S-28 · ClamAV (clamd) runs in compose and on the cluster #191

Closed
opened 2026-10-02 06:59:40 +00:00 by not · 0 comments
Contributor

Outcome: a ClamAV daemon (clamd) runs alongside the stack, in docker compose and in the Helm chart on the Talos cluster, with up-to-date signatures and a green health check.

Acceptance:

  • docker compose up starts a clamav service (official clamav/clamav, pinned tag) that turns healthy, with its signature DB on a named volume.
  • The Helm chart has a clamav workload with a readiness probe on clamd's port 3310 and a PVC for /var/lib/clamav; make k8s-drift stays green.
  • A verify check sends the EICAR test string to clamd over INSTREAM and expects FOUND, plus a clean payload that comes back OK.
  • Memory is capped (ConcurrentDatabaseReload no) so verify-stack stays within the runner's ceiling (#182).
  • ADR-0036 (from the ADR proposal) lands in this PR.

Touches: infra/docker-compose.yml, infra/helm/big-reference/values.yaml, infra/ verify script, docs/architecture/adr-0036-*.md, docs/runbooks/kubernetes-talos.md.

Out of scope: calling clamd from any service (next slice); on-access scanning; scanning files already stored in OpenZaak.

Definition of Done

  • This linked Gitea issue exists and is on the right milestone.
  • Failing test written and committed first (test(scope): … (refs #NN)).
  • Implementation makes the test pass (feat(scope): … (refs #NN)).
  • Refactor commit follows if structure improved.
  • Conventional Commit messages referencing this issue.
  • All Gitea Actions CI jobs green (or make ci green while no runner exists).
  • docker compose up from a fresh clone reaches green health checks within 3 minutes.
  • Docs touched if behaviour, contracts, or operations changed.
  • ADR added in docs/architecture/ if a non-obvious decision was made.
  • Demo note appended to docs/demo-script.md if the slice is user-visible.
  • This issue closed by the merging PR (closes #NN).
**Outcome:** a ClamAV daemon (clamd) runs alongside the stack, in `docker compose` and in the Helm chart on the Talos cluster, with up-to-date signatures and a green health check. **Acceptance:** - `docker compose up` starts a `clamav` service (official `clamav/clamav`, pinned tag) that turns healthy, with its signature DB on a named volume. - The Helm chart has a `clamav` workload with a readiness probe on clamd's port 3310 and a PVC for `/var/lib/clamav`; `make k8s-drift` stays green. - A verify check sends the EICAR test string to clamd over INSTREAM and expects `FOUND`, plus a clean payload that comes back `OK`. - Memory is capped (`ConcurrentDatabaseReload no`) so verify-stack stays within the runner's ceiling (#182). - ADR-0036 (from the ADR proposal) lands in this PR. **Touches:** `infra/docker-compose.yml`, `infra/helm/big-reference/values.yaml`, `infra/` verify script, `docs/architecture/adr-0036-*.md`, `docs/runbooks/kubernetes-talos.md`. **Out of scope:** calling clamd from any service (next slice); on-access scanning; scanning files already stored in OpenZaak. ## Definition of Done - [ ] This linked Gitea issue exists and is on the right milestone. - [ ] Failing test written and committed first (`test(scope): … (refs #NN)`). - [ ] Implementation makes the test pass (`feat(scope): … (refs #NN)`). - [ ] Refactor commit follows if structure improved. - [ ] Conventional Commit messages referencing this issue. - [ ] All Gitea Actions CI jobs green (or `make ci` green while no runner exists). - [ ] `docker compose up` from a fresh clone reaches green health checks within 3 minutes. - [ ] Docs touched if behaviour, contracts, or operations changed. - [ ] ADR added in `docs/architecture/` if a non-obvious decision was made. - [ ] Demo note appended to `docs/demo-script.md` if the slice is user-visible. - [ ] This issue closed by the merging PR (`closes #NN`).
not added this to the Iteration 6 — Production Posture milestone 2026-10-02 06:59:40 +00:00
not added the type:slicearea:infra labels 2026-10-02 06:59:42 +00:00
not closed this issue 2026-10-02 07:53:18 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: eho/register-referentie#191