||||
# Default: true
|
|
||||||
#wazuh.monitoring.enabled: true
|
|
||||||
#
|
|
||||||
# Custom setting to set the frequency for wazuh-monitoring indices cron task.
|
|
||||||
# Default: 900 (s)
|
|
||||||
#wazuh.monitoring.frequency: 900
|
|
||||||
#
|
|
||||||
# Configure wazuh-monitoring-* indices shards and replicas.
|
|
||||||
#wazuh.monitoring.shards: 2
|
|
||||||
#wazuh.monitoring.replicas: 0
|
|
||||||
#
|
|
||||||
# Configure wazuh-monitoring-* indices custom creation interval.
|
|
||||||
# Values: h (hourly), d (daily), w (weekly), m (monthly)
|
|
||||||
# Default: d
|
|
||||||
#wazuh.monitoring.creation: d
|
|
||||||
#
|
|
||||||
# Default index pattern to use for Wazuh monitoring
|
|
||||||
#wazuh.monitoring.pattern: wazuh-monitoring-*
|
|
||||||
#
|
|
||||||
# --------------------------------- wazuh-cron ----------------------------------
|
|
||||||
#
|
|
||||||
# Customize the index prefix of predefined jobs
|
|
||||||
# This change is not retroactive, if you change it new indexes will be created
|
|
||||||
# cron.prefix: test
|
|
||||||
#
|
|
||||||
# ------------------------------ wazuh-statistics -------------------------------
|
|
||||||
#
|
|
||||||
# Custom setting to enable/disable statistics tasks.
|
|
||||||
#cron.statistics.status: true
|
|
||||||
#
|
|
||||||
# Enter the ID of the APIs you want to save data from, leave this empty to run
|
|
||||||
# the task on all configured APIs
|
|
||||||
#cron.statistics.apis: []
|
|
||||||
#
|
|
||||||
# Define the frequency of task execution using cron schedule expressions
|
|
||||||
#cron.statistics.interval: 0 0 * * * *
|
|
||||||
#
|
|
||||||
# Define the name of the index in which the documents are to be saved.
|
|
||||||
#cron.statistics.index.name: statistics
|
|
||||||
#
|
|
||||||
# Define the interval in which the index will be created
|
|
||||||
#cron.statistics.index.creation: w
|
|
||||||
#
|
|
||||||
# ------------------------------- App privileges --------------------------------
|
|
||||||
#admin: true
|
|
||||||
#
|
|
||||||
# ---------------------------- Hide manager alerts ------------------------------
|
|
||||||
# Hide the alerts of the manager in all dashboards and discover
|
|
||||||
#hideManagerAlerts: false
|
|
||||||
#
|
|
||||||
# ------------------------------- App logging level -----------------------------
|
|
||||||
# Set the logging level for the Wazuh App log files.
|
|
||||||
# Default value: info
|
|
||||||
# Allowed values: info, debug
|
|
||||||
#logs.level: info
|
|
||||||
#
|
|
||||||
# -------------------------------- Enrollment DNS -------------------------------
|
|
||||||
# Set the variable WAZUH_REGISTRATION_SERVER in agents deployment.
|
|
||||||
# Default value: ''
|
|
||||||
#enrollment.dns: ''
|
|
||||||
#
|
|
||||||
#-------------------------------- API entries -----------------------------------
|
|
||||||
#The following configuration is the default structure to define an API entry.
|
|
||||||
#
|
|
||||||
#hosts:
|
|
||||||
# - <id>:
|
|
||||||
# url: http(s)://<url>
|
|
||||||
# port: <port>
|
|
||||||
# username: <username>
|
|
||||||
# password: <password>
|
|
||||||
@@ -32,11 +32,6 @@ do
|
|||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|
||||||
|
|
||||||
grep -q 1513629884013 $dashboard_config_file
|
|
||||||
_config_exists=$?
|
|
||||||
|
|
||||||
if [[ $_config_exists -ne 0 ]]; then
|
|
||||||
cat << EOF >> $dashboard_config_file
|
cat << EOF >> $dashboard_config_file
|
||||||
hosts:
|
hosts:
|
||||||
- 1513629884013:
|
- 1513629884013:
|
||||||
@@ -46,7 +41,4 @@ hosts:
|
|||||||
password: $api_password
|
password: $api_password
|
||||||
run_as: $api_run_as
|
run_as: $api_run_as
|
||||||
EOF
|
EOF
|
||||||
else
|
|
||||||
echo "Wazuh APP already configured"
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|||||||
@@ -13,20 +13,8 @@ RUN chmod 775 /check_repository.sh && \
|
|||||||
RUN yum install wazuh-indexer-${WAZUH_VERSION}-${WAZUH_TAG_REVISION} -y && \
|
RUN yum install wazuh-indexer-${WAZUH_VERSION}-${WAZUH_TAG_REVISION} -y && \
|
||||||
yum clean all
|
yum clean all
|
||||||
|
|
||||||
COPY config/opensearch.yml /
|
|
||||||
|
|
||||||
COPY config/config.sh .
