We use Vault in our environment and deployments... Vault has a concept of using tokens for authentication to pull secrets. You can assign max number of uses, max TTL and other parameters when you generate them.
For our deployments, we generate a single token with a max # of uses that matches the target server count for our deploy and also a very short TTL of 5 seconds. Our code gets pushed and the token is passed to each server (in an env var) during that time and a command is passed to refresh environment vars with secrets from Vault. So if a token gets compromised it's very likely to be used up and/or expired.