feat: Initial commit of ludus_elastic_agent

This commit is contained in:
arod
2024-03-24 00:18:54 -04:00
parent 112cccf203
commit 17b5cdb0df
6 changed files with 334 additions and 2 deletions
+39
View File
@@ -0,0 +1,39 @@
---
# This workflow requires a GALAXY_API_KEY secret present in the GitHub
# repository or organization.
#
# See: https://github.com/marketplace/actions/publish-ansible-role-to-galaxy
# See: https://github.com/ansible/galaxy/issues/46
name: Release
"on":
push:
tags:
- "*"
defaults:
run:
working-directory: "badsectorlabs.ludus_elastic_agent"
jobs:
release:
name: Release
runs-on: ubuntu-latest
steps:
- name: Check out the codebase.
uses: actions/checkout@v4
with:
path: "badsectorlabs.ludus_elastic_agent"
- name: Set up Python 3.
uses: actions/setup-python@v5
with:
python-version: "3.x"
- name: Install Ansible.
run: pip3 install ansible-core
- name: Trigger a new import on Galaxy.
run: >-
ansible-galaxy role import --api-key ${{ secrets.GALAXY_API_KEY }}
$(echo ${{ github.repository }} | cut -d/ -f1) $(echo ${{ github.repository }} | cut -d/ -f2)
+53
View File
@@ -0,0 +1,53 @@
### Ansible ###
*.retry
### macOS ###
# General
.DS_Store
.AppleDouble
.LSOverride
# Icon must end with two \r
Icon
# Thumbnails
._*
# Files that might appear in the root of a volume
.DocumentRevisions-V100
.fseventsd
.Spotlight-V100
.TemporaryItems
.Trashes
.VolumeIcon.icns
.com.apple.timemachine.donotpresent
# Directories potentially created on remote AFP share
.AppleDB
.AppleDesktop
Network Trash Folder
Temporary Items
.apdisk
### macOS Patch ###
# iCloud generated files
*.icloud
### VisualStudioCode ###
.vscode
# Local History for Visual Studio Code
.history/
# Built Visual Studio Code Extensions
*.vsix
### VisualStudioCode Patch ###
# Ignore all local history of files
.history
.ionide
# Sensitive or high-churn files
.env
# End of https://www.toptal.com/developers/gitignore/api/visualstudiocode,macos,ansible
+97 -2
View File
@@ -1,2 +1,97 @@
# ludus_elastic_agent
An Ansible role that installs an Elastic Agent on a windows device
# Ansible Role: Elastic Agent Deployment
An Ansible role that deploys Elastic Agents to Windows, Debian, and Ubuntu systems.
## Description
- The role checks if the Elastic Agents have been downloaded to the Ludus host. If not, it will attempt to download the agents based on the `ludus_elastic_agent_version` variable.
- Agent versions can be [found here](https://www.elastic.co/downloads/past-releases#elastic-agent)
- The role is designed to work with Windows, Debian, Ubuntu systems.
- This role compliments the [ludus_elastic_container](https://github.com/badsectorlabs/ludus_elastic_container)
Warning:
- `--force` flag is used during agent installation. This overwrites the current installation and does not prompt for confirmation.
- `--insecure` flag is used during agent installation. This is to ignore the self-signed certs.
## Requirements
None.
## Role Variables
Available variables are listed below, along with default values (see `defaults/main.yml`):
# The ludus_elastic_container role will output this to the console if you're monitoring the logs.
# Also accessible via the kibana UI.
# Also accessible in /opt/{{ ludus_elastic_container_install_path }}/enrollment_token.txt
ludus_elastic_enrollment_token: ""
# the IP address of your elastic server and port (defaults to 8220)
# `ludus range status` will provide you with the IP address
ludus_elastic_fleet_server: ""
# A valid agent version to download and install
ludus_elastic_agent_version: ""
## Dependencies
None.
