You run your agent in a container and you only give it access to agent-specific secrets that can be rotated easily.