Compare commits
4 Commits
a8816c6408
...
0886eec44c
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0886eec44c | ||
|
|
4543a31013 | ||
| dd1a1478ff | |||
|
|
2b3fee4c2b |
62
.vscode/settings.json
vendored
62
.vscode/settings.json
vendored
@@ -1,62 +0,0 @@
|
||||
{
|
||||
"cSpell.words": [
|
||||
"ALLMATCHSCAN",
|
||||
"authenticode",
|
||||
"behaviour",
|
||||
"bofh",
|
||||
"clamav",
|
||||
"clamd",
|
||||
"clamdscan",
|
||||
"clamonacc",
|
||||
"clamscan",
|
||||
"Clamuko",
|
||||
"clamupdate",
|
||||
"concurrentdatabasereload",
|
||||
"Dazuko",
|
||||
"dbname",
|
||||
"epel",
|
||||
"excludepaths",
|
||||
"fanotify",
|
||||
"fdpass",
|
||||
"filesize",
|
||||
"freshclam",
|
||||
"getsebool",
|
||||
"INADDR",
|
||||
"kubelet",
|
||||
"libclamav",
|
||||
"logclean",
|
||||
"logfacility",
|
||||
"logfile",
|
||||
"logfilemaxsize",
|
||||
"logfileunlock",
|
||||
"logrotation",
|
||||
"logsyslog",
|
||||
"logtime",
|
||||
"logverbose",
|
||||
"MAINPID",
|
||||
"multiscan",
|
||||
"mypass",
|
||||
"myproxy",
|
||||
"myusername",
|
||||
"NOFILE",
|
||||
"normalisation",
|
||||
"PCRE",
|
||||
"pipefail",
|
||||
"preludeanalyzername",
|
||||
"preludeenable",
|
||||
"recieve",
|
||||
"RLIMIT",
|
||||
"safebrowsing",
|
||||
"setsebool",
|
||||
"subsig",
|
||||
"subsigs",
|
||||
"tcpaddre",
|
||||
"tcpaddress",
|
||||
"tcpsocket",
|
||||
"VIRUSEVENT",
|
||||
"virusgroup",
|
||||
"VIRUSNAME",
|
||||
"XMLDOCS",
|
||||
"xxxyyzzzz"
|
||||
]
|
||||
}
|
||||
128
Jenkinsfile
vendored
128
Jenkinsfile
vendored
@@ -1,128 +0,0 @@
|
||||
pipeline {
|
||||
agent {
|
||||
label 'puppet'
|
||||
}
|
||||
|
||||
post {
|
||||
always {
|
||||
deleteDir() /* clean up our workspace */
|
||||
}
|
||||
success {
|
||||
updateGitlabCommitStatus state: 'success'
|
||||
}
|
||||
failure {
|
||||
updateGitlabCommitStatus state: 'failed'
|
||||
step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true])
|
||||
}
|
||||
}
|
||||
|
||||
options {
|
||||
gitLabConnection('gitlab.confdroid.com')
|
||||
}
|
||||
|
||||
stages {
|
||||
|
||||
stage('pull master') {
|
||||
steps {
|
||||
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
|
||||
sh '''
|
||||
git config user.name "Jenkins Server"
|
||||
git config user.email jenkins@confdroid.com
|
||||
# Ensure we're on the development branch (triggered by push)
|
||||
git checkout development
|
||||
# Create jenkins branch from development
|
||||
git checkout -b jenkins-build-$BUILD_NUMBER
|
||||
# Optionally merge master into jenkins to ensure compatibility
|
||||
git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; }
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
stage('puppet parser') {
|
||||
steps {
|
||||
sh '''for file in $(find . -iname \'*.pp\'); do
|
||||
/opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1;
|
||||
done;'''
|
||||
}
|
||||
}
|
||||
|
||||
stage('check templates') {
|
||||
steps{
|
||||
sh '''for file in $(find . -iname \'*.erb\');
|
||||
do erb -P -x -T "-" $file | ruby -c || exit 1;
|
||||
done;'''
|
||||
}
|
||||
}
|
||||
|
||||
stage('puppet-lint') {
|
||||
steps {
|
||||
sh '''/usr/local/bin/puppet-lint . \\
|
||||
--no-variable_scope-check \\
|
||||
|| { echo "Puppet lint failed"; exit 1; }
|
||||
'''
|
||||
}
|
||||
}
|
||||
|
||||
stage('SonarScan') {
|
||||
steps {
|
||||
withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) {
|
||||
sh '''
|
||||
/opt/sonar-scanner/bin/sonar-scanner \
|
||||
-Dsonar.projectKey=confdroid_clamav \
|
||||
-Dsonar.sources=. \
|
||||
-Dsonar.host.url=https://sonarqube.confdroid.com \
|
||||
-Dsonar.token=$SONAR_TOKEN
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
