simonw, I have been seeing "credential injection" and "credential tokenizing" (a la tokenizer:
https://github.com/superfly/tokenizer). I'm also seeing credential "surrogates" mentioned.
I am currently working on a mitm proxy for use with devcontainers to try to implement this pattern, but I'm certainly not the only one!