
Kubernetes上の15のAIサービング、ベクトルデータベース、MCP Helmチャートのセキュリティデフォルトに関するSoramiテクニカルレポートのためのエビデンスとデータ。
このリポジトリには、Soramiの技術レポート**「Kubernetes上のAI: 14個のHelmチャートのうち10個がAPI認証なしで提供されている」**(バージョン1.2)の背景となるデータとエビデンスが含まれています。
レポートはこちら: https://sorami.com.au/research/ai-kubernetes-helm-chart-security/
手法、調査結果、深刻度評価、およびハードニングのアドバイスはレポートに記載されています。このリポジトリではそれらを繰り返しません。レポートが引用するデータファイルを保持しており、読者が各主張を確認できるようになっています。
デフォルト値、2026年9月24日にレンダリング。一部のライブプローブは2026年9月25日に再実行されました。
| チャート | バージョン | ソース |
|---|---|---|
| vllm/vllm-stack | 0.1.12 | https://vllm-project.github.io/production-stack |
| kserve-resources | v0.20.0 | oci://ghcr.io/kserve/charts/kserve-resources |
| kuberay/kuberay-operator, kuberay/ray-cluster | 1.7.1 | https://ray-project.github.io/kuberay-helm/ |
| vllm-project/aibrix dist/chart | 0.7.0 | git tag v0.7.0 |
| otwld/ollama | 1.83.0 | https://helm.otwld.com/ |
| open-webui/open-webui | 16.6.0 | https://helm.openwebui.com/ |
| go-skynet/local-ai | 3.4.2 | https://go-skynet.github.io/helm-charts/ |
| litellm-helm | 1.102.1 | oci://ghcr.io/berriai/litellm-helm |
| langfuse/langfuse | 2.1.2 | https://langfuse.github.io/langfuse-k8s |
| n8n-io/n8n-hosting charts/n8n | 1.13.0 | git commit 359e1772 |
| qdrant/qdrant | 1.19.1 | https://qdrant.github.io/qdrant-helm |
| weaviate/weaviate | 17.8.3 | https://weaviate.github.io/weaviate-helm |
| milvus/milvus | 5.0.28 | https://zilliztech.github.io/milvus-helm/ |
| containers/kubernetes-mcp-server | 0.1.0 | oci://ghcr.io/containers/charts/kubernetes-mcp-server |
| Flux159/mcp-server-kubernetes helm-chart | 2.8.0 | git tag v4.1.7 |
results.csv: チャートごとに1行、チェックごとに1列で、各値のエビデンスを含みます。tools.tsv: チャートのソース、固定バージョン、および各チャートに必要だったレンダリングオーバーライド(ある場合)。manual-checks.tsv: API認証とテレメトリのデフォルト値。ベンダーのドキュメントとソースに対して手作業で確認したもの。dynamic-results.tsv: ローカルテストクラスタ上でのライブプローブの結果。evidence/totals.json: レポートで使用された主要な集計値。evidence/doc-urls.tsv: 各主張で引用されたベンダードキュメントと、2026年9月24日時点のHTTPステータス。evidence/scans/scan-summary.json、evidence/scans/scan-detail.json: Kubescape 4.0.14、Checkov 3.3.19、kube-linter 0.8.3、Trivy 0.74.0によるチャートごとの集計値。evidence/dynamic/: ライブプローブのリクエストとレスポンスのログ、およびレポートで言及されているServiceAccountに対するkubectl auth can-iの出力。figures/: レポートで使用された図。values.yaml:17のようなfile:line参照は、上記の固定バージョンにおけるチャート自身のファイルを指します。charts/repo-qdrant/qdrant/values.yamlのようなパスは、展開されたチャートからの相対パスです。off、on、not_enforcedなどの値はレポートで定義されています。<kubeconfig>、<kind-context>、<charts>、<pod-ip>などのプレースホルダに置き換えられています。リクエストやレスポンスのその他の部分は変更されていません。REDACTED-RENDER-TIME-PASSWORDに置き換えられています。ベンダーがチャートに同梱しているプレースホルダ認証情報はそのまま残されています。それがまさに調査結果だからです。ベンダーのチャートファイルやレンダリングされたマニフェストは再配布しません。誰でも公開チャートから再生成できます:
helm repo add vllm https://vllm-project.github.io/production-stack
helm repo add kuberay https://ray-project.github.io/kuberay-helm/
