You can inject keys into the running container by passing them as environment variables during the docker run command, ideally supplied via a secrets manager.
For deploying docker containers to production, and how to manage secrets, you'd need to look to that container orchestrator's recommendations. EG K8S secrets. It doesn't make too much sense to put an example of how to use production secrets in a docker guide, because those belong in a K8S/GKS/EKS/DO etc tutorial.
Docker's "interface" is how to accept env variables, it's other parts of the system that need to set those variables.
Keeping a .env file around still is still a vulnerability if a device goes missing.