There is a solution to this coming in v1.5 - https://github.com/kubernetes/kubernetes/pull/32518
As such there needs to be a level of hardening done from an out of the box perspective where they're being used in a high-security environment (e.g. banking).
For Docker we have resources like docker_bench and the CIS guide which provide a list of possible hardening steps, but I've not managed to find anything like that for Kubernetes, which is why I'm interested in how Monzo are addressing that issue.
[1] https://www.twistlock.com/
[2] https://cloudplatform.googleblog.com/2015/11/enhancements-to...