Per the Infisical operator notes: a service token scoped to / ignores the CRD secretsPath and always returns root secrets. Scope the token to /** (or /myapp/** for isolation) to make sub-path folders work.

Context: Problem: An InfisicalSecret CRD sets secretsPath to /app-name, but the synced Kubernetes Secret contains the root / secrets instead. Cause: the service token used by the operator is scoped to the path / rather than /**. A token scoped to / always returns root secrets no matter what secretsPath the CRD specifies. Fix: create a new service token whose path is literally /** (self-hosted Infisical has no "grant sub-folder access" checkbox - just type /** in the path field), then update the auth Secret (key infisicalToken) the operator reads. Note the operator does not isolate sub-paths from root by default, so scoping the token to /myapp/** keeps one app from inheriting every root secret.

## Matched source
Source: Source: https://github.com/bnaylor/agent_skills/blob/HEAD/infisical-pro/SKILL.md
Original query: "Infisical operator syncs root secrets instead of the sub-path in secretsPath"
Key terms: infisical, instead, operator, path, root, secrets, secretspath, syncs
