For .NET env's, we're in the process of putting each element into an AWS SSM secret or non-secret which can then be pulled out to form an appsettings.json.
All SSM parameters will be managed through pulumi.
Pulled via a script run via aws-vault.
Should be fine once the work is done, all