I run my Spring Boot application in the Kubernetes environment as a root user and with JMX authentication turned on.
My k8s containers are being flagged as a security risk by the security professionals in my company. Is it really a security risk or just plain old housekeeping?