Earlier quoted context omitted.
Hmm, that's confusing. So they're eventually encrypted but plain-text at some point? Doesn't sound good TBH.
Env vars are not secure. Anything that has root access can see all env vars of all applications via /proc. (And modern Linux is unusable without root access, thanks to Docker and other fast-and-loose approaches.)
Because I never do, unless I'm down in the depths of /var/lib/docker doing stuff I shouldn't.