Most organizations I know will still use something like ExternalSecret for source control and then populate the Secret with the values once in cluster and to an object with very few access points.
And you can encode it for example using an external KMS.
You can set up encryption at rest, you can use RBAC to control the access, etc — those features are possible because Secret gives a specific resource for secret data.
If the interface were redesigned today, Secrets would probably look like a renamed clone of ConfigMap.
You can also configure the apiserver/etcd to encrypt specific keyspaces, such as the secrets/ key space.
https://kubernetes.io/docs/tasks/administer-cluster/encrypt-...
- You can configure etcd to encrypt Secrets without taking the encryption performance hit on ConfigMaps
- You can configure the audit logs to log the diff whenever a ConfigMap was created or updated while only logging metadata and redacting content when Secrets are created or updated
- You can configure RBAC policies that grant access to ConfigMaps without Secrets (e.g. for a controller or operator)