|
COPY config/config.sh .
|
||||||
|
|
||||||
COPY config/config.yml /
|
|
||||||
|
|
||||||
COPY config/action_groups.yml /
|
|
||||||
|
|
||||||
COPY config/internal_users.yml /
|
|
||||||
|
|
||||||
COPY config/roles_mapping.yml /
|
|
||||||
|
|
||||||
COPY config/roles.yml /
|
|
||||||
|
|
||||||
RUN bash config.sh
|
RUN bash config.sh
|
||||||
|
|
||||||
################################################################################
|
################################################################################
|
||||||
@@ -34,7 +22,6 @@ RUN bash config.sh
|
|||||||
#
|
#
|
||||||
# Copy wazuh-indexer from stage 0
|
# Copy wazuh-indexer from stage 0
|
||||||
# Add entrypoint
|
# Add entrypoint
|
||||||
|
|
||||||
################################################################################
|
################################################################################
|
||||||
FROM amazonlinux:2023
|
FROM amazonlinux:2023
|
||||||
|
|
||||||
@@ -43,47 +30,39 @@ ENV USER="wazuh-indexer" \
|
|||||||
NAME="wazuh-indexer" \
|
NAME="wazuh-indexer" \
|
||||||
INSTALL_DIR="/usr/share/wazuh-indexer"
|
INSTALL_DIR="/usr/share/wazuh-indexer"
|
||||||
|
|
||||||
RUN yum install curl-minimal shadow-utils findutils hostname -y
|
|
||||||
|
|
||||||
RUN getent group $GROUP || groupadd -r -g 1000 $GROUP
|
COPY config/entrypoint.sh /
|
||||||
|
COPY config/securityadmin.sh /
|
||||||
|
|
||||||
RUN useradd --system \
|
RUN yum install curl-minimal shadow-utils findutils hostname -y && \
|
||||||
|
yum clean all && \
|
||||||
|
getent group $GROUP || groupadd -r -g 1000 $GROUP && \
|
||||||
|
useradd --system \
|
||||||
--uid 1000 \
|
--uid 1000 \
|
||||||
--no-create-home \
|
--no-create-home \
|
||||||
--home-dir $INSTALL_DIR \
|
--home-dir $INSTALL_DIR \
|
||||||
--gid $GROUP \
|
--gid $GROUP \
|
||||||
--shell /sbin/nologin \
|
--shell /sbin/nologin \
|
||||||
--comment "$USER user" \
|
--comment "$USER user" \
|
||||||
$USER
|
$USER && \
|
||||||
|
chmod 700 /entrypoint.sh && chmod 700 /securityadmin.sh && \
|
||||||
WORKDIR $INSTALL_DIR
|
mkdir -p $INSTALL_DIR && \
|
||||||
|
chown 1000:1000 $INSTALL_DIR && \
|
||||||
COPY config/entrypoint.sh /
|
chown 1000:1000 /*.sh && \
|
||||||
|
mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer && \
|
||||||
COPY config/securityadmin.sh /
|
mkdir -p $INSTALL_DIR/logs && chown 1000:1000 $INSTALL_DIR/logs && \
|
||||||
|
|
||||||
RUN chmod 700 /entrypoint.sh && chmod 700 /securityadmin.sh && \
|
|
||||||
mkdir -p /usr/share/wazuh-indexer && \
|
|
||||||
chown 1000:1000 /usr/share/wazuh-indexer && \
|
|
||||||
chown 1000:1000 /*.sh
|
|
||||||
|
|
||||||
COPY --from=builder --chown=1000:1000 /usr/share/wazuh-indexer /usr/share/wazuh-indexer
|
|
||||||
COPY --from=builder --chown=1000:1000 /etc/wazuh-indexer /usr/share/wazuh-indexer/config
|
|
||||||
COPY --from=builder --chown=1000:1000 /debian/wazuh-indexer/usr/share/wazuh-indexer /usr/share/wazuh-indexer
|
|
||||||
COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/systemd /usr/lib/systemd
|
|
||||||
COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/sysctl.d /usr/lib/sysctl.d
|
|
||||||
COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/tmpfiles.d /usr/lib/tmpfiles.d
|
|
||||||
|
|
||||||
RUN mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer && \
|
|
||||||
mkdir -p /usr/share/wazuh-indexer/logs && chown 1000:1000 /usr/share/wazuh-indexer/logs && \
|
|
||||||
mkdir -p /run/wazuh-indexer && chown 1000:1000 /run/wazuh-indexer && \
|
mkdir -p /run/wazuh-indexer && chown 1000:1000 /run/wazuh-indexer && \
