Docker image for ClamAV with unofficial signatures via fangfrisch.
_FILE environment variables| Tag | OS | Description |
|---|---|---|
latest | Alpine 3.23 | Latest stable Alpine build |
alpine-latest | Alpine 3.23 | Latest Alpine build |
alpine-3.23-1.4.3-1.9.2-2 | Alpine 3.23 | Versioned Alpine build |
1.4.3-alpine | Alpine | ClamAV version specific |
ubuntu-latest | Ubuntu 24.04 | Latest Ubuntu build |
ubuntu-24.04-1.4.3-1.9.2-1 | Ubuntu 24.04 | Versioned Ubuntu build |
1.4.3-ubuntu | Ubuntu | ClamAV version specific |
Git tags use / as separator for clarity with version numbers containing -:
<os_flavor>/<os_version>/<clamav_version>/<fangfrisch_version>/<build>
Examples:
alpine/3.23/1.4.3/1.9.2/1ubuntu/24.04/1.4.3/1.9.2/1docker run -d \
--name clamav \
-p 3310:3310 \
-v clamav_data:/clamav/data \
ghcr.io/jloehel/clamav:latest
services:
clamav:
image: ghcr.io/jloehel/clamav:latest
container_name: clamav
restart: unless-stopped
volumes:
- clamav_data:/clamav/data
ports:
- "127.0.0.1:3310:3310"
environment:
# Optional: Adjust log level
- FANGFRISCH_LOG_LEVEL=INFO
# Optional: SecuriteInfo credentials
# - SECURITEINFO_CUSTOMER_ID=your_customer_id
healthcheck:
test: ["CMD", "/healthcheck.sh"]
interval: 30s
timeout: 10s
retries: 3
start_period: 120s
volumes:
clamav_data:
services:
clamav:
image: ghcr.io/jloehel/clamav:latest
volumes:
- clamav_data:/clamav/data
networks:
- internal
secrets:
- securiteinfo_customer_id
environment:
- SECURITEINFO_CUSTOMER_ID_FILE=/run/secrets/securiteinfo_customer_id
deploy:
replicas: 1
restart_policy:
condition: on-failure
delay: 5s
max_attempts: 3
resources:
limits:
memory: 2G
reservations:
memory: 512M
healthcheck:
test: ["CMD", "/healthcheck.sh"]
interval: 30s
timeout: 10s
retries: 3
start_period: 120s
volumes:
clamav_data:
networks:
internal:
driver: overlay
secrets:
securiteinfo_customer_id:
external: true
| Variable | Default | Description |
|---|---|---|
DISABLE_WELCOME_MESSAGE | false | Disable welcome banner |
BASH_DEBUG | false | Enable debug output |
| Variable | Default | Description |
|---|---|---|
FANGFRISCH_LOG_LEVEL | INFO | Log level: DEBUG, INFO, WARNING, ERROR, FATAL |
FANGFRISCH_MAX_SIZE | 10MB | Default maximum file size |
FANGFRISCH_ON_UPDATE_EXEC | clamdscan --reload | Command to run after signature updates |
FANGFRISCH_ON_UPDATE_TIMEOUT | 60 | Timeout for on_update_exec in seconds |
FANGFRISCH_CONNECTION_TIMEOUT | (not set) | Network connection timeout in seconds |
FANGFRISCH_DB_PATH | /var/lib/fangfrisch/db.sqlite | SQLite database path |
FANGFRISCH_LOCAL_DIRECTORY | /clamav/data/unofficial | Directory for unofficial signatures |
These providers are enabled by default and do not require credentials.
Community-maintained signatures with broad coverage.
| Variable | Default | Description |
|---|---|---|
SANESECURITY_ENABLED | true | Enable/disable provider |
SANESECURITY_INTERVAL | 1h | Update interval |
SANESECURITY_PREFIX | (fangfrisch default) | Custom mirror URL |
Abuse.ch malware URL database - frequently updated.
| Variable | Default | Description |
|---|---|---|
URLHAUS_ENABLED | true | Enable/disable provider |
URLHAUS_INTERVAL | 10m | Update interval |
URLHAUS_MAX_SIZE | 5MB | Maximum file size |
InterServer security signatures.
| Variable | Default | Description |
|---|---|---|
INTERSERVER_ENABLED | true | Enable/disable provider |
INTERSERVER_INTERVAL | 1h | Update interval |
These providers require credentials. They are enabled by default but will only be activated if credentials are provided.
