
الأدلة والبيانات للتقرير الفني Sorami حول الإعدادات الافتراضية الأمنية لـ 15 من مخططات Helm الخاصة بخدمة الذكاء الاصطناعي وقواعد البيانات المتجهة و MCP على Kubernetes.
يحتوي هذا المستودع على البيانات والأدلة التي يستند إليها التقرير الفني لـ Sorami "الذكاء الاصطناعي على Kubernetes: 10 من أصل 14 Helm chart تُشحن بدون مصادقة API" (الإصدار 1.2).
اقرأ التقرير هنا: https://sorami.com.au/research/ai-kubernetes-helm-chart-security/
المنهجية والنتائج وتقييمات الخطورة ونصائح التقوية موجودة في التقرير. لا يكررها هذا المستودع. إنه يحتوي على ملفات البيانات التي يستشهد بها التقرير، حتى يتمكن القراء من التحقق من كل ادعاء.
القيم الافتراضية، تم توليدها في 24 سبتمبر 2026. تمت إعادة تشغيل فحوصات حية مختارة في 25 سبتمبر 2026.
| Chart | الإصدار | المصدر |
|---|---|---|
| vllm/vllm-stack | 0.1.12 | https://vllm-project.github.io/production-stack |
| kserve-resources | v0.20.0 | oci://ghcr.io/kserve/charts/kserve-resources |
| kuberay/kuberay-operator, kuberay/ray-cluster | 1.7.1 | https://ray-project.github.io/kuberay-helm/ |
| vllm-project/aibrix dist/chart | 0.7.0 | git tag v0.7.0 |
| otwld/ollama | 1.83.0 | https://helm.otwld.com/ |
| open-webui/open-webui | 16.6.0 | https://helm.openwebui.com/ |
| go-skynet/local-ai | 3.4.2 | https://go-skynet.github.io/helm-charts/ |
| litellm-helm | 1.102.1 | oci://ghcr.io/berriai/litellm-helm |
| langfuse/langfuse | 2.1.2 | https://langfuse.github.io/langfuse-k8s |
| n8n-io/n8n-hosting charts/n8n | 1.13.0 | git commit 359e1772 |
| qdrant/qdrant | 1.19.1 | https://qdrant.github.io/qdrant-helm |
| weaviate/weaviate | 17.8.3 | https://weaviate.github.io/weaviate-helm |
| milvus/milvus | 5.0.28 | https://zilliztech.github.io/milvus-helm/ |
| containers/kubernetes-mcp-server | 0.1.0 | oci://ghcr.io/containers/charts/kubernetes-mcp-server |
| Flux159/mcp-server-kubernetes helm-chart | 2.8.0 | git tag v4.1.7 |
results.csv: صف واحد لكل chart، وعمود واحد لكل فحص، مع الدليل على كل قيمة.tools.tsv: مصادر الـ charts، والإصدارات المثبتة، وتجاوز التوليد (إن وُجد) الذي احتاجه كل chart.manual-checks.tsv: الإعدادات الافتراضية لمصادقة API والقياس عن بُعد، تم فحصها يدويًا مقابل وثائق المورّد والمصدر.dynamic-results.tsv: نتائج الفحوصات الحية على عنقود اختبار محلي.evidence/totals.json: الأعداد الرئيسية المستخدمة في التقرير.evidence/doc-urls.tsv: وثائق المورّد المستشهد بها لكل ادعاء، مع حالة HTTP في 24 سبتمبر 2026.evidence/scans/scan-summary.json، evidence/scans/scan-detail.json: أعداد لكل chart من Kubescape 4.0.14 وCheckov 3.3.19 وkube-linter 0.8.3 وTrivy 0.74.0.evidence/dynamic/: سجلات الطلبات والاستجابات من الفحوصات الحية، ومخرجات kubectl auth can-i لحسابات ServiceAccounts التي نوقشت في التقرير.figures/: الأشكال المستخدمة في التقرير.file:line مثل values.yaml:17 تشير إلى ملفات الـ chart نفسه عند الإصدار المثبت أعلاه. المسارات مثل charts/repo-qdrant/qdrant/values.yaml نسبية إلى الـ chart بعد فك ضغطه.off وon وnot_enforced وما شابهها معرّفة في التقرير.<kubeconfig> و<kind-context> و<charts> و<pod-ip>. لم يتم تغيير أي شيء آخر في الطلب أو الاستجابة.REDACTED-RENDER-TIME-PASSWORD. بيانات الاعتماد النائبة التي يشحنها المورّدون في الـ charts الخاصة بهم تُركت كما هي، لأنها هي النتيجة.نحن لا نعيد توزيع ملفات الـ charts الخاصة بالمورّدين أو الـ manifests المولّدة. يمكن لأي شخص إعادة توليدها من الـ charts العامة:
