Compare commits

...

41 Commits

Author SHA1 Message Date
Jenkins Server
d8143691dd Recommit for updates in build 18 2026-09-22 15:17:48 +02:00
Jenkins Server
4356c549db Merge remote-tracking branch 'origin/master' into jenkins-build-18 2026-09-22 15:16:53 +02:00
9792e3c268 OP#785 revert 2026-09-22 15:16:36 +02:00
Jenkins Server
170e087a3c Recommit for updates in build 17 2026-09-22 15:03:41 +02:00
Jenkins Server
e65c98a16e Merge remote-tracking branch 'origin/master' into jenkins-build-17 2026-09-22 15:03:02 +02:00
5e3dcbbd1b OP#785 temp disable service file control 2026-09-22 15:02:45 +02:00
Jenkins Server
ec9f3674f2 Merge remote-tracking branch 'origin/master' into jenkins-build-16 2026-09-22 14:59:32 +02:00
ab50ce82f2 OP#785 switch MemoryLimit to MemoryMax 2026-09-22 14:59:17 +02:00
Jenkins Server
bda2cfda73 Merge remote-tracking branch 'origin/master' into jenkins-build-15 2026-09-22 14:31:17 +02:00
dfb9601a5d OP#785 switch MemoryLimit to MemoryMax 2026-09-22 14:30:56 +02:00
Jenkins Server
3e0ccc94d0 Recommit for updates in build 14 2026-09-22 14:10:46 +02:00
Jenkins Server
ca315d9f4e Merge remote-tracking branch 'origin/master' into jenkins-build-14 2026-09-22 14:10:06 +02:00
dfd2cba657 OP#785 add variables for clamd service limits 2026-09-22 14:00:02 +02:00
Jenkins Server
63540d9d22 Recommit for updates in build 12 2026-09-22 13:55:53 +02:00
Jenkins Server
97de17ae32 Merge remote-tracking branch 'origin/master' into jenkins-build-12 2026-09-22 13:55:16 +02:00
d0dc4b2fc8 OP#785 add variables for clamd service limits 2026-09-22 13:55:00 +02:00
Jenkins Server
5c456b4c30 Recommit for updates in build 11 2026-09-22 13:54:05 +02:00
Jenkins Server
4543a31013 Merge remote-tracking branch 'origin/master' into jenkins-build-11 2026-09-22 13:53:26 +02:00
dd1a1478ff OP#785 add variables for clamd service limits 2026-09-22 13:53:05 +02:00
Jenkins Server
2b3fee4c2b Recommit for updates in build 10 2026-09-22 13:40:54 +02:00
Jenkins Server
3da895df4d Merge remote-tracking branch 'origin/master' into jenkins-build-10 2026-09-22 13:40:16 +02:00
beea16b8c4 OP#785 update Readme 2026-09-22 13:39:48 +02:00
Jenkins Server
234821e921 Recommit for updates in build 9 2026-09-22 13:39:15 +02:00
Jenkins Server
5a1c95427c Merge remote-tracking branch 'origin/master' into jenkins-build-9 2026-09-22 13:38:36 +02:00
8e32d2ad32 OP#785 add control for clamd service config file 2026-09-22 13:38:17 +02:00
66173a7573 OP#785 add control for clamd service config file 2026-09-22 13:37:25 +02:00
Jenkins Server
5d46317b6a Recommit for updates in build 8 2026-09-22 13:17:45 +02:00
Jenkins Server
442e9070c9 Merge remote-tracking branch 'origin/master' into jenkins-build-8 2026-09-22 13:17:06 +02:00
905676c71a OP#785 fix syntax 2026-09-22 13:16:48 +02:00
Jenkins Server
f9ae014080 Recommit for updates in build 7 2026-09-22 13:15:32 +02:00
Jenkins Server
f653fadbba Merge remote-tracking branch 'origin/master' into jenkins-build-7 2026-09-22 13:14:51 +02:00
e8f292967e OP#785 add ConcurrentDatabaseReload option 2026-09-22 13:14:33 +02:00
Jenkins Server
164673a5ba Merge remote-tracking branch 'origin/master' into jenkins-build-6 2026-09-22 12:57:31 +02:00
5cf60685b7 OP#785 add newline 2026-09-22 12:57:15 +02:00
Jenkins Server
d63385552a Merge remote-tracking branch 'origin/master' into jenkins-build-5 2026-09-22 12:52:36 +02:00
0b24fcdb8e OP#785 move to clamdscan command 2026-09-22 12:52:19 +02:00
Jenkins Server
b600b953ec Recommit for updates in build 4 2026-09-22 12:46:07 +02:00
Jenkins Server
deb6f938ae Merge remote-tracking branch 'origin/master' into jenkins-build-4 2026-09-22 12:45:26 +02:00
7f20c0e45e OP#785 add excludepaths and option to use it 2026-09-22 12:45:06 +02:00
2d3304abac OP#785 fix heading 2026-09-22 12:18:50 +02:00
Jenkins Server
048c910a4b Recommit for updates in build 3 2026-09-22 12:14:50 +02:00
14 changed files with 334 additions and 279 deletions

