But secrets are next to useless if they are:
- not used to limit number of people that have access to them (it is quite typical in small teams to give everybody access to production, which essentially gives you access to keys)
- not regularly rotated (at the very least when a person that had access to them leaves the company)
And rotation is hard: a lot of systems still don't support multiple keys, so rotation has to be very carefully tied to some form of blue-green deployment, which is often not possible.