ClamAV docker & GKE deployment error connection ECONNREFUSED when I run docker image

Viewed 329

I am trying to build a ClamAV malware scanner docker image that runs on a squid proxy and I get:

!NotifyClamd: Can't connect to clamd on 127.0.0.1:3310: Connection refused

and error:

connect ECONNREFUSED 127.0.0.1:3310
    at TCPConnectWrap.afterConnect [as oncomplete] (node:net:1158:16) {
  errno: -111,
  code: 'ECONNREFUSED',
  syscall: 'connect',
  address: '127.0.0.1',
  port: 3310 }

Stopping ClamAV daemon:

clamd.
Clamav signatures not found in /var/lib/clamav ... failed!
Please retrieve them using freshclam ... failed!
Then run 'invoke-rc.d clamav-daemon start' ... failed!

This is my dockerfile :


FROM node:17.6.0-bullseye-slim
# Set versions
ENV CLOUD_SDK_VERSION=372.0.0
# Install base packages 
ENV PATH $PATH:/usr/local/gcloud/google-cloud-sdk/bin
RUN apt-get update && \
    apt-get install -y build-essential clamav-daemon clamav-freshclam curl python3 sudo && \
    rm -rf /var/lib/apt/lists/* && \
    mkdir -p /usr/local/gcloud && \
    curl -O https://dl.google.com/dl/cloudsdk/channels/rapid/downloads/google-cloud-sdk-${CLOUD_SDK_VERSION}-linux-x86_64.tar.gz && \
    tar -C /usr/local/gcloud -xvf google-cloud-sdk-${CLOUD_SDK_VERSION}-linux-x86_64.tar.gz && \
    rm google-cloud-sdk-${CLOUD_SDK_VERSION}-linux-x86_64.tar.gz && \
    ln -s /lib /lib64 && \
    gcloud config set core/disable_usage_reporting true && \
    gcloud config set component_manager/disable_update_check true && \
    mkdir -p /home/node/app && \
    chown -R node:node /home/node/app && \
    chmod 777 /var/log/clamav/freshclam.log && \
    chmod 777 /var/lib/clamav && \
    echo "TCPSocket 3310" >> /etc/clamav/clamd.conf && \
    echo "TCPAddr 127.0.0.1" >> /etc/clamav/clamd.conf && \
    echo "User node" >> /etc/clamav/clamd.conf && \
    echo "DatabaseOwner node" >> /etc/clamav/freshclam.conf && \
    echo "HTTPProxyServer squid-proxy.neds.local" >> /etc/clamav/freshclam.conf && \
    echo "HTTPProxyPort 3128"  >> /etc/clamav/freshclam.conf && \
    echo "node ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers.d/node
# Bring in app code
WORKDIR /home/node/app
COPY --chown=node:node . .
# Set up app
RUN npm config set python $(which python3) && \
    npm install
# Run the rest as the node user
USER 1000
CMD ["/bin/bash", "bootstrap.sh"]

and this is bootstrap.sh :

#!/bin/bash
sudo service clamav-freshclam stop && \
sudo freshclam && \
sudo service clamav-freshclam start && \
sudo service clamav-daemon force-reload && \
npm start

It fails when I docker run it OR when I deploy it on a GKE cluster, all IPs required are whitelisted on the squid.

0 Answers
Related