Commercial malware signature database.
| Variable | Default | Description |
|---|---|---|
MALWAREPATROL_ENABLED | true | Enable/disable provider |
MALWAREPATROL_RECEIPT | (required) | MalwarePatrol receipt code |
MALWAREPATROL_PRODUCT | 8 | MalwarePatrol product code |
MALWAREPATROL_INTERVAL | 1d | Update interval |
Commercial security signatures with extended coverage.
| Variable | Default | Description |
|---|---|---|
SECURITEINFO_ENABLED | true | Enable/disable provider |
SECURITEINFO_CUSTOMER_ID | (required) | SecuriteInfo customer ID |
SECURITEINFO_INTERVAL | 1h | Update interval |
SECURITEINFO_MAX_SIZE | 20MB | Maximum file size |
All credential variables support the _FILE suffix for Docker secrets:
services:
clamav:
secrets:
- securiteinfo_customer_id
- malwarepatrol_receipt
environment:
- SECURITEINFO_CUSTOMER_ID_FILE=/run/secrets/securiteinfo_customer_id
- MALWAREPATROL_RECEIPT_FILE=/run/secrets/malwarepatrol_receipt
secrets:
securiteinfo_customer_id:
external: true
malwarepatrol_receipt:
external: true
services:
ocis:
environment:
ANTIVIRUS_SCANNER_TYPE: "clamav"
ANTIVIRUS_CLAMAV_SOCKET: "tcp://clamav:3310"
| Path | Description |
|---|---|
/clamav/data | Database directory (official + unofficial signatures) |
The volume contains:
/clamav/data/official/ - Official ClamAV signatures (freshclam)/clamav/data/unofficial/ - Unofficial signatures (fangfrisch)| Port | Description |
|---|---|
3310/tcp | ClamAV daemon TCP socket |
./docker_build.sh
OS_FLAVOR=ubuntu OS_VERSION=24.04 ./docker_build.sh
export OS_FLAVOR=alpine
export OS_VERSION=3.23
export APP_VERSION=1.4.3
export FANGFRISCH_VERSION=1.9.2
./docker_build.sh
overlay/
├── alpine/
│ └── etc/clamav/
│ ├── clamd.conf
│ └── freshclam.conf
├── base/
│ ├── build/
│ │ ├── clean.sh
│ │ ├── dependencies/
│ │ ├── install-app.sh
│ │ ├── install-dependencies.sh
│ │ └── update.sh
│ ├── clamav/data/
│ ├── entrypoint.sh
│ ├── healthcheck.sh
│ ├── opt/
│ │ ├── base/functions
│ │ └── fangfrisch/
│ │ ├── fangfrisch.conf.j2
│ │ └── generate_config.py
│ └── run.sh
└── ubuntu/
└── etc/clamav/
├── clamd.conf
└── freshclam.conf
The fangfrisch configuration is generated at container startup using a Jinja2 template. This allows:
The template is located at /opt/fangfrisch/fangfrisch.conf.j2 and can be replaced via volume mount for advanced customization.
This image previously used clamav-unofficial-sigs. It has been migrated to fangfrisch because:
If you're upgrading from a version using clamav-unofficial-sigs:
| Old Variable | New Variable |
|---|---|
SECURITEINFO_AUTHORISATION_SIGNATURE | SECURITEINFO_CUSTOMER_ID |
MALWAREPATROL_RECEIPT_CODE | MALWAREPATROL_RECEIPT |
MALWAREPATROL_PRODUCT_CODE | MALWAREPATROL_PRODUCT |
Additional changes:
MIT License - See LICENSE for details.
Content type
Image
Digest
sha256:7d0fdd8a4…
Size
65.6 MB
Last updated
6 days ago
docker pull jloehel/clamav