feat(clamav): add clamav (#1725)

* feat(clamav): add clamav

* typo and update defaults

* update questions

* use this for test

* no quotes

* readrootfs

* varrun

* rofs

* try this user

* without varrun

* readonly

* var

* root

* probe

* disable probe

* false runasnonroot

* test probes

* doc ports

* sync questions

* update image
This commit is contained in:
Stavros Kois
2022-01-18 00:27:08 +01:00
committed by GitHub
parent e951cb7093
commit f163445ecf
6 changed files with 609 additions and 83 deletions
+29
View File
@@ -0,0 +1,29 @@
apiVersion: v2
appVersion: "0.104.2"
dependencies:
- name: common
repository: https://truecharts.org
version: 8.13.0
description: ClamAV® is an open source antivirus engine for detecting trojans, viruses, malware & other malicious threats.
home: https://github.com/truecharts/apps/tree/master/charts/stable/clamav
icon: https://truecharts.org/_static/img/appicons/clamav-icon.png
keywords:
- clamav
- antivirus
kubeVersion: '>=1.16.0-0'
maintainers:
- email: info@truecharts.org
name: TrueCharts
url: https://truecharts.org
name: clamav
sources:
- https://github.com/Cisco-Talos/clamav
- https://hub.docker.com/r/clamav/clamav
- https://docs.clamav.net/
type: application
version: 0.0.1
annotations:
truecharts.org/catagories: |
- utilities
truecharts.org/SCALE-support: "true"
truecharts.org/grade: U
+418
View File
@@ -0,0 +1,418 @@
# Include{groups}
portals: {}
questions:
# Include{global}
- variable: controller
group: "Controller"
label: ""
schema:
type: dict
attrs:
- variable: advanced
label: "Show Advanced Controller Settings"
schema:
type: boolean
default: false
show_subquestions_if: true
subquestions:
- variable: type
description: "Please specify type of workload to deploy"
label: "(Advanced) Controller Type"
schema:
type: string
default: "deployment"
required: true
enum:
- value: "deployment"
description: "Deployment"
- value: "statefulset"
description: "Statefulset"
- value: "daemonset"
description: "Daemonset"
- variable: replicas
description: "Number of desired pod replicas"
label: "Desired Replicas"
schema:
type: int
default: 1
required: true
- variable: strategy
description: "Please specify type of workload to deploy"
label: "(Advanced) Update Strategy"
schema:
type: string
default: "Recreate"
required: true
enum:
- value: "Recreate"
description: "Recreate: Kill existing pods before creating new ones"
- value: "RollingUpdate"
description: "RollingUpdate: Create new pods and then kill old ones"
- value: "OnDelete"
description: "(Legacy) OnDelete: ignore .spec.template changes"
# Include{controllerExpert}
- variable: env
group: "Container Configuration"
label: "Image Environment"
schema:
type: dict
attrs:
# Include{fixedEnv}
- variable: CLAMAV_NO_CLAMD
label: "NO CLAMD"
description: "Do not start clamd."
schema:
type: boolean
default: false
- variable: CLAMAV_NO_FRESHCLAMD
label: "NO FRESHCLAMD"
description: "Do not start the freshclam daemon."
schema:
type: boolean
default: false
- variable: CLAMAV_NO_MILTERD
label: "NO MILTERD"
description: "Do not start the clamav-milter daemon."
schema:
type: boolean
default: true
- variable: CLAMD_STARTUP_TIMEOUT
label: "STARTUP TIMEOUT"
description: "Seconds to wait for clamd to start."
schema:
type: int
default: 1800
- variable: FRESHCLAM_CHECKS
label: "FRESHCLAM CHECKS "
description: "Freshclam daily update frequency."
schema:
type: int
default: 1
# Include{containerConfig}
- variable: service
group: "Networking and Services"
label: "Configure Service(s)"
schema:
type: dict
attrs:
- variable: main
label: "Main Service"
description: "The Primary service on which the healthcheck runs, often the webUI"
schema:
type: dict
attrs:
# Include{serviceSelector}
- variable: main
label: "Main Service Port Configuration"
schema:
type: dict
attrs:
- variable: port
label: "Port"
description: "This port exposes the container port on the service"
schema:
type: int
default: 3310
required: true
- variable: advanced
label: "Show Advanced settings"
schema:
type: boolean
default: false
show_subquestions_if: true
subquestions:
- variable: enabled
label: "Enable the port"
schema:
type: boolean
default: true
- variable: protocol
label: "Port Type"
schema:
type: string
default: "HTTP"
enum:
- value: HTTP
description: "HTTP"
- value: "HTTPS"
description: "HTTPS"
- value: TCP
description: "TCP"
- value: "UDP"
description: "UDP"
- variable: nodePort
label: "Node Port (Optional)"
description: "This port gets exposed to the node. Only considered when service type is NodePort, Simple or LoadBalancer"
schema:
type: int
min: 9000
max: 65535
- variable: targetPort
label: "Target Port"
description: "The internal(!) port on the container the Application runs on"
schema:
type: int
default: 3310
- variable: milter
label: "Milter Service"
description: "The Primary service on which the healthcheck runs, often the webUI"
schema:
type: dict
attrs:
# Include{serviceSelector}
- variable: milter
label: "Main Service Port Configuration"
schema:
type: dict
attrs:
- variable: port
label: "Port"
description: "This port exposes the container port on the service"
schema:
type: int
default: 7357
required: true
- variable: advanced
label: "Show Advanced settings"
schema:
type: boolean
default: false
show_subquestions_if: true
subquestions:
- variable: enabled
label: "Enable the port"
schema:
type: boolean
default: true
- variable: protocol
label: "Port Type"
schema:
type: string
default: "HTTP"
enum:
- value: HTTP
description: "HTTP"
- value: "HTTPS"
description: "HTTPS"
- value: TCP
description: "TCP"
- value: "UDP"
description: "UDP"
