diff --git a/.gitignore b/.gitignore
index 38bf9b6c..0b40ae5e 100644
--- a/.gitignore
+++ b/.gitignore
@@ -10,4 +10,5 @@ wazuh-manager.yml
Pipfile.lock
*.swp
molecule/**/es_certs/
-molecule/**/opendistro/
\ No newline at end of file
+molecule/**/opendistro/
+repository_bumper_*.log
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 76d5290c..c030709a 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,6 +1,25 @@
# Change Log
All notable changes to this project will be documented in this file.
+## [4.13.0]
+
+### Added
+
+- Added repository_bumper.sh script. ([#1621](https://github.com/wazuh/wazuh-ansible/pull/1621))
+
+### Changed
+
+- None
+
+### Fixed
+
+- Fix invalid active response ca_store setting ([#1655](https://github.com/wazuh/wazuh-ansible/pull/1655))
+
+### Deleted
+
+- Remove root-ca.key from the list of certificates copied to indexer nodes ([#1653](https://github.com/wazuh/wazuh-ansible/pull/1653))
+- Remove 'stable' branch ocurrencies ([#1593](https://github.com/wazuh/wazuh-ansible/pull/1593))
+
## [4.12.1]
### Added
@@ -19,7 +38,7 @@ All notable changes to this project will be documented in this file.
- None
-## [v4.12.0]
+## [4.12.0]
### Added
diff --git a/README.md b/README.md
index 0ba52696..e43083e7 100644
--- a/README.md
+++ b/README.md
@@ -9,57 +9,13 @@ These playbooks install and configure Wazuh agent, manager and indexer and dashb
## Branches
-- `master` branch contains the latest code, be aware of possible bugs on this branch.
-- `stable` branch on correspond to the last Wazuh stable version.
+- `main` branch contains the latest code, be aware of possible bugs on this branch.
## Compatibility Matrix
| Wazuh version | Elastic | ODFE |
|---------------|---------|--------|
-| v4.12.1 | | |
-| v4.12.0 | | |
-| v4.11.2 | | |
-| v4.11.1 | | |
-| v4.11.0 | | |
-| v4.10.1 | | |
-| v4.10.0 | | |
-| v4.9.2 | | |
-| v4.9.1 | | |
-| v4.9.0 | | |
-| v4.8.2 | | |
-| v4.8.1 | | |
-| v4.8.0 | | |
-| v4.7.5 | | |
-| v4.7.4 | | |
-| v4.7.3 | | |
-| v4.7.2 | | |
-| v4.7.1 | | |
-| v4.7.0 | | |
-| v4.6.0 | | |
-| v4.5.4 | | |
-| v4.5.3 | | |
-| v4.5.2 | | |
-| v4.5.1 | | |
-| v4.5.0 | | |
-| v4.4.5 | | |
-| v4.4.4 | | |
-| v4.4.3 | | |
-| v4.4.2 | | |
-| v4.4.1 | | |
-| v4.4.0 | | |
-| v4.3.11 | | |
-| v4.3.10 | | |
-| v4.4.0 | | |
-| v4.3.9 | | |
-| v4.3.8 | | |
-| v4.3.7 | | |
-| v4.3.6 | | |
-| v4.3.5 | | |
-| v4.3.4 | | |
-| v4.3.3 | | |
-| v4.3.2 | | |
-| v4.3.1 | | |
-| v4.3.0 | | |
+| v4.3.0+ | N/A | N/A |
| v4.2.6 | 7.10.2 | 1.13.2 |
| v4.2.5 | 7.10.2 | 1.13.2 |
| v4.2.4 | 7.10.2 | 1.13.2 |
diff --git a/VERSION.json b/VERSION.json
index 8e062521..dfee93c3 100644
--- a/VERSION.json
+++ b/VERSION.json
@@ -1,4 +1,4 @@
{
- "version": "4.12.1",
- "stage": "rc1"
+ "version": "4.13.0",
+ "stage": "alpha0"
}
diff --git a/roles/elastic-stack/ansible-kibana/defaults/main.yml b/roles/elastic-stack/ansible-kibana/defaults/main.yml
index 2a911a4e..29ddb4e8 100644
--- a/roles/elastic-stack/ansible-kibana/defaults/main.yml
+++ b/roles/elastic-stack/ansible-kibana/defaults/main.yml
@@ -7,7 +7,7 @@ kibana_server_host: "0.0.0.0"
kibana_server_port: "5601"
kibana_conf_path: /etc/kibana
elastic_stack_version: 7.10.2
-wazuh_version: 4.4.1
+wazuh_version: 4.13.0
wazuh_app_url: https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana
elasticrepo:
