Keeps your passwords and API keys in a proper secrets vault (Vault, AWS Secrets Manager, etc.) instead of loose in Kubernetes config, while still letting your apps read them the normal Kubernetes way — free, open source, and CNCF-backed.
external-secrets.io