HashiCorp Vault
Use Vault to store provider client secrets (Google, Microsoft, GitHub) outside .env.
Start Vault with the main stack:
docker compose -f docker-compose.yaml -f vault/docker-compose.vault.yml up -d
After Vault is unsealed, set:
VAULT_ADDRVAULT_TOKEN
in .env.