On the Docker DevRel team... yes! This is it. The secret is injected only into headers in which the hostname matches.
There's also an ability to create kits where you can setup credential injection into other services as well.