Audit of 15 self-hosted AI stacks finds 14 ship with zero NetworkPolicies
No-Peanut-6988 · reddit · 2026-09-27
A security team audited default Helm/Docker configs for 15 popular AI stacks (LiteLLM, vLLM, Ray, Weaviate) and found serious defaults: LiteLLM's migration Job embeds the Postgres password in plaintext; KubeRay accepts unauthenticated job submissions while workers have passwordless sudo (instant root); some Kubernetes MCP servers get cluster-wide Secret read and pod exec with no auth; vector DB charts ship with anonymous read/write. 14 of 15 charts have zero NetworkPolicies and default token automounting enabled. Remediation snippets and open-source probe scripts are available.
More from Infra
- Is Agentic scores how AI-agent-ready your website is, via a single npx command — seanwbren · 2026-09-28
- TQ: calibration-free 4-bit quantization open-sourced, hits 92.4% top-1 on Qwen 27B — textclf · 2026-09-28
- Modal's free GPU glossary mini-book surfaces via Gergely Orosz — charles_irl · 2026-09-28
- Estimating 100M DAU infra for Meta Muse: 1-4GW of power, tiny $3B sandbox layer — SuB8u · 2026-09-28
- $350 Dell from 2007 beats $1500 RTX 5070 rig on agentic LLM tasks — Truth-Does-Not-Exist · 2026-09-28
- Rural town promises every household $10k if a data center gets built — JumpCrisscross · 2026-09-28