In practice the difference is that while RDP (or database or WordPress) credentials are vulnerable to bruteforce, in almost all cases k8s clusters are secured by either mtls or jwt tokens - both utterly non bruteforcable. You're not completely right though, unsecured k8s clusters do happen[1]. And there is some defense in depth component, as you've mentioned.
And yeah, we're one RCE away from the cloud melting disaster. But then, the same is true for nginx or openssh.
[1] http://redhuntlabs.com/blog/unsecured-kubernetes-clusters-ex...
[2] Fun but meaningless fact: kube-api defaults for both authentication and authorization are to allow anonymous users and allow everything to everyone (AlwaysAllow)[3]. This is meaningless because every k8s distribution in existence changes authorization default with appropriate flags.
[3] https://kubernetes.io/docs/reference/access-authn-authz/kube...