Currently we end up using the secret managers available in AWS or GCP, which seems pretty half baked. In GCP, for example, secrets are stored at a project level. It's not unusual to have certain secrets that are needed by more than one project, which means they get duplicated. The granularity also prevents me from controlling which secrets are visible to a given user.
I'd love to have one centralized source of truth for all infrastructure secrets.