Privileged containers weaken the host boundary

Running a container as privileged effectively removes the separation it was providing.

It is done to make something work: a tool that needs device access, an agent that needs to see the host. Each instance is justified and the result is a workload that can reach the host directly. The question is always whether a narrower capability would do, and usually one would.

More on Kubernetes