[Docs] add cache directory security guidance#38920
Merged
Merged
Conversation
Contributor
|
Documentation preview: https://vllm--38920.org.readthedocs.build/en/38920/ |
Contributor
There was a problem hiding this comment.
Code Review
This pull request introduces a 'Cache Directory Security' section to the documentation, detailing the security implications of vLLM's cache management and listing relevant environment variables. The review feedback highlights that the documentation inaccurately implies all caches are under a single root, specifically noting that the Triton cache is a separate, critical path for security. Suggestions were made to include TRITON_CACHE_DIR in the configuration table and to broaden permission recommendations to cover these external cache locations.
Document that vLLM cache directories are assumed private and trusted, and that providing untrusted access could result in crashes or arbitrary code execution. List the relevant environment variables that control cache locations. Signed-off-by: Russell Bryant <rbryant@redhat.com>
Address review feedback by noting that vLLM redirects TRITON_CACHE_DIR under VLLM_CACHE_ROOT when compile caching is enabled (the default), and that ~/.triton/cache is only used as a fallback when compile caching is disabled. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Russell Bryant <rbryant@redhat.com>
e530353 to
9068d2a
Compare
sfeng33
approved these changes
May 6, 2026
libinta
pushed a commit
to libinta/vllm
that referenced
this pull request
May 8, 2026
Signed-off-by: Russell Bryant <rbryant@redhat.com> Signed-off-by: Libin Tang <libin.tang@intel.com>
weifang231
pushed a commit
to weifang231/eb-vllm
that referenced
this pull request
May 13, 2026
Signed-off-by: Russell Bryant <rbryant@redhat.com>
mfylcek
pushed a commit
to mfylcek/vllm
that referenced
this pull request
May 19, 2026
Signed-off-by: Russell Bryant <rbryant@redhat.com>
jhu960213
pushed a commit
to jhu960213/vllm
that referenced
this pull request
May 20, 2026
Signed-off-by: Russell Bryant <rbryant@redhat.com>
mvanhorn
pushed a commit
to mvanhorn/vllm
that referenced
this pull request
Jun 4, 2026
Signed-off-by: Russell Bryant <rbryant@redhat.com> Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
knight0528
pushed a commit
to knight0528/vllm
that referenced
this pull request
Jun 8, 2026
Signed-off-by: Russell Bryant <rbryant@redhat.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Document that vLLM cache directories are assumed private and trusted,
and that providing untrusted access could result in crashes or arbitrary
code execution. List the relevant environment variables that control
cache locations.
Signed-off-by: Russell Bryant rbryant@redhat.com