majorwiki/02-selfhosting/security
MajorLinux a852f7b7bd ClamAV fleet caveat: add follow-up on the polite-CPU-on-1vCPU edge case
Same-day correction. The proposed per-droplet relaxed alert (>95%/30m)
turned out to also trip on a 1 vCPU box during low-traffic weekly scans,
because there's literally no real load for nice 19 to yield to —
clamscan opportunistically fills the vCPU and DO sees 100% utilization
regardless of `%nice` vs `%user` split. Documents the three realistic
options (accept page / switch to clamdscan / disable alert) and the
underlying limit (no DO threshold can distinguish polite from impolite
CPU when the box is fully utilized).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-10 02:32:35 -04:00
..
ansible-unattended-upgrades-fleet.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
clamav-fleet-deployment.md ClamAV fleet caveat: add follow-up on the polite-CPU-on-1vCPU edge case 2026-05-10 02:32:35 -04:00
fail2ban-apache-404-scanner-jail.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
fail2ban-apache-bad-request-jail.md Add 4 articles: nginx/apache bad-request jails, SSH fleet hardening, Watchtower localhost relay 2026-04-17 21:06:09 -04:00
fail2ban-apache-php-probe-jail.md wiki: add fail2ban jail for Apache PHP webshell probes 2026-04-13 10:17:24 -04:00
fail2ban-digest-mode-fleet.md wiki: update fail2ban digest + netdata docker health + 3 new articles 2026-05-02 14:58:07 -04:00
fail2ban-nginx-bad-request-jail.md Add 4 articles: nginx/apache bad-request jails, SSH fleet hardening, Watchtower localhost relay 2026-04-17 21:06:09 -04:00
fail2ban-wordpress-login-jail.md Add wiki article: Fail2ban WordPress login brute force jail 2026-04-02 16:04:13 -04:00
firewalld-fleet-hardening.md Add 5 wiki articles from 2026-04-17/18 work 2026-04-18 11:13:39 -04:00
linux-server-hardening-checklist.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
selinux-fail2ban-execmem-fix.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
ssh-hardening-ansible-fleet.md Add 4 articles: nginx/apache bad-request jails, SSH fleet hardening, Watchtower localhost relay 2026-04-17 21:06:09 -04:00
ufw-firewall-management.md Update UFW article: add web server ports lesson from tttpod outage 2026-04-03 03:57:27 -04:00
wp-fail2ban-logpath-debian-ubuntu.md wiki: update fail2ban digest + netdata docker health + 3 new articles 2026-05-02 14:58:07 -04:00