|
||||||
mkdir -p /var/log/wazuh-indexer && chown 1000:1000 /var/log/wazuh-indexer && \
|
mkdir -p /var/log/wazuh-indexer && chown 1000:1000 /var/log/wazuh-indexer
|
||||||
chmod 700 /usr/share/wazuh-indexer && \
|
|
||||||
chmod 700 /usr/share/wazuh-indexer/config && \
|
COPY --from=builder --chown=1000:1000 $INSTALL_DIR $INSTALL_DIR
|
||||||
chmod 600 /usr/share/wazuh-indexer/config/jvm.options && \
|
|
||||||
chmod 600 /usr/share/wazuh-indexer/config/opensearch.yml
|
RUN chmod 700 $INSTALL_DIR && \
|
||||||
|
chmod 700 $INSTALL_DIR/config && \
|
||||||
|
chmod 600 $INSTALL_DIR/config/jvm.options && \
|
||||||
|
chmod 600 $INSTALL_DIR/config/opensearch.yml
|
||||||
|
|
||||||
USER wazuh-indexer
|
USER wazuh-indexer
|
||||||
|
WORKDIR $INSTALL_DIR
|
||||||
|
|
||||||
# Services ports
|
# Services ports
|
||||||
EXPOSE 9200
|
EXPOSE 9200
|
||||||
|
|||||||
@@ -1,12 +0,0 @@
|
|||||||
---
|
|
||||||
_meta:
|
|
||||||
type: "actiongroups"
|
|
||||||
config_version: 2
|
|
||||||
|
|
||||||
# ISM API permissions group
|
|
||||||
manage_ism:
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
allowed_actions:
|
|
||||||
- "cluster:admin/opendistro/ism/*"
|
|
||||||
static: false
|
|
||||||
@@ -3,7 +3,6 @@
|
|||||||
export DH_OPTIONS
|
export DH_OPTIONS
|
||||||
|
|
||||||
export NAME=wazuh-indexer
|
export NAME=wazuh-indexer
|
||||||
export TARGET_DIR=${CURDIR}/debian/${NAME}
|
|
||||||
|
|
||||||
# Package build options
|
# Package build options
|
||||||
export USER=${NAME}
|
export USER=${NAME}
|
||||||
@@ -14,89 +13,81 @@ export LIB_DIR=/var/lib/${NAME}
|
|||||||
export PID_DIR=/run/${NAME}
|
export PID_DIR=/run/${NAME}
|
||||||
export INSTALLATION_DIR=/usr/share/${NAME}
|
export INSTALLATION_DIR=/usr/share/${NAME}
|
||||||
export CONFIG_DIR=${INSTALLATION_DIR}/config
|
export CONFIG_DIR=${INSTALLATION_DIR}/config
|
||||||
export BASE_DIR=${NAME}-*
|
|
||||||
export INDEXER_FILE=wazuh-indexer-base.tar.xz
|
|
||||||
export BASE_FILE=wazuh-indexer-base-${VERSION}-linux-x64.tar.xz
|
##############################################################################
|
||||||
export REPO_DIR=/unattended_installer
|
# Downloading Cert Gen Tool
|
||||||
|
##############################################################################
|
||||||
|
|
||||||
## Variables
|
## Variables
|
||||||
CERT_TOOL=wazuh-certs-tool.sh
|
CERT_TOOL=wazuh-certs-tool.sh
|
||||||
PASSWORD_TOOL=wazuh-passwords-tool.sh
|
CERT_CONFIG_FILE=config.yml
|
||||||
PACKAGES_URL=https://packages.wazuh.com/4.14/
|
CERT_TOOL_VERSION="${WAZUH_VERSION%.*}"
|
||||||
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.14/
|
PACKAGES_URL=https://packages.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
|
PACKAGES_DEV_URL=https://packages-dev.wazuh.com/$CERT_TOOL_VERSION/
|
||||||
|
|
||||||
## Check if the cert tool exists in S3 buckets
|
download_package() {
|
||||||
CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}')
|
local url=$1
|
||||||
CERT_TOOL_PACKAGES_DEV=$(curl --silent -I $PACKAGES_DEV_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}')
|
local package=$2
|
||||||
|
local output=$2
|
||||||
|
echo "Checking $url$package ..."
|
||||||
|
if curl -fsL "$url$package" -o "$output"; then
|
||||||
|
echo "Downloaded $package from $url"
|
||||||
|
return 0
|
||||||
|
else
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
## If cert tool exists in some bucket, download it, if not exit 1
|
# Download the tool to create the certificates
|
||||||
if [ "$CERT_TOOL_PACKAGES" = "200" ]; then
|
echo "Downloading the tool to create the certificates..."
