Name Mode Size
..
7z 040000
c++ 040000
jsparse 040000
lzw 040000
nsis 040000
regex 040000
tomsfastmath 040000
7z_iface.c 100644 7 kb
7z_iface.h 100644 1 kb
CMakeLists.txt 100644 20 kb
Doxyfile 100644 4 kb
adc.c 100644 10 kb
adc.h 100644 2 kb
apm.c 100644 12 kb
apm.h 100644 4 kb
arc4.c 100644 3 kb
arc4.h 100644 1 kb
asn1.c 100644 99 kb
asn1.h 100644 1 kb
aspack.c 100644 16 kb
aspack.h 100644 1 kb
autoit.c 100644 48 kb
autoit.h 100644 1 kb
bcfeatures.h 100644 2 kb
bignum.h 100644 1 kb
bignum_fast.h 100644 14 kb
binhex.c 100644 10 kb
binhex.h 100644 1 kb
blob.c 100644 16 kb
blob.h 100644 3 kb
builtin_bytecodes.h 100644 12 kb
bytecode.c 100644 124 kb
bytecode.h 100644 6 kb
bytecode_api.c 100644 70 kb
bytecode_api.h 100644 48 kb
bytecode_api_decl.c 100644 22 kb
bytecode_api_impl.h 100644 10 kb
bytecode_detect.c 100644 9 kb
bytecode_detect.h 100644 4 kb
bytecode_hooks.h 100644 2 kb
bytecode_nojit.c 100644 3 kb
bytecode_priv.h 100644 6 kb
bytecode_vm.c 100644 53 kb
cache.c 100644 29 kb
cache.h 100644 1 kb
clamav.h 100644 60 kb
clambc.h 100644 3 kb
conv.c 100644 5 kb
conv.h 100644 1 kb
cpio.c 100644 11 kb
cpio.h 100644 1 kb
crtmgr.c 100644 20 kb
crtmgr.h 100644 3 kb
crypto.c 100644 26 kb
cvd.c 100644 21 kb
cvd.h 100644 2 kb
dconf.c 100644 16 kb
dconf.h 100644 5 kb
default.h 100644 2 kb
disasm-common.h 100644 17 kb
disasm.c 100644 87 kb
disasm.h 100644 1 kb
disasmpriv.h 100644 2 kb
dlp.c 100644 22 kb
dlp.h 100644 5 kb
dmg.c 100644 43 kb
dmg.h 100644 4 kb
dsig.c 100644 6 kb
dsig.h 100644 1 kb
egg.c 100644 95 kb
egg.h 100644 4 kb
elf.c 100644 31 kb
elf.h 100644 4 kb
encoding_aliases.h 100644 2 kb
entconv.c 100644 40 kb
entconv.h 100644 14 kb
entitylist.h 100644 41 kb
events.c 100644 14 kb
events.h 100644 4 kb
execs.c 100644 2 kb
execs.h 100644 6 kb
explode.c 100644 12 kb
explode.h 100644 2 kb
filetypes.c 100644 20 kb
filetypes.h 100644 4 kb
filetypes_int.h 100644 14 kb
filtering.c 100644 26 kb
filtering.h 100644 2 kb
fmap.c 100644 33 kb
fmap.h 100644 16 kb
fpu.c 100644 2 kb
fpu.h 100644 1 kb
fsg.c 100644 4 kb
fsg.h 100644 1 kb
gif.c 100644 17 kb
gif.h 100644 1 kb
gpt.c 100644 24 kb
gpt.h 100644 3 kb
hashtab.c 100644 31 kb
hashtab.h 100644 6 kb
hfsplus.c 100644 65 kb
hfsplus.h 100644 10 kb
hostid_internal.c 100644 7 kb
hostid_internal.h 100644 1 kb
htmlnorm.c 100644 83 kb
htmlnorm.h 100644 2 kb
hwp.c 100644 79 kb
hwp.h 100644 2 kb
iana_cctld.h 100644 11 kb
iana_tld.h 100644 19 kb
inffixed64.h 100644 8 kb
inflate64.c 100644 42 kb
inflate64.h 100644 3 kb
inflate64_priv.h 100644 8 kb
iowrap.c 100644 2 kb
iowrap.h 100644 1 kb
is_tar.c 100644 2 kb
is_tar.h 100644 1 kb
ishield.c 100644 29 kb
ishield.h 100644 1 kb
iso9660.c 100644 12 kb
iso9660.h 100644 1 kb
jpeg.c 100644 29 kb
jpeg.h 100644 1 kb
json_api.c 100644 14 kb
json_api.h 100644 4 kb
libclamav.map 100644 6 kb
libclamav_main.c 100644 2 kb
libmspack.c 100644 16 kb
libmspack.h 100644 0 kb
line.c 100644 3 kb
line.h 100644 2 kb
lzma_iface.c 100644 4 kb
lzma_iface.h 100644 2 kb
macho.c 100644 21 kb
macho.h 100644 1 kb
matcher-ac.c 100644 106 kb
matcher-ac.h 100644 5 kb
matcher-bm.c 100644 15 kb
matcher-bm.h 100644 2 kb
matcher-byte-comp.c 100644 38 kb
matcher-byte-comp.h 100644 3 kb
matcher-hash.c 100644 10 kb
matcher-hash.h 100644 2 kb
matcher-pcre.c 100644 31 kb
matcher-pcre.h 100644 3 kb
matcher.c 100644 52 kb
matcher.h 100644 13 kb
mbox.c 100644 155 kb
mbox.h 100644 2 kb
mbr.c 100644 21 kb
mbr.h 100644 2 kb
message.c 100644 77 kb
message.h 100644 4 kb
mew.c 100644 31 kb
mew.h 100644 1 kb
mpool.c 100644 20 kb
mpool.h 100644 3 kb
msdoc.c 100644 33 kb
msdoc.h 100644 5 kb
msexpand.c 100644 5 kb
msexpand.h 100644 1 kb
msxml.c 100644 9 kb
msxml.h 100644 2 kb
msxml_parser.c 100644 25 kb
msxml_parser.h 100644 2 kb
ole2_extract.c 100644 66 kb
ole2_extract.h 100644 1 kb
ooxml.c 100644 19 kb
ooxml.h 100644 1 kb
openioc.c 100644 11 kb
openioc.h 100644 1 kb
others.c 100644 60 kb
others.h 100644 45 kb
others_common.c 100644 45 kb
packlibs.c 100644 11 kb
packlibs.h 100644 1 kb
partition_intersection.c 100644 3 kb
partition_intersection.h 100644 2 kb
pdf.c 100644 157 kb
pdf.h 100644 8 kb
pdfdecode.c 100644 39 kb
pdfdecode.h 100644 3 kb
pdfng.c 100644 31 kb
pe.c 100644 219 kb
