Files
confdroid_clamav/README.md

94 lines
3.4 KiB
Markdown

# Readme
[![Build Status](https://jenkins.confdroid.com/buildStatus/icon?job=confdroid_clamav&style=plastic)](https://jenkins.confdroid.com/job/confdroid_clamav/)
[![Security Hotspots](https://sonarqube.confdroid.com/api/project_badges/measure?project=confdroid_clamav&metric=security_hotspots&token=sqb_cdcd204545668e8367aed118aa87ad814b58863b)](https://sonarqube.confdroid.com/dashboard?id=confdroid_clamav)
[![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/grizzlycoda/puppet_collection)
- [Readme](#readme)
- [Synopsis](#synopsis)
- [WARNING](#warning)
- [Features](#features)
- [Dependencies](#dependencies)
- [Deployment](#deployment)
- [Parameters](#parameters)
- [SELINUX](#selinux)
- [Support](#support)
- [Tests](#tests)
- [Contact Us](#contact-us)
- [Disclaimer](#disclaimer)
## Synopsis
`Clamav` is a powerful antivirus scanner with several components.
`confdroid_clamav` is a puppet module to manage clamav installations and configurations.
## WARNING
***Attention: Never use this puppet module on systems which have been previously configured manually. It is impossible to predict how and what would have been configured, hence previous configurations outside the scope of this module may be overwritten! Automated configurations require a test environment to verify that the module suits the purpose intended by the user, as well as tune the parameters, before deploying into live production***
## Features
- install all required binaries including s-nail as mail program to send alerts when infected files are found
- manage required config files
- manage cronjob settings via parameters
- run cron job to scan the file system (by default starting at root, configurable) via clamdscan
- set ConcurrentDatabaseReload option `yes`/`no` to optimize RAM consumption. defaults to `no`
- manage services
## Dependencies
All dependencies must be included in the catalogue.
- [confdroid_resources](https://sourcecode.confdroid.com/confdroid/confdroid_resources) for managing yum repo resources.
## Deployment
- native Puppet deployment
via site.pp or nodes.pp
```bash
node 'example.example.net' {
include confdroid_clamav
}
```
- through Foreman:
In order to apply parameters through Foreman, **__confdroid_clamav::params__*- must be added to the host or host group in question.
See [more details about class deployment on Confdroid.com](https://confdroid.com/2017/05/deploying-our-puppet-modules/).
## Parameters
The parameters are documented via puppet strings and [listed here](/docs/index.html). Simply open in web browser.
## SELINUX
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.
## Support
- OS: Rocky 9
- Puppet 8
## Tests
- Puppet Lint
- excluded tests:
- `--no-class_inherits_from_params_class-check`:relevant only to non-supported outdated puppet versions
- Puppet Parser
- ERB Template Parser
- Sonar Quality Gate
## Contact Us
- [contact Us](https://confdroid.com/contact/)
- [Feedback Portal](https://feedback.confdroid.com)
## Disclaimer
ConfDroid as entity is entirely independent from Puppet. We provide custom configuration modules, written for specific purposes and specific environments.
The modules are tested and supported only as documented, and require testing in designated environments (i.e. lab or development environments) for parameter tuning etc. before deploying into production environments.