helm repo add otwld https://helm.otwld.com/
helm repo add open-webui https://helm.openwebui.com/
helm repo add langfuse https://langfuse.github.io/langfuse-k8s
helm repo add qdrant https://qdrant.github.io/qdrant-helm
helm repo add weaviate https://weaviate.github.io/weaviate-helm
helm repo add milvus https://zilliztech.github.io/milvus-helm/
helm repo add localai https://go-skynet.github.io/helm-charts/
helm repo update
helm template rel vllm/vllm-stack --version 0.1.12 --namespace sbd
helm template rel kuberay/kuberay-operator --version 1.7.1 --namespace sbd
helm template rel kuberay/ray-cluster --version 1.7.1 --namespace sbd
helm template rel otwld/ollama --version 1.83.0 --namespace sbd
helm template rel open-webui/open-webui --version 16.6.0 --namespace sbd
helm template rel langfuse/langfuse --version 2.1.2 --namespace sbd --set clickhouse.crdCheck=false
helm template rel qdrant/qdrant --version 1.19.1 --namespace sbd
helm template rel weaviate/weaviate --version 17.8.3 --namespace sbd
helm template rel milvus/milvus --version 5.0.28 --namespace sbd
helm template rel localai/local-ai --version 3.4.2 --namespace sbd
helm template rel oci://ghcr.io/berriai/litellm-helm --version 1.102.1 --namespace sbd
helm template rel oci://ghcr.io/kserve/charts/kserve-resources --version v0.20.0 --namespace sbd
helm template rel oci://ghcr.io/containers/charts/kubernetes-mcp-server --version 0.1.0 --namespace sbd --set ingress.host=mcp.example.invalid
git clone --depth 1 --branch v0.7.0 https://github.com/vllm-project/aibrix.git
helm template rel aibrix/dist/chart --namespace sbd
git clone --depth 1 --branch v4.1.7 https://github.com/Flux159/mcp-server-kubernetes.git
helm template rel mcp-server-kubernetes/helm-chart --namespace sbd
git clone https://github.com/n8n-io/n8n-hosting.git && git -C n8n-hosting checkout 359e1772f9e4987c964aa4d6ab1621d07bdb107f
helm template rel n8n-hosting/charts/n8n --namespace sbd --set secretRefs.env.N8N_ENCRYPTION_KEY=research-placeholder-not-a-secret
Helm 3.19以降を使用してください(LangfuseチャートはfromTomlを必要とします)。レンダリングにkubeコンテキストは不要です。一部のチャートはフローティングイメージタグを使用しているため、後でレンダリングすると新しいイメージを参照する可能性があります。
すべての調査結果はベンダーが文書化しているデフォルトであり、レポートはそれぞれについてベンダー自身のドキュメントにリンクしています。テストは本研究のために作成され、その後削除されたローカルクラスタ上でのみ実行されました。第三者、顧客、またはインターネットに公開されたシステムはスキャンも接触もされていません。調査結果について質問のあるベンダーは[email protected]までご連絡ください。
このリポジトリのデータ、エビデンスファイル、および図はCC BY 4.0の下で公開されています。Copyright 2026 Sorami Consulting Pty Ltd. 詳細はLICENSEを参照してください。
引用: Sorami (2026). AI on Kubernetes: 10 of 14 Helm charts ship with no API auth. Sorami Technical Report, version 1.2. https://sorami.com.au/research/ai-kubernetes-helm-chart-security/
連絡先: [email protected]