You need to create the key outside the cluster and pass in as part of your deployment.
This PR added the functionality to do this using a KubernetesSecretsRepository