IIUC, there is no way to use an existing secret for S3 credentials (s3.accessKey and s3.secretKey). It's counter-intuitive since Helm values are supposed to be pushed to the VCS.
I guess the same goes for redis.password, redis.external.password, and azs.accessKey.