Compare commits

..

1 Commits

Author SHA1 Message Date
Jenkins Server
23e21ae0d2 Recommit for updates in build 8 2026-09-22 13:17:49 +02:00
8 changed files with 19 additions and 194 deletions

View File

@@ -33,8 +33,8 @@
- manage required config files - manage required config files
- manage cronjob settings via parameters - manage cronjob settings via parameters
- run cron job to scan the file system (by default starting at root, configurable) via clamdscan - run cron job to scan the file system (by default starting at root, configurable) via clamdscan
- set ConcurrentDatabaseReload option `yes`/`no` to optimize RAM consumption. defaults to `no` - set ConcurrentDatabaseReload option yes/no to optimize RAM consumption
- manage `freshclam` and `clamd` services - manage services
## Dependencies ## Dependencies

View File

@@ -107,9 +107,9 @@
</li><li> </li><li>
<p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p> <p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p>
</li><li> </li><li>
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p> <p>set ConcurrentDatabaseReload option yes/no to optimize RAM consumption</p>
</li><li> </li><li>
<p>manage <code>freshclam</code> and <code>clamd</code> services</p> <p>manage services</p>
</li></ul> </li></ul>
<h2 id="label-Dependencies">Dependencies</h2> <h2 id="label-Dependencies">Dependencies</h2>

View File

@@ -107,9 +107,9 @@
</li><li> </li><li>
<p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p> <p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p>
</li><li> </li><li>
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p> <p>set ConcurrentDatabaseReload option yes/no to optimize RAM consumption</p>
</li><li> </li><li>
<p>manage <code>freshclam</code> and <code>clamd</code> services</p> <p>manage services</p>
</li></ul> </li></ul>
<h2 id="label-Dependencies">Dependencies</h2> <h2 id="label-Dependencies">Dependencies</h2>

View File

@@ -158,23 +158,7 @@
60 60
61 61
62 62
63 63</pre>
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span> <pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span>
@@ -209,7 +193,6 @@ class confdroid_clamav::main::files (
seltype =&gt; etc_t, seltype =&gt; etc_t,
seluser =&gt; system_u, seluser =&gt; system_u,
content =&gt; template($cv_freshclam_erb), content =&gt; template($cv_freshclam_erb),
notify =&gt; Service[$cv_freshclam],
} }
# freshclam service config file # freshclam service config file
@@ -223,21 +206,6 @@ class confdroid_clamav::main::files (
seltype =&gt; etc_t, seltype =&gt; etc_t,
seluser =&gt; system_u, seluser =&gt; system_u,
content =&gt; template($cv_freshclam_svc_erb), content =&gt; template($cv_freshclam_svc_erb),
notify =&gt; Service[$cv_freshclam],
}
# clamd service config file
file { $cv_clamd_svc :
ensure =&gt; file,
owner =&gt; &#39;root&#39;,
group =&gt; &#39;root&#39;,
mode =&gt; &#39;0600&#39;,
selrange =&gt; s0,
selrole =&gt; object_r,
seltype =&gt; etc_t,
seluser =&gt; system_u,
content =&gt; template($cv_clamd_svc_erb),
notify =&gt; Service[$cv_service],
} }
# shell script for scanning and alerting # shell script for scanning and alerting

View File

@@ -550,83 +550,6 @@ inherited by all classes except defines.
<em class="default">(defaults to: <tt>&#39;no&#39;</tt>)</em> <em class="default">(defaults to: <tt>&#39;no&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>whether to enable concurrent database reloads. This is useful when you have multiple clamd instances running on the same machine. If you have only one clamd instance, this should be set to ‘no’.</p>
</div>
</li>
<li>
<span class='name'>cv_clamd_max_mem</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;512M&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>maximum memory usage for clamd.</p>
</div>
</li>
<li>
<span class='name'>cv_clamd_cpu_quota</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;30%&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>maximum CPU usage for clamd.</p>
</div>
</li>
<li>
<span class='name'>cv_nice_value</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;19&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>nice value for clamd. This is a number between -20 and 19. The lower the number, the higher the priority. The default is 19, which is the lowest priority.</p>
</div>
</li>
<li>
<span class='name'>cv_timeout_start_sec</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;420&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>timeout for starting the clamd service.</p>
</div>
</li> </li>
</ul> </ul>
@@ -640,6 +563,16 @@ inherited by all classes except defines.
<pre class="lines"> <pre class="lines">
40
41
42
43
44
45
46
47
48
49
50 50
51 51
52 52
@@ -682,26 +615,10 @@ inherited by all classes except defines.
89 89
90 90
91 91
92 92</pre>
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 50</span> <pre class="code"><span class="info file"># File 'manifests/params.pp', line 40</span>
class confdroid_clamav::params ( class confdroid_clamav::params (
@@ -733,10 +650,6 @@ class confdroid_clamav::params (
Boolean $cv_enable_clamd = true, Boolean $cv_enable_clamd = true,
Boolean $cv_use_excludepaths = true, Boolean $cv_use_excludepaths = true,
String $cv_concurrentdatabasereload = &#39;no&#39;, String $cv_concurrentdatabasereload = &#39;no&#39;,
String $cv_clamd_max_mem = &#39;512M&#39;,
String $cv_clamd_cpu_quota = &#39;30%&#39;,
String $cv_nice_value = &#39;19&#39;,
String $cv_timeout_start_sec = &#39;420&#39;
) { ) {
# service # service
@@ -753,8 +666,6 @@ class confdroid_clamav::params (
$cv_freshclam_erb = &#39;confdroid_clamav/freshclam_conf.erb&#39; $cv_freshclam_erb = &#39;confdroid_clamav/freshclam_conf.erb&#39;
$cv_freshclam_svc = &#39;/usr/lib/systemd/system/freshclam.service&#39; $cv_freshclam_svc = &#39;/usr/lib/systemd/system/freshclam.service&#39;
$cv_freshclam_svc_erb = &#39;confdroid_clamav/freshclam_svc.erb&#39; $cv_freshclam_svc_erb = &#39;confdroid_clamav/freshclam_svc.erb&#39;
$cv_clamd_svc = &#39;/usr/lib/systemd/system/clamd@.service&#39;
$cv_clamd_svc_erb = &#39;confdroid_clamav/clamd_svc.erb&#39;
$cv_shell_script = &quot;${cv_config_d_dir}/scan.sh&quot; $cv_shell_script = &quot;${cv_config_d_dir}/scan.sh&quot;
$cv_shell_script_erb = &#39;confdroid_clamav/scan.sh.erb&#39; $cv_shell_script_erb = &#39;confdroid_clamav/scan.sh.erb&#39;