diff --git a/roles/wazuh/ansible-filebeat-oss/defaults/main.yml b/roles/wazuh/ansible-filebeat-oss/defaults/main.yml
index 982b0b6a..70a645ea 100644
--- a/roles/wazuh/ansible-filebeat-oss/defaults/main.yml
+++ b/roles/wazuh/ansible-filebeat-oss/defaults/main.yml
@@ -1,7 +1,7 @@
---
filebeat_version: 7.10.2
-wazuh_template_branch: v4.12.1
+wazuh_template_branch: v4.13.0
filebeat_node_name: node-1
diff --git a/roles/wazuh/ansible-wazuh-agent/defaults/main.yml b/roles/wazuh/ansible-wazuh-agent/defaults/main.yml
index 31653865..a8fb2354 100644
--- a/roles/wazuh/ansible-wazuh-agent/defaults/main.yml
+++ b/roles/wazuh/ansible-wazuh-agent/defaults/main.yml
@@ -1,5 +1,5 @@
---
-wazuh_agent_version: 4.12.1
+wazuh_agent_version: 4.13.0
# Custom packages installation
diff --git a/roles/wazuh/ansible-wazuh-agent/templates/var-ossec-etc-ossec-agent.conf.j2 b/roles/wazuh/ansible-wazuh-agent/templates/var-ossec-etc-ossec-agent.conf.j2
index 99fd93f9..7fe83cb8 100644
--- a/roles/wazuh/ansible-wazuh-agent/templates/var-ossec-etc-ossec-agent.conf.j2
+++ b/roles/wazuh/ansible-wazuh-agent/templates/var-ossec-etc-ossec-agent.conf.j2
@@ -481,15 +481,7 @@
{{ wazuh_agent_config.active_response.ar_disabled|default('no') }}
-
- {% if ansible_os_family == "Windows" %}{{ wazuh_agent_config.active_response.ca_store_win }}
- {% else %}
- {% if ansible_system == "Darwin" %}{{ wazuh_agent_config.active_response.ca_store_macos }}
- {% else %}
- {{ wazuh_agent_config.active_response.ca_store }}
- {% endif %}
- {% endif %}
-
+ {% if ansible_os_family == "Windows" %}{{ wazuh_agent_config.active_response.ca_store_win }}{% elif ansible_system == "Darwin" %}{{ wazuh_agent_config.active_response.ca_store_macos }}{% else %}{{ wazuh_agent_config.active_response.ca_store }}{% endif %}
{{ wazuh_agent_config.active_response.ca_verification }}
diff --git a/roles/wazuh/ansible-wazuh-manager/defaults/main.yml b/roles/wazuh/ansible-wazuh-manager/defaults/main.yml
index 49f599dc..408468f9 100644
--- a/roles/wazuh/ansible-wazuh-manager/defaults/main.yml
+++ b/roles/wazuh/ansible-wazuh-manager/defaults/main.yml
@@ -1,5 +1,5 @@
---
-wazuh_manager_version: 4.12.1
+wazuh_manager_version: 4.13.0
wazuh_manager_fqdn: "wazuh-server"
wazuh_manager_package_state: present
diff --git a/roles/wazuh/check-packages/defaults/main.yml b/roles/wazuh/check-packages/defaults/main.yml
index 55ffc925..0694a697 100644
--- a/roles/wazuh/check-packages/defaults/main.yml
+++ b/roles/wazuh/check-packages/defaults/main.yml
@@ -1,2 +1,2 @@
---
-wazuh_version: 4.12.1
+wazuh_version: 4.13.0
diff --git a/roles/wazuh/vars/repo.yml b/roles/wazuh/vars/repo.yml
index bddab500..c8e92a9c 100644
--- a/roles/wazuh/vars/repo.yml
+++ b/roles/wazuh/vars/repo.yml
@@ -14,7 +14,7 @@ wazuh_macos_arm_package_name: "wazuh-agent-{{ wazuh_agent_version }}-1.arm64.pkg
wazuh_macos_intel_package_url: "https://packages.wazuh.com/4.x/macos/{{ wazuh_macos_intel_package_name }}"
wazuh_macos_arm_package_url: "https://packages.wazuh.com/4.x/macos/{{ wazuh_macos_arm_package_name }}"
-certs_gen_tool_version: "4.12"
+certs_gen_tool_version: "4.13"
# Url of certificates generator tool
certs_gen_tool_url: "https://packages.wazuh.com/{{ certs_gen_tool_version }}/wazuh-certs-tool.sh"
diff --git a/roles/wazuh/vars/repo_pre-release.yml b/roles/wazuh/vars/repo_pre-release.yml
index 4a7c2558..5c9a4412 100644
