I didn't say something different. But having one bad solution makes another bad solution not better. Both are no-gos!
So you do not put passphrases on your ssh keys? Because you don't give the private key away why protect it? So imagine you have development process that includes a jenkins that needs to build the source and therefor needs access to the repository. What do you do?
And it is not only for access to git repos and such. If we want to develop decent systems we need a way to store credentials safe and external to the image.
Norbert