You may consider these objectives to store sensitive data used by GKE clusters as secrets:
Create a secret in Google Cloud Secret Manager.
Create a GKE Autopilot cluster, Kubernetes namespaces, and Kubernetes service accounts.
Create IAM Allow policies to grant access to your Kubernetes service accounts on the secret.
Use test applications to verify service account access.
Run a sample app that accesses the secret using the Secret Manager API.