r/devops
We audited the default Helm charts and Docker configs of popular AI stack tools (Ray, Weaviate, MCP servers, LangChain). The out-of-the-box security defaults are surprisingly bad.
- upvotes
- 21
- comments
- 12
Post
Highlighted: the lines this signal was extracted from
Over the past few weeks, we set up a fresh cluster to test what actually gets deployed when an engineer runs helm install with zero extra configuration on popular AI, vector DB, and MCP charts (Ray, vLLM, LiteLLM, Qdrant, Weaviate, KubeRay, etc.). Everyone focuses on prompt injection and model jailbreaks, but the platform-level defaults on these workloads look like Kubernetes five to seven years ago: Ray / KubeRay (Distributed Compute) The default deployment accepts unauthenticated job submissions over internal cluster networking. Worker containers run with passwordless sudo out of the box. Any compromised pod on the flat cluster network that can reach the Ray API gets arbitrary remote execution as root with zero barrier. MCP (Model Context Protocol) Servers Several popular MCP server implementations implement local protection solely by checking Host: localhost. Any basic SSRF or internal proxy passing -H "Host: localhost" bypasses this immediately. In live testing, one Kubernetes MCP server mounted a ClusterRole with cluster-wide Secret read and pod exec permissions, exposed over unauthenticated HTTP. LiteLLM Migration Job Credential Leak The primary deployment pulls the database password from a Secret using secretKeyRef, but the database migration Job embeds the raw database password in plain-text environment variables. Anyone with basic cluster read...
Keep reading with a free account
The rest of this post, and every signal for Weaviate, is in your free account.
Also quoted as evidence
Multiple upstream charts still ship with default values that enable anonymous read and write access.
From the post
Raw embeddings and ingested document payloads are queryable by any internal service without an authentication header.
From the post