Do your container images actually drop root? A quick way to check (and what 25 popular projects do)
If a container's final image never drops to a non-root user, a process that breaks out of your app runs as root inside the container — a bigger blast radius if it then finds a runtime or kernel escape