55
.vscode/settings.json vendored
View File

@@ -1,55 +0,0 @@
{
"cSpell.words": [
"ALLMATCHSCAN",
"authenticode",
"behaviour",
"bofh",
"clamav",
"clamd",
"clamdscan",
"clamonacc",
"clamscan",
"Clamuko",
"clamupdate",
"Dazuko",
"dbname",
"epel",
"fanotify",
"filesize",
"freshclam",
"getsebool",
"INADDR",
"libclamav",
"logclean",
"logfacility",
"logfile",
"logfilemaxsize",
"logfileunlock",
"logrotation",
"logsyslog",
"logtime",
"logverbose",
"mypass",
"myproxy",
"myusername",
"NOFILE",
"normalisation",
"PCRE",
"preludeanalyzername",
"preludeenable",
"recieve",
"RLIMIT",
"safebrowsing",
"setsebool",
"subsig",
"subsigs",
"tcpaddre",
"tcpaddress",
"tcpsocket",
"VIRUSEVENT",
"virusgroup",
"VIRUSNAME",
"XMLDOCS",
"xxxyyzzzz"
]
}

128
Jenkinsfile vendored
View File

@@ -1,128 +0,0 @@
pipeline {
agent {
label 'puppet'
}
post {
always {
deleteDir() /* clean up our workspace */
}
success {
updateGitlabCommitStatus state: 'success'
}
failure {
updateGitlabCommitStatus state: 'failed'
step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true])
}
}
options {
gitLabConnection('gitlab.confdroid.com')
}
stages {
stage('pull master') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
sh '''
git config user.name "Jenkins Server"
git config user.email jenkins@confdroid.com
# Ensure we're on the development branch (triggered by push)
git checkout development
# Create jenkins branch from development
git checkout -b jenkins-build-$BUILD_NUMBER
# Optionally merge master into jenkins to ensure compatibility
git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; }
'''
}
}
}
stage('puppet parser') {
steps {
sh '''for file in $(find . -iname \'*.pp\'); do
/opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1;
done;'''
}
}
stage('check templates') {
steps{
sh '''for file in $(find . -iname \'*.erb\');
do erb -P -x -T "-" $file | ruby -c || exit 1;
done;'''
}
}
stage('puppet-lint') {
steps {
sh '''/usr/local/bin/puppet-lint . \\
--no-variable_scope-check \\
|| { echo "Puppet lint failed"; exit 1; }
'''
}
}
stage('SonarScan') {
steps {
withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) {
sh '''
/opt/sonar-scanner/bin/sonar-scanner \
-Dsonar.projectKey=confdroid_clamav \
-Dsonar.sources=. \
-Dsonar.host.url=https://sonarqube.confdroid.com \
-Dsonar.token=$SONAR_TOKEN
'''
}
}
}
stage('create Puppet documentation') {
steps {
sh '/opt/puppetlabs/bin/puppet strings'
}
}
stage('update repo') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
sh '''
git config user.name "Jenkins Server"
git config user.email jenkins@confdroid.com
git rm -r --cached .vscode || echo "No .vscode to remove from git"
git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit"
git push origin HEAD:master
'''
}
}
}
stage('Mirror to Gitea') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
withCredentials([usernamePassword(
credentialsId: 'Jenkins-gitea',
usernameVariable: 'GITEA_USER',
passwordVariable: 'GITEA_TOKEN')]) {
script {
// Checkout from GitLab (already done implicitly)
sh '''
git checkout master
git pull origin master
git branch -D development
git branch -D jenkins-build-$BUILD_NUMBER
git rm -f Jenkinsfile
git rm -r --cached .vscode || echo "No .vscode to remove from git"
git commit --amend --no-edit --allow-empty
git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_clamav.git
git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \
push master --mirror
'''
}
}
}
}
}
}
}