pe.h 100644 4 kb
pe_icons.c 100644 80 kb
pe_icons.h 100644 1 kb
pe_structs.h 100644 5 kb
perflogging.c 100644 4 kb
perflogging.h 100644 3 kb
petite.c 100644 20 kb
petite.h 100644 1 kb
phish_allow_list.c 100644 3 kb
phish_allow_list.h 100644 1 kb
phish_domaincheck_db.c 100644 2 kb
phish_domaincheck_db.h 100644 1 kb
phishcheck.c 100644 55 kb
phishcheck.h 100644 3 kb
png.c 100644 17 kb
png.h 100644 1 kb
qsort.c 100644 9 kb
queue.h 100644 24 kb
readdb.c 100644 193 kb
readdb.h 100644 6 kb
rebuildpe.c 100644 8 kb
rebuildpe.h 100644 1 kb
regex_list.c 100644 26 kb
regex_list.h 100644 2 kb
regex_pcre.c 100644 16 kb
regex_pcre.h 100644 3 kb
regex_suffix.c 100644 14 kb
regex_suffix.h 100644 2 kb
rijndael.c 100644 55 kb
rijndael.h 100644 1 kb
rtf.c 100644 25 kb
rtf.h 100644 1 kb
scanners.c 100644 192 kb
scanners.h 100644 5 kb
sf_base64decode.c 100644 6 kb
sf_base64decode.h 100644 1 kb
sis.c 100644 47 kb
sis.h 100644 1 kb
special.c 100644 10 kb
special.h 100644 1 kb
spin.c 100644 16 kb
spin.h 100644 1 kb
stats.c 100644 18 kb
stats.h 100644 1 kb
stats_json.c 100644 7 kb
stats_json.h 100644 1 kb
str.c 100644 29 kb
str.h 100644 4 kb
strlcat.c 100644 2 kb
swf.c 100644 21 kb
swf.h 100644 10 kb
table.c 100644 5 kb
table.h 100644 2 kb
text.c 100644 10 kb
text.h 100644 2 kb
textdet.c 100644 7 kb
textdet.h 100644 1 kb
textnorm.c 100644 6 kb
textnorm.h 100644 2 kb
tiff.c 100644 8 kb
tiff.h 100644 1 kb
tnef.c 100644 12 kb
tnef.h 100644 1 kb
type_desc.h 100644 3 kb
unarj.c 100644 37 kb
unarj.h 100644 1 kb
uniq.c 100644 5 kb
uniq.h 100644 6 kb
unsp.c 100644 18 kb
unsp.h 100644 2 kb
untar.c 100644 13 kb
untar.h 100644 1 kb
unzip.c 100644 57 kb
unzip.h 100644 6 kb
upack.c 100644 29 kb
upack.h 100644 1 kb
upx.c 100644 21 kb
upx.h 100644 1 kb
uuencode.c 100644 3 kb
uuencode.h 100644 1 kb
vba_extract.c 100644 84 kb
vba_extract.h 100644 2 kb
version.c 100644 0 kb
version.h.in 100644 0 kb
wwunpack.c 100644 9 kb
wwunpack.h 100644 1 kb
www.c 100644 8 kb
www.h 100644 1 kb
xar.c 100644 34 kb
xar.h 100644 2 kb
xdp.c 100644 6 kb
xdp.h 100644 2 kb
xlm_extract.c 100644 284 kb
xlm_extract.h 100644 2 kb
xz_iface.c 100644 3 kb
xz_iface.h 100644 1 kb
yara_arena.c 100644 23 kb
yara_arena.h 100644 2 kb
yara_clam.h 100644 12 kb
yara_compiler.c 100644 21 kb
yara_compiler.h 100644 4 kb
yara_exec.c 100644 20 kb
yara_exec.h 100644 3 kb
yara_grammar.c 100644 114 kb
yara_grammar.h 100644 4 kb
yara_grammar.y 100644 45 kb
yara_hash.c 100644 6 kb
yara_hash.h 100644 1 kb
yara_lexer.c 100644 82 kb
yara_lexer.h 100644 2 kb
yara_lexer.l 100644 16 kb
yara_parser.c 100644 27 kb
yara_parser.h 100644 2 kb
yc.c 100644 10 kb
yc.h 100644 1 kb
README.Docker.md
# ClamAV in Docker ClamAV can be run within a Docker container. This provides isolation from other processes by running it in a containerized environment. If new or unfamiliar with Docker, containers or cgroups see [docker.com](https://www.docker.com). ## The official images on Docker Hub ClamAV image tags [on Docker Hub](https://hub.docker.com/u/clamav/clamav) follow this naming convention: - `clamav/clamav:<version>`: A release preloaded with signature databases. Using this container will save the ClamAV project some bandwidth. Use this if you will keep the image around so that you don't download the entire database set every time you start a new container. Updating with FreshClam from existing databases set does not use much data. - `clamav/clamav:<version>_base`: A release with no signature databases. Use this container **only** if you mount a volume in your container under `/var/lib/clamav` to persist your signature database databases. This method is the best option because it will reduce data costs for ClamAV and for the Docker registry, but it does require advanced familiarity with Linux and Docker. > _Caution_: Using this image without mounting an existing database directory will cause FreshClam to download the entire database set each time you start a new container. You can use the `unstable` version (i.e. `clamav/clamav:unstable` or `clamav/clamav:unstable_base`) to try the latest from our development branch. ## Building the ClamAV image While it is recommended to pull the image from our [Docker