Uppsats
Security Analysis of Kubernetes Helm Charts in Artifact Hub : Investigating their security misconfigurations systematically
Magister-uppsats
Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Background. Kubernetes has become the de facto standard for deploying cloud native applications, and Helm charts are widely used to package and distribute Kubernetes configurations via repositories such as Artifact Hub. While prior research has examined security misconfigurations in raw Kubernetes manifests, less is known about the security posture of reusable Helm charts when rendered with default values, and about how reliably existing static analysis tools capture such issues. Objectives. This thesis pursues three objectives: (i) to characterise security relevant configuration patterns in Helm charts hosted on Artifact Hub, (ii) to quantify how frequently these patterns occur across rendered manifests and charts, and (iii) to design and evaluate a stricter reimplementation of the SLI–KUBE scanner with clarified rule semantics, comparing its behaviour to the original Python prototype. Methods. Following a design science research approach, we design and implement a Go-based scanner that refines the semantics of existing misconfiguration rules, including explicit workload scoping, chart-level reasoning, and defensive traversal of rendered YAML. A reproducible pipeline downloads Helm charts from Artifact Hub, renders them using default values, and scans each document with both the Python and Go implementations. The final dataset consists of 171 renderable charts and 2 178 Kubernetes YAML documents. Results are aggregated into per-rule and per-chart summaries, and differences between the two tools are analysed to attribute observed deltas to semantic refinement rather than language choice. Results. Across the analysed corpus, structural configuration issues dominate the observed signals. Missing resource specifications (NO_RESO), missing security contexts (NO_SECU_CONTEXT), and absent namespace or network isolation primitives (NO_DEFAULT_NSPACE, NO_NETWORK_POLICY) occur frequently in default renders. In contrast, host-level privileges and powerful Linux capabilities are rare and concentrated in a small subset of system-level charts. The Go scanner reports more structural findings than the Python prototype due to stricter and more consistent rule semantics, while producing slightly fewer insecure HTTP detections. Overall agreement between the tools is high, and the Go implementation achieves lower runtime overhead. Conclusions. The study shows that many Helm charts on Artifact Hub render with weak security and resource defaults, even when they avoid extreme privilege settings. It also demonstrates that clarifying rule semantics and re–implementing them in a robust analysis artefact improves consistency, explainability, and performance without fundamentally altering the empirical picture. These findings are relevant for researchers studying configuration security, for tool builders designing static analysers, and for practitioners who adopt third-party Helm charts in production environments.
Information
- Författare
- Rafiei, Vahid
- Lärosäte / institution
- Blekinge Tekniska Högskola/Institutionen för programvaruteknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- Magister-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Magister-uppsats, Linnéuniversitetet/Institutionen för datavetenskap (DV)
Matar, Khaled, Mohammad, Yousef
Publicerad: 2026
Kandidat-uppsats, Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Abdullah, Adam, Krembi, Samra
Publicerad: 2026
Yrkesexamen på avancerad nivå, Luleå tekniska universitet/Institutionen för system- och rymdteknik
Larsson, Sune
Publicerad: 2026
Master-uppsats, Umeå universitet/Institutionen för datavetenskap
Alexeyev, Konstantin
Publicerad: 2026
Yrkesexamen på grundnivå, Mälardalens universitet/Institutionen för datavetenskap och datateknik
Norrman, Johnny, Rynger, Ida
Publicerad: 2026
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Correia, Diogo
Publicerad: 2026