kube api gives you auditing, events, rbac, across pretty much all layers of the infra stack. if the agent does something in a VM you have to figure out what happened. if it does something on the control plane, it’s obvious what happened. i agree with you that security is any issue either way (especially based on recent events) but doing it under the kube umbrella makes it easier to manage at scale
> if the agent does something in a VM you have to figure out what happened.
If you can't audit what users are doing on a Linux system you have no business pretending you can run a k8s cluster.
(k8s was a ZIRP-fueled evolutionary mistake for most of the industry.)
no one is saying you can’t audit a VM. it’s about where you should audit and place controls. the k8s control plane makes me care less about what’s going on in the VM.
hard disagree on your last point. k8s powers pretty much all clouds as we know it