That's the only way right now. The other ways I'm considering is with an environment variable and/or acl.
Environment variables are prone to leak or be passed to child processes when it is not desired. But if they are just a file path/pointer to where the secret is, that is mitigated somewhat as one then would still need access to that file.