From 73be1d092737ca53bb57cdacff6a0ec0abcfc800 Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Tue, 17 Mar 2020 17:06:37 -0400 Subject: [PATCH 1/3] Update Stuff Round 1 --- exclude-list.txt | 2 - salt/common/tools/sbin/soup | 36 +++++++ salt/registry/init.sls | 16 ++-- setup/so-functions | 10 +- setup/so-setup | 3 + so-setup-network | 2 +- updatemaster | 15 --- upgrade/so-update-functions | 183 ++++++++++++++++++++++++++++++++++++ upgrade/soup | 26 +++++ 9 files changed, 265 insertions(+), 28 deletions(-) create mode 100644 salt/common/tools/sbin/soup delete mode 100644 updatemaster create mode 100644 upgrade/so-update-functions create mode 100644 upgrade/soup diff --git a/exclude-list.txt b/exclude-list.txt index 98efb2c36..e69de29bb 100644 --- a/exclude-list.txt +++ b/exclude-list.txt @@ -1,2 +0,0 @@ -salt/bro/files/local.bro -salt/bro/files/local.bro.community diff --git a/salt/common/tools/sbin/soup b/salt/common/tools/sbin/soup new file mode 100644 index 000000000..17d360b6c --- /dev/null +++ b/salt/common/tools/sbin/soup @@ -0,0 +1,36 @@ +#!/bin/bash + +# Copyright 2014,2015,2016,2017,2018,2019,2020 Security Onion Solutions, LLC + +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . + +clone_to_tmp() { + + # TODO Need to add a air gap option + # Make a temp location for the files + rm -rf /tmp/soup + mkdir -p /tmp/soup + cd /tmp/soup + #git clone -b dev https://github.com/Security-Onion-Solutions/securityonion-saltstack.git + git clone https://github.com/Security-Onion-Solutions/securityonion-saltstack.git + +} + +# Prompt the user that this requires internets + +clone_to_tmp +cd /tmp/soup/securityonion-saltstack +./soup + + diff --git a/salt/registry/init.sls b/salt/registry/init.sls index c0b4bf038..ed56d25ae 100644 --- a/salt/registry/init.sls +++ b/salt/registry/init.sls @@ -27,15 +27,15 @@ dockerregistryconf: - source: salt://registry/etc/config.yml # Copy the registry script -dockerregistrybuild: - file.managed: - - name: /opt/so/conf/docker-registry/so-buildregistry - - source: salt://registry/bin/so-buildregistry - - mode: 755 +#dockerregistrybuild: +# file.managed: +# - name: /opt/so/conf/docker-registry/so-buildregistry +# - source: salt://registry/bin/so-buildregistry +# - mode: 755 -dockerexpandregistry: - cmd.run: - - name: /opt/so/conf/docker-registry/so-buildregistry +#dockerexpandregistry: +# cmd.run: +# - name: /opt/so/conf/docker-registry/so-buildregistry # Install the registry container so-dockerregistry: diff --git a/setup/so-functions b/setup/so-functions index 7a516f95f..0ec8b53b0 100755 --- a/setup/so-functions +++ b/setup/so-functions @@ -17,6 +17,7 @@ SCRIPTDIR=$(dirname "$0") source $SCRIPTDIR/so-whiptail +SOVERSION=1.2.1 accept_salt_key_local() { echo "Accept the key locally on the master" >> $SETUPLOG 2>&1 @@ -460,7 +461,7 @@ docker_registry() { } docker_seed_registry() { - VERSION="HH1.1.4" + VERSION="HH$SOVERSION" if [ $INSTALLTYPE != 'HELIXSENSOR' ]; then TRUSTED_CONTAINERS=( \ "so-acng:$VERSION" \ @@ -743,7 +744,7 @@ master_static() { touch /opt/so/saltstack/pillar/static.sls echo "static:" > /opt/so/saltstack/pillar/static.sls - echo " soversion: HH1.1.4" >> /opt/so/saltstack/pillar/static.sls + echo " soversion: $SOVERSION" >> /opt/so/saltstack/pillar/static.sls echo " hnmaster: $HNMASTER" >> /opt/so/saltstack/pillar/static.sls echo " ntpserver: $NTPSERVER" >> /opt/so/saltstack/pillar/static.sls echo " proxy: $PROXY" >> /opt/so/saltstack/pillar/static.sls @@ -1412,6 +1413,11 @@ set_updates() { fi } +set_version() { + # Drop a file with the current version + echo "$SOVERSION" > /etc/soversion +} + update_sudoers() { if ! grep -qE '^socore\ ALL=\(ALL\)\ NOPASSWD:(\/usr\/bin\/salt\-key|\/opt\/so\/saltstack)' /etc/sudoers; then diff --git a/setup/so-setup b/setup/so-setup index d3956a845..d9d10cf8c 100755 --- a/setup/so-setup +++ b/setup/so-setup @@ -159,6 +159,7 @@ if (whiptail_you_sure) ; then calculate_useable_cores whiptail_make_changes set_hostname + set_version clear_master mkdir -p /nsm get_filesystem_root @@ -302,6 +303,7 @@ if (whiptail_you_sure) ; then # Last Chance to back out whiptail_make_changes set_hostname + set_version generate_passwords auth_pillar clear_master @@ -570,6 +572,7 @@ if (whiptail_you_sure) ; then fi whiptail_make_changes set_hostname + set_version generate_passwords auth_pillar clear_master diff --git a/so-setup-network b/so-setup-network index a24fc76f5..ae9af4ffa 100755 --- a/so-setup-network +++ b/so-setup-network @@ -1,6 +1,6 @@ #!/bin/bash -# Copyright 2014,2015,2016,2017,2018,2019 Security Onion Solutions, LLC +# Copyright 2014,2015,2016,2017,2018,2019,2020 Security Onion Solutions, LLC # This program is free software: you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by diff --git a/updatemaster b/updatemaster deleted file mode 100644 index c66c01d86..000000000 --- a/updatemaster +++ /dev/null @@ -1,15 +0,0 @@ -#!/bin/bash - -# Clone github -mkdir /tmp/sogh -cd /tmp/sogh -#git clone -b dev https://github.com/Security-Onion-Solutions/securityonion-saltstack.git -git clone https://github.com/Security-Onion-Solutions/securityonion-saltstack.git -cd securityonion-saltstack -rsync -a --exclude-from 'exclude-list.txt' salt /opt/so/saltstack/ -chown -R socore:socore /opt/so/saltstack/salt -chmod 755 /opt/so/saltstack/pillar/firewall/addfirewall.sh -cd ~ -rm -rf /tmp/sogh -# Run so-elastic-download here and call this soup with some magic -salt-call state.highstate diff --git a/upgrade/so-update-functions b/upgrade/so-update-functions new file mode 100644 index 000000000..ccd208723 --- /dev/null +++ b/upgrade/so-update-functions @@ -0,0 +1,183 @@ +#!/bin/bash + +# Copyright 2014,2015,2016,2017,2018,2019,2020 Security Onion Solutions, LLC + +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . + +# Set the SO Version +VERSION=1.2.1 +BUILD=HH +OLDVERSION=$(cat /etc/soversion) + +clone_to_tmp() { + + # TODO Need to add a air gap option + # Make a temp location for the files + mkdir /tmp/sogh + cd /tmp/sogh + #git clone -b dev https://github.com/Security-Onion-Solutions/securityonion-saltstack.git + git clone https://github.com/Security-Onion-Solutions/securityonion-saltstack.git + +} + +detect_os() { + + # Detect Base OS + echo "Detecting Base OS" >> $UPDATELOG 2>&1 + if [ -f /etc/redhat-release ]; then + OS=centos + if grep -q "CentOS Linux release 7" /etc/redhat-release; then + OSVER=7 + elif grep -q "CentOS Linux release 8" /etc/redhat-release; then + OSVER=8 + echo "We currently do not support CentOS $OSVER but we are working on it!" + exit + else + echo "We do not support the version of CentOS you are trying to use" + exit + fi + + elif [ -f /etc/os-release ]; then + OS=ubuntu + if grep -q "UBUNTU_CODENAME=bionic" /etc/os-release; then + OSVER=bionic + elif grep -q "UBUNTU_CODENAME=xenial" /etc/os-release; then + OSVER=xenial + else + echo "We do not support your current version of Ubuntu" + exit + fi + # Install network manager so we can do interface stuff + apt install -y network-manager + /bin/systemctl enable network-manager + /bin/systemctl start network-manager + else + echo "We were unable to determine if you are using a supported OS." >> $UPDATELOG 2>&1 + exit + fi + + echo "Found OS: $OS $OSVER" >> $UPDATELOG 2>&1 + +} + +update_held_packages() { + + if [ $OS == "centos" ] + SALTVER=2019.2.3 + DOCKERVER= + yum -y --disableexcludes=all update salt-$SALTVER + yum -y --disableexcludes=all update docker-ce-$DOCKERVER + else + SALTVER=2019.2.3+ds-1 + DOCKERVER=5:19.03.8~3-0~ubuntu-xenial + fi + +} + +update_all_packages() { + + # Update all the things based on OS + if [ $OS == "centos" ]; then + yum -y update + else + apt -y update && apt -y upgrade + fi + +} + +update_docker_containers() { + if [ $INSTALLTYPE != 'HELIXSENSOR' ]; then + TRUSTED_CONTAINERS=( \ + "so-acng:$BUILD$VERSION" \ + "so-auth-api:$BUILD$VERSION" \ + "so-auth-ui:$BUILD$VERSION" \ + "so-core:$BUILD$VERSION" \ + "so-thehive-cortex:$BUILD$VERSION" \ + "so-curator:$BUILD$VERSION" \ + "so-domainstats:$BUILD$VERSION" \ + "so-elastalert:$BUILD$VERSION" \ + "so-elasticsearch:$BUILD$VERSION" \ + "so-filebeat:$BUILD$VERSION" \ + "so-fleet:$BUILD$VERSION" \ + "so-fleet-launcher:$BUILD$VERSION" \ + "so-freqserver:$BUILD$VERSION" \ + "so-grafana:$BUILD$VERSION" \ + "so-idstools:$BUILD$VERSION" \ + "so-influxdb:$BUILD$VERSION" \ + "so-kibana:$BUILD$VERSION" \ + "so-logstash:$BUILD$VERSION" \ + "so-mysql:$BUILD$VERSION" \ + "so-navigator:$BUILD$VERSION" \ + "so-playbook:$BUILD$VERSION" \ + "so-redis:$BUILD$VERSION" \ + "so-sensoroni:$BUILD$VERSION" \ + "so-soctopus:$BUILD$VERSION" \ + "so-steno:$BUILD$VERSION" \ + #"so-strelka:$BUILD$VERSION" \ + "so-suricata:$BUILD$VERSION" \ + "so-telegraf:$BUILD$VERSION" \ + "so-thehive:$BUILD$VERSION" \ + "so-thehive-es:$BUILD$VERSION" \ + "so-wazuh:$BUILD$VERSION" \ + "so-zeek:$BUILD$VERSION" ) + else + TRUSTED_CONTAINERS=( \ + "so-core:$BUILD$VERSION" \ + "so-filebeat:$BUILD$VERSION" \ + "so-idstools:$BUILD$VERSION" \ + "so-logstash:$BUILD$VERSION" \ + "so-redis:$BUILD$VERSION" \ + "so-sensoroni:$BUILD$VERSION" \ + "so-steno:$BUILD$VERSION" \ + "so-suricata:$BUILD$VERSION" \ + "so-telegraf:$BUILD$VERSION" \ + "so-zeek:$BUILD$VERSION" ) + fi + + # Download the container from the interwebs + for i in "${TRUSTED_CONTAINERS[@]}" + do + # Pull down the trusted docker image + echo "Downloading $i" + docker pull --disable-content-trust=false docker.io/soshybridhunter/$i + # Tag it with the new registry destination + docker tag soshybridhunter/$i $HOSTNAME:5000/soshybridhunter/$i + docker push $HOSTNAME:5000/soshybridhunter/$i + done + + for i in "${TRUSTED_CONTAINERS[@]}" + do + echo "Removing $i locally" + docker rmi soshybridhunter/$i + done + +} +update_hh_version() { + # Change the version number in the static pillar + +} + +# Clone github +mkdir /tmp/sogh +cd /tmp/sogh +#git clone -b dev https://github.com/Security-Onion-Solutions/securityonion-saltstack.git +git clone https://github.com/Security-Onion-Solutions/securityonion-saltstack.git +cd securityonion-saltstack +rsync -a --exclude-from 'exclude-list.txt' salt /opt/so/saltstack/ +chown -R socore:socore /opt/so/saltstack/salt +chmod 755 /opt/so/saltstack/pillar/firewall/addfirewall.sh +cd ~ +rm -rf /tmp/sogh +# Run so-elastic-download here and call this soup with some magic +salt-call state.highstate diff --git a/upgrade/soup b/upgrade/soup new file mode 100644 index 000000000..6ae8def42 --- /dev/null +++ b/upgrade/soup @@ -0,0 +1,26 @@ +#!/bin/bash + +# Copyright 2014,2015,2016,2017,2018,2019,2020 Security Onion Solutions, LLC + +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . + +SCRIPTDIR=$(dirname "$0") +source $SCRIPTDIR/so-update-functions + +# Update Packages +update_all_packages +update_held_packages + + + From b48612dd3b23de77140f490ed9aad52b9bb4082d Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Thu, 19 Mar 2020 13:46:19 -0400 Subject: [PATCH 2/3] Update Stuff Round 2 --- salt/common/tools/sbin/soup | 3 +- upgrade/so-update-functions | 164 +++++++++++++++++++++--------------- upgrade/soup | 1 + 3 files changed, 97 insertions(+), 71 deletions(-) diff --git a/salt/common/tools/sbin/soup b/salt/common/tools/sbin/soup index 17d360b6c..7c471aa34 100644 --- a/salt/common/tools/sbin/soup +++ b/salt/common/tools/sbin/soup @@ -30,7 +30,8 @@ clone_to_tmp() { # Prompt the user that this requires internets clone_to_tmp -cd /tmp/soup/securityonion-saltstack +cd /tmp/soup/securityonion-saltstack/update +chmod +x soup ./soup diff --git a/upgrade/so-update-functions b/upgrade/so-update-functions index ccd208723..0961bbf7a 100644 --- a/upgrade/so-update-functions +++ b/upgrade/so-update-functions @@ -15,10 +15,71 @@ # You should have received a copy of the GNU General Public License # along with this program. If not, see . -# Set the SO Version -VERSION=1.2.1 +# Set the new SO Version + +UPDATEVERSION=1.2.1 BUILD=HH -OLDVERSION=$(cat /etc/soversion) + +#Determine the current install version + +if [ -f /etc/soversion ]; then + OLDVERSION=$(cat /etc/soversion) +else + OLDVERSION=1.1.4 +fi + +# Use the hostname +HOSTNAME=$(hostname) + +# List all the containers +if [ $MASTERCHECK != 'so-helix' ]; then + TRUSTED_CONTAINERS=( \ + "so-acng:$BUILD$UPDATEVERSION" \ + "so-auth-api:$BUILD$UPDATEVERSION" \ + "so-auth-ui:$BUILD$UPDATEVERSION" \ + "so-core:$BUILD$UPDATEVERSION" \ + "so-thehive-cortex:$BUILD$UPDATEVERSION" \ + "so-curator:$$BUILD$UPDATEVERSION" \ + "so-domainstats:$$BUILD$UPDATEVERSION" \ + "so-elastalert:$$BUILD$UPDATEVERSION" \ + "so-elasticsearch:$$BUILD$UPDATEVERSION" \ + "so-filebeat:$$BUILD$UPDATEVERSION" \ + "so-fleet:$$BUILD$UPDATEVERSION" \ + "so-fleet-launcher:$$BUILD$UPDATEVERSION" \ + "so-freqserver:$$BUILD$UPDATEVERSION" \ + "so-grafana:$$BUILD$UPDATEVERSION" \ + "so-idstools:$$BUILD$UPDATEVERSION" \ + "so-influxdb:$$BUILD$UPDATEVERSION" \ + "so-kibana:$$BUILD$UPDATEVERSION" \ + "so-logstash:$$BUILD$UPDATEVERSION" \ + "so-mysql:$$BUILD$UPDATEVERSION" \ + "so-navigator:$$BUILD$UPDATEVERSION" \ + "so-playbook:$$BUILD$UPDATEVERSION" \ + "so-redis:$$BUILD$UPDATEVERSION" \ + "so-sensoroni:$$BUILD$UPDATEVERSION" \ + "so-soctopus:$$BUILD$UPDATEVERSION" \ + "so-steno:$$BUILD$UPDATEVERSION" \ + "so-strelka:$$BUILD$UPDATEVERSION" \ + "so-suricata:$$BUILD$UPDATEVERSION" \ + "so-telegraf:$$BUILD$UPDATEVERSION" \ + "so-thehive:$$BUILD$UPDATEVERSION" \ + "so-thehive-es:$$BUILD$UPDATEVERSION" \ + "so-wazuh:$$BUILD$UPDATEVERSION" \ + "so-zeek:$$BUILD$UPDATEVERSION" ) + else + TRUSTED_CONTAINERS=( \ + "so-core:$$BUILD$UPDATEVERSION" \ + "so-filebeat:$$BUILD$UPDATEVERSION" \ + "so-idstools:$$BUILD$UPDATEVERSION" \ + "so-logstash:$$BUILD$UPDATEVERSION" \ + "so-redis:$$BUILD$UPDATEVERSION" \ + "so-sensoroni:$$BUILD$UPDATEVERSION" \ + "so-steno:$$BUILD$UPDATEVERSION" \ + "so-suricata:$$BUILD$UPDATEVERSION" \ + "so-telegraf:$$BUILD$UPDATEVERSION" \ + "so-zeek:$$BUILD$UPDATEVERSION" ) + fi + clone_to_tmp() { @@ -28,9 +89,20 @@ clone_to_tmp() { cd /tmp/sogh #git clone -b dev https://github.com/Security-Onion-Solutions/securityonion-saltstack.git git clone https://github.com/Security-Onion-Solutions/securityonion-saltstack.git + cd /tmp } +copy_new_files() { + + # Copy new files over to the salt dir + cd /tmp/sogh/securityonion-saltstack + rsync -a --exclude-from 'exclude-list.txt' salt /opt/so/saltstack/ + chown -R socore:socore /opt/so/saltstack/salt + chmod 755 /opt/so/saltstack/pillar/firewall/addfirewall.sh + cd /tmp +} + detect_os() { # Detect Base OS @@ -58,10 +130,6 @@ detect_os() { echo "We do not support your current version of Ubuntu" exit fi - # Install network manager so we can do interface stuff - apt install -y network-manager - /bin/systemctl enable network-manager - /bin/systemctl start network-manager else echo "We were unable to determine if you are using a supported OS." >> $UPDATELOG 2>&1 exit @@ -71,6 +139,22 @@ detect_os() { } +master_check() { + # Check to see if this is a master + MASTERCHECK=$(cat /etc/salt/grains | grep role | awk '{print $2}') + if [ $MASTERCHECK == 'so-eval' OR $MASTERCHECK == 'so-master' OR $MASTERCHECK == 'so-mastersearch' ]; then + echo "This is a master. We can proceed" + else + echo "Please run soup on the master. The master controls all updates." + exit +} + +salt_highstate() { + + salt-call state.highstate + +} + update_held_packages() { if [ $OS == "centos" ] @@ -97,55 +181,8 @@ update_all_packages() { } update_docker_containers() { - if [ $INSTALLTYPE != 'HELIXSENSOR' ]; then - TRUSTED_CONTAINERS=( \ - "so-acng:$BUILD$VERSION" \ - "so-auth-api:$BUILD$VERSION" \ - "so-auth-ui:$BUILD$VERSION" \ - "so-core:$BUILD$VERSION" \ - "so-thehive-cortex:$BUILD$VERSION" \ - "so-curator:$BUILD$VERSION" \ - "so-domainstats:$BUILD$VERSION" \ - "so-elastalert:$BUILD$VERSION" \ - "so-elasticsearch:$BUILD$VERSION" \ - "so-filebeat:$BUILD$VERSION" \ - "so-fleet:$BUILD$VERSION" \ - "so-fleet-launcher:$BUILD$VERSION" \ - "so-freqserver:$BUILD$VERSION" \ - "so-grafana:$BUILD$VERSION" \ - "so-idstools:$BUILD$VERSION" \ - "so-influxdb:$BUILD$VERSION" \ - "so-kibana:$BUILD$VERSION" \ - "so-logstash:$BUILD$VERSION" \ - "so-mysql:$BUILD$VERSION" \ - "so-navigator:$BUILD$VERSION" \ - "so-playbook:$BUILD$VERSION" \ - "so-redis:$BUILD$VERSION" \ - "so-sensoroni:$BUILD$VERSION" \ - "so-soctopus:$BUILD$VERSION" \ - "so-steno:$BUILD$VERSION" \ - #"so-strelka:$BUILD$VERSION" \ - "so-suricata:$BUILD$VERSION" \ - "so-telegraf:$BUILD$VERSION" \ - "so-thehive:$BUILD$VERSION" \ - "so-thehive-es:$BUILD$VERSION" \ - "so-wazuh:$BUILD$VERSION" \ - "so-zeek:$BUILD$VERSION" ) - else - TRUSTED_CONTAINERS=( \ - "so-core:$BUILD$VERSION" \ - "so-filebeat:$BUILD$VERSION" \ - "so-idstools:$BUILD$VERSION" \ - "so-logstash:$BUILD$VERSION" \ - "so-redis:$BUILD$VERSION" \ - "so-sensoroni:$BUILD$VERSION" \ - "so-steno:$BUILD$VERSION" \ - "so-suricata:$BUILD$VERSION" \ - "so-telegraf:$BUILD$VERSION" \ - "so-zeek:$BUILD$VERSION" ) - fi - - # Download the container from the interwebs + + # Download the containers from the interwebs for i in "${TRUSTED_CONTAINERS[@]}" do # Pull down the trusted docker image @@ -163,21 +200,8 @@ update_docker_containers() { done } + update_hh_version() { # Change the version number in the static pillar } - -# Clone github -mkdir /tmp/sogh -cd /tmp/sogh -#git clone -b dev https://github.com/Security-Onion-Solutions/securityonion-saltstack.git -git clone https://github.com/Security-Onion-Solutions/securityonion-saltstack.git -cd securityonion-saltstack -rsync -a --exclude-from 'exclude-list.txt' salt /opt/so/saltstack/ -chown -R socore:socore /opt/so/saltstack/salt -chmod 755 /opt/so/saltstack/pillar/firewall/addfirewall.sh -cd ~ -rm -rf /tmp/sogh -# Run so-elastic-download here and call this soup with some magic -salt-call state.highstate diff --git a/upgrade/soup b/upgrade/soup index 6ae8def42..19fa0203f 100644 --- a/upgrade/soup +++ b/upgrade/soup @@ -19,6 +19,7 @@ SCRIPTDIR=$(dirname "$0") source $SCRIPTDIR/so-update-functions # Update Packages +master_check update_all_packages update_held_packages From 98caae8ec9a8b61f9d75638f07b6a1fa9b972252 Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Mon, 23 Mar 2020 15:12:36 -0400 Subject: [PATCH 3/3] Update Stuff round 3 --- upgrade/so-update-functions | 74 ++++++++++++++++++------------------- 1 file changed, 37 insertions(+), 37 deletions(-) diff --git a/upgrade/so-update-functions b/upgrade/so-update-functions index 0961bbf7a..71e8eac69 100644 --- a/upgrade/so-update-functions +++ b/upgrade/so-update-functions @@ -39,45 +39,45 @@ if [ $MASTERCHECK != 'so-helix' ]; then "so-auth-ui:$BUILD$UPDATEVERSION" \ "so-core:$BUILD$UPDATEVERSION" \ "so-thehive-cortex:$BUILD$UPDATEVERSION" \ - "so-curator:$$BUILD$UPDATEVERSION" \ - "so-domainstats:$$BUILD$UPDATEVERSION" \ - "so-elastalert:$$BUILD$UPDATEVERSION" \ - "so-elasticsearch:$$BUILD$UPDATEVERSION" \ - "so-filebeat:$$BUILD$UPDATEVERSION" \ - "so-fleet:$$BUILD$UPDATEVERSION" \ - "so-fleet-launcher:$$BUILD$UPDATEVERSION" \ - "so-freqserver:$$BUILD$UPDATEVERSION" \ - "so-grafana:$$BUILD$UPDATEVERSION" \ - "so-idstools:$$BUILD$UPDATEVERSION" \ - "so-influxdb:$$BUILD$UPDATEVERSION" \ - "so-kibana:$$BUILD$UPDATEVERSION" \ - "so-logstash:$$BUILD$UPDATEVERSION" \ - "so-mysql:$$BUILD$UPDATEVERSION" \ - "so-navigator:$$BUILD$UPDATEVERSION" \ - "so-playbook:$$BUILD$UPDATEVERSION" \ - "so-redis:$$BUILD$UPDATEVERSION" \ - "so-sensoroni:$$BUILD$UPDATEVERSION" \ - "so-soctopus:$$BUILD$UPDATEVERSION" \ - "so-steno:$$BUILD$UPDATEVERSION" \ - "so-strelka:$$BUILD$UPDATEVERSION" \ - "so-suricata:$$BUILD$UPDATEVERSION" \ - "so-telegraf:$$BUILD$UPDATEVERSION" \ - "so-thehive:$$BUILD$UPDATEVERSION" \ - "so-thehive-es:$$BUILD$UPDATEVERSION" \ - "so-wazuh:$$BUILD$UPDATEVERSION" \ - "so-zeek:$$BUILD$UPDATEVERSION" ) + "so-curator:$BUILD$UPDATEVERSION" \ + "so-domainstats:$BUILD$UPDATEVERSION" \ + "so-elastalert:$BUILD$UPDATEVERSION" \ + "so-elasticsearch:$BUILD$UPDATEVERSION" \ + "so-filebeat:$BUILD$UPDATEVERSION" \ + "so-fleet:$BUILD$UPDATEVERSION" \ + "so-fleet-launcher:$BUILD$UPDATEVERSION" \ + "so-freqserver:$BUILD$UPDATEVERSION" \ + "so-grafana:$BUILD$UPDATEVERSION" \ + "so-idstools:$BUILD$UPDATEVERSION" \ + "so-influxdb:$BUILD$UPDATEVERSION" \ + "so-kibana:$BUILD$UPDATEVERSION" \ + "so-logstash:$BUILD$UPDATEVERSION" \ + "so-mysql:$BUILD$UPDATEVERSION" \ + "so-navigator:$BUILD$UPDATEVERSION" \ + "so-playbook:$BUILD$UPDATEVERSION" \ + "so-redis:$BUILD$UPDATEVERSION" \ + "so-sensoroni:$BUILD$UPDATEVERSION" \ + "so-soctopus:$BUILD$UPDATEVERSION" \ + "so-steno:$BUILD$UPDATEVERSION" \ + "so-strelka:$BUILD$UPDATEVERSION" \ + "so-suricata:$BUILD$UPDATEVERSION" \ + "so-telegraf:$BUILD$UPDATEVERSION" \ + "so-thehive:$BUILD$UPDATEVERSION" \ + "so-thehive-es:$BUILD$UPDATEVERSION" \ + "so-wazuh:$BUILD$UPDATEVERSION" \ + "so-zeek:$BUILD$UPDATEVERSION" ) else TRUSTED_CONTAINERS=( \ - "so-core:$$BUILD$UPDATEVERSION" \ - "so-filebeat:$$BUILD$UPDATEVERSION" \ - "so-idstools:$$BUILD$UPDATEVERSION" \ - "so-logstash:$$BUILD$UPDATEVERSION" \ - "so-redis:$$BUILD$UPDATEVERSION" \ - "so-sensoroni:$$BUILD$UPDATEVERSION" \ - "so-steno:$$BUILD$UPDATEVERSION" \ - "so-suricata:$$BUILD$UPDATEVERSION" \ - "so-telegraf:$$BUILD$UPDATEVERSION" \ - "so-zeek:$$BUILD$UPDATEVERSION" ) + "so-core:$BUILD$UPDATEVERSION" \ + "so-filebeat:$BUILD$UPDATEVERSION" \ + "so-idstools:$BUILD$UPDATEVERSION" \ + "so-logstash:$BUILD$UPDATEVERSION" \ + "so-redis:$BUILD$UPDATEVERSION" \ + "so-sensoroni:$BUILD$UPDATEVERSION" \ + "so-steno:$BUILD$UPDATEVERSION" \ + "so-suricata:$BUILD$UPDATEVERSION" \ + "so-telegraf:$BUILD$UPDATEVERSION" \ + "so-zeek:$BUILD$UPDATEVERSION" ) fi