94 lines
3.4 KiB
Markdown
94 lines
3.4 KiB
Markdown
# Readme
|
|
|
|
[](https://jenkins.confdroid.com/job/confdroid_clamav/)
|
|
[](https://sonarqube.confdroid.com/dashboard?id=confdroid_clamav)
|
|
[](https://deepwiki.com/grizzlycoda/puppet_collection)
|
|
|
|
- [Readme](#readme)
|
|
- [Synopsis](#synopsis)
|
|
- [WARNING](#warning)
|
|
- [Features](#features)
|
|
- [Dependencies](#dependencies)
|
|
- [Deployment](#deployment)
|
|
- [Parameters](#parameters)
|
|
- [SELINUX](#selinux)
|
|
- [Support](#support)
|
|
- [Tests](#tests)
|
|
- [Contact Us](#contact-us)
|
|
- [Disclaimer](#disclaimer)
|
|
|
|
## Synopsis
|
|
|
|
`Clamav` is a powerful antivirus scanner with several components.
|
|
|
|
`confdroid_clamav` is a puppet module to manage clamav installations and configurations.
|
|
|
|
## WARNING
|
|
|
|
***Attention: Never use this puppet module on systems which have been previously configured manually. It is impossible to predict how and what would have been configured, hence previous configurations outside the scope of this module may be overwritten! Automated configurations require a test environment to verify that the module suits the purpose intended by the user, as well as tune the parameters, before deploying into live production***
|
|
|
|
## Features
|
|
|
|
- install all required binaries including s-nail as mail program to send alerts when infected files are found
|
|
- manage required config files
|
|
- manage cronjob settings via parameters
|
|
- run cron job to scan the file system (by default starting at root, configurable) via clamdscan
|
|
- set ConcurrentDatabaseReload option yes/no to optimize RAM consumption
|
|
- manage services
|
|
|
|
## Dependencies
|
|
|
|
All dependencies must be included in the catalogue.
|
|
|
|
- [confdroid_resources](https://sourcecode.confdroid.com/confdroid/confdroid_resources) for managing yum repo resources.
|
|
|
|
## Deployment
|
|
|
|
- native Puppet deployment
|
|
|
|
via site.pp or nodes.pp
|
|
|
|
```bash
|
|
node 'example.example.net' {
|
|
include confdroid_clamav
|
|
}
|
|
```
|
|
|
|
- through Foreman:
|
|
|
|
In order to apply parameters through Foreman, **__confdroid_clamav::params__*- must be added to the host or host group in question.
|
|
|
|
See [more details about class deployment on Confdroid.com](https://confdroid.com/2017/05/deploying-our-puppet-modules/).
|
|
|
|
## Parameters
|
|
|
|
The parameters are documented via puppet strings and [listed here](/docs/index.html). Simply open in web browser.
|
|
|
|
## SELINUX
|
|
|
|
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.
|
|
|
|
## Support
|
|
|
|
- OS: Rocky 9
|
|
- Puppet 8
|
|
|
|
## Tests
|
|
|
|
- Puppet Lint
|
|
- excluded tests:
|
|
- `--no-class_inherits_from_params_class-check`:relevant only to non-supported outdated puppet versions
|
|
- Puppet Parser
|
|
- ERB Template Parser
|
|
- Sonar Quality Gate
|
|
|
|
## Contact Us
|
|
|
|
- [contact Us](https://confdroid.com/contact/)
|
|
- [Feedback Portal](https://feedback.confdroid.com)
|
|
|
|
## Disclaimer
|
|
|
|
ConfDroid as entity is entirely independent from Puppet. We provide custom configuration modules, written for specific purposes and specific environments.
|
|
The modules are tested and supported only as documented, and require testing in designated environments (i.e. lab or development environments) for parameter tuning etc. before deploying into production environments.
|