[v5.0.0]
Added
| Issue | Comment |
|---|---|
| #2706 | Add Wazuh indexer dependencies on builder final stage |
| #2619 | Add CA verification |
| #2606 | Support the unified WAZUH_MANAGER_ENDPOINT connection URL in the Wazuh agent, alongside WAZUH_MANAGER_SERVER and WAZUH_MANAGER_PORT
|
| #2524 | Set authd password in agents installation. |
| #2505 | Added bump-issue-link support for Revert Stage Bump. |
| #2491 | Add integration test module docs |
| #2188 | Implement the wazuh-docker integration testing module |
| #2320 | Support Revert bump functionality in wazuh-docker |
| #35457 | Docker and AMI workflows failing during stage release (v5.0.0-beta1) |
| #2276 | Add --set-as-main flag support to repository bumper — wazuh-docker
|
Changed
| Issue | Comment |
|---|---|
| #2674 | Adapt Docker images to install-time credential generation |
| #2676 | Replace manual authd.pass/<endpoint> writing in the agent's 0-wazuh-init with WAZUH_ENROLLMENT_TOKEN support, following wazuh/wazuh#39063
|
| #2652 | Mount the Wazuh manager agent listener certificate, and forward --agent-san to the certificate creation tool
|
| #2635 | Honour the scheme given in WAZUH_INDEXER_HOSTS, and drop the <ssl> block from the indexer configuration when it resolves to http
|
| #2621 | Change cluster key assigment |
| #2622 | Check the Wazuh API accounts of every manager node in check-default-credentials.sh, and document the worker step of the multi-node password change
|
| #6058 | Remove the OpenSearch demo users from the indexer image, add password-tool.sh to change the indexer and API passwords of a running deployment, and stop publishing the indexer port 9200
|
| #2601 | Regenerate the manager self-signed server certificate per container at first boot |
| #2564 | Add default AI assistant encryption key in the post installation script |
| #2581 | Change Codebuild runners to Github runners |
| #2537 | Update deployment for Wazuh Indexer 5.0.0 RBAC |
| #2539 | Add new WF for changelog check |
| #2502 | Change artifact upload and download |
| #2471 | Change runners on repository workflows 5.x |
| #2446 | PR revamp modifications 5.x |
| #2399 | Forbid pr_check workflow execution in draft PRs |
| #2375 | Unification of user UID and GID |
| #2392 | Wazuh indexer engine requirements |
| #2356 | Image build process update |
| #2344 | Add new path on artifact_urls file |
| #2341 | Unable to generate single component in Procedure_push_docker_images
|
| #2294 | Adapt bumper workflows to change main branch |
| #2288 | Ensure default values are used for variables and passwords |
| #2283 | Docker - Ensure correct Wazuh manager certificates ownership |
| #2278 | Docker - Standarize Artifact URL keys |
| #2266 | Modify artifact URLs file name. |
| #2218 | URL presigned file - Update the Wazuh Docker image creation workflow |
| #2264 | Updated wazuh-docker documentation config and tooling versions to meet new standards. |
| #2250 | Align cert generation steps with current cert-tool ip validation |
| #2252 | Modify Healthchecks |
| #2251 | Add deployment healthchecks |
| #2242 | Update artifact generation jobs to use wz-linux dedicated runner group |
| #2237 | Error during Wazuh manager entrypoint |
| #2230 | Adapt PR test for workflow_dispatch option |
| #2227 | Wazuh Manager/agent Separation - Breaking changes summary |
| #2222 | Errors in wazuh-docker PR Test |
| #2206 | Development - Separate Agent/Manager - Docker - Adapt image build process |
| #2217 | Remove revision input |
| #2196 | Build images script improvement |
| #2197 | Missing documentation in the wazuh-docker repository |
| #2195 | Add Wazuh version and revision into wazuh-certs-tool and config file |
| #2172 | Improve S3 artifact URLs handling |
| #2164 | Allow building separate targets |
