If the ALM input parameters include a prefix, then any generated secrets (ibmcloud-api-key and the specified signing-key) should also have that prefix, to avoid duplication.
This would allow us to use prefixes to properly scope ALM installations, and to be able to reuse secrets manager instances.
Link to related issue: terraform-ibm-modules/terraform-ibm-rag-sample-da#138
fyi @ocofaigh