Table of Contents
- Kubernetes System Directories
- Container Runtime Directories
- Apinizer Application Directories
- Log Directories
- Data Directories (Persistent Volumes)
- Container Image Directories
- Network Files
- Process and System Files
- Apinizer Component Ports (Network Exclusion)
- Process Exclusions
- Summary Exclusion List
- Important Notes
1. Kubernetes System Directories
Directories required for Kubernetes operation:/var/run/secrets/kubernetes.io/serviceaccount/namespace/var/run/secrets/kubernetes.io/serviceaccount/token
2. Container Runtime Directories
3. Apinizer Application Directories
In-container working directories:java.io.tmpdir (typically /tmp or /var/tmp).
4. Log Directories
Log files for Apinizer components:5. Data Directories (Persistent Volumes)
For MongoDB, Elasticsearch, and Hazelcast:6. Container Image Directories
7. Network Files
Kubernetes network plugin files:8. Process and System Files
9. Apinizer Component Ports (Network Exclusion)
To prevent antivirus from scanning network traffic:10. Process Exclusions
The following processes should be exempt from scanning:Summary Exclusion List
The following format can be used with most antivirus solutions:Important Notes
- Performance: Excluding these directories reduces the performance impact of antivirus and ensures Apinizer runs normally.
- Security: Limit exclusions to necessary directories only. Unnecessary exclusions can create security risks.
- Monitoring: Perform security monitoring on excluded directories. Even if antivirus does not scan them, log monitoring and behavioral analysis should continue.
- Documentation: When DMZ and LAN separation is applied as described on the Network Topology and Port Requirements page, separate exclusion policies per zone can be considered.
Apinizer Deployment Topology
Apinizer is deployed on Kubernetes as follows:DMZ Zone (Demilitarized Zone)
Worker Nodes:- Local Cache
- Token Provider API
- Proxy Handler
- 32080 (NodePort) - Manager access
- 30080/30090 (NodePort) - Apinizer API Gateway
- 443/80 (HTTPS/HTTP) - Client access
LAN Zone (Local Area Network)
Manager Module:- Scheduled Jobs
- Monitoring & Alerting
- Analytics Engine
- Web Manager
- 8080 (Management API) - Access from Workers
- 8080 (HTTP) - Web Manager
- Port 25080 (Apinizer DB Port)
- Port 27017 (MongoDB)
- Port 9200 (HTTP) - Log submission
- Port 9300 (Transport) - Cluster communication
- Port 5701 - Cluster communication
Configuration by Antivirus Solution
- Symantec Endpoint Protection: File and Folder Exclusions
- McAfee: Real-Time Scan Exclusions
- Trend Micro: Scan Exclusions
- Windows Defender: Exclusion paths
- ClamAV: ExcludePath directive
Resources
Last Updated: 2026-02-04

