Sign inSign up

jloehel/clamav

By jloehel

•Updated 6 days ago

Docker image for clamav + fangfrisch

Image
0

4.3K

jloehel/clamav repository overview

⁠Docker ClamAV

Release Build Weekly Build

Docker image for ClamAV with unofficial signatures via fangfrisch⁠.

⁠Features

  • Multi-OS Support: Alpine Linux and Ubuntu
  • Multi-Architecture: amd64 and arm64
  • Unofficial Signatures: Integrated fangfrisch for extended malware detection
  • Rootless Support: NSS wrapper for OpenShift/Kubernetes compatibility
  • Docker Secrets: Support for sensitive configuration via _FILE environment variables
  • Weekly Rebuilds: Automated weekly builds via GitHub Actions
  • Dynamic Configuration: Fangfrisch config generated at runtime via Jinja2 templates

⁠Supported Tags

TagOSDescription
latestAlpine 3.23Latest stable Alpine build
alpine-latestAlpine 3.23Latest Alpine build
alpine-3.23-1.4.3-1.9.2-2Alpine 3.23Versioned Alpine build
1.4.3-alpineAlpineClamAV version specific
ubuntu-latestUbuntu 24.04Latest Ubuntu build
ubuntu-24.04-1.4.3-1.9.2-1Ubuntu 24.04Versioned Ubuntu build
1.4.3-ubuntuUbuntuClamAV version specific
⁠Git Tag Format

Git tags use / as separator for clarity with version numbers containing -:

<os_flavor>/<os_version>/<clamav_version>/<fangfrisch_version>/<build>

Examples:

  • alpine/3.23/1.4.3/1.9.2/1
  • ubuntu/24.04/1.4.3/1.9.2/1

⁠Quick Start

docker run -d \
  --name clamav \
  -p 3310:3310 \
  -v clamav_data:/clamav/data \
  ghcr.io/jloehel/clamav:latest

⁠Docker Compose

services:
  clamav:
    image: ghcr.io/jloehel/clamav:latest
    container_name: clamav
    restart: unless-stopped
    volumes:
      - clamav_data:/clamav/data
    ports:
      - "127.0.0.1:3310:3310"
    environment:
      # Optional: Adjust log level
      - FANGFRISCH_LOG_LEVEL=INFO
      # Optional: SecuriteInfo credentials
      # - SECURITEINFO_CUSTOMER_ID=your_customer_id
    healthcheck:
      test: ["CMD", "/healthcheck.sh"]
      interval: 30s
      timeout: 10s
      retries: 3
      start_period: 120s

volumes:
  clamav_data:

⁠Docker Swarm Stack

services:
  clamav:
    image: ghcr.io/jloehel/clamav:latest
    volumes:
      - clamav_data:/clamav/data
    networks:
      - internal
    secrets:
      - securiteinfo_customer_id
    environment:
      - SECURITEINFO_CUSTOMER_ID_FILE=/run/secrets/securiteinfo_customer_id
    deploy:
      replicas: 1
      restart_policy:
        condition: on-failure
        delay: 5s
        max_attempts: 3
      resources:
        limits:
          memory: 2G
        reservations:
          memory: 512M
    healthcheck:
      test: ["CMD", "/healthcheck.sh"]
      interval: 30s
      timeout: 10s
      retries: 3
      start_period: 120s

volumes:
  clamav_data:

networks:
  internal:
    driver: overlay

secrets:
  securiteinfo_customer_id:
    external: true

⁠Environment Variables

⁠General Settings
VariableDefaultDescription
DISABLE_WELCOME_MESSAGEfalseDisable welcome banner
BASH_DEBUGfalseEnable debug output
⁠Fangfrisch General Settings
VariableDefaultDescription
FANGFRISCH_LOG_LEVELINFOLog level: DEBUG, INFO, WARNING, ERROR, FATAL
FANGFRISCH_MAX_SIZE10MBDefault maximum file size
FANGFRISCH_ON_UPDATE_EXECclamdscan --reloadCommand to run after signature updates
FANGFRISCH_ON_UPDATE_TIMEOUT60Timeout for on_update_exec in seconds
FANGFRISCH_CONNECTION_TIMEOUT(not set)Network connection timeout in seconds
FANGFRISCH_DB_PATH/var/lib/fangfrisch/db.sqliteSQLite database path
FANGFRISCH_LOCAL_DIRECTORY/clamav/data/unofficialDirectory for unofficial signatures
⁠Free Signature Providers

These providers are enabled by default and do not require credentials.

⁠Sanesecurity

Community-maintained signatures with broad coverage.

VariableDefaultDescription
SANESECURITY_ENABLEDtrueEnable/disable provider
SANESECURITY_INTERVAL1hUpdate interval
SANESECURITY_PREFIX(fangfrisch default)Custom mirror URL
⁠URLhaus

Abuse.ch malware URL database - frequently updated.