Hub registry](https://hub.docker.com/u/clamav/clamav), some may want to build the image locally instead. All that is needed is: ```bash docker build --tag "clamav:TICKET-123" . ``` in the current directory. This will build the ClamAV image and tag it with the name "clamav:TICKET-123". Any name can generally be used and it is this name that needs to be referred to later when running the image. ## Running ClamD To run `clamd` in a Docker container, first, an image either has to be built or pulled from a Docker registry. ### Running ClamD using the official ClamAV images from Docker Hub To pull the ClamAV "unstable" image from Docker Hub, run: ```bash docker pull clamav/clamav:unstable ``` > _Tip_: Substitute `unstable` with a different version as needed. To pull _and run_ the official ClamAV images from the Docker Hub registry, try the following command: ```bash docker run \ --interactive \ --tty \ --rm \ --name "clam_container_01" \ clamav/clamav:unstable ``` The above creates an interactive container with the current TTY connected to it. This is optional but useful when getting started as it allows one to directly see the output and, in the case of `clamd`, send `ctrl-c` to close the container. The `--rm` parameter ensures the container is cleaned up again after it exits and the `--name` parameter names the container, so it can be referenced through other (Docker) commands, as several containers of the same image can be started without conflicts. > _Note_: Pulling is not always required. `docker run` will pull the image if it cannot be found locally. `docker run --pull always` will always pull beforehand to ensure the most up-to-date container is being used. Do not use `--pull always` with the larger ClamAV images. > _Tip_: It's common to see `-it` instead of `--interactive --tty`. In some situations it may be desirable to set (any of) the containers to a specific timezone. The `--env` parameter can be used to set the `TZ` variable to change the default of `Etc/UTC`. ### Running ClamD using a Locally Built Image You can run a container using an image built locally ([see "Building the ClamAV Image"](#building-the-clamav-image)). Just run: ```bash docker run -it --rm \ --name "clam_container_01" \ clamav:TICKET-123 ``` ### Persisting the virus database (volume) The virus database in `/var/lib/clamav` is by default unique to each container and thus is normally not shared. For simple setups this is fine, where only one instance of `clamd` is expected to run in a dockerized environment. However some use cases may want to efficiently share the database or at least persist it across short-lived ClamAV containers. To do so, you have two options: 1. Create a [Docker volume](https://docs.docker.com/storage/volumes/) using the `docker volume` command. Volumes are completely managed by Docker and are the best choice for creating a persistent database volume. For example, create a "clam_db" volume: ```bash docker volume create clam_db ``` Then start one or more containers using this volume. The first container to use a new database volume will download the full database set. Subsequent containers will use the existing databases and may update them as needed: ```bash docker run -it --rm \ --name "clam_container_01" \ --mount source=clam_db,target=/var/lib/clamav \ clamav/clamav:unstable_base ``` 2. Create a [Bind Mount](https://docs.docker.com/storage/bind-mounts/) that maps a file system directory to a path within the container. Bind Mounts depend on the directory structure, permissions, and operating system of the Docker host machine. Run the container with these arguments to mount the a directory from your host environment as a volume in the container. ```bash --mount type=bind,source=/path/to/databases,target=/var/lib/clamav ``` When doing this, it's best to use the `<version>_base` image tags so as to save on bandwith. E.g.: ```bash docker run -it --rm \ --name "clam_container_01" \ --mount type=bind,source=/path/to/databases,target=/var/lib/clamav \ clamav/clamav:unstable_base ``` > _Disclaimer_: When using a Bind Mount, the container's entrypoint script will change ownership of this directory to its "clamav" user. This enables FreshClam and ClamD with the required permissions to read and write to the directory, though these changes will also affect those files on the host. If you're thinking about running multiple containers that share a single database volume, [here are some notes on how this might work](#multiple-containers-sharing-the-same-mounted-databases). ## Running Clam(D)Scan Scanning files using `clamscan` or `clamdscan` is possible in various ways with Docker. This section briefly describes them, but the other sections of this document are best read before hand to better understand some of the concepts. One important aspect is however to realize that Docker by default does not have access to any of the hosts files. And so to scan these within Docker, they need to be mounted with a [bind mount](https://docs.docker.com/storage/bind-mounts/) to be made accessible. For example, running the container with these arguments ... ```bash --mount type=bind,source=/path/to/scan,target=/scandir --mount type=bind,source=/path/to/scan,target=/scandir ``` ... would make the hosts file/directory `/path/to/scan` available in the container as `/scandir` and thus invoking `clamscan` would thus be done on `/scandir`. Note that while technically possible to run either scanners via `docker exec` this is not described as it is unlikely the container has access to the files to be scanned. ### ClamScan Using `clamscan` outside of the Docker container is how normally `clamscan` is invoked. To make use of the available shared dockerized resources however, it is possible to expose the virus database and share that for example. E.g. it could be possible to run a Docker container with only the `freshclam` daemon running, and share the virus database directory `/var/lib/clamav`. This could be useful for file servers for example, where only `clamscan` is installed on the host, and `freshclam` is managed in a Docker container. > _Note_: Running the `freshclam` daemon separated from `clamd` is less recommended, unless the `clamd` socket is shared with `freshclam` as `freshclam` would not be able to inform `clamd` of database updates. ### Dockerized ClamScan To run `clamscan` in a Docker container, the Docker container can be invoked as: ```bash docker run -it --rm \ --mount type=bind,source=/path/to/scan,target=/scandir \ clamav/clamav:unstable \ clamscan /scandir ``` However, this will use whatever signatures are found in the image, which may be slightly out of date. If using `clamscan` in this way, it would be best to use a [database volume](#running-with-a-mounted-database-directory-volume) that is up-to-date so that you scan with the latest signatures. E.g.: ```bash docker run -it --rm \ --mount type=bind,source=/path/to/scan,target=/scandir \ --mount type=bind,source=/path/to/databases,target=/var/lib/clamav \ clamav/clamav:unstable_base \ clamscan /scandir ``` ### ClamDScan As with `clamscan`, `clamdscan` can also be run when installed on the host, by connecting to the dockerized `clamd`. This can be done by either pointing `clamdscan` to the exposed TCP/UDP port or unix socket. ### Dockerized ClamDScan Running both `clamd` and `clamdscan` is also easily possible, as all that is needed is the shared socket between the two containers. The only cavaet here is to: 1. mount the files to be scanned in the container that will run `clamd`, or 2. mount the files to be scanned in the container that will `clamdscan` run if using `clamdscan --stream`. The `--stream` option will be slower, but enables submitting files from a different machine on a network. For example: ```bash docker run -it --rm \ --mount type=bind,source=/path/to/scan,target=/scandir \ --mount type=bind,source=/var/lib/docker/data/clamav/sockets/,target=/run/clamav/ clamav/clamav:unstable ``` ```bash docker run -it --rm \ --mount type=bind,source=/path/to/scan,target=/scandir \ --mount type=bind,source=/var/lib/docker/data/clamav/sockets/,target=/run/clamav/ clamav/clamav:unstable_base \ clamdscan /scandir ``` ## Controlling the container The ClamAV container actually runs both `freshclam` and `clamd` daemons by default. Optionally available to the