helm repo add vllm https://vllm-project.github.io/production-stack
helm repo add kuberay https://ray-project.github.io/kuberay-helm/
helm repo add otwld https://helm.otwld.com/
helm repo add open-webui https://helm.openwebui.com/
helm repo add langfuse https://langfuse.github.io/langfuse-k8s
helm repo add qdrant https://qdrant.github.io/qdrant-helm
helm repo add weaviate https://weaviate.github.io/weaviate-helm
helm repo add milvus https://zilliztech.github.io/milvus-helm/
helm repo add localai https://go-skynet.github.io/helm-charts/
helm repo update
helm template rel vllm/vllm-stack --version 0.1.12 --namespace sbd
helm template rel kuberay/kuberay-operator --version 1.7.1 --namespace sbd
helm template rel kuberay/ray-cluster --version 1.7.1 --namespace sbd
helm template rel otwld/ollama --version 1.83.0 --namespace sbd
helm template rel open-webui/open-webui --version 16.6.0 --namespace sbd
helm template rel langfuse/langfuse --version 2.1.2 --namespace sbd --set clickhouse.crdCheck=false
helm template rel qdrant/qdrant --version 1.19.1 --namespace sbd
helm template rel weaviate/weaviate --version 17.8.3 --namespace sbd
helm template rel milvus/milvus --version 5.0.28 --namespace sbd
helm template rel localai/local-ai --version 3.4.2 --namespace sbd
helm template rel oci://ghcr.io/berriai/litellm-helm --version 1.102.1 --namespace sbd
helm template rel oci://ghcr.io/kserve/charts/kserve-resources --version v0.20.0 --namespace sbd
helm template rel oci://ghcr.io/containers/charts/kubernetes-mcp-server --version 0.1.0 --namespace sbd --set ingress.host=mcp.example.invalid
git clone --depth 1 --branch v0.7.0 https://github.com/vllm-project/aibrix.git
helm template rel aibrix/dist/chart --namespace sbd
git clone --depth 1 --branch v4.1.7 https://github.com/Flux159/mcp-server-kubernetes.git
helm template rel mcp-server-kubernetes/helm-chart --namespace sbd
git clone https://github.com/n8n-io/n8n-hosting.git && git -C n8n-hosting checkout 359e1772f9e4987c964aa4d6ab1621d07bdb107f
helm template rel n8n-hosting/charts/n8n --namespace sbd --set secretRefs.env.N8N_ENCRYPTION_KEY=research-placeholder-not-a-secret
استخدم Helm 3.19 أو أحدث (يحتاج chart الخاص بـ Langfuse إلى fromToml). لا حاجة إلى سياق kube للتوليد. بعض الـ charts تستخدم وسوم صور متغيرة، لذا قد يشير توليد لاحق إلى صور أحدث.
كل نتيجة هي إعداد افتراضي يوثّقه المورّد، ويحتوي التقرير على روابط لوثائق المورّد نفسه لكل واحدة منها. أُجري الاختبار فقط على عنقود محلي أُنشئ للدراسة وحُذف بعدها. لم يتم فحص أو الاتصال بأي نظام تابع لطرف ثالث أو عميل أو متاح على الإنترنت. يمكن للمورّدين الذين لديهم سؤال حول أي نتيجة الكتابة إلى [email protected].
البيانات وملفات الأدلة والأشكال في هذا المستودع مُصدرة بموجب CC BY 4.0. حقوق النشر 2026 Sorami Consulting Pty Ltd. راجع LICENSE.
الاستشهاد: Sorami (2026). الذكاء الاصطناعي على Kubernetes: 10 من أصل 14 Helm chart تُشحن بدون مصادقة API. تقرير Sorami الفني، الإصدار 1.2. https://sorami.com.au/research/ai-kubernetes-helm-chart-security/
للتواصل: [email protected]