- variable: nodePort
label: "Node Port (Optional)"
description: "This port gets exposed to the node. Only considered when service type is NodePort, Simple or LoadBalancer"
schema:
type: int
min: 9000
max: 65535
- variable: targetPort
label: "Target Port"
description: "The internal(!) port on the container the Application runs on"
schema:
type: int
default: 7357
- variable: serviceexpert
group: "Networking and Services"
label: "Show Expert Config"
schema:
type: boolean
default: false
show_subquestions_if: true
subquestions:
- variable: hostNetwork
group: "Networking and Services"
label: "Host-Networking (Complicated)"
schema:
type: boolean
default: false
# Include{serviceExpert}
# Include{serviceList}
- variable: persistence
label: "Integrated Persistent Storage"
description: "Integrated Persistent Storage"
group: "Storage and Persistence"
schema:
type: dict
attrs:
- variable: sigdatabase
label: "App Signature Database Storage"
description: "Stores the Application Signature Database."
schema:
type: dict
attrs:
- variable: type
label: "Type of Storage"
description: "Sets the persistence type, Anything other than PVC could break rollback!"
schema:
type: string
default: "simplePVC"
enum:
- value: "simplePVC"
description: "PVC (simple)"
- value: "simpleHP"
description: "HostPath (simple)"
- value: "emptyDir"
description: "emptyDir"
- value: "pvc"
description: "pvc"
- value: "hostPath"
description: "hostPath"
# Include{persistenceBasic}
- variable: hostPath
label: "hostPath"
description: "Path inside the container the storage is mounted"
schema:
show_if: [["type", "=", "hostPath"]]
type: hostpath
- variable: medium
label: "EmptyDir Medium"
schema:
show_if: [["type", "=", "emptyDir"]]
type: string
default: ""
enum:
- value: ""
description: "Default"
- value: "Memory"
description: "Memory"
# Include{persistenceAdvanced}
- variable: scandir
label: "App Scan Dir Storage"
description: "Stores the Application Scan Directory."
schema:
type: dict
attrs:
- variable: type
label: "Type of Storage"
description: "Sets the persistence type, Anything other than PVC could break rollback!"
schema:
type: string
default: "simplePVC"
enum:
- value: "simplePVC"
description: "PVC (simple)"
- value: "simpleHP"
description: "HostPath (simple)"
- value: "emptyDir"
description: "emptyDir"
- value: "pvc"
description: "pvc"
- value: "hostPath"
description: "hostPath"
# Include{persistenceBasic}
- variable: hostPath
label: "hostPath"
description: "Path inside the container the storage is mounted"
schema:
show_if: [["type", "=", "hostPath"]]
type: hostpath
- variable: medium
label: "EmptyDir Medium"
schema:
show_if: [["type", "=", "emptyDir"]]
type: string
default: ""
enum:
- value: ""
description: "Default"
- value: "Memory"
description: "Memory"
# Include{persistenceAdvanced}
# Include{persistenceList}
- variable: ingress
label: ""
group: "Ingress"
schema:
type: dict
attrs:
- variable: main
label: "Main Ingress"
schema:
type: dict
attrs:
# Include{ingressDefault}
# Include{ingressTLS}
# Include{ingressTraefik}
# Include{ingressExpert}
# Include{ingressList}
- variable: advancedSecurity
label: "Show Advanced Security Settings"
group: "Security and Permissions"
schema:
type: boolean
default: false
show_subquestions_if: true
subquestions:
- variable: securityContext
label: "Security Context"
schema:
type: dict
attrs:
- variable: privileged
label: "Privileged mode"
schema:
type: boolean
default: false
- variable: readOnlyRootFilesystem
label: "ReadOnly Root Filesystem"
schema:
type: boolean
default: false
- variable: allowPrivilegeEscalation
label: "Allow Privilege Escalation"
schema:
type: boolean
default: false
- variable: runAsNonRoot
label: "runAsNonRoot"
schema:
type: boolean
default: false
# Include{securityContextAdvanced}
- variable: podSecurityContext
group: "Security and Permissions"
label: "Pod Security Context"
schema:
type: dict
attrs:
- variable: runAsUser
label: "runAsUser"
description: "The UserID of the user running the application"
schema:
type: int
default: 0
- variable: runAsGroup
label: "runAsGroup"
description: The groupID this App of the user running the application"
schema:
type: int
default: 0
- variable: fsGroup
label: "fsGroup"
description: "The group that should own ALL storage."
schema:
type: int
default: 568
# Include{podSecurityContextAdvanced}
# Include{resources}
# Include{advanced}
# Include{addons}
@@ -0,0 +1 @@
{{ include "common.all" . }}
+75
View File
@@ -0,0 +1,75 @@
image:
repository: tccr.io/truecharts/clamav
pullPolicy: IfNotPresent
tag: v0.104.2@sha256:9b600aac57738b292236fc534220b317ee3185fc96d0a995e08f44b19c4dcb25
podSecurityContext:
runAsUser: 0
runAsGroup: 0
securityContext:
readOnlyRootFilesystem: false
runAsNonRoot: false
probes:
liveness:
enabled: true
custom: true
spec:
exec:
command:
- clamdcheck.sh
initialDelaySeconds: 15
periodSeconds: 30
failureThreshold: 10
timeoutSeconds: 1
readiness:
enabled: true
custom: true
spec:
exec:
command:
- clamdcheck.sh
initialDelaySeconds: 15
periodSeconds: 30
failureThreshold: 10
timeoutSeconds: 1
startup:
enabled: true
custom: true
spec:
exec:
command:
- clamdcheck.sh
initialDelaySeconds: 15
periodSeconds: 30
failureThreshold: 10
timeoutSeconds: 1
service:
main:
ports:
main:
port: 3310
targetPort: 3310
milter:
ports:
milter:
port: 7357
targetPort: 7357
env:
CLAMAV_NO_CLAMD: false
CLAMAV_NO_FRESHCLAMD: false
CLAMAV_NO_MILTERD: true
CLAMD_STARTUP_TIMEOUT: 1800
FRESHCLAM_CHECKS: 1
persistence:
sigdatabase:
enabled: true
mountPath: "/var/lib/clamav"
scandir:
enabled: true
mountPath: "/scandir"
readOnly: true
Binary file not shown.

