- Exposing secrets as in-memory files has a lot of advantages over ENV variables (harder to leak).
- We already started updating a few images (MySQL, for example), so they can use Docker secrets.
- Definitely not DDC only, but note that RBAC over secrets is a feature of the commercial product.