Runs a ClamAV daemon next to the stack, so the domain can scan uploaded diplomas in #192. Records the decision in ADR-0036 (#190).
clamav service (official clamav/clamav:1.4.6) in compose and the Helm chart. Signatures live on a volume, ConcurrentDatabaseReload no keeps a reload from doubling memory, compose caps it at 2g and the chart requests 1200Mi. It is in WAIT_SVCS.
make verify-clamav / CI verify-stack step: over INSTREAM, EICAR comes back FOUND and a clean stream OK.
ADR-0036 and a runbook row for slow or throttled signature downloads.
Dependency justification (§13): clamd gives us a maintained signature engine with daily updates. Replacing it would mean a commercial scanning API, or nothing. Risks: about 1 GB more RAM on the verify runner (#182), and the first start needs outbound internet to the ClamAV CDN, which rate-limits by IP.
Verified locally:docker compose up clamav was healthy in 12s (about 950 MiB), verify-clamav passed, k8s-lint and k8s-drift are green. Not run: the full verify-stack, which runs only on main (#184), and mkdocs build --strict, since mkdocs isn't installed locally.
Runs a ClamAV daemon next to the stack, so the domain can scan uploaded diplomas in #192. Records the decision in ADR-0036 (#190).
- `clamav` service (official `clamav/clamav:1.4.6`) in compose and the Helm chart. Signatures live on a volume, `ConcurrentDatabaseReload no` keeps a reload from doubling memory, compose caps it at 2g and the chart requests 1200Mi. It is in `WAIT_SVCS`.
- `make verify-clamav` / CI verify-stack step: over INSTREAM, EICAR comes back `FOUND` and a clean stream `OK`.
- ADR-0036 and a runbook row for slow or throttled signature downloads.
**Dependency justification (§13):** clamd gives us a maintained signature engine with daily updates. Replacing it would mean a commercial scanning API, or nothing. Risks: about 1 GB more RAM on the verify runner (#182), and the first start needs outbound internet to the ClamAV CDN, which rate-limits by IP.
**Verified locally:** `docker compose up clamav` was healthy in 12s (about 950 MiB), `verify-clamav` passed, `k8s-lint` and `k8s-drift` are green. Not run: the full verify-stack, which runs only on main (#184), and `mkdocs build --strict`, since mkdocs isn't installed locally.
closes #191
🤖 Generated with [Claude Code](https://claude.com/claude-code)
not
added this to the Iteration 6 — Production Posture milestone 2026-10-02 07:03:11 +00:00
Official clamav/clamav:1.4.6 with signatures on a volume, ConcurrentDatabaseReload
off to cap memory, health-gated in WAIT_SVCS. verify-clamav is green: EICAR is
FOUND, a clean stream is OK.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
make local waits on the same WAIT_SVCS, so without it the local stack never
turns healthy.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
clamd matches EICAR only at the start of a file, so a type check in front of
the scan would report malware as merely not-a-PDF.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Runs a ClamAV daemon next to the stack, so the domain can scan uploaded diplomas in #192. Records the decision in ADR-0036 (#190).
clamavservice (officialclamav/clamav:1.4.6) in compose and the Helm chart. Signatures live on a volume,ConcurrentDatabaseReload nokeeps a reload from doubling memory, compose caps it at 2g and the chart requests 1200Mi. It is inWAIT_SVCS.make verify-clamav/ CI verify-stack step: over INSTREAM, EICAR comes backFOUNDand a clean streamOK.Dependency justification (§13): clamd gives us a maintained signature engine with daily updates. Replacing it would mean a commercial scanning API, or nothing. Risks: about 1 GB more RAM on the verify runner (#182), and the first start needs outbound internet to the ClamAV CDN, which rate-limits by IP.
Verified locally:
docker compose up clamavwas healthy in 12s (about 950 MiB),verify-clamavpassed,k8s-lintandk8s-driftare green. Not run: the full verify-stack, which runs only on main (#184), andmkdocs build --strict, since mkdocs isn't installed locally.closes #191
🤖 Generated with Claude Code