argocd-notifications-secret and argocd-secret are defined as empty secrets in the upstream install.yaml. Without the merge annotation, kustomize errors on duplicate resource IDs when the KSOPS generator also produces them.
KSOPS cannot handle multi-document YAML files; each secret needs its own encrypted file. Updated ksops-generator.yaml to reference all 7 secrets.