View File

@@ -9,7 +9,7 @@
- [WARNING](#warning)
- [Features](#features)
- [Dependencies](#dependencies)
- [Deployment](#deployment)
- [Deployment](#deployment)
- [Parameters](#parameters)
- [SELINUX](#selinux)
- [Support](#support)
@@ -33,7 +33,8 @@
- manage required config files
- manage cronjob settings via parameters
- run cron job to scan the file system (by default starting at root, configurable) via clamdscan
- manage services
- set ConcurrentDatabaseReload option `yes`/`no` to optimize RAM consumption. defaults to `no`
- manage `freshclam` and `clamd` services
## Dependencies
@@ -41,7 +42,7 @@ All dependencies must be included in the catalogue.
- [confdroid_resources](https://sourcecode.confdroid.com/confdroid/confdroid_resources) for managing yum repo resources.
### Deployment
## Deployment
- native Puppet deployment

View File

@@ -60,9 +60,7 @@
<div id="content"><div id='filecontents'>
<h1 id="label-Readme">Readme</h1>
<p><a href="https://jenkins.confdroid.com/job/confdroid_clamav/"><img src="https://jenkins.confdroid.com/buildStatus/icon?job=confdroid_clamav&amp;style=plastic"></a></p>
<p><a href="https://deepwiki.com/grizzlycoda/puppet_collection"><img src="https://deepwiki.com/badge.svg"></a></p>
<p><a href="https://jenkins.confdroid.com/job/confdroid_clamav/"><img src="https://jenkins.confdroid.com/buildStatus/icon?job=confdroid_clamav&amp;style=plastic"></a> <a href="https://sonarqube.confdroid.com/dashboard?id=confdroid_clamav"><img src="https://sonarqube.confdroid.com/api/project_badges/measure?project=confdroid_clamav&amp;metric=security_hotspots&amp;token=sqb_cdcd204545668e8367aed118aa87ad814b58863b"></a> <a href="https://deepwiki.com/grizzlycoda/puppet_collection"><img src="https://deepwiki.com/badge.svg"></a></p>
<ul><li>
<p><a href="#readme">Readme</a></p>
</li><li>
@@ -73,9 +71,8 @@
<p><a href="#features">Features</a></p>
</li><li>
<p><a href="#dependencies">Dependencies</a></p>
<ul><li>
</li><li>
<p><a href="#deployment">Deployment</a></p>
</li></ul>
</li><li>
<p><a href="#parameters">Parameters</a></p>
</li><li>
@@ -110,7 +107,9 @@
</li><li>
<p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p>
</li><li>
<p>manage services</p>
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p>
</li><li>
<p>manage <code>freshclam</code> and <code>clamd</code> services</p>
</li></ul>
<h2 id="label-Dependencies">Dependencies</h2>
@@ -120,7 +119,7 @@
<p><a href="https://sourcecode.confdroid.com/confdroid/confdroid_resources">confdroid_resources</a> for managing yum repo resources.</p>
</li></ul>
<h3 id="label-Deployment">Deployment</h3>
<h2 id="label-Deployment">Deployment</h2>
<ul><li>
<p>native Puppet deployment</p>
</li></ul>