--- a/roles/wazuh/vars/repo_pre-release.yml
+++ b/roles/wazuh/vars/repo_pre-release.yml
@@ -14,7 +14,7 @@ wazuh_macos_arm_package_name: "wazuh-agent-{{ wazuh_agent_version }}-1.arm64.pkg
wazuh_macos_intel_package_url: "https://packages-dev.wazuh.com/pre-release/{{ wazuh_macos_intel_package_name }}"
wazuh_macos_arm_package_url: "https://packages-dev.wazuh.com/pre-release/macos/{{ wazuh_macos_arm_package_name }}"
-certs_gen_tool_version: "4.12"
+certs_gen_tool_version: "4.13"
# Url of certificates generator tool
certs_gen_tool_url: "https://packages-dev.wazuh.com/{{ certs_gen_tool_version }}/wazuh-certs-tool.sh"
diff --git a/roles/wazuh/vars/repo_staging.yml b/roles/wazuh/vars/repo_staging.yml
index 4e91443f..d7adafb5 100644
--- a/roles/wazuh/vars/repo_staging.yml
+++ b/roles/wazuh/vars/repo_staging.yml
@@ -15,7 +15,7 @@ wazuh_macos_arm_package_name: "wazuh-agent-{{ wazuh_agent_version }}-1.arm64.pkg
wazuh_macos_intel_package_url: "https://packages-dev.wazuh.com/staging/macos/{{ wazuh_macos_intel_package_name }}"
wazuh_macos_arm_package_url: "https://packages-dev.wazuh.com/staging/macos/{{ wazuh_macos_arm_package_name }}"
-certs_gen_tool_version: "4.12"
+certs_gen_tool_version: "4.13"
# Url of certificates generator tool
certs_gen_tool_url: "https://packages-dev.wazuh.com/{{ certs_gen_tool_version }}/wazuh-certs-tool.sh"
diff --git a/roles/wazuh/wazuh-dashboard/defaults/main.yml b/roles/wazuh/wazuh-dashboard/defaults/main.yml
index f604cd12..08d4a424 100644
--- a/roles/wazuh/wazuh-dashboard/defaults/main.yml
+++ b/roles/wazuh/wazuh-dashboard/defaults/main.yml
@@ -8,12 +8,12 @@ dashboard_node_name: node-1
dashboard_server_host: "0.0.0.0"
dashboard_server_port: "443"
dashboard_server_name: "dashboard"
-wazuh_version: 4.12.1
+wazuh_version: 4.13.0
indexer_cluster_nodes:
- 127.0.0.1
# The Wazuh dashboard package repository
-dashboard_version: "4.12.1"
+dashboard_version: "4.13.0"
# API credentials
wazuh_api_credentials:
diff --git a/roles/wazuh/wazuh-dashboard/vars/debian.yml b/roles/wazuh/wazuh-dashboard/vars/debian.yml
index 523af096..baa259ee 100644
--- a/roles/wazuh/wazuh-dashboard/vars/debian.yml
+++ b/roles/wazuh/wazuh-dashboard/vars/debian.yml
@@ -1,2 +1,2 @@
---
-dashboard_version: 4.12.1
+dashboard_version: 4.13.0
diff --git a/roles/wazuh/wazuh-indexer/defaults/main.yml b/roles/wazuh/wazuh-indexer/defaults/main.yml
index 522c5cf7..9a15df43 100644
--- a/roles/wazuh/wazuh-indexer/defaults/main.yml
+++ b/roles/wazuh/wazuh-indexer/defaults/main.yml
@@ -1,6 +1,6 @@
---
# Cluster Settings
-indexer_version: 4.12.1
+indexer_version: 4.13.0
single_node: false
indexer_node_name: node-1
diff --git a/roles/wazuh/wazuh-indexer/tasks/security_actions.yml b/roles/wazuh/wazuh-indexer/tasks/security_actions.yml
index f87a3f75..6df4de92 100644
--- a/roles/wazuh/wazuh-indexer/tasks/security_actions.yml
+++ b/roles/wazuh/wazuh-indexer/tasks/security_actions.yml
@@ -27,7 +27,6 @@
mode: 0400
with_items:
- root-ca.pem
- - root-ca.key
- "{{ indexer_node_name }}-key.pem"
- "{{ indexer_node_name }}.pem"
- admin-key.pem
diff --git a/tools/repository_bumper.sh b/tools/repository_bumper.sh
new file mode 100644
index 00000000..30c5285f
--- /dev/null
+++ b/tools/repository_bumper.sh
@@ -0,0 +1,151 @@
+#!/bin/bash
+
+# This script is used to update the version of a repository in the specified files.
