Its been known for quite sometime to not expose the dashboard. GKE explicitly disables it by default. TESLA's in-house cluster was pwned because their dashboard was publicly accessible etc.
phpMyAdmin or what it's called, back in the days of LAMP stacks that was deployed almost everywhere without much security around. Not sure if it also had sql injection bugs etc, but just the low amount of security considerations most people gave this direct access to the database was probably enough to hack into most servers of that time.
Don't worry about security, we need to ship.