View File

@@ -60,9 +60,7 @@
<div id="content"><div id='filecontents'>
<h1 id="label-Readme">Readme</h1>
<p><a href="https://jenkins.confdroid.com/job/confdroid_clamav/"><img src="https://jenkins.confdroid.com/buildStatus/icon?job=confdroid_clamav&amp;style=plastic"></a></p>
<p><a href="https://deepwiki.com/grizzlycoda/puppet_collection"><img src="https://deepwiki.com/badge.svg"></a></p>
<p><a href="https://jenkins.confdroid.com/job/confdroid_clamav/"><img src="https://jenkins.confdroid.com/buildStatus/icon?job=confdroid_clamav&amp;style=plastic"></a> <a href="https://sonarqube.confdroid.com/dashboard?id=confdroid_clamav"><img src="https://sonarqube.confdroid.com/api/project_badges/measure?project=confdroid_clamav&amp;metric=security_hotspots&amp;token=sqb_cdcd204545668e8367aed118aa87ad814b58863b"></a> <a href="https://deepwiki.com/grizzlycoda/puppet_collection"><img src="https://deepwiki.com/badge.svg"></a></p>
<ul><li>
<p><a href="#readme">Readme</a></p>
</li><li>
@@ -73,9 +71,8 @@
<p><a href="#features">Features</a></p>
</li><li>
<p><a href="#dependencies">Dependencies</a></p>
<ul><li>
</li><li>
<p><a href="#deployment">Deployment</a></p>
</li></ul>
</li><li>
<p><a href="#parameters">Parameters</a></p>
</li><li>
@@ -110,7 +107,9 @@
</li><li>
<p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p>
</li><li>
<p>manage services</p>
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p>
</li><li>
<p>manage <code>freshclam</code> and <code>clamd</code> services</p>
</li></ul>
<h2 id="label-Dependencies">Dependencies</h2>
@@ -120,7 +119,7 @@
<p><a href="https://sourcecode.confdroid.com/confdroid/confdroid_resources">confdroid_resources</a> for managing yum repo resources.</p>
</li></ul>
<h3 id="label-Deployment">Deployment</h3>
<h2 id="label-Deployment">Deployment</h2>
<ul><li>
<p>native Puppet deployment</p>
</li></ul>

View File

@@ -158,7 +158,23 @@
60
61
62
63</pre>
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span>
@@ -193,6 +209,7 @@ class confdroid_clamav::main::files (
seltype =&gt; etc_t,
seluser =&gt; system_u,
content =&gt; template($cv_freshclam_erb),
notify =&gt; Service[$cv_freshclam],
}
# freshclam service config file
@@ -206,6 +223,21 @@ class confdroid_clamav::main::files (
seltype =&gt; etc_t,
seluser =&gt; system_u,
content =&gt; template($cv_freshclam_svc_erb),
notify =&gt; Service[$cv_freshclam],
}
# clamd service config file
file { $cv_clamd_svc :
ensure =&gt; file,
owner =&gt; &#39;root&#39;,
group =&gt; &#39;root&#39;,
mode =&gt; &#39;0600&#39;,
selrange =&gt; s0,
selrole =&gt; object_r,
seltype =&gt; etc_t,
seluser =&gt; system_u,
content =&gt; template($cv_clamd_svc_erb),
notify =&gt; Service[$cv_service],
}
# shell script for scanning and alerting

View File

@@ -120,8 +120,8 @@ class confdroid_clamav::main::install (
) inherits confdroid_clamav::params {
require confdroid_resources::main::epel
package { $reqpackages:
ensure =&gt; $pkg_ensure,
package { $cv_reqpackages:
ensure =&gt; $cv_pkg_ensure,
}
}</pre>
</td>