|
||||||
curl -o $CERT_TOOL $PACKAGES_URL$CERT_TOOL
|
# Try first the prod URL, if it fails try the dev URL
|
||||||
echo "Cert tool exists in Packages bucket"
|
if download_package "$PACKAGES_URL" "$CERT_TOOL"; then
|
||||||
elif [ "$CERT_TOOL_PACKAGES_DEV" = "200" ]; then
|
:
|
||||||
curl -o $CERT_TOOL $PACKAGES_DEV_URL$CERT_TOOL
|
elif download_package "$PACKAGES_DEV_URL" "$CERT_TOOL"; then
|
||||||
echo "Cert tool exists in Packages-dev bucket"
|
:
|
||||||
else
|
else
|
||||||
echo "Cert tool does not exist in any bucket"
|
echo "The tool to create the certificates does not exist in any bucket"
|
||||||
exit 1
|
echo "ERROR: certificates were not created"
|
||||||
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Download the config file for the certificate tool
|
||||||
## Check if the password tool exists in S3 buckets
|
echo "Downloading the config file for the certificate tool..."
|
||||||
PASSWORD_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$PASSWORD_TOOL | grep -E "^HTTP" | awk '{print $2}')
|
# Try first the prod URL, if it fails try the dev URL
|
||||||
PASSWORD_TOOL_PACKAGES_DEV=$(curl --silent -I $PACKAGES_DEV_URL$PASSWORD_TOOL | grep -E "^HTTP" | awk '{print $2}')
|
if download_package "$PACKAGES_URL" "$CERT_CONFIG_FILE"; then
|
||||||
|
:
|
||||||
## If password tool exists in some bucket, download it, if not exit 1
|
elif download_package "$PACKAGES_DEV_URL" "$CERT_CONFIG_FILE"; then
|
||||||
if [ "$PASSWORD_TOOL_PACKAGES" = "200" ]; then
|
:
|
||||||
curl -o $PASSWORD_TOOL $PACKAGES_URL$PASSWORD_TOOL
|
|
||||||
echo "Password tool exists in Packages bucket"
|
|
||||||
elif [ "$PASSWORD_TOOL_PACKAGES_DEV" = "200" ]; then
|
|
||||||
curl -o $PASSWORD_TOOL $PACKAGES_DEV_URL$PASSWORD_TOOL
|
|
||||||
echo "Password tool exists in Packages-dev bucket"
|
|
||||||
else
|
else
|
||||||
echo "Password tool does not exist in any bucket"
|
echo "The config file for the certificate tool does not exist in any bucket"
|
||||||
exit 1
|
echo "ERROR: certificates were not created"
|
||||||
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
chmod 755 $CERT_TOOL && bash /$CERT_TOOL -A
|
# Modify the config file to set the IP to localhost
|
||||||
|
sed -i 's/ ip:.*/ ip: "127.0.0.1"/' $CERT_CONFIG_FILE
|
||||||
|
|
||||||
# copy to target
|
chmod 700 "$CERT_CONFIG_FILE"
|
||||||
mkdir -p ${TARGET_DIR}${INSTALLATION_DIR}
|
# Create the certificates
|
||||||
mkdir -p ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
chmod 755 "$CERT_TOOL" && bash "$CERT_TOOL" -A
|
||||||
mkdir -p ${TARGET_DIR}${CONFIG_DIR}
|
|
||||||
mkdir -p ${TARGET_DIR}${LIB_DIR}
|
# Copy Wazuh indexer's certificates and config files to $CONFIG_DIR
|
||||||
mkdir -p ${TARGET_DIR}${LOG_DIR}
|
mkdir -p ${CONFIG_DIR}/certs
|
||||||
mkdir -p ${TARGET_DIR}/etc/init.d
|
mv /etc/wazuh-indexer/* ${CONFIG_DIR}/
|
||||||
mkdir -p ${TARGET_DIR}/etc/default
|
cp -pr /wazuh-certificates/node-1.pem ${CONFIG_DIR}/certs/indexer.pem
|
||||||
mkdir -p ${TARGET_DIR}/usr/lib/tmpfiles.d
|
cp -pr /wazuh-certificates/node-1-key.pem ${CONFIG_DIR}/certs/indexer-key.pem
|
||||||
mkdir -p ${TARGET_DIR}/usr/lib/sysctl.d
|
cp -pr /wazuh-certificates/root-ca.key ${CONFIG_DIR}/certs/root-ca.key
|
||||||
mkdir -p ${TARGET_DIR}/usr/lib/systemd/system
|
cp -pr /wazuh-certificates/root-ca.pem ${CONFIG_DIR}/certs/root-ca.pem
|
||||||
mkdir -p ${TARGET_DIR}${CONFIG_DIR}/certs
|
cp -pr /wazuh-certificates/admin.pem ${CONFIG_DIR}/certs/admin.pem
|
||||||
