So then how do you manage the secret that authenticates an application's identity? And what good is the logging if after an application has the secret it can do whatever it wants with it?
you should only let the instance access the secret it requires.
As OP wrote, you did not solve it, just moved it to a different level.