Kubernetes RBAC controls API actions, not what a running container can then do

Permissions govern what can be asked of the cluster, not what happens inside the container once it is running.

A tightly restricted role can still schedule a pod that does whatever it likes on the node, subject to pod security settings. The two controls sit at different layers and people regularly assume one covers the other, which leaves a gap exactly where workloads execute.

More on Kubernetes