build(infra): run ClamAV in compose and on the cluster (closes #191) #193

Merged
not merged 5 commits from build/191-clamav into main 2026-10-02 07:53:17 +00:00
2 changed files with 22 additions and 1 deletions
Showing only changes of commit d698267fba - Show all commits
+21
View File
@@ -751,6 +751,26 @@ services:
condition: service_completed_successfully condition: service_completed_successfully
networks: [cg] networks: [cg]
# ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM
# protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of
# signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory
# (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents
# that, at the cost of clamd pausing scans during a signature reload.
clamav:
image: docker.io/clamav/clamav:1.4.6
environment:
CLAMD_CONF_ConcurrentDatabaseReload: "no"
# The image's own healthcheck (clamdcheck.sh: PING → PONG) polls every 30s; poll faster so
# wait-healthy sees it as soon as the signatures are loaded.
healthcheck:
test: ["CMD-SHELL", "clamdcheck.sh"]
interval: 5s
start_period: 360s
mem_limit: 2g
volumes:
- clamav-db:/var/lib/clamav
networks: [cg]
volumes: volumes:
oz-db: oz-db:
nrc-db: nrc-db:
@@ -758,6 +778,7 @@ volumes:
projection-db: projection-db:
objecttypen-db: objecttypen-db:
objecten-db: objecten-db:
clamav-db:
# Carries the seed-generated acl.env (server-assigned zaaktype URLs) from local-seed to the ACL. # Carries the seed-generated acl.env (server-assigned zaaktype URLs) from local-seed to the ACL.
seed-env: seed-env:
+1 -1
View File
@@ -788,7 +788,7 @@ services:
# ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM # ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM
# protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of # protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of
# signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory # signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory
# (~1.2 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents # (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents
# that, at the cost of clamd pausing scans during a signature reload. # that, at the cost of clamd pausing scans during a signature reload.
clamav: clamav:
image: docker.io/clamav/clamav:1.4.6 image: docker.io/clamav/clamav:1.4.6