This seems pretty reasonable. The obvious risk is that if the encryption keys leak, all of your credentials may be retroactively compromised...
Still, much better than keeping the passwords in VC unprotected, of course.
My preference still is using environment variables so that the secure bits can be fully decoupled from your code, however..