# Copy Wazuh's config files for the security plugin
|
cp -pr /wazuh-certificates/admin-key.pem ${CONFIG_DIR}/certs/admin-key.pem
|
||||||
cp -pr /roles_mapping.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
|
||||||
cp -pr /roles.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
# Modify opensearch.yml config paths
|
||||||
cp -pr /action_groups.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
sed -i "s|/etc/wazuh-indexer|${CONFIG_DIR}|g" ${CONFIG_DIR}/opensearch.yml
|
||||||
cp -pr /internal_users.yml ${TARGET_DIR}${INSTALLATION_DIR}/opensearch-security/
|
|
||||||
cp -pr /opensearch.yml ${TARGET_DIR}${CONFIG_DIR}
|
|
||||||
# Copy Wazuh indexer's certificates
|
|
||||||
cp -pr /wazuh-certificates/demo.indexer.pem ${TARGET_DIR}${CONFIG_DIR}/certs/indexer.pem
|
|
||||||
cp -pr /wazuh-certificates/demo.indexer-key.pem ${TARGET_DIR}${CONFIG_DIR}/certs/indexer-key.pem
|
|
||||||
cp -pr /wazuh-certificates/root-ca.key ${TARGET_DIR}${CONFIG_DIR}/certs/root-ca.key
|
|
||||||
cp -pr /wazuh-certificates/root-ca.pem ${TARGET_DIR}${CONFIG_DIR}/certs/root-ca.pem
|
|
||||||
cp -pr /wazuh-certificates/admin.pem ${TARGET_DIR}${CONFIG_DIR}/certs/admin.pem
|
|
||||||
cp -pr /wazuh-certificates/admin-key.pem ${TARGET_DIR}${CONFIG_DIR}/certs/admin-key.pem
|
|
||||||
|
|
||||||
# Delete xms and xmx parameters in jvm.options
|
# Delete xms and xmx parameters in jvm.options
|
||||||
sed '/-Xms/d' -i /etc/wazuh-indexer/jvm.options
|
|
||||||
sed '/-Xmx/d' -i /etc/wazuh-indexer/jvm.options
|
|
||||||
sed -i 's/-Djava.security.policy=file:\/\/\/etc\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/-Djava.security.policy=file:\/\/\/usr\/share\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/g' /etc/wazuh-indexer/jvm.options
|
sed -i 's/-Djava.security.policy=file:\/\/\/etc\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/-Djava.security.policy=file:\/\/\/usr\/share\/wazuh-indexer\/opensearch-performance-analyzer\/opensearch_security.policy/g' /etc/wazuh-indexer/jvm.options
|
||||||
|
|
||||||
|
chown -R ${USER}:${GROUP} ${CONFIG_DIR}
|
||||||
chmod -R 500 ${TARGET_DIR}${CONFIG_DIR}/certs
|
chmod -R 500 ${CONFIG_DIR}/certs
|
||||||
chmod -R 400 ${TARGET_DIR}${CONFIG_DIR}/certs/*
|
chmod -R 400 ${CONFIG_DIR}/certs/*
|
||||||
|
|
||||||
find ${TARGET_DIR} -type d -exec chmod 750 {} \;
|
|
||||||
find ${TARGET_DIR} -type f -perm 644 -exec chmod 640 {} \;
|
|
||||||
find ${TARGET_DIR} -type f -perm 664 -exec chmod 660 {} \;
|
|
||||||
find ${TARGET_DIR} -type f -perm 755 -exec chmod 750 {} \;
|
|
||||||
find ${TARGET_DIR} -type f -perm 744 -exec chmod 740 {} \;
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
nodes:
|
|
||||||
# Wazuh indexer server nodes
|
|
||||||
indexer:
|
|
||||||
- name: demo.indexer
|
|
||||||
ip: demo.indexer
|
|
||||||
@@ -1,74 +0,0 @@
|
|||||||
---
|
|
||||||
# This is the internal user database
|
|
||||||
# The hash value is a bcrypt hash and can be generated with plugin/tools/hash.sh
|
|
||||||
|
|
||||||
_meta:
|
|
||||||
type: "internalusers"
|
|
||||||
config_version: 2
|
|
||||||
|
|
||||||
# Define your internal users here
|
|
||||||
|
|
||||||
## Demo users
|
|
||||||
|
|
||||||
admin:
|
|
||||||
hash: "$2a$12$VcCDgh2NDk07JGN0rjGbM.Ad41qVR/YFJcgHp0UGns5JDymv..TOG"
|
|
||||||
reserved: true
|
|
||||||
backend_roles:
|
|
||||||
- "admin"
|
|
||||||
description: "Demo admin user"
|
|
||||||
|
|
||||||
kibanaserver:
|
|
||||||
hash: "$2a$12$4AcgAt3xwOWadA5s5blL6ev39OXDNhmOesEoo33eZtrq2N0YrU3H."
