Tanzu Build Service uses standard Kubernetes secrets to store credentials for registries and git based repositories. These credentials include the following:
Git credentials added to namespaces
Registry credentials added to namespaces
Registry credentials provided during installation
Encrypting Secrets at Rest
Because Tanzu Build Service uses standard Kubernetes secrets, administrators may configure the cluster to encrypt secrets at rest. For more information, see the following link: https://kubernetes.io/docs/tasks/administer-cluster/encrypt-data/
Using Synced Secrets to access Cluster Builders