View File

@@ -109,7 +109,7 @@ inherited by all classes except defines.
<li>
<span class='name'>reqpackages</span>
<span class='name'>cv_reqpackages</span>
<span class='type'>(<tt>Array</tt>)</span>
@@ -127,7 +127,7 @@ inherited by all classes except defines.
<li>
<span class='name'>pkg_ensure</span>
<span class='name'>cv_pkg_ensure</span>
<span class='type'>(<tt>String</tt>)</span>
@@ -517,6 +517,114 @@ inherited by all classes except defines.
&mdash;
<div class='inline'>
<p>whether to enable the clamd service</p>
</div>
</li>
<li>
<span class='name'>cv_use_excludepaths</span>
<span class='type'>(<tt>Boolean</tt>)</span>
<em class="default">(defaults to: <tt>true</tt>)</em>
&mdash;
<div class='inline'>
<p>whether to use advanced exclude paths</p>
</div>
</li>
<li>
<span class='name'>cv_concurrentdatabasereload</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;no&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>whether to enable concurrent database reloads. This is useful when you have multiple clamd instances running on the same machine. If you have only one clamd instance, this should be set to ‘no’.</p>
</div>
</li>
<li>
<span class='name'>cv_clamd_max_mem</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;512M&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>maximum memory usage for clamd.</p>
</div>
</li>
<li>
<span class='name'>cv_clamd_cpu_quota</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;30%&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>maximum CPU usage for clamd.</p>
</div>
</li>
<li>
<span class='name'>cv_nice_value</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;19&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>nice value for clamd. This is a number between -20 and 19. The lower the number, the higher the priority. The default is 19, which is the lowest priority.</p>
</div>
</li>
<li>
<span class='name'>cv_timeout_start_sec</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;420&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>timeout for starting the clamd service.</p>
</div>
</li>
@@ -532,17 +640,6 @@ inherited by all classes except defines.
<pre class="lines">
39
40
41
42
43
44
45
46
47
48
49
50
51
52
@@ -582,39 +679,64 @@ inherited by all classes except defines.
86
87
88
89</pre>
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 39</span>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 50</span>
class confdroid_clamav::params (
# installation
Array $reqpackages = [&#39;clamav&#39;,&#39;clamd&#39;,&#39;s-nail&#39;],
String $pkg_ensure = &#39;present&#39;,