container is ClamAV's milter daemon. To control the behavior of the services started within the container, the following flags can be passed to the `docker run` command with the `--env` (`-e`) parameter. * CLAMAV_NO_CLAMD [true|**false**] Do not start `clamd`. (default: start `clamd`) * CLAMAV_NO_FRESHCLAMD [true|**false**] Do not start the `freshclam` daemon. (default: start the `freshclam` daemon) * CLAMAV_NO_MILTERD [**true**|false] Do not start the `clamav-milter` daemon. (default: start the `clamav-milter` daemon ) * CLAMD_STARTUP_TIMEOUT [integer] Seconds to wait for `clamd` to start. (default: 1800) * FRESHCLAM_CHECKS [integer] `freshclam` daily update frequency. (default: once per day) So to additionally also enable `clamav-milter`, the following flag can be added: ```bash --env 'CLAMAV_NO_MILTERED=false' ``` Further more, all of the configuration files that live in `/etc/clamav` can be overridden by doing a volume-mount to the specific file. The following argument can be added for this purpose. The example uses the entire configuration directory, but this can be supplied multiple times if individual files deem to be replaced. ```bash --mount type=bind,source=/full/path/to/clamav/,target/etc/clamav ``` > _Note_: Even when disabling the `freshclam` daemon, `freshclam` will always run at least once during container startup if there is no virus database. While not recommended, the virus database location itself `/var/lib/clamav/` could be a persistent Docker volume. This however is slightly more advanced and out of scope of this document. ## Connecting to the container ### Executing commands within a running container To connect to a running ClamAV container, `docker exec` can be used to run a command on an already running container. To do so, the name needs to be either obtained from `docker ps` or supplied during container start via the `--name` parameter. The most interesting command in this case can be `clamdtop`. ```bash docker exec --interactive --tty "clamav_container_01" clamdtop ``` Alternatively, a shell can be started to inspect and run commands within the container as well. ```bash docker exec --interactive --tty "clamav_container_01" /bin/sh ``` ### Unix sockets The default socket for `clamd` is located inside the container as `/run/clamav/clamd.sock` and can be connected to when exposed via a Docker volume mount. To ensure, that `clamd` within the container can freely create and remove the socket, the path for the socket is to be volume-mounted, to expose it for others on the same host to use. The following volume can be used for this purpose. Do ensure that the directory on the host actually exists and clamav inside the container has permission to access it. Caution is required when managing permissions, as incorrect permission could open clamd for anyone on the host system. ```bash --mount type=bind,source=/var/lib/docker/data/clamav/sockets/,target=/run/clamav/ ``` With the socket exposed to the host, any other service can now talk to `clamd` as well. If for example `clamdtop` where installed on the local host, calling ```bash clamdtop "/var/lib/docker/data/clamav/sockets/clamd.sock" ``` should work just fine. Likewise, running `clamdtop` in a different container, but sharing the socket will equally work. While `clamdtop` works well as an example here, it is of course important to realize, this can also be used to connect a mail server to `clamd`. ### TCP ClamAV in the official Docker images is configured to listen for TCP connections on these ports: - `clamd`: 3310 - `clamav-milter`: 7357 While `clamd` and `clamav-milter` will listen on the above TCP ports, Docker does not expose these by default to the host. Only within containers can these ports be accessed. To expose, or "publish", these ports to the host, and thus potentially over the (inter)network, the `--publish` (or `--publish-all`) flag to `docker run` can be used. While more advanced/secure mappings can be done as per documentation, the basic way is to `--publish [<host_port>:]<container_port>` to make the port available to the host. ```bash --publish 73310:3310 \ --publish 7357 ``` The above would thus publish the