Kubernetes Secrets and ConfigMaps haven't changed functionally since 2016, but everything around them has. The K8s Secret object is now the last mile of a longer pipeline, not the source of truth. Modern production setups use external secret managers (AWS Secrets Manager, Vault, etc.) synced via External Secrets Operator, or GitOps-native approaches like SOPS or Sealed Secrets. The biggest avoidable vulnerability in 2026 is still long-lived cloud credentials mounted as Secrets — workload identity (IRSA, Azure AD Workload Identity, GKE Workload Identity) eliminates this. Encryption at rest via KMS is table stakes, but RBAC drift is the more common real-world compromise vector. The post also touches on SPIFFE/SPIRE as a cluster-agnostic identity layer and how agentic AI workloads are pushing credential lifetimes toward seconds.