View File

@@ -33,7 +33,6 @@ class confdroid_clamav::main::files (
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($cv_freshclam_erb), content => template($cv_freshclam_erb),
notify => Service[$cv_freshclam],
} }
# freshclam service config file # freshclam service config file
@@ -47,21 +46,6 @@ class confdroid_clamav::main::files (
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($cv_freshclam_svc_erb), content => template($cv_freshclam_svc_erb),
notify => Service[$cv_freshclam],
}
# clamd service config file
file { $cv_clamd_svc :
ensure => file,
owner => 'root',
group => 'root',
mode => '0600',
selrange => s0,
selrole => object_r,
seltype => etc_t,
seluser => system_u,
content => template($cv_clamd_svc_erb),
notify => Service[$cv_service],
} }
# shell script for scanning and alerting # shell script for scanning and alerting

View File

@@ -36,16 +36,6 @@
# @param [Boolean] cv_enable_freshclam whether to enable the freshclam service # @param [Boolean] cv_enable_freshclam whether to enable the freshclam service
# @param [Boolean] cv_enable_clamd whether to enable the clamd service # @param [Boolean] cv_enable_clamd whether to enable the clamd service
# @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths # @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths
# @param [String] cv_concurrentdatabasereload whether to enable concurrent
# database reloads. This is useful when you have multiple clamd instances
# running on the same machine. If you have only one clamd instance, this
# should be set to 'no'.
# @param [String] cv_clamd_max_mem maximum memory usage for clamd.
# @param [String] cv_clamd_cpu_quota maximum CPU usage for clamd.
# @param [String] cv_nice_value nice value for clamd. This is a number between
# -20 and 19. The lower the number, the higher the priority. The default is
# 19, which is the lowest priority.
# @param [String] cv_timeout_start_sec timeout for starting the clamd service.
############################################################################## ##############################################################################
class confdroid_clamav::params ( class confdroid_clamav::params (
@@ -77,10 +67,6 @@ class confdroid_clamav::params (
Boolean $cv_enable_clamd = true, Boolean $cv_enable_clamd = true,
Boolean $cv_use_excludepaths = true, Boolean $cv_use_excludepaths = true,
String $cv_concurrentdatabasereload = 'no', String $cv_concurrentdatabasereload = 'no',
String $cv_clamd_max_mem = '512M',
String $cv_clamd_cpu_quota = '30%',
String $cv_nice_value = '19',
String $cv_timeout_start_sec = '420'
) { ) {
# service # service
@@ -97,8 +83,6 @@ class confdroid_clamav::params (
$cv_freshclam_erb = 'confdroid_clamav/freshclam_conf.erb' $cv_freshclam_erb = 'confdroid_clamav/freshclam_conf.erb'
$cv_freshclam_svc = '/usr/lib/systemd/system/freshclam.service' $cv_freshclam_svc = '/usr/lib/systemd/system/freshclam.service'
$cv_freshclam_svc_erb = 'confdroid_clamav/freshclam_svc.erb' $cv_freshclam_svc_erb = 'confdroid_clamav/freshclam_svc.erb'
$cv_clamd_svc = '/usr/lib/systemd/system/clamd@.service'
$cv_clamd_svc_erb = 'confdroid_clamav/clamd_svc.erb'
$cv_shell_script = "${cv_config_d_dir}/scan.sh" $cv_shell_script = "${cv_config_d_dir}/scan.sh"
$cv_shell_script_erb = 'confdroid_clamav/scan.sh.erb' $cv_shell_script_erb = 'confdroid_clamav/scan.sh.erb'

View File

@@ -1,22 +0,0 @@
################################################################################
### clamd.svc created by Puppet, manual changes will be overwritten!!! ###
################################################################################
[Unit]
Description = clamd scanner (%i) daemon
Documentation=man:clamd(8) man:clamd.conf(5) https://www.clamav.net/documents/
After = syslog.target nss-lookup.target network.target
[Service]
Type = forking
ExecStart = /usr/sbin/clamd -c /etc/clamd.d/%i.conf
# Reload the database
ExecReload=/bin/kill -USR2 $MAINPID
Restart = on-failure
TimeoutStartSec=<%= @cv_timeout_start_sec %>
MemoryMax=<%= @cv_clamd_max_mem %>
CPUQuota=<%= @cv_clamd_cpu_quota %>
Nice=<%= @cv_nice_value %>
[Install]
WantedBy = multi-user.target