+# It takes a version number as an argument and updates the version in the specified files.
+# Usage: ./repository_bumper.sh
+
+# Global variables
+DIR=$(dirname "$(pwd)")
+LOG_FILE="${DIR}/tools/repository_bumper_$(date +"%Y-%m-%d_%H-%M-%S-%3N").log"
+VERSION=""
+STAGE=""
+FILES_EDITED=()
+FILES_EXCLUDED='--exclude="repository_bumper_*.log" --exclude="CHANGELOG.md" --exclude="repository_bumper.sh"'
+
+get_old_version_and_stage() {
+ local VERSION_FILE="${DIR}/VERSION.json"
+
+ OLD_VERSION=$(jq -r '.version' "${VERSION_FILE}")
+ OLD_STAGE=$(jq -r '.stage' "${VERSION_FILE}")
+ echo "Old version: ${OLD_VERSION}" | tee -a "${LOG_FILE}"
+ echo "Old stage: ${OLD_STAGE}" | tee -a "${LOG_FILE}"
+}
+
+grep_command() {
+ # This function is used to search for a specific string in the specified directory.
+ # It takes two arguments: the string to search for and the directory to search in.
+ # Usage: grep_command
+ eval grep -Rl "${1}" "${2}" --exclude-dir=".git" $FILES_EXCLUDED "${3}"
+}
+
+update_version_in_files() {
+
+ local OLD_MAYOR="$(echo "${OLD_VERSION}" | cut -d '.' -f 1)"
+ local OLD_MINOR="$(echo "${OLD_VERSION}" | cut -d '.' -f 2)"
+ local OLD_PATCH="$(echo "${OLD_VERSION}" | cut -d '.' -f 3)"
+ local NEW_MAYOR="$(echo "${VERSION}" | cut -d '.' -f 1)"
+ local NEW_MINOR="$(echo "${VERSION}" | cut -d '.' -f 2)"
+ local NEW_PATCH="$(echo "${VERSION}" | cut -d '.' -f 3)"
+ m_m_p_files=( $(grep_command "${OLD_MAYOR}\.${OLD_MINOR}\.${OLD_PATCH}" "${DIR}") )
+ for file in "${m_m_p_files[@]}"; do
+ sed -i "s/\bv${OLD_MAYOR}\.${OLD_MINOR}\.${OLD_PATCH}\b/v${NEW_MAYOR}\.${NEW_MINOR}\.${NEW_PATCH}/g; s/\b${OLD_MAYOR}\.${OLD_MINOR}\.${OLD_PATCH}/${NEW_MAYOR}\.${NEW_MINOR}\.${NEW_PATCH}/g" "${file}"
+ if [[ $(git diff --name-only "${file}") ]]; then
+ FILES_EDITED+=("${file}")
+ fi
+ done
+ m_m_files=( $(grep_command "${OLD_MAYOR}\.${OLD_MINOR}" "${DIR}") )
+ for file in "${m_m_files[@]}"; do
+ sed -i -E "/[0-9]+\.[0-9]+\.[0-9]+/! s/(^|[^0-9.])(${OLD_MAYOR}\.${OLD_MINOR})([^0-9.]|$)/\1${NEW_MAYOR}.${NEW_MINOR}\3/g" "$file"
+ if [[ $(git diff --name-only "${file}") ]]; then
+ FILES_EDITED+=("${file}")
+ fi
+ done
+ m_x_files=( $(grep_command "${OLD_MAYOR}\.x" "${DIR}" | grep -v "${DIR}/kitchen/README.md") )
+ for file in "${m_x_files[@]}"; do
+ sed -i "s/\b${OLD_MAYOR}\.x\b/${NEW_MAYOR}\.x/g" "${file}"
+ if [[ $(git diff --name-only "${file}") ]]; then
+ FILES_EDITED+=("${file}")
+ fi
+ done
+ if ! sed -i "/^All notable changes to this project will be documented in this file.$/a \\\n## [${VERSION}]\\n\\n### Added\\n\\n- None\\n\\n### Changed\\n\\n- None\\n\\n### Fixed\\n\\n- None\\n\\n### Deleted\\n\\n- None" "${DIR}/CHANGELOG.md"; then
