In devenc, you shouldnt need a ton of secrets anyhow. Each dev should have many of their own unique "secret" bits.

Being able to roatate a secret in devenv & have things keep working is early intermediate maturity model, but I'd wager most orgs have nothing.

This isn't a dotenv problem, isn't a security problem. It's that no one has soaked time or your department stoggily refuses to try out the really good Ansible or whatnot env to set your various microservices up for local dev.