But I Use SOPS
Summary
The article argues that SecretSpec offers a provider-agnostic interface for app secrets, decoupling secret declarations from encryption at rest. It compares SecretSpec to SOPS, explains how secrets are declared with secretspec.toml and retrieved via various providers, and highlights the supported SDKs and migration considerations. It also outlines future proposals to extend secret management workflows.