I'm curious if you're familiar with the particulars of how Huggingface was hacked. They were negligent in their own ways and rights. Mounting a host path volume in a Kubernetes pod is really not "super hacker" territory!