Ask HN: How are you keeping up with your app secrets?
Tokens, passwords, API keys, and stuff like that.
a hashicorp vault you change your secret there and every supporting application can retrieve it from there and use it. once they are done they delete it from the ram. If you can/want use specific kernel apis i would propose keyctl( https://www.man7.org/linux/man-pages/man2/keyctl.2.html ) this apis can store secrets limited to an specific range(threat, process, user, ...) outside of the process.
There is also the startup Doppler (https://www.doppler.com/) that is directly taking on the Hashicorp Vault space. It’s probably easier to get up and running and friendlier for a smaller team. No affiliation!
Disclaimer: I'm one of the founders