|
|
||||||
reserved: true
|
|
||||||
description: "Demo kibanaserver user"
|
|
||||||
|
|
||||||
kibanaro:
|
|
||||||
hash: "$2a$12$JJSXNfTowz7Uu5ttXfeYpeYE0arACvcwlPBStB1F.MI7f0U9Z4DGC"
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "kibanauser"
|
|
||||||
- "readall"
|
|
||||||
attributes:
|
|
||||||
attribute1: "value1"
|
|
||||||
attribute2: "value2"
|
|
||||||
attribute3: "value3"
|
|
||||||
description: "Demo kibanaro user"
|
|
||||||
|
|
||||||
logstash:
|
|
||||||
hash: "$2a$12$u1ShR4l4uBS3Uv59Pa2y5.1uQuZBrZtmNfqB3iM/.jL0XoV9sghS2"
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "logstash"
|
|
||||||
description: "Demo logstash user"
|
|
||||||
|
|
||||||
readall:
|
|
||||||
hash: "$2a$12$ae4ycwzwvLtZxwZ82RmiEunBbIPiAmGZduBAjKN0TXdwQFtCwARz2"
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "readall"
|
|
||||||
description: "Demo readall user"
|
|
||||||
|
|
||||||
snapshotrestore:
|
|
||||||
hash: "$2y$12$DpwmetHKwgYnorbgdvORCenv4NAK8cPUg8AI6pxLCuWf/ALc0.v7W"
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "snapshotrestore"
|
|
||||||
description: "Demo snapshotrestore user"
|
|
||||||
|
|
||||||
wazuh_admin:
|
|
||||||
hash: "$2y$12$d2awHiOYvZjI88VfsDON.u6buoBol0gYPJEgdG1ArKVE0OMxViFfu"
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
backend_roles: []
|
|
||||||
attributes: {}
|
|
||||||
opendistro_security_roles: []
|
|
||||||
static: false
|
|
||||||
|
|
||||||
wazuh_user:
|
|
||||||
hash: "$2y$12$BQixeoQdRubZdVf/7sq1suHwiVRnSst1.lPI2M0.GPZms4bq2D9vO"
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
backend_roles: []
|
|
||||||
attributes: {}
|
|
||||||
opendistro_security_roles: []
|
|
||||||
static: false
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
network.host: "0.0.0.0"
|
|
||||||
node.name: "wazuh.indexer"
|
|
||||||
cluster.name: "wazuh-cluster"
|
|
||||||
path.data: /var/lib/wazuh-indexer
|
|
||||||
path.logs: /var/log/wazuh-indexer
|
|
||||||
discovery.type: single-node
|
|
||||||
compatibility.override_main_response_version: true
|
|
||||||
plugins.security.ssl.http.pemcert_filepath: /usr/share/wazuh-indexer/config/certs/indexer.pem
|
|
||||||
plugins.security.ssl.http.pemkey_filepath: /usr/share/wazuh-indexer/config/certs/indexer-key.pem
|
|
||||||
plugins.security.ssl.http.pemtrustedcas_filepath: /usr/share/wazuh-indexer/config/certs/root-ca.pem
|
|
||||||
plugins.security.ssl.transport.pemcert_filepath: /usr/share/wazuh-indexer/config/certs/indexer.pem
|
|
||||||
plugins.security.ssl.transport.pemkey_filepath: /usr/share/wazuh-indexer/config/certs/indexer-key.pem
|
|
||||||
plugins.security.ssl.transport.pemtrustedcas_filepath: /usr/share/wazuh-indexer/config/certs/root-ca.pem
|
|
||||||
plugins.security.ssl.http.enabled: true
|
|
||||||
plugins.security.ssl.transport.enforce_hostname_verification: false
|
|
||||||
plugins.security.ssl.transport.resolve_hostname: false
|
|
||||||
plugins.security.authcz.admin_dn:
|
|
||||||
- "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
|
|
||||||
plugins.security.check_snapshot_restore_write_privileges: true
|
|
||||||
plugins.security.enable_snapshot_restore_privilege: true
|
|
||||||
plugins.security.nodes_dn:
|
|
||||||
- "CN=demo.indexer,OU=Wazuh,O=Wazuh,L=California,C=US"
|
|
||||||
plugins.security.restapi.roles_enabled:
|
|
||||||
- "all_access"
|
|
||||||
- "security_rest_api_access"
|
|
||||||
plugins.security.system_indices.enabled: true
|
|
||||||
plugins.security.system_indices.indices: [".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opendistro-notifications-*", ".opendistro-notebooks", ".opensearch-observability", ".opendistro-asynchronous-search-response*", ".replication-metadata-store"]
|
|
||||||
@@ -1,171 +0,0 @@
|
|||||||
_meta:
|
|
||||||
type: "roles"
|
|
||||||
config_version: 2
|
|
||||||
|
|
||||||
# Restrict users so they can only view visualization and dashboards on kibana
|
|
||||||
kibana_read_only:
|
|
||||||
reserved: true
|
|
||||||
|
|
||||||
# The security REST API access role is used to assign specific users access to change the security settings through the REST API.
