RCKT doesnt require root access, only a basic SELECT, INSERT and DELETE user. We highly recommend that people create MySQL credentials specifically for RCKT, and we always prioritize security in our platform architecture
Is phpMyAdmin deserving of trust? My memory is that it's basically a security nightmare.
It might be, but if its running in my DC I can isolate it to authenticated VPN users and audit the hell out of it. Also helps that I can deploy it single tenant.