Ray + vLLM clusters expose unauthenticated control-plane ports, benchmark finds

No-Peanut-6988 · reddit · 2026-09-29

Benchmarking a multi-node Ray + vLLM inference cluster on AWS EKS under vendor defaults, a team found: 15 of 17 active listening sockets never appeared in declared containerPort manifests; a neighbor container in an unrelated namespace could reach Ray GCS (6379) and raylet RPCs (10002–10006) over unauthenticated cleartext gRPC; four default scanners (Trivy, Checkov, Kubescape, kube-linter) missed it entirely since they don't inspect the RayCluster custom resource; and a single-GPU vLLM deployment exposed 26 unauthenticated API routes.

Mitigations: an ingress default-deny NetworkPolicy blocked all neighbor-pod access to the Ray control plane with no measurable latency. WireGuard encryption (Cilium chained with AWS VPC CNI) carried the workload but cost 3.4%–6.5% throughput and 3.2%–8.4% latency under load. Full report and hardening guide available.

Original post →

More from Infra

Infra channel →