## Example Playbook
```yaml
- hosts: elastic-agent
roles:
- badsectorlabs.ludus_elastic_agent
role_vars:
- ludus_elastic_enrollment_token: "<TOKEN>"
- ludus_elastic_fleet_server: "https://<IP>:8220" #8220 by default
- ludus_elastic_agent_version: "8.12.2"
```
## Example Ludus Range Config
```yaml
ludus:
- vm_name: "{{ range_id }}-jumpbox01"
hostname: "{{ range_id }}-jumpbox01"
template: debian-12-x64-server-template
vlan: 20
ip_last_octet: 25
ram_gb: 4
cpus: 2
linux: true
testing:
snapshot: false
block_internet: false
roles:
- badsectorlabs.ludus_elastic_agent
role_vars:
- ludus_elastic_enrollment_token: "<TOKEN>"
- ludus_elastic_fleet_server: "https://<IP>:8220" #8220 by default
```
## Ludus setup
```
# Add the role to your ludus host
ludus ansible roles add badsectorlabs.ludus_elastic_agent
# Get your config into a file so you can assign to your VMs
ludus range config get > config.yml
# Edit config to add the role to the VMs you wish to make an elastic server
ludus range config set -f config.yml
# Deploy the range with the user-defined-roles ONLY :)
ludus range deploy -t user-defined-roles
```
## License
GPLv3
## Author Information
This role was created by [Bad Sector Labs](https://badsectorlabs.com/), for [Ludus](https://ludus.cloud/). PRs are welcomed.
+4
View File
@@ -0,0 +1,4 @@
---
ludus_elastic_enrollment_token: ""
ludus_elastic_fleet_server: ""
ludus_elastic_agent_version: "8.12.2"
+24
View File
@@ -0,0 +1,24 @@
---
dependencies: []
galaxy_info:
role_name: ludus_elastic_agent
author: badsectorlabs
description: Installs an Elastic Agent on a windows, debian or ubuntu target
company: Bad Sector Labs
license: GPLv3
min_ansible_version: "2.10"
platforms:
- name: Windows
versions:
- "all"
- name: Debian
versions:
- "buster"
- "bullseye"
- name: Ubuntu
versions:
- "focal"
- "bionic"
galaxy_tags:
- elastic-agent
+117
View File
@@ -0,0 +1,117 @@
---
- name: Stop the role if ludus_elastic_enrollment_token is not set
fail:
msg: "ludus_elastic_enrollment_token is not set. Please set it in the defaults/main.yml file."
when: ludus_elastic_enrollment_token == ""
- name: Check if Elastic agent bin exists on Ludus for Windows targets
stat:
path: "/opt/ludus/resources/windows/elastic-agent-{{ ludus_elastic_agent_version }}-windows-x86_64.zip"
register: windows_agent_exists
delegate_to: localhost
when: ansible_os_family == 'Windows'
- name: Check if Elastic agent bin exists on Ludus for Debian/Ubuntu Targets
stat:
path: "/opt/ludus/resources/linux/elastic-agent-{{ ludus_elastic_agent_version }}-linux-x86_64.tar.gz"
register: linux_agent_exists
delegate_to: localhost
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
- name: Download the Windows Elastic agent if it doesn't exist
ansible.builtin.get_url:
url: "https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-{{ ludus_elastic_agent_version }}-windows-x86_64.zip"
dest: "/opt/ludus/resources/windows/elastic-agent-{{ ludus_elastic_agent_version }}-windows-x86_64.zip"
mode: "0644"
delegate_to: localhost
when: ansible_os_family == 'Windows' and not windows_agent_exists.stat.exists
- name: Download the Linux Elastic agent if it doesn't exist
ansible.builtin.get_url:
url: "https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-{{ ludus_elastic_agent_version }}-linux-x86_64.tar.gz"
dest: "/opt/ludus/resources/linux/elastic-agent-{{ ludus_elastic_agent_version }}-linux-x86_64.tar.gz"
mode: "0644"
delegate_to: localhost
when: (ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu') and not linux_agent_exists.stat.exists
- name: Check if Ludus directory exists on Windows target
