Secrets should really be stored in services, not files outside of maybe a single bootstrap file (unless you're working on the secret storage service itself).
I generate my secrets once, send them off to the secrets service, and then my service queries that service. I never see the secrets with my own eyes.