ClamAV
| Description / name | Input element |
|---|---|
| Container Registry | |
| Container Configuration Root Path | |
| Timezone | |
| User ID | |
| Group ID | |
| ClamAV Host Port | |
| ClamAV /config Path |
Open-source anti-virus engine: clamd scans files and mail over TCP, with freshclam keeping signatures current.
| Port | 3310 |
| Registry | ghcr.io/daemonless/clamav |
| Daemonless | daemonless/clamav |
| Source | Cisco-Talos/clamav |
| Website | www.clamav.net |
Version Tags
Multi-arch manifests — resolve automatically to the right image for your platform.
| Tag | Description | Best For |
|---|---|---|
pkg |
FreeBSD Quarterly. Uses stable, tested packages. | Production stability. |
latest / pkg-latest |
FreeBSD Latest. Rolling package updates. | Staying current. |
| Tag | Description | Best For |
|---|---|---|
pkg-amd64 |
FreeBSD Quarterly. Uses stable, tested packages. | Production stability. |
latest-amd64 / pkg-latest-amd64 |
FreeBSD Latest. Rolling package updates. | Staying current. |
| Tag | Description | Best For |
|---|---|---|
pkg-aarch64 |
FreeBSD Quarterly. Uses stable, tested packages. | Production stability. |
latest-aarch64 / pkg-latest-aarch64 |
FreeBSD Latest. Rolling package updates. | Staying current. |
Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.
Deployment
Save as compose.yaml, then run podman-compose up -d.
Save as run.sh, then run sh run.sh.
Save as clamav-deploy.yaml, then run ansible-playbook clamav-deploy.yaml.
Warning
Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.
Save the files above, then run appjail-director up.
Save the files above, then run sh run.sh.
Experimental
Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.
Save as bastille-compose.yml, then run bastille up.
Interactive Configuration
Parameters
Environment Variables
| Variable | Default | Description |
|---|---|---|
PUID |
1000 |
User ID for the application process |
PGID |
1000 |
Group ID for the application process |
TZ |
UTC |
Timezone for the container |
CLAMAV_OFFLINE |
`` | Set to true to disable freshclam (air-gapped hosts). clamd then keeps using the signatures shipped in the image, or whatever you put in /config/db. |
Volumes
| Path | Description |
|---|---|
/config |
clamd.conf, freshclam.conf and the signature database (db/) |
Ports
| Port | Protocol | Description |
|---|---|---|
3310 |
TCP | clamd TCP socket (INSTREAM scanning) |
7357 |
TCP | clamav-milter, for MTAs such as Stalwart or Postfix |
First start
The image ships a signature database. On first start it is copied into
/config/db, so clamd is scanning within seconds, and freshclam then
brings it up to date. Keep /config on a persistent volume: ClamAV's
mirrors rate-limit hosts that re-download the whole database repeatedly.
Connecting
Scanners talk to clamd directly on TCP port 3310. Mail servers that speak
the milter protocol (Stalwart, Postfix, Sendmail) use clamav-milter on
port 7357 instead; it rejects infected messages during the SMTP session.
To check clamd from the host:
podman exec clamav clamdscan --ping 1 --config-file=/config/clamd.conf.
Memory
clamd keeps every signature in RAM, and while it reloads after an update it briefly holds two copies. Give the container a few GB of headroom.
Implementation Details
- Architectures: amd64, aarch64
- User:
bsd(UID/GID set via PUID/PGID). Defaults to1000:1000. - Base: Built on
ghcr.io/daemonless/base(FreeBSD 15.1).
Need help? Join our Discord community.