if it is an instance on the cloud, GCP and AWS let you define ServiceAccounts that get populated on the Instance at boot time.
you should only let the instance access the secret it requires.
you should only let the instance access the secret it requires.
As OP wrote, you did not solve it, just moved it to a different level.