How are you handling secrets? I want hermes to do stuff on the internet but I am not enthused about dumping the requried keys in .env.local or using process wrapper services like infisical yet. Encapsulating hermes in a docker sandbox feels slippery and I'm always left thinking if i've hardened my server enough.