I also use env vars.
https://systemd.io/CREDENTIALS/
https://kubernetes.io/docs/concepts/configuration/secret/#us...
(Systemd also has more complex modes that are safer than files. And the Linux kernel has a concept of keyrings that might be even better.)
I also use env vars.