> there are going to be bad actors poking around in your private network eventually
Sure, but will those bad actors be poking around in your network at the same time as you've got an unpatched vulnerability in Kubernetes? Or will it just be the 1000s of Internet scanners and botnets looking to exploit it?
> There is no such thing as a "private" network that is magically more secure than the internet
Obviously there is, although it's not magic. I could equally say "There is no such thing as a 'private' key that is magically more secure than nothing".
> if you don't trust it on the internet, you shouldn't trust it on your private network
This bit is true. But just because you trust it doesn't mean it needs to be exposed.