Uninstalling the Wazuh Docker deployment

Follow these steps to uninstall your Wazuh Docker deployment from your Docker host:

Uninstalling single-node and multi-node deployment

Follow these steps to remove a single-node or multi-node deployment.

You need root user privileges to run the commands below. If you use Docker as a non-root user, run them with sudo.

  1. Navigate to the directory of your deployment, wazuh-docker/single-node/ or wazuh-docker/multi-node/. For example, for a single-node deployment:

    # cd wazuh-docker/single-node/
    
  2. Stop the stack and remove its containers. Choose one of the following commands:

    • To keep the data volumes, for example, to deploy the stack again later:

      # docker compose down
      
    • To delete the data volumes too, with your indexed data and the configuration each component stored:

      # docker compose down -v
      

      The -v flag permanently deletes the stack's named volumes, which are listed in the volumes section of wazuh-docker/single-node/docker-compose.yml or wazuh-docker/multi-node/docker-compose.yml. It also deletes any custom volume you added to that section.

  3. Remove the generated files, including the certificates and the passwords of the deployment in config/credentials/:

    # rm -rf wazuh-certificates/ wazuh-certificates-tool.log config.yml wazuh-certs-tool.sh wazuh-credentials.sh config/*/certs config/credentials
    

    If you kept the volumes in step 2, keep config/credentials/ too. The volumes hold the passwords from these files, and the files are the only record of them.

  4. Optional: remove the root CA. The certificate creation script keeps the root CA and its private key in /etc/wazuh/ca. The steps above do not remove them. The next run of the script on this host reuses them. Remove them only if you deleted the volumes in step 2 and no other Wazuh deployment on this host uses them:

    # rm -rf /etc/wazuh/ca
    
  5. Optional: remove the images of the stack. For a single-node deployment:

    # docker image rm wazuh/wazuh-manager:5.0.0-rc1 wazuh/wazuh-indexer:5.0.0-rc1 wazuh/wazuh-dashboard:5.0.0-rc1
    

    A multi-node deployment also uses the nginx:stable image. Add it to the command unless another container on this host uses it. If you upgraded the deployment, use the tags in wazuh-docker/single-node/docker-compose.yml or wazuh-docker/multi-node/docker-compose.yml.

  6. Run the following command to confirm that the deployment's containers are removed:

    # docker ps
    

    The output no longer lists any container whose name starts with single-node- or multi-node-. A Wazuh agent container on this host still appears until you remove it. See Uninstalling the Wazuh agent deployment.

Uninstalling the Wazuh agent deployment

Follow these steps to remove a Wazuh agent container deployment.

You need root user privileges to run the commands below. If you use Docker as a non-root user, run them with sudo.

  1. Navigate to the Wazuh agent directory, wazuh-docker/wazuh-agent/:

    • From the directory where you cloned the Wazuh Docker repository:

      # cd wazuh-docker/wazuh-agent
      
    • From wazuh-docker/single-node/ or wazuh-docker/multi-node/, for example, after you remove the stack on the same host:

      # cd ../wazuh-agent
      
  2. Stop and remove the Wazuh agent stack and its wazuh_agent_etc volume, which holds the Wazuh agent enrollment:

    # docker compose down -v
    

    Restore the docker-compose.yml file, which still holds the enrollment token:

    # git checkout docker-compose.yml
    
  3. Run the following command to confirm that the Wazuh agent container is removed:

    # docker ps
    

    The output no longer lists the wazuh-agent-wazuh.agent-1 container.

  4. Optional: remove the Wazuh agent image:

    # docker image rm wazuh/wazuh-agent:5.0.0-rc1