Environment variables are not secret vaults

Putting a secret in an environment variable keeps it out of the code, which is an improvement, and it is not a vault.

They leak readily: into crash reports, into debug output, into process listings, into logs that capture the whole environment for troubleshooting, into child processes nobody thought about. They also cannot be rotated without a restart and leave no record of who read them. It is a reasonable step up from hardcoding. It is not the destination.

More on Passwords and secrets