clamav

Automates the installation, scanning, and reporting of ClamAV antivirus software.

Maintainer

Igor Aleksandrychev

Module stats

Total Downloads: 0
Updated: Aug 28, 2026

Installation version

Version
Released on Aug 28, 2026

Tags

Installation

                    
cfbs add clamav@0.0.1
Description
Dependencies
Discussion

cfengine-clamav

CFEngine build module that installs ClamAV from upstream packages, keeps its signatures fresh, runs periodic scans, and reports the results as CFEngine Enterprise inventory.

Mission Portal inventory

What it does

  • Installs the upstream ClamAV .deb/.rpm from clamav.net (Debian/Ubuntu and RHEL-family, x86_64/aarch64) and creates the clamav user.
  • Runs freshclam when signatures are older than 48 hours (configurable).
  • Runs clamscan over /home, /root, /tmp, /var/tmp when the last report is older than 3 days (configurable).
  • Parses the scan log and inventories: engine version, signature count, scanned files, infected files, data scanned, last scan time, signature freshness, and detected threats. Infections are reported as an alert on every run.

Only Linux is supported. Windows support is coming soon.

Installation

cfbs add clamav
cfbs build

Configuration

Override defaults via augments, e.g.:

{
  "variables": {
    "clamav:globals.clamav_version": "1.5.4",
    "clamav:globals.max_age_days": "1",
    "clamav:globals.signature_max_age_hours": "24",
    "clamav:globals.scan_target_linux": ["/home", "/srv"]
  }
}

Trigger actions immediately:

cf-agent -KI --define clamav:want_scan_now      # force a scan
cf-agent -KI --define clamav:want_freshen_now   # force a signature update

Notes

  • clamscan and freshclam load the full signature database into memory, ensure at least ~2 GB of available RAM on scanned hosts.
  • On Debian/Ubuntu, the distro’s clamav-freshclam daemon locks the signature database while running, which causes the module’s freshclam runs to fail. Disable it with systemctl disable --now clamav-freshclam if CFEngine should manage updates.

Dependencies

This module has no dependencies