Secrets in env vars in production is not too secure either, ideally you’ll move to your app pulling secrets in-process from your infrastructure at boot-up or upon use. This also gives a nice advantage of not needing to rebuild the app or container or whatever to rotate a secret.
This just moves the problem to a different step. How are you going to manage access to said secrets, especially when your application lives off premises?
I am far too clumsy to trust myself to push secrets in encrypted form, personally