The password below comes from 1Password item cluster-hetzner-demo-1p,
synced into a Kubernetes Secret by the 1Password Operator and injected as an
env var. Rotate it in the 1Password UI and watch the pod restart with a new value.
"password (env)" and "pod" only change after a pod restart (auto-restart on rotation). "item-version (live)" updates as soon as the Operator patches the Secret — so during a rotation you may briefly see a new item-version while the env password is still the old one.