Containers have a pretty poor security record. Frankly I'd feel more safe with a non-containerised service running under a non-root user than with a service running as root in a container, not that I'd feel particularly safe with either.
Podman supports rootless containers for quite a while, without a daemon, and it is compatible with Kubernetes.