Array $cv_reqpackages = [&#39;clamav&#39;,&#39;clamd&#39;,&#39;s-nail&#39;],
String $cv_pkg_ensure = &#39;present&#39;,
# clamd
String $cv_logfile = &#39;/var/log/clamd.scan&#39;,
String $cv_logfileunlock = &#39;no&#39;,
String $cv_logfilemaxsize = &#39;2M&#39;,
String $cv_logtime = &#39;yes&#39;,
String $cv_logclean = &#39;no&#39;,
String $cv_logsyslog = &#39;yes&#39;,
String $cv_logfacility = &#39;LOG_MAIL&#39;,
String $cv_logverbose = &#39;no&#39;,
String $cv_logrotate = &#39;yes&#39;,
String $cv_preludeenable = &#39;no&#39;,
String $cv_preludeanalyzername = &#39;ClamAV&#39;,
String $cv_tcpsocket = &#39;3310&#39;,
String $cv_tcpaddress = &#39;localhost&#39;,
String $cv_alert_email = &#39;you@example.com&#39;,
String $cv_cron_hour = &#39;2&#39;,
String $cv_cron_minute = &#39;0&#39;,
String $cv_cron_user = &#39;root&#39;,
String $cv_scan_dir = &#39;/&#39;,
String $cv_alert_file = &#39;tmp/clamav-alert.txt&#39;,
Boolean $cv_enable_freshclam = true,
Boolean $cv_enable_clamd = true,
String $cv_logfile = &#39;/var/log/clamd.scan&#39;,
String $cv_logfileunlock = &#39;no&#39;,
String $cv_logfilemaxsize = &#39;2M&#39;,
String $cv_logtime = &#39;yes&#39;,
String $cv_logclean = &#39;no&#39;,
String $cv_logsyslog = &#39;yes&#39;,
String $cv_logfacility = &#39;LOG_MAIL&#39;,
String $cv_logverbose = &#39;no&#39;,
String $cv_logrotate = &#39;yes&#39;,
String $cv_preludeenable = &#39;no&#39;,
String $cv_preludeanalyzername = &#39;ClamAV&#39;,
String $cv_tcpsocket = &#39;3310&#39;,
String $cv_tcpaddress = &#39;localhost&#39;,
String $cv_alert_email = &#39;you@example.com&#39;,
String $cv_cron_hour = &#39;2&#39;,
String $cv_cron_minute = &#39;0&#39;,
String $cv_cron_user = &#39;root&#39;,
String $cv_scan_dir = &#39;/&#39;,
String $cv_alert_file = &#39;tmp/clamav-alert.txt&#39;,
Boolean $cv_enable_freshclam = true,
Boolean $cv_enable_clamd = true,
Boolean $cv_use_excludepaths = true,
String $cv_concurrentdatabasereload = &#39;no&#39;,
String $cv_clamd_max_mem = &#39;512M&#39;,
String $cv_clamd_cpu_quota = &#39;30%&#39;,
String $cv_nice_value = &#39;19&#39;,
String $cv_timeout_start_sec = &#39;420&#39;
) {
# service
@@ -631,6 +753,8 @@ class confdroid_clamav::params (
$cv_freshclam_erb = &#39;confdroid_clamav/freshclam_conf.erb&#39;
$cv_freshclam_svc = &#39;/usr/lib/systemd/system/freshclam.service&#39;
$cv_freshclam_svc_erb = &#39;confdroid_clamav/freshclam_svc.erb&#39;
$cv_clamd_svc = &#39;/usr/lib/systemd/system/clamd@.service&#39;
$cv_clamd_svc_erb = &#39;confdroid_clamav/clamd_svc.erb&#39;
$cv_shell_script = &quot;${cv_config_d_dir}/scan.sh&quot;
$cv_shell_script_erb = &#39;confdroid_clamav/scan.sh.erb&#39;

