build(infra): run clamd in the local compose stack too (refs #191)
CI / k8s (pull_request) Successful in 8s
CI / build (pull_request) Successful in 1m41s
CI / lint (pull_request) Successful in 1m53s
CI / docs (pull_request) Successful in 55s
CI / unit (pull_request) Successful in 1m22s
CI / frontend (pull_request) Successful in 2m31s
CI / verify-stack (pull_request) Canceled after 0s
CI / mutation (pull_request) Canceled after 8m0s

make local waits on the same WAIT_SVCS, so without it the local stack never
turns healthy.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-10-02 09:23:50 +02:00
co-authored by Claude Opus 5.5
parent f541254de7
commit d698267fba
2 changed files with 22 additions and 1 deletions
+21
View File
@@ -751,6 +751,26 @@ services:
condition: service_completed_successfully
networks: [cg]
# ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM
# protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of
# signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory
# (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents
# that, at the cost of clamd pausing scans during a signature reload.
clamav:
image: docker.io/clamav/clamav:1.4.6
environment:
CLAMD_CONF_ConcurrentDatabaseReload: "no"
# The image's own healthcheck (clamdcheck.sh: PING → PONG) polls every 30s; poll faster so
# wait-healthy sees it as soon as the signatures are loaded.
healthcheck:
test: ["CMD-SHELL", "clamdcheck.sh"]
interval: 5s
start_period: 360s
mem_limit: 2g
volumes:
- clamav-db:/var/lib/clamav
networks: [cg]
volumes:
oz-db:
nrc-db:
@@ -758,6 +778,7 @@ volumes:
projection-db:
objecttypen-db:
objecten-db:
clamav-db:
# Carries the seed-generated acl.env (server-assigned zaaktype URLs) from local-seed to the ACL.
seed-env:
+1 -1
View File
@@ -788,7 +788,7 @@ services:
# ClamAV daemon (S-28, ADR-0036): the domain scans uploaded diplomas over clamd's INSTREAM
# protocol on :3310 before they reach OpenZaak (S-29). The first start downloads ~300 MB of
# signatures with freshclam; the volume keeps them across restarts. clamd holds them in memory
# (~1.2 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents
# (~1 GB), and a reload would briefly hold two copies — ConcurrentDatabaseReload off prevents
# that, at the cost of clamd pausing scans during a signature reload.
clamav:
image: docker.io/clamav/clamav:1.4.6