They pointed out quite explicitly, that you shouldn't just pass raw secrets around. However, they didn't mention any secret storage for whatever reason. For example, you can use
vault_generic_secret resource to store credentials in Vault and then something like the External Secrets Operator to fetch them from there. I am not saying, you should, but you can.P.S. This article was shared in our chat. Come join us! The chat is in Ukrainian, and it's usually fun!
#terraform #argocd #cd #kubernetes