Audit of 15 self-hosted AI stacks finds 14 ship with zero NetworkPolicies

No-Peanut-6988 · reddit · 2026-09-27

A security team audited default Helm/Docker configs for 15 popular AI stacks (LiteLLM, vLLM, Ray, Weaviate) and found serious defaults: LiteLLM's migration Job embeds the Postgres password in plaintext; KubeRay accepts unauthenticated job submissions while workers have passwordless sudo (instant root); some Kubernetes MCP servers get cluster-wide Secret read and pod exec with no auth; vector DB charts ship with anonymous read/write. 14 of 15 charts have zero NetworkPolicies and default token automounting enabled. Remediation snippets and open-source probe scripts are available.

Original post →

More from Infra

Infra channel →