win_shell: Test-Path -Path "C:\\ludus"
register: windows_ludus_dir_exists
when: ansible_os_family == 'Windows'
- name: Check if Ludus directory exists on Linux target
stat:
path: "/opt/ludus"
register: linux_ludus_dir_exists
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
- name: Create Ludus directory on Windows target if it doesn't exist
win_shell: New-Item -Path "C:\\ludus" -ItemType Directory -Force
when: ansible_os_family == 'Windows' and windows_ludus_dir_exists.stdout == "False"
- name: Create Ludus directory on Linux target if it doesn't exist
file:
path: "/opt/ludus"
state: directory
when: (ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu') and not linux_ludus_dir_exists.stat.exists
- name: Copy Elastic agent to Windows target
win_copy:
src: "/opt/ludus/resources/windows/elastic-agent-{{ ludus_elastic_agent_version }}-windows-x86_64.zip"
dest: "C:\\ludus"
when: ansible_os_family == 'Windows'
- name: Copy Elastic agent to Linux target
copy:
src: "/opt/ludus/resources/linux/elastic-agent-{{ ludus_elastic_agent_version }}-linux-x86_64.tar.gz"
dest: "/opt/ludus"
mode: "0644"
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
- name: Uninstall Elastic agent if installed on Windows
ansible.windows.win_shell: "& 'C:\\Program Files\\Elastic\\Agent\\elastic-agent.exe' uninstall -f"
when: ansible_os_family == 'Windows'
ignore_errors: true
- name: Check if elastic-agent is installed on Linux
ansible.builtin.shell: 'if [ -f /usr/bin/elastic-agent ]; then echo true; fi'
register: elastic_agent_installed_linux
changed_when: elastic_agent_installed_linux.stdout == "true"
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
ignore_errors: true
- name: Uninstall Elastic agent if installed on Linux
ansible.builtin.shell: '/usr/bin/elastic-agent uninstall -f'
when: elastic_agent_installed_linux.stdout | default('false') == "true" and (ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu')
- name: Unzip Elastic agent on Windows target
ansible.windows.win_shell: "Expand-Archive -Path 'C:\\ludus\\elastic-agent-{{ ludus_elastic_agent_version }}-windows-x86_64.zip' -force -DestinationPath 'C:\\ludus'"
when: ansible_os_family == 'Windows'
- name: Remove existing Elastic agent directory
ansible.builtin.shell: 'rm -rf /opt/ludus/elastic-agent-{{ ludus_elastic_agent_version }}'
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
- name: Unzip Elastic agent on Linux target
ansible.builtin.shell: 'tar -xzf "/opt/ludus/elastic-agent-{{ ludus_elastic_agent_version }}-linux-x86_64.tar.gz" -C "/opt/ludus"'
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
- name: Install Elastic agent on Windows target
ansible.windows.win_shell: "C:\\ludus\\elastic-agent-{{ ludus_elastic_agent_version }}-windows-x86_64\\elastic-agent.exe install --url={{ ludus_elastic_fleet_server }} --enrollment-token={{ ludus_elastic_enrollment_token }} --force --insecure"
when: ansible_os_family == 'Windows'
- name: Remove existing Elastic Agent directory
ansible.builtin.file:
path: "/opt/Elastic/Agent"
state: absent
become: true
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
- name: Install Elastic agent on Linux target
ansible.builtin.command: "/opt/ludus/elastic-agent-{{ ludus_elastic_agent_version }}-linux-x86_64/elastic-agent install --url={{ ludus_elastic_fleet_server }} --enrollment-token={{ ludus_elastic_enrollment_token }} --force --insecure"
become: true
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
- name: Tell the user to check the Kibana Dashboard
debug:
msg: "Check the Kibana Dashboard for the status of the Elastic agent!"