|
|
||||||
security_rest_api_access:
|
|
||||||
reserved: true
|
|
||||||
|
|
||||||
# Allows users to view monitors, destinations and alerts
|
|
||||||
alerting_read_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/alerting/alerts/get'
|
|
||||||
- 'cluster:admin/opendistro/alerting/destination/get'
|
|
||||||
- 'cluster:admin/opendistro/alerting/monitor/get'
|
|
||||||
- 'cluster:admin/opendistro/alerting/monitor/search'
|
|
||||||
|
|
||||||
# Allows users to view and acknowledge alerts
|
|
||||||
alerting_ack_alerts:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/alerting/alerts/*'
|
|
||||||
|
|
||||||
# Allows users to use all alerting functionality
|
|
||||||
alerting_full_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster_monitor'
|
|
||||||
- 'cluster:admin/opendistro/alerting/*'
|
|
||||||
index_permissions:
|
|
||||||
- index_patterns:
|
|
||||||
- '*'
|
|
||||||
allowed_actions:
|
|
||||||
- 'indices_monitor'
|
|
||||||
- 'indices:admin/aliases/get'
|
|
||||||
- 'indices:admin/mappings/get'
|
|
||||||
|
|
||||||
# Allow users to read Anomaly Detection detectors and results
|
|
||||||
anomaly_read_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/ad/detector/info'
|
|
||||||
- 'cluster:admin/opendistro/ad/detector/search'
|
|
||||||
- 'cluster:admin/opendistro/ad/detectors/get'
|
|
||||||
- 'cluster:admin/opendistro/ad/result/search'
|
|
||||||
- 'cluster:admin/opendistro/ad/tasks/search'
|
|
||||||
|
|
||||||
# Allows users to use all Anomaly Detection functionality
|
|
||||||
anomaly_full_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster_monitor'
|
|
||||||
- 'cluster:admin/opendistro/ad/*'
|
|
||||||
index_permissions:
|
|
||||||
- index_patterns:
|
|
||||||
- '*'
|
|
||||||
allowed_actions:
|
|
||||||
- 'indices_monitor'
|
|
||||||
- 'indices:admin/aliases/get'
|
|
||||||
- 'indices:admin/mappings/get'
|
|
||||||
|
|
||||||
# Allows users to read Notebooks
|
|
||||||
notebooks_read_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/notebooks/list'
|
|
||||||
- 'cluster:admin/opendistro/notebooks/get'
|
|
||||||
|
|
||||||
# Allows users to all Notebooks functionality
|
|
||||||
notebooks_full_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/notebooks/create'
|
|
||||||
- 'cluster:admin/opendistro/notebooks/update'
|
|
||||||
- 'cluster:admin/opendistro/notebooks/delete'
|
|
||||||
- 'cluster:admin/opendistro/notebooks/get'
|
|
||||||
- 'cluster:admin/opendistro/notebooks/list'
|
|
||||||
|
|
||||||
# Allows users to read and download Reports
|
|
||||||
reports_instances_read_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/reports/instance/list'
|
|
||||||
- 'cluster:admin/opendistro/reports/instance/get'
|
|
||||||
- 'cluster:admin/opendistro/reports/menu/download'
|
|
||||||
|
|
||||||
# Allows users to read and download Reports and Report-definitions
|
|
||||||
reports_read_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/get'
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/list'
|
|
||||||
- 'cluster:admin/opendistro/reports/instance/list'
|
|
||||||
- 'cluster:admin/opendistro/reports/instance/get'
|
|
||||||
- 'cluster:admin/opendistro/reports/menu/download'
|
|
||||||
|
|
||||||
# Allows users to all Reports functionality
|
|
||||||
reports_full_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/create'
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/update'
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/on_demand'
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/delete'
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/get'
|
|
||||||
- 'cluster:admin/opendistro/reports/definition/list'
|
|
||||||
- 'cluster:admin/opendistro/reports/instance/list'
|
|
||||||