View File

@@ -33,6 +33,7 @@ class confdroid_clamav::main::files (
seltype => etc_t,
seluser => system_u,
content => template($cv_freshclam_erb),
notify => Service[$cv_freshclam],
}
# freshclam service config file
@@ -46,6 +47,21 @@ class confdroid_clamav::main::files (
seltype => etc_t,
seluser => system_u,
content => template($cv_freshclam_svc_erb),
notify => Service[$cv_freshclam],
}
# clamd service config file
file { $cv_clamd_svc :
ensure => file,
owner => 'root',
group => 'root',
mode => '0600',
selrange => s0,
selrole => object_r,
seltype => etc_t,
seluser => system_u,
content => template($cv_clamd_svc_erb),
notify => Service[$cv_service],
}
# shell script for scanning and alerting

View File

@@ -9,7 +9,7 @@ class confdroid_clamav::main::install (
) inherits confdroid_clamav::params {
require confdroid_resources::main::epel
package { $reqpackages:
ensure => $pkg_ensure,
package { $cv_reqpackages:
ensure => $cv_pkg_ensure,
}
}

View File

@@ -3,8 +3,8 @@
# Author: 12ww1160 (12ww1160@confdroid.com)
# @summary Class holds all parameters for the confdroid_clamav module and is
# inherited by all classes except defines.
# @param [Array] reqpackages List of packages to install.
# @param [String] pkg_ensure
# @param [Array] cv_reqpackages List of packages to install.
# @param [String] cv_pkg_ensure
# which [package type](https://confdroid.com/2017/05/puppet-type-package/)
# to choose, i.e. `latest` or `present`.
# @param [String] cv_logfile where to log messages for the clamd service.
@@ -35,35 +35,52 @@
# @param [String] cv_alert_file location and name of the alert file
# @param [Boolean] cv_enable_freshclam whether to enable the freshclam service
# @param [Boolean] cv_enable_clamd whether to enable the clamd service
# @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths
# @param [String] cv_concurrentdatabasereload whether to enable concurrent
# database reloads. This is useful when you have multiple clamd instances
# running on the same machine. If you have only one clamd instance, this
# should be set to 'no'.
# @param [String] cv_clamd_max_mem maximum memory usage for clamd.
# @param [String] cv_clamd_cpu_quota maximum CPU usage for clamd.
# @param [String] cv_nice_value nice value for clamd. This is a number between
# -20 and 19. The lower the number, the higher the priority. The default is
# 19, which is the lowest priority.
# @param [String] cv_timeout_start_sec timeout for starting the clamd service.
##############################################################################
class confdroid_clamav::params (
# installation
Array $reqpackages = ['clamav','clamd','s-nail'],
String $pkg_ensure = 'present',
Array $cv_reqpackages = ['clamav','clamd','s-nail'],
String $cv_pkg_ensure = 'present',
# clamd
String $cv_logfile = '/var/log/clamd.scan',
String $cv_logfileunlock = 'no',
String $cv_logfilemaxsize = '2M',
String $cv_logtime = 'yes',
String $cv_logclean = 'no',
String $cv_logsyslog = 'yes',
String $cv_logfacility = 'LOG_MAIL',
String $cv_logverbose = 'no',
String $cv_logrotate = 'yes',
String $cv_preludeenable = 'no',
String $cv_preludeanalyzername = 'ClamAV',
String $cv_tcpsocket = '3310',
String $cv_tcpaddress = 'localhost',
String $cv_alert_email = 'you@example.com',
String $cv_cron_hour = '2',
String $cv_cron_minute = '0',
String $cv_cron_user = 'root',
String $cv_scan_dir = '/',
String $cv_alert_file = 'tmp/clamav-alert.txt',
Boolean $cv_enable_freshclam = true,
Boolean $cv_enable_clamd = true,
String $cv_logfile = '/var/log/clamd.scan',
String $cv_logfileunlock = 'no',
String $cv_logfilemaxsize = '2M',
String $cv_logtime = 'yes',
String $cv_logclean = 'no',
String $cv_logsyslog = 'yes',
String $cv_logfacility = 'LOG_MAIL',
String $cv_logverbose = 'no',
String $cv_logrotate = 'yes',
String $cv_preludeenable = 'no',
String $cv_preludeanalyzername = 'ClamAV',
String $cv_tcpsocket = '3310',
String $cv_tcpaddress = 'localhost',
String $cv_alert_email = 'you@example.com',
String $cv_cron_hour = '2',
String $cv_cron_minute = '0',
String $cv_cron_user = 'root',
String $cv_scan_dir = '/',
String $cv_alert_file = 'tmp/clamav-alert.txt',
Boolean $cv_enable_freshclam = true,
Boolean $cv_enable_clamd = true,
Boolean $cv_use_excludepaths = true,
String $cv_concurrentdatabasereload = 'no',
String $cv_clamd_max_mem = '512M',
String $cv_clamd_cpu_quota = '30%',
String $cv_nice_value = '19',
String $cv_timeout_start_sec = '420'
) {
# service
@@ -80,6 +97,8 @@ class confdroid_clamav::params (
$cv_freshclam_erb = 'confdroid_clamav/freshclam_conf.erb'
$cv_freshclam_svc = '/usr/lib/systemd/system/freshclam.service'
$cv_freshclam_svc_erb = 'confdroid_clamav/freshclam_svc.erb'
$cv_clamd_svc = '/usr/lib/systemd/system/clamd@.service'
$cv_clamd_svc_erb = 'confdroid_clamav/clamd_svc.erb'
$cv_shell_script = "${cv_config_d_dir}/scan.sh"
$cv_shell_script_erb = 'confdroid_clamav/scan.sh.erb'

