build(infra): run ClamAV in compose and on the cluster (closes #191) (#193)
Deploy to Talos / deploy (push) Successful in 2m40s
CI / k8s (push) Successful in 1m23s
CI / build (push) Successful in 4m55s
CI / lint (push) Successful in 6m25s
CI / unit (push) Successful in 1m6s
CI / docs (push) Successful in 1m22s
CI / frontend (push) Successful in 2m44s
CI / mutation (push) Successful in 4m22s
CI / verify-stack (push) Successful in 21m56s
Deploy to Talos / deploy (push) Successful in 2m40s
CI / k8s (push) Successful in 1m23s
CI / build (push) Successful in 4m55s
CI / lint (push) Successful in 6m25s
CI / unit (push) Successful in 1m6s
CI / docs (push) Successful in 1m22s
CI / frontend (push) Successful in 2m44s
CI / mutation (push) Successful in 4m22s
CI / verify-stack (push) Successful in 21m56s
Runs a ClamAV daemon (clamav/clamav:1.4.6) in both compose stacks and the Helm chart, health-gated, with a verify-clamav check (EICAR found, clean OK) in verify-stack. ADR-0036 records the scan-in-domain, fail-closed decision (#190). closes #191 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit was merged in pull request #193.
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
#!/usr/bin/env python3
|
||||
"""S-28 (#191): prove clamd is up, has signatures loaded, and scans a stream over INSTREAM.
|
||||
|
||||
The EICAR test file must come back FOUND and a clean payload OK — the same protocol the domain's
|
||||
scanner adapter will speak (ADR-0036). EICAR is assembled from two halves so this file itself is
|
||||
not flagged by an on-access scanner on a developer laptop. Stdlib only (python:3-slim).
|
||||
"""
|
||||
import os
|
||||
import socket
|
||||
import struct
|
||||
import sys
|
||||
import time
|
||||
|
||||
HOST = os.environ["CLAMAV"]
|
||||
TIMEOUT = int(os.environ.get("CLAMAV_TIMEOUT", "60"))
|
||||
EICAR = (r"X5O!P%@AP[4\PZX54(P^)7CC)7}$" + r"EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*").encode()
|
||||
|
||||
|
||||
def instream(payload):
|
||||
with socket.create_connection((HOST, 3310), timeout=30) as s:
|
||||
s.sendall(b"zINSTREAM\0" + struct.pack(">I", len(payload)) + payload + struct.pack(">I", 0))
|
||||
return s.recv(4096).rstrip(b"\0").decode()
|
||||
|
||||
|
||||
deadline = time.time() + TIMEOUT
|
||||
while True:
|
||||
try:
|
||||
clean, infected = instream(b"%PDF-1.4 clean"), instream(EICAR)
|
||||
break
|
||||
except OSError as e:
|
||||
if time.time() > deadline:
|
||||
sys.exit(f"FAIL: clamd at {HOST}:3310 unreachable: {e}")
|
||||
time.sleep(3)
|
||||
|
||||
print(f"clean → {clean!r}; eicar → {infected!r}")
|
||||
if clean != "stream: OK":
|
||||
sys.exit("FAIL: clean payload was not reported OK")
|
||||
if not infected.endswith("FOUND"):
|
||||
sys.exit("FAIL: EICAR was not detected")
|
||||
print("OK: clamd detects EICAR and passes a clean stream")
|
||||
@@ -751,6 +751,26 @@ services:
|
||||
condition: service_completed_successfully
|
||||
networks: [cg]
|
||||
|
||||
# ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM
|
||||
# protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of
|
||||
# signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory
|
||||
# (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents
|
||||
# that, at the cost of clamd pausing scans during a signature reload.
|
||||
clamav:
|
||||
image: docker.io/clamav/clamav:1.4.6
|
||||
environment:
|
||||
CLAMD_CONF_ConcurrentDatabaseReload: "no"
