I’ve never commented on a HN post, but finally you’ve all got to me. Why are people mostly commenting moaning about something completely different to what the article is about? Fine, I get it, you don’t like 1Password’s tactics regarding subscription models. But this is about infrastructure secret management. It’s the same with Google Cloud announcements “hOw LoNg UnTiL tHeY dEprEcAtE iT???” ... boooooooring
Secrets management for network systems has been an issue since before kerberos. Having different models, isolating secrets from the repo and deployment codebase into a 3rd party module is one of the rational choices.
I would want to understand a secure secret import and export model, much as for an HSM you want to know how to move shrouded keys (if its not in FIPS mode i guess)