stage('create Puppet documentation') {
|
||||
steps {
|
||||
sh '/opt/puppetlabs/bin/puppet strings'
|
||||
}
|
||||
}
|
||||
|
||||
stage('update repo') {
|
||||
steps {
|
||||
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
|
||||
sh '''
|
||||
git config user.name "Jenkins Server"
|
||||
git config user.email jenkins@confdroid.com
|
||||
git rm -r --cached .vscode || echo "No .vscode to remove from git"
|
||||
git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit"
|
||||
git push origin HEAD:master
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
stage('Mirror to Gitea') {
|
||||
steps {
|
||||
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
|
||||
withCredentials([usernamePassword(
|
||||
credentialsId: 'Jenkins-gitea',
|
||||
usernameVariable: 'GITEA_USER',
|
||||
passwordVariable: 'GITEA_TOKEN')]) {
|
||||
script {
|
||||
// Checkout from GitLab (already done implicitly)
|
||||
sh '''
|
||||
git checkout master
|
||||
git pull origin master
|
||||
git branch -D development
|
||||
git branch -D jenkins-build-$BUILD_NUMBER
|
||||
git rm -f Jenkinsfile
|
||||
git rm -r --cached .vscode || echo "No .vscode to remove from git"
|
||||
git commit --amend --no-edit --allow-empty
|
||||
git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_clamav.git
|
||||
git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \
|
||||
push master --mirror
|
||||
'''
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -109,7 +109,7 @@
|
||||
</li><li>
|
||||
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p>
|
||||
</li><li>
|
||||
<p>manage services</p>
|
||||
<p>manage <code>freshclam</code> and <code>clamd</code> services</p>
|
||||
</li></ul>
|
||||
|
||||
<h2 id="label-Dependencies">Dependencies</h2>
|
||||
|
||||
@@ -109,7 +109,7 @@
|
||||
</li><li>
|
||||
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p>
|
||||
</li><li>
|
||||
<p>manage services</p>
|
||||
<p>manage <code>freshclam</code> and <code>clamd</code> services</p>
|
||||
</li></ul>
|
||||
|
||||
<h2 id="label-Dependencies">Dependencies</h2>
|
||||
|
||||
@@ -553,6 +553,60 @@ inherited by all classes except defines.
|
||||
—
|
||||
<div class='inline'>
|
||||
<p>whether to enable concurrent database reloads. This is useful when you have multiple clamd instances running on the same machine. If you have only one clamd instance, this should be set to ‘no’.</p>
|
||||
</div>
|
||||
|
||||
</li>
|
||||
|
||||
<li>
|
||||
|
||||
<span class='name'>cv_clamd_max_mem</span>
|
||||
|
||||
|
||||
<span class='type'>(<tt>String</tt>)</span>
|
||||
|
||||
|
||||
<em class="default">(defaults to: <tt>'512M'</tt>)</em>
|
||||
|
||||
|
||||
—
|
||||
<div class='inline'>
|
||||
<p>maximum memory usage for clamd.</p>
|
||||
</div>
|
||||
|
||||
</li>
|
||||
|
||||
<li>
|
||||
|
||||
<span class='name'>cv_clamd_cpu_quota</span>
|
||||
|
||||
|
||||
<span class='type'>(<tt>String</tt>)</span>
|
||||
|
||||
|
||||
<em class="default">(defaults to: <tt>'30%'</tt>)</em>
|
||||
|
||||
|
||||
—
|
||||
<div class='inline'>
|
||||
<p>maximum CPU usage for clamd.</p>
|
||||
</div>
|
||||
|
||||
</li>
|
||||
|
||||
<li>
|
||||
|
||||
<span class='name'>cv_nice_value</span>
|
||||
|
||||
|
||||
<span class='type'>(<tt>String</tt>)</span>
|
||||
|
||||
|
||||
<em class="default">(defaults to: <tt>'19'</tt>)</em>
|
||||
|
||||
|
||||
—
|
||||
<div class='inline'>
|
||||
<p>nice value for clamd. This is a number between -20 and 19. The lower the number, the higher the priority. The default is 19, which is the lowest priority.</p>
|
||||
</div>
|
||||
|
||||
</li>
|
||||
@@ -568,11 +622,6 @@ inherited by all classes except defines.
