build(infra): run clamd in compose and the Helm chart (refs #191)

Official clamav/clamav:1.4.6 with signatures on a volume, ConcurrentDatabaseReload
off to cap memory, health-gated in WAIT_SVCS. verify-clamav is green: EICAR is
FOUND, a clean stream is OK.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-10-02 09:02:57 +02:00
co-authored by Claude Opus 5.5
parent 3e9bda9031
commit 39bc6ee0c5
4 changed files with 41 additions and 2 deletions
+18
View File
@@ -588,6 +588,24 @@ workloads:
envFrom: [objecten]
waitFor: [objecten-db:5432, objecten-redis:6379]
# ── ClamAV (S-28, ADR-0036) ─────────────────────────────────────────────────
# The domain scans uploaded diplomas over clamd's INSTREAM protocol (S-29).
# First start pulls ~300 MB of signatures, so the node needs outbound internet
# (like seed-zaaktype); the data volume keeps them when persistence is on.
clamav:
image: docker.io/clamav/clamav:1.4.6
env:
CLAMD_CONF_ConcurrentDatabaseReload: "no"
ports: [{ name: clamd, port: 3310 }]
data: { mountPath: /var/lib/clamav, size: 1Gi }
probe:
exec: { command: [clamdcheck.sh] }
periodSeconds: 5
failureThreshold: 72
resources:
requests: { memory: 1200Mi }
limits: { memory: 2Gi }
# ── Bootstrap the flow, like the local compose stack does (S-B04, ADR-0020) ──
# Seeds + publishes the BIG zaaktype through the same FQDN the ACL uses, so the
# server-assigned URLs are host-consistent. The ACL then resolves them by