There should be a way for pods to be marked as "update-aware", where we are allowed to update the secrets in-place rather than do a full pod restart.