Unfortunately, as the author alludes to later on in the article, 'encryption at rest' is usually required by compliance standards, e.g., PCI-DSS, SOC2, etc. Just about every environment I've seen either turns on etcd encryption as a box-ticking exercise or simply forbids Kubernetes secrets.