The Twelve-Factor App
12factor.net
12factor.net
I know I'm not the only one who thinks so... Here's what the Docker security lead says about it: "When you store your secret keys in the environment, you are prone to accidentally expose them"
Details are here: https://github.com/docker/docker/pull/9176#issuecomment-9954...
In many cases the env vars are stored in files and those files have the same problem regular config files have when they are checked in to a repo :-)