From d698267fba772f5b3d568ea9be4a215bd367fa8b Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Fri, 2 Oct 2026 09:23:50 +0200 Subject: [PATCH] build(infra): run clamd in the local compose stack too (refs #191) make local waits on the same WAIT_SVCS, so without it the local stack never turns healthy. Co-Authored-By: Claude Opus 5.5 (1M context) --- infra/docker-compose.local.yml | 21 +++++++++++++++++++++ infra/docker-compose.yml | 2 +- 2 files changed, 22 insertions(+), 1 deletion(-) diff --git a/infra/docker-compose.local.yml b/infra/docker-compose.local.yml index c90de0b..2e7fdba 100644 --- a/infra/docker-compose.local.yml +++ b/infra/docker-compose.local.yml @@ -751,6 +751,26 @@ services: condition: service_completed_successfully networks: [cg] + # ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM + # protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of + # signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory + # (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents + # that, at the cost of clamd pausing scans during a signature reload. + clamav: + image: docker.io/clamav/clamav:1.4.6 + environment: + CLAMD_CONF_ConcurrentDatabaseReload: "no" + # The image's own healthcheck (clamdcheck.sh: PING → PONG) polls every 30s; poll faster so + # wait-healthy sees it as soon as the signatures are loaded. + healthcheck: + test: ["CMD-SHELL", "clamdcheck.sh"] + interval: 5s + start_period: 360s + mem_limit: 2g + volumes: + - clamav-db:/var/lib/clamav + networks: [cg] + volumes: oz-db: nrc-db: @@ -758,6 +778,7 @@ volumes: projection-db: objecttypen-db: objecten-db: + clamav-db: # Carries the seed-generated acl.env (server-assigned zaaktype URLs) from local-seed to the ACL. seed-env: diff --git a/infra/docker-compose.yml b/infra/docker-compose.yml index c528455..f737d9f 100644 --- a/infra/docker-compose.yml +++ b/infra/docker-compose.yml @@ -788,7 +788,7 @@ services: # ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM # protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of # signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory - # (~1.2 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents + # (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents # that, at the cost of clamd pausing scans during a signature reload. clamav: image: docker.io/clamav/clamav:1.4.6