After

Width:  |  Height:  |  Size: 25 KiB

+4 -1
View File
@@ -62,6 +62,7 @@ These defaults can of course be changed, but as we guarantee "sane, working defa
| loki | main | main | 3100 | HTTP | |
| jdownloader2 | myjd | myjd | 3129 | TCP | |
| pylon | main | main | 3131 | TCP | |
| clamav | main | main | 3310 | TCP | |
| unifi | stun | mstunain | 3478 | UDP | |
| logitech-media-server | playertcp | slimprototcp | 3483 | TCP | |
| logitech-media-server | playerudp | slimprotoudp | 3483 | UDP | |
@@ -93,6 +94,7 @@ These defaults can of course be changed, but as we guarantee "sane, working defa
| qbittorrent | torrentudp | torrentudp | 6881 | UDP | |
| aria2 | listen | listen | 6888 | TCP | |
| logitech-media-server | main | main | 7000 | TCP | |
| clamav | milter | milter | 7357 | TCP | |
| foldingathome | main | main | 7396 | TCP | |
| haste-server | main | main | 7777 | TCP | |
| nextcloud | hpb | hpb | 7867 | TCP | |
@@ -368,7 +370,7 @@ These defaults can of course be changed, but as we guarantee "sane, working defa
## Ports that are blocked in major web browsers
| Port | Used by (example) |
| :---: | :---: |
| :---: | :--------------------------------------: |
| 1 | tcpmux |
| 7 | echo |
| 9 | discard |
@@ -449,6 +451,7 @@ These defaults can of course be changed, but as we guarantee "sane, working defa
| 6669 | Alternate IRC [Apple addition] |
| 6697 | IRC + TLS |
| 10080 | Amanda |
##### Note: TCP and UDP ports that are the same in some Apps, are not by mistake.
##### If you notice a port conflict, please notify us so we can resolve it (when possible).