+ echo "Error: Failed to update CHANGELOG.md" | tee -a "${LOG_FILE}"
+ fi
+ if [[ $(git diff --name-only "${DIR}/CHANGELOG.md") ]]; then
+ FILES_EDITED+=("${DIR}/CHANGELOG.md")
+ fi
+}
+
+update_stage_in_files() {
+ local OLD_STAGE="$(echo "${OLD_STAGE}")"
+ files=( $(grep_command "${OLD_STAGE}" "${DIR}") )
+ for file in "${files[@]}"; do
+ sed -i "s/${OLD_STAGE}/${STAGE}/g" "${file}"
+ if [[ $(git diff --name-only "${file}") ]]; then
+ FILES_EDITED+=("${file}")
+ fi
+ done
+}
+
+main() {
+
+ echo "Starting repository version bumping process..." | tee -a "${LOG_FILE}"
+ echo "Log file: ${LOG_FILE}"
+ # Parse arguments
+ while [[ $# -gt 0 ]]; do
+ case $1 in
+ --version)
+ VERSION="$2"
+ shift 2
+ ;;
+ --stage)
+ STAGE="$2"
+ shift 2
+ ;;
+ *)
+ echo "Unknown argument: $1"
+ exit 1
+ ;;
+ esac
+ done
+
+ # Validate arguments
+ if [[ -z "$VERSION" ]]; then
+ echo "Error: --version argument is required." | tee -a "${LOG_FILE}"
+ exit 1
+ fi
+
+ if [[ -z "$STAGE" ]]; then
+ echo "Error: --stage argument is required." | tee -a "${LOG_FILE}"
+ exit 1
+ fi
+
+ # Validate if version is in the correct format
+ if ! [[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
+ echo "Error: Version must be in the format X.Y.Z (e.g., 1.2.3)." | tee -a "${LOG_FILE}"
+ exit 1
+ fi
+
+ # Validate if stage is in the correct format
+ STAGE=$(echo "$STAGE" | tr '[:upper:]' '[:lower:]')
+ if ! [[ "$STAGE" =~ ^(alpha[0-9]*|beta[0-9]*|rc[0-9]*|stable)$ ]]; then
+ echo "Error: Stage must be one of the following examples: alpha1, beta1, rc1, stable." | tee -a "${LOG_FILE}"
+ exit 1
+ fi
+
+ # Get old version and stage
+ get_old_version_and_stage
+
+ if [[ "$OLD_VERSION" == "$VERSION" && "$OLD_STAGE" == "$STAGE" ]]; then
+ echo "Version and stage are already up to date." | tee -a "${LOG_FILE}"
+ echo "No changes needed." | tee -a "${LOG_FILE}"
+ exit 0
+ fi
+ if [[ "$OLD_VERSION" != "$VERSION" ]]; then
+ echo "Updating version from $OLD_VERSION to $VERSION" | tee -a "${LOG_FILE}"
+ update_version_in_files "$VERSION"
+ fi
+ if [[ "$OLD_STAGE" != "$STAGE" ]]; then
+ echo "Updating stage from $OLD_STAGE to $STAGE" | tee -a "${LOG_FILE}"
+ update_stage_in_files "$STAGE"
+ fi
+
+ echo "The following files were edited:" | tee -a "${LOG_FILE}"
+ for file in $(printf "%s\n" "${FILES_EDITED[@]}" | sort -u); do
+ echo "${file}" | tee -a "${LOG_FILE}"
+ done
+
+ echo "Version and stage updated successfully." | tee -a "${LOG_FILE}"
+}
+
+# Call the main method with all arguments
+main "$@"