Currently the namespace-scoped CRD allows reference to secrets in other namespaces, which may enable namespace-scoped users to access secrets in unauthorized namespaces. Perhaps it's better to add webhooks to authorize users before referencing secrets.