Secrets and LIE-Abilities: The State of Modern Secret Management (2017)
medium.com
medium.com
KeyWhiz: Provides everything you need but with complex PKI management, meaning setup and maintenance is a pain. Secure.
Vault: A+ would test again. Awesome rotation policies, on-demand secret generation via backends, master key sharing. Legit and secure, everything you need but has to be configured on top of your cluster.
Docker: Super easy to use, and it's built in. 10/10 would use again. Keys encrypted at rest, keys encrypted over the wire, and shared with only nodes who need them. Secure all round
Kube: Totally insecure. Plaintext at rest, plaintext over the network, shared everywhere. Basically a plaintext POC
Key one to watch for is down the end though, be careful with what Kubernetes calls "secrets"!