milter port 3310 as 73310 on the host and the clamd port 7357 as a random to the host. The random port can be inspected via `docker ps`. > **Warning**: Extreme caution is to be taken when using `clamd` over TCP as there are no protections on that level. All traffic is un-encrypted. Extra care is to be taken when using TCP communications. ## Container ClamD health-check Docker has the ability to run simple `ping` checks on services running inside containers. If `clamd` is running inside the container, Docker will on occasion send a `ping` to `clamd` on the default port and wait for the pong from `clamd`. If `clamd` fails to respond, Docker will treat this as an error. The healthcheck results can be viewed with `docker inspect`. When the container starts up, the health-check also starts up. As loading the virus database can take some time, there is a delay configured in the `Dockerfile` to try and avoid this race condition. ## Performance The performance impact of running `clamd` in Docker is negligible. Docker is in essence just a wrapper around Linux's cgroups and cgroups can be thought of as `chroot` or FreeBSD's `jail`. All code is executed on the host without any translation. Docker does however do some isolation (through cgroups) to isolate the various systems somewhat. Of course, nothing in life is free, and so there is some overhead. Disk-space being the most prominent one. The Docker container might have some duplication of files for example between the host and the container. Further more, also RAM memory may be duplicated for each instance, as there is no RAM-deduplication. Both of which can be solved on the host however. A filesystem that supports disk-deduplication and a memory manager that does RAM-deduplication. The base container in itself is already very small ~16 MiB, at the time of this writing, this cost is still very tiny, where the advantages are very much worth the cost in general. The container including the virus database is about ~240 MiB at the time of this writing. ## Bandwidth Please, be kind when using 'free' bandwidth, both for the virus databases but also the Docker registry. Try not to download the entire database set or the larger ClamAV database images on a regular basis. ## Advanced container configurations ### Multiple containers sharing the same mounted databases You can run multiple containers that share the same database volume, but be aware that the FreshClam daemons on each would compete to update the databases. Most likely, one would update the databases and trigger its ClamD to load the new databases, while the others would be oblivious to the new databases and would continue with the old signatures until the next ClamD self-check. This is fine, honestly. It won't take that long before the new signatures are detected by ClamD's self-check and the databases are reloaded automatically. To reload the databases on all ClamD containers immediately after an update, you could [disable the FreshClam daemon](#controlling-the-container) when you start the containers. Later, use `docker exec` to perform an update and again as needed to have ClamD load updated databases. > _Note_: This really isn't necessary but you could do this if you wish. Exactly how you orchestrate this will depend on your environment. You might do something along these lines: 1. Create a "clam_db" volume, if you don't already have one: ```bash docker volume create clam_db ``` 2. Start your containers: ```bash docker run -it --rm \ --name "clam_container_01" \ --mount source=clam_db,target=/var/lib/clamav \ --env 'CLAMAV_NO_FRESHCLAMD=true' \ clamav/clamav:unstable_base ``` Wait for the first one to download the databases (if it's a new database volume). Then start more: ```bash docker run -it --rm \ --name "clam_container_02" \ --mount source=clam_db,target=/var/lib/clamav \ --env 'CLAMAV_NO_FRESHCLAMD=true' \ clamav/clamav:unstable_base ``` 3. Check for updates, as needed: ```bash docker exec -it clam_container_01 freshclam --on-update-execute=EXIT_1 || \ if [ $? == 1 ]; then \ docker exec -it clam_container_01 clamdscan --reload; \ docker exec -it clam_container_02 clamdscan --reload; \ fi ```