I think you are misunderstanding. The secret does not need to be hardcoded in the python file. If it's read in from an environment variable or some other external source, it will also be in the pyc
It's very easy to verify:
secrets.py:
import os
SECRET = os.getenv('SECRET')
Then $ python -m compileall secrets.py
$ uncompyle6 __pycache__/secrets.cpython-38.pyc
# uncompyle6 version 3.7.0
# Python bytecode 3.8 (3413)
# Decompiled from: Python 3.8.2 (default, Mar 10 2020, 12:58:02)
# [Clang 11.0.0 (clang-1100.0.33.17)]
# Embedded file name: secrets.py
# Compiled at: ...
# Size of source mod 2**32: 40 bytes
import os
SECRET = os.getenv('SECRET')
# okay decompiling __pycache__/secrets.cpython-38.pycSo a snippet like “os.environ[‘my_super_secret’]” won’t contain anything else than the bytecode to fetch that environment variable.