Sign inSign up

encircle/restingclam

By encircle

•Updated over 3 years ago

Image
0

6.4K

encircle/restingclam repository overview

⁠Resting Clam

This repo contains the source code for the clamd/flask based antivirus rest API.

⁠Default Settings

Host:    localhost
Port:    8433
API Key: helloworld

⁠Getting Started

Change directory into the repo root directory.

cd restingclam

Run the stack.

docker-compose up -d

Execute a test request to ensure the API is functioning.

It takes a while for clamd to start, during this time a 502 will be returned

curl -k -H 'X-API-Key: helloworld' https://localhost:8433/heartbeat

The response should be 200 status code.

⁠Scan a test file

Nice file:

curl -X POST --form "data=@testfiles/good.txt" -k -H 'X-Api-Key: helloworld' https://localhost:8433/scan

Bad file:

curl -X POST --form "data=@testfiles/bad.txt" -k -H 'X-Api-Key: helloworld' https://localhost:8433/scan

Example output:

{"task_id":"a7c716d5-6823-444b-9346-cde7b632a568"}

⁠Check the result

curl -s -k -H 'X-Api-Key: helloworld' https://localhost:8433/task?id=a7c716d5-6823-444b-9346-cde7b632a568 | jq -r '.task_result'

An OK task result means the file has been flagged as clean. A NOTOK task result means the file has been flagged as a virus.

⁠Notes

  • File scanning is asynchronous (via celery tasks), to avoid gunicorn threads being occupied for long periods of time
  • Files are placed in /data/scandir (mounted as ./scandir for persistence) for scanning
  • Bad files are preserved within the scandir, for analysis if needed
  • Good files are removed from the scandir, to conserve space

Tag summary

Content type

Image

Digest

sha256:00da5c042…

Size

289 MB

Last updated

over 3 years ago

docker pull encircle/restingclam