22
templates/clamd_svc.erb Normal file
View File

@@ -0,0 +1,22 @@
################################################################################
### clamd.svc created by Puppet, manual changes will be overwritten!!! ###
################################################################################
[Unit]
Description = clamd scanner (%i) daemon
Documentation=man:clamd(8) man:clamd.conf(5) https://www.clamav.net/documents/
After = syslog.target nss-lookup.target network.target
[Service]
Type = forking
ExecStart = /usr/sbin/clamd -c /etc/clamd.d/%i.conf
# Reload the database
ExecReload=/bin/kill -USR2 $MAINPID
Restart = on-failure
TimeoutStartSec=<%= @cv_timeout_start_sec %>
MemoryMax=<%= @cv_clamd_max_mem %>
CPUQuota=<%= @cv_clamd_cpu_quota %>
Nice=<%= @cv_nice_value %>
[Install]
WantedBy = multi-user.target

View File

@@ -1,23 +1,26 @@
#!/bin/bash
set -euo pipefail
# Set paths
SCAN_DIR="<%= @cv_scan_dir %>"
LOG_FILE="<%= @cv_logfile %>"
TMP_ALERT="<%= @cv_alert_file %>"
EMAIL="<%= @cv_alert_email %>"
# Run clamscan
clamscan -r --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null
# Ensure the log directory exists
mkdir -p "$(dirname "$LOG_FILE")"
# Check if infections were found
if grep -q "Infected files: [^0]" "$LOG_FILE"; then
echo "ClamAV has found infected files on $(hostname)!" > "$TMP_ALERT"
echo "" >> "$TMP_ALERT"
grep "FOUND" "$LOG_FILE" >> "$TMP_ALERT"
# Preferred: clamdscan with multiscan + fdpass
clamdscan --multiscan --fdpass --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null || true
# Check for infections (same logic as before)
if grep -q "Infected files: [^0]" "$LOG_FILE" 2>/dev/null; then
{
echo "ClamAV has found infected files on $(hostname)!"
echo ""
grep "FOUND" "$LOG_FILE" || true
} > "$TMP_ALERT"
# Send the alert email
mail -s "⚠️ ClamAV Alert on $(hostname)" "$EMAIL" < "$TMP_ALERT"
fi
# Clean up
rm -f "$TMP_ALERT"

View File

@@ -14,6 +14,7 @@ LogRotate <%= @cv_logrotate %>
PreludeEnable <%= @cv_preludeenable %>
TCPSocket <%= @cv_tcpsocket %>
TCPAddr <%= @cv_tcpaddress %>
ConcurrentDatabaseReload <%= @cv_concurrentdatabasereload %>
#
# Set the name of the analyzer used by prelude-admin.
# Default: ClamAV
@@ -21,7 +22,7 @@ PreludeAnalyzerName ClamAV
# Log additional information about the infected file, such as its
# size and hash, together with the virus name.
#ExtendedDetectionInfo yes
ExtendedDetectionInfo yes
# This option allows you to save a process identifier of the listening
# daemon (main thread).
@@ -132,6 +133,28 @@ PreludeAnalyzerName ClamAV
#ExcludePath ^/proc/
#ExcludePath ^/sys/
<% if @cv_use_excludepaths %>
ExcludePath ^/proc
ExcludePath ^/sys
ExcludePath ^/dev
ExcludePath ^/run
ExcludePath ^/var/run
ExcludePath ^/var/tmp
ExcludePath ^/tmp
ExcludePath ^/var/lib/clamav
ExcludePath ^/var/log/clamav
ExcludePath ^/var/lib/docker
ExcludePath ^/var/lib/containerd
ExcludePath ^/var/lib/kubelet/pods
ExcludePath ^/var/lib/kubelet/plugins
ExcludePath ^/var/lib/kubelet/plugins_registry
ExcludePath ^/var/log/pods
ExcludePath ^/var/log/containers
ExcludePath ^/var/cache
ExcludePath ^/run/containerd
ExcludePath ^/run/docker
<% end %>
# Maximum depth directories are scanned at.
# Default: 15
#MaxDirectoryRecursion 20