VariableDefaultDescription
URLHAUS_ENABLEDtrueEnable/disable provider
URLHAUS_INTERVAL10mUpdate interval
URLHAUS_MAX_SIZE5MBMaximum file size
⁠InterServer

InterServer security signatures.

VariableDefaultDescription
INTERSERVER_ENABLEDtrueEnable/disable provider
INTERSERVER_INTERVAL1hUpdate interval
⁠Premium Signature Providers

These providers require credentials. They are enabled by default but will only be activated if credentials are provided.

⁠MalwarePatrol

Commercial malware signature database.

VariableDefaultDescription
MALWAREPATROL_ENABLEDtrueEnable/disable provider
MALWAREPATROL_RECEIPT(required)MalwarePatrol receipt code
MALWAREPATROL_PRODUCT8MalwarePatrol product code
MALWAREPATROL_INTERVAL1dUpdate interval
⁠SecuriteInfo

Commercial security signatures with extended coverage.

VariableDefaultDescription
SECURITEINFO_ENABLEDtrueEnable/disable provider
SECURITEINFO_CUSTOMER_ID(required)SecuriteInfo customer ID
SECURITEINFO_INTERVAL1hUpdate interval
SECURITEINFO_MAX_SIZE20MBMaximum file size
⁠Docker Secrets

All credential variables support the _FILE suffix for Docker secrets:

services:
  clamav:
    secrets:
      - securiteinfo_customer_id
      - malwarepatrol_receipt
    environment:
      - SECURITEINFO_CUSTOMER_ID_FILE=/run/secrets/securiteinfo_customer_id
      - MALWAREPATROL_RECEIPT_FILE=/run/secrets/malwarepatrol_receipt

secrets:
  securiteinfo_customer_id:
    external: true
  malwarepatrol_receipt:
    external: true

⁠Integration with ownCloud OCIS

services:
  ocis:
    environment:
      ANTIVIRUS_SCANNER_TYPE: "clamav"
      ANTIVIRUS_CLAMAV_SOCKET: "tcp://clamav:3310"

⁠Volumes

PathDescription
/clamav/dataDatabase directory (official + unofficial signatures)

The volume contains:

  • /clamav/data/official/ - Official ClamAV signatures (freshclam)
  • /clamav/data/unofficial/ - Unofficial signatures (fangfrisch)

⁠Ports

PortDescription
3310/tcpClamAV daemon TCP socket

⁠Building Locally

⁠Alpine (default)
./docker_build.sh
⁠Ubuntu
OS_FLAVOR=ubuntu OS_VERSION=24.04 ./docker_build.sh
⁠With specific versions
export OS_FLAVOR=alpine
export OS_VERSION=3.23
export APP_VERSION=1.4.3
export FANGFRISCH_VERSION=1.9.2
./docker_build.sh

⁠Directory Structure

overlay/
├── alpine/
│   └── etc/clamav/
│       ├── clamd.conf
│       └── freshclam.conf
├── base/
│   ├── build/
│   │   ├── clean.sh
│   │   ├── dependencies/
│   │   ├── install-app.sh
│   │   ├── install-dependencies.sh
│   │   └── update.sh
│   ├── clamav/data/
│   ├── entrypoint.sh
│   ├── healthcheck.sh
│   ├── opt/
│   │   ├── base/functions
│   │   └── fangfrisch/
│   │       ├── fangfrisch.conf.j2
│   │       └── generate_config.py
│   └── run.sh
└── ubuntu/
    └── etc/clamav/
        ├── clamd.conf
        └── freshclam.conf

⁠Configuration Architecture

The fangfrisch configuration is generated at container startup using a Jinja2 template. This allows:

  1. Dynamic configuration based on environment variables
  2. Docker Secrets support for sensitive credentials
  3. Extensibility for future ClamAV configuration templating

The template is located at /opt/fangfrisch/fangfrisch.conf.j2 and can be replaced via volume mount for advanced customization.

⁠Migration from clamav-unofficial-sigs

This image previously used clamav-unofficial-sigs⁠. It has been migrated to fangfrisch⁠ because:

  • fangfrisch is actively maintained (last update 2025)
  • clamav-unofficial-sigs was last updated in 2021
  • fangfrisch uses efficient digest-based downloads
  • fangfrisch has cleaner state management via SQLite
⁠Breaking Changes

If you're upgrading from a version using clamav-unofficial-sigs:

Old VariableNew Variable
SECURITEINFO_AUTHORISATION_SIGNATURESECURITEINFO_CUSTOMER_ID
MALWAREPATROL_RECEIPT_CODEMALWAREPATROL_RECEIPT
MALWAREPATROL_PRODUCT_CODEMALWAREPATROL_PRODUCT

Additional changes:

  • Whitelist functionality is not yet available
  • The unofficial signatures directory structure has changed
  • Configuration is now generated via Jinja2 template

⁠License

MIT License - See LICENSE⁠ for details.

⁠Credits

Tag summary

Content type

Image

Digest

sha256:7d0fdd8a4…

Size

65.6 MB

Last updated

6 days ago

docker pull jloehel/clamav