If I want my random DigitalOcean VPS to have access to an account elsewhere, it's going to need a secret of some sort. If it gets issued ephemeral secrets from something like Vault it still needs to be able to identify itself to Vault as "I'm DigitalOcean VPS ID=32443 and I need a 1 hour secret to access this GitHub repo".
Eventually, something needs to have a non-expiring secret to help identify it.
The more complicated we make this stuff the more chance someone will make a mistake in configuring it and open themselves up to a breach.