| #2179 | Add developement option when tag name is only version without stage |
| #2178 | Add IMAGE_TAG stage reference |
| #2171 | Remove Wazuh agent configuration template |
| #2156 | Docker - Ensure run_as set to true for every deployment alternative
|
| #2150 | Change macOS and Windows deployment documentation |
| #2131 | Modify docker build image process |
| #2136 | Update documentation for Wazuh Docker image builder and workflow usage |
| #2081 | Configure deployment with environment variables |
| #2058 | Modify Wazuh components install method |
| #2054 | Image builder Workflow Rebuild |
| #1933 | Remove Wazuh Manager deprecated daemons and CLI tools |
| #1891 | DevOps - Docker - OpenSearch 3.0 deprecated settings |
Removed
| Issue | Comment |
|---|
Fixed
| Issue | Comment |
|---|---|
| #2690 | Unset INDEXER_PASSWORD and DASHBOARD_PASSWORD after keystore write |
| #2675 | Fixed docker-agent package generation: seed the CHANGE_MANAGER_ENDPOINT placeholder in the Dockerfile itself instead of relying on the installer, which stopped writing it without an enrollment token
|
| #2628 | Persist the Wazuh manager data directory on a named volume in the single-node and multi-node deployments, so the deployed detection content survives recreating the container, and refresh the content the image owns from the image on every start
|
| #2629 | Append opensearch_security.cookie.ttl when missing from opensearch_dashboards.yml instead of silently discarding OPENSEARCH_SECURITY_COOKIE_TTL; removed the PATTERN, CHECKS_*, APP_TIMEOUT, API_SELECTOR, IP_SELECTOR, IP_IGNORE and WAZUH_MONITORING_* environment variables, which no longer correspond to any setting the dashboard plugin accepts
|
| #2638 | Fixed manager/dashboard environment variable attribution and documented missing manager variables |
| #2631 | Escape special sed replacement characters so passwords and keys with &, , or the delimiter are no longer corrupted or silently discarded |
| #2632 | Fix agent re creation and re-enrollment |
| #2626 | Supervise the manager daemons from the entrypoint and exit if a critical one dies, so restart: always can bring the container back instead of it staying up indefinitely with a dead API
|
| #2634 | Default WAZUH_CLUSTER_BIND_ADDR to 0.0.0.0 so the published manager image actually starts |
| #2630 | Fixed WAZUH_INDEXER_HOSTS parsing: hosts without an explicit port, URLs with a scheme, and bracketed IPv6 addresses were silently mangled instead of being parsed correctly, and unparseable values were written to the config without any error |
| #2627 | Fixed manager and dashboard healthchecks to correctly detect failures instead of always reporting healthy |
| #2604 | Adapt Wazuh manager image to new enroll process |
| #2594 | Added diffutils to the Wazuh agent image so FIM report_changes can generate content diffs
|
| #2590 | Restore WAZUH_MANAGER_PORT support in the Wazuh agent image and document the enrollment variables removed in 5.0.0
|
| #2578 | Report skipped bumps in the repository bumper workflow |
| #2584 | Adapt certificate deployment to the unified manager certificate layout (root:wazuh-manager 0640, dir 1770) |
| #2563 | Fixed changelog check workflow to accept Prior versions entries |
| #2533 | Fix bumper workflow failure when bump produces no changes |
| #2477 | Bumper script issue when the tag is set to false |
| #2443 | Fix reported WF vulnerabilities |
| #2422 | Adapt Wazuh manager healthcheck with local binaries |
| #2337 | The Wazuh Docker image cannot be built during the Nightly |
| #35457 | Docker and AMI workflows failing during stage release (v5.0.0-beta1) |
| #2274 | PR check issues |
| #2271 | Wazuh manager Healthcheck |
| #2258 | Delete WAZUH_AGENT_GROUPS of Wazuh 5.0.0 images build |
| #2128 | Development - DevOps 5.0 adaptation - Docker - Delete lists directory references |