Prepare a common template that can be shared across all the projects. And keeping a common github action workflows that can be imported in the individual repos.
Management cluster currently has an auto approval that simply allows everything that passes through it. If we can gate it through the policies that enforces best practices guidelines, that could be an easier win.
Runtime policies in the target workload clusters can also be orchestrated through this mechanism (by using Mutating controller) .. but this could be a second phase.
<open floor>
Action items
Prashant to add the Secrets Management user story template
Call for review for the Secrets management User Story document. (All)
subhash to prepare fine grained requirements for the approval policy framework.