After thinking a while, I believe I was in wrong way bridging LE and armbian with docker. When running container in docker, even in priviledged mode, there are limitations in container. My goal is not to containerize LE, but just to use kodi well prepared in armbian. So, I decide to simply chroot to LE fs, so that kodi can run with full compability as in host. If we want to put some restriction to it by using 'unshare' and 'runuser' commands.
I recommend that you try the latest versions of Buster-legacy-desktop Armbian + media script for Firefly Station P1 (rk3399) \ M1 (rk3328). In it, KODI and Rockchip Gst Player works with HW without any containers (including 4k). Details can be seen at the end of these topics.
rk3399
rk3328