The spec is focused (properly) on what implementations must and must not do. It's hard for an implementor trying to understand how they can implement the specification. We should create an implementor guide that gives a non-normative overview of the concepts and recommendations for implementing the spec.
Topics to cover include:
mounting secrets as readonly