- 'cluster:admin/opendistro/reports/instance/get'
|
|
||||||
- 'cluster:admin/opendistro/reports/menu/download'
|
|
||||||
|
|
||||||
# Allows users to use all asynchronous-search functionality
|
|
||||||
asynchronous_search_full_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/asynchronous_search/*'
|
|
||||||
index_permissions:
|
|
||||||
- index_patterns:
|
|
||||||
- '*'
|
|
||||||
allowed_actions:
|
|
||||||
- 'indices:data/read/search*'
|
|
||||||
|
|
||||||
# Allows users to read stored asynchronous-search results
|
|
||||||
asynchronous_search_read_access:
|
|
||||||
reserved: true
|
|
||||||
cluster_permissions:
|
|
||||||
- 'cluster:admin/opendistro/asynchronous_search/get'
|
|
||||||
|
|
||||||
wazuh_ui_user:
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
cluster_permissions: []
|
|
||||||
index_permissions:
|
|
||||||
- index_patterns:
|
|
||||||
- "wazuh-*"
|
|
||||||
dls: ""
|
|
||||||
fls: []
|
|
||||||
masked_fields: []
|
|
||||||
allowed_actions:
|
|
||||||
- "read"
|
|
||||||
tenant_permissions: []
|
|
||||||
static: false
|
|
||||||
|
|
||||||
wazuh_ui_admin:
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
cluster_permissions: []
|
|
||||||
index_permissions:
|
|
||||||
- index_patterns:
|
|
||||||
- "wazuh-*"
|
|
||||||
dls: ""
|
|
||||||
fls: []
|
|
||||||
masked_fields: []
|
|
||||||
allowed_actions:
|
|
||||||
- "read"
|
|
||||||
- "delete"
|
|
||||||
- "manage"
|
|
||||||
- "index"
|
|
||||||
tenant_permissions: []
|
|
||||||
static: false
|
|
||||||
|
|
||||||
# ISM API permissions role
|
|
||||||
manage_ism:
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
cluster_permissions:
|
|
||||||
- "manage_ism"
|
|
||||||
static: false
|
|
||||||
@@ -1,78 +0,0 @@
|
|||||||
---
|
|
||||||
# In this file users, backendroles and hosts can be mapped to Wazuh indexer Security roles.
|
|
||||||
# Permissions for Wazuh indexer roles are configured in roles.yml
|
|
||||||
|
|
||||||
_meta:
|
|
||||||
type: "rolesmapping"
|
|
||||||
config_version: 2
|
|
||||||
|
|
||||||
# Define your roles mapping here
|
|
||||||
|
|
||||||
## Demo roles mapping
|
|
||||||
|
|
||||||
all_access:
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "admin"
|
|
||||||
description: "Maps admin to all_access"
|
|
||||||
|
|
||||||
own_index:
|
|
||||||
reserved: false
|
|
||||||
users:
|
|
||||||
- "*"
|
|
||||||
description: "Allow full access to an index named like the username"
|
|
||||||
|
|
||||||
logstash:
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "logstash"
|
|
||||||
|
|
||||||
kibana_user:
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "kibanauser"
|
|
||||||
users:
|
|
||||||
- "wazuh_user"
|
|
||||||
- "wazuh_admin"
|
|
||||||
description: "Maps kibanauser to kibana_user"
|
|
||||||
|
|
||||||
readall:
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "readall"
|
|
||||||
|
|
||||||
manage_snapshots:
|
|
||||||
reserved: false
|
|
||||||
backend_roles:
|
|
||||||
- "snapshotrestore"
|
|
||||||
|
|
||||||
kibana_server:
|
|
||||||
reserved: true
|
|
||||||
users:
|
|
||||||
- "kibanaserver"
|
|
||||||
|
|
||||||
wazuh_ui_admin:
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
backend_roles: []
|
|
||||||
hosts: []
|
|
||||||
users:
|
|
||||||
- "wazuh_admin"
|
|
||||||
- "kibanaserver"
|
|
||||||
and_backend_roles: []
|
|
||||||
|
|
||||||
wazuh_ui_user:
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
backend_roles: []
|
|
||||||
hosts: []
|
|
||||||
users:
|
|
||||||
- "wazuh_user"
|
|
||||||
and_backend_roles: []
|
|
||||||
|
|
||||||
# ISM API permissions role mapping
|
|
||||||
manage_ism:
|
|
||||||
reserved: true
|
|
||||||
hidden: false
|
|
||||||
users:
|
|
||||||
- "kibanaserver"
|
|
||||||
Reference in New Issue
Block a user