I would expect that cehadm_key will be able to accept secret. It's also defined [here](https://github.com/stackhpc/ansible-collection-cephadm/blob/04fc76e620d460d37b06d2d9f44a97c0d019ac36/roles/keys/tasks/main.yml#L7) But module don't support it.