|
||||
<pre class="lines">
|
||||
|
||||
|
||||
44
|
||||
45
|
||||
46
|
||||
47
|
||||
48
|
||||
49
|
||||
50
|
||||
51
|
||||
@@ -622,10 +671,18 @@ inherited by all classes except defines.
|
||||
95
|
||||
96
|
||||
97
|
||||
98</pre>
|
||||
98
|
||||
99
|
||||
100
|
||||
101
|
||||
102
|
||||
103
|
||||
104
|
||||
105
|
||||
106</pre>
|
||||
</td>
|
||||
<td>
|
||||
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 44</span>
|
||||
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 49</span>
|
||||
|
||||
class confdroid_clamav::params (
|
||||
|
||||
@@ -657,6 +714,9 @@ class confdroid_clamav::params (
|
||||
Boolean $cv_enable_clamd = true,
|
||||
Boolean $cv_use_excludepaths = true,
|
||||
String $cv_concurrentdatabasereload = 'no',
|
||||
String $cv_clamd_max_mem = '512M',
|
||||
String $cv_clamd_cpu_quota = '30%',
|
||||
String $cv_nice_value = '19'
|
||||
|
||||
) {
|
||||
# service
|
||||
|
||||
@@ -40,6 +40,11 @@
|
||||
# database reloads. This is useful when you have multiple clamd instances
|
||||
# running on the same machine. If you have only one clamd instance, this
|
||||
# should be set to 'no'.
|
||||
# @param [String] cv_clamd_max_mem maximum memory usage for clamd.
|
||||
# @param [String] cv_clamd_cpu_quota maximum CPU usage for clamd.
|
||||
# @param [String] cv_nice_value nice value for clamd. This is a number between
|
||||
# -20 and 19. The lower the number, the higher the priority. The default is
|
||||
# 19, which is the lowest priority.
|
||||
##############################################################################
|
||||
class confdroid_clamav::params (
|
||||
|
||||
@@ -71,6 +76,9 @@ class confdroid_clamav::params (
|
||||
Boolean $cv_enable_clamd = true,
|
||||
Boolean $cv_use_excludepaths = true,
|
||||
String $cv_concurrentdatabasereload = 'no',
|
||||
String $cv_clamd_max_mem = '512M',
|
||||
String $cv_clamd_cpu_quota = '30%',
|
||||
String $cv_nice_value = '19'
|
||||
|
||||
) {
|
||||
# service
|
||||
|
||||
@@ -14,9 +14,9 @@ ExecStart = /usr/sbin/clamd -c /etc/clamd.d/%i.conf
|
||||
ExecReload=/bin/kill -USR2 $MAINPID
|
||||
Restart = on-failure
|
||||
TimeoutStartSec=420
|
||||
MemoryLimit=1024M
|
||||
CPUQuota=30%
|
||||
Nice=19
|
||||
MemoryLimit=<%= @cv_clamd_max_mem %>
|
||||
CPUQuota=<%= @cv_clamd_cpu_quota %>
|
||||
Nice=<%= @cv_nice_value %>
|
||||
|
||||
[Install]
|
||||
WantedBy = multi-user.target
|
||||
|
||||
Reference in New Issue
Block a user