Right now we use 1Password through Terraform and provision secrets in K8S. We could try either [1Password Kubernetes integrations](https://developer.1password.com/docs/k8s/k8s-integrations/), or [External Secrets](https://external-secrets.io/latest/provider/1password-automation/), or Hashicorp Vault.