Sorry to be snarky, but after all this great job, I still have to put the db password in clear text, as an environment variable...
Why not use secrets manager for this? It can even rotate the secret with not much headache.
/edit: I could have a wrapper script that reads the secret and then os.execve()...