Problems with the Kubernetes special agent

And when I try:

kubectl auth can-i get deployment --as=system:serviceaccount:check-mk:check-mk

I get:

yes

I can use at “all” any verbs of K8S.

So with the service account everything should be fine… (Regarding rbac and so on).