PHP's phpinfo() function comes to mind immediately: https://www.php.net/manual/en/function.phpinfo.php
PHP's phpinfo() function comes to mind immediately: https://www.php.net/manual/en/function.phpinfo.php
In any case, defense in depth seems like reason alone to do this.
It's a good question.
But consider, containers are (in modern infra) transient and usually sit in a constrained security context where access to other resources is pretty limited. Meanwhile the login credentials and security tokens are often long-lived and (usually) give broad access to a wide security context.
If you give me a back door to a container, the first thing I would be trying to do is use it to level up my credentials before the container dies. One of the first things I would try is dumping the environment!
But if the secrets were learned via an ephemeral file or through a temporary network connection, and even better if they were exchanged for time limited or single use type tokens, I am really left with both a challenging task to dig them out and / or something of limited value anyway.
Then the blame is on the logging system configuration, not the env vars. Like you sanitize sensitive information out of logs, you should sanitize and not expose environment variables in your logs.
But also note, in such a case the key probably isn’t coming from an environment variable, more likely is a subkey generated by a HSM.