|
||||
# The image's own healthcheck (clamdcheck.sh: PING → PONG) polls every 30s; poll faster so
|
||||
# wait-healthy sees it as soon as the signatures are loaded.
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "clamdcheck.sh"]
|
||||
interval: 5s
|
||||
start_period: 360s
|
||||
mem_limit: 2g
|
||||
volumes:
|
||||
- clamav-db:/var/lib/clamav
|
||||
networks: [cg]
|
||||
|
||||
volumes:
|
||||
oz-db:
|
||||
nrc-db:
|
||||
@@ -758,6 +778,7 @@ volumes:
|
||||
projection-db:
|
||||
objecttypen-db:
|
||||
objecten-db:
|
||||
clamav-db:
|
||||
# Carries the seed-generated acl.env (server-assigned zaaktype URLs) from local-seed to the ACL.
|
||||
seed-env:
|
||||
|
||||
|
||||
@@ -785,6 +785,26 @@ services:
|
||||
condition: service_completed_successfully
|
||||
networks: [cg]
|
||||
|
||||
# ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM
|
||||
# protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of
|
||||
# signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory
|
||||
# (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents
|
||||
# that, at the cost of clamd pausing scans during a signature reload.
|
||||
clamav:
|
||||
image: docker.io/clamav/clamav:1.4.6
|
||||
environment:
|
||||
CLAMD_CONF_ConcurrentDatabaseReload: "no"
|
||||
# The image's own healthcheck (clamdcheck.sh: PING → PONG) polls every 30s; poll faster so
|
||||
# wait-healthy sees it as soon as the signatures are loaded.
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "clamdcheck.sh"]
|
||||
interval: 5s
|
||||
start_period: 360s
|
||||
mem_limit: 2g
|
||||
volumes:
|
||||
- clamav-db:/var/lib/clamav
|
||||
networks: [cg]
|
||||
|
||||
# ── Observability backplane (S-16a, ADR-0023) ──────────────────────────────
|
||||
# Grafana-native stack: Tempo ingests OTLP traces (the .NET services export
|
||||
# straight to it — no collector hop, S-16b), Prometheus scrapes service
|
||||
@@ -836,6 +856,7 @@ volumes:
|
||||
projection-db:
|
||||
objecttypen-db:
|
||||
objecten-db:
|
||||
clamav-db:
|
||||
# Config volumes — created and populated out-of-band by infra/seed-config.sh
|
||||
# (docker cp), because bind mounts don't reach sibling containers on the CI
|
||||
# runner. `external` keeps the names deterministic; the seed step manages them.
|
||||
|
||||
@@ -588,6 +588,24 @@ workloads:
|
||||
envFrom: [objecten]
|
||||
waitFor: [objecten-db:5432, objecten-redis:6379]
|
||||
|
||||
# ── ClamAV (S-28, ADR-0036) ─────────────────────────────────────────────────
|
||||
# The domain scans uploaded diplomas over clamd's INSTREAM protocol (S-29).
|
||||
# First start pulls ~300 MB of signatures, so the node needs outbound internet
|
||||
# (like seed-zaaktype); the data volume keeps them when persistence is on.
|
||||
clamav:
|
||||
image: docker.io/clamav/clamav:1.4.6
|
||||
env:
|
||||
CLAMD_CONF_ConcurrentDatabaseReload: "no"
|
||||
ports: [{ name: clamd, port: 3310 }]
|
||||
data: { mountPath: /var/lib/clamav, size: 1Gi }
|
||||
probe:
|
||||
exec: { command: [clamdcheck.sh] }
|
||||
periodSeconds: 5
|
||||
failureThreshold: 72
|
||||
resources:
|
||||
requests: { memory: 1200Mi }
|
||||
limits: { memory: 2Gi }
|
||||
|
||||
# ── Bootstrap the flow, like the local compose stack does (S-B04, ADR-0020) ──
|
||||
# Seeds + publishes the BIG zaaktype through the same FQDN the ACL uses, so the
|
||||
# server-assigned URLs are host-consistent. The ACL then resolves them by
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# S-28 (#191): assert clamd scans over INSTREAM (EICAR → FOUND, clean → OK), against an
|
||||
# ALREADY-RUNNING stack. Runs the check in a python:3-slim container on the stack network (the
|
||||
# runner can't reach published ports — gitea-actions-gotchas.md §5/§6).
|
||||
set -euo pipefail
|
||||
|
||||
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
|
||||
av="$(docker ps -q --filter 'name=[-_]clamav[-_][0-9]+$' | head -1)"
|
||||
[ -n "$av" ] || { echo "ERROR: no running clamav container — bring the stack up first" >&2; exit 1; }
|
||||
net="$(docker inspect -f '{{range $k,$_ := .NetworkSettings.Networks}}{{$k}}{{"\n"}}{{end}}' "$av" | head -1)"
|
||||
ip="$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$av")"
|
||||
echo ">> network=$net clamav=$ip"
|
||||
|
||||
cid="$(docker create --network "$net" -e "CLAMAV=$ip" -e "CLAMAV_TIMEOUT=${CLAMAV_TIMEOUT:-60}" \
|
||||
python:3-slim python /clamav-check.py)"
|
||||
docker cp "$here/clamav-check.py" "$cid:/clamav-check.py" >/dev/null
|
||||
rc=0; docker start -a "$cid" || rc=$?
|
||||
docker rm -f "$cid" >/dev/null
|
||||
exit $rc
|
||||
Reference in New Issue
Block a user