Base64 Is Not Encryption. Vault Is Not Custody. What Kubernetes Secrets Actually Need.
The K8s secrets debate is well-documented. Common delivery patterns — Vault, ESO, Sealed Secrets, CSI, SOPS — leave a runtime exposure gap: plaintext as a standing cluster-level artifact in Secret resources, environment variables, or mounted files. The architectural question is not which secrets manager to pick. It is where the key lives and how plaintext is recovered for the operation that actually needs it.