Environment variables. If they’re in my network, that has no open ports to the internet, I’ve got plenty more problems.
Even a dev machine, think about how many env vars a normal dev has, plenty to loose.
Secrets management tool for self hosting on my level would bring more complexity for little gain.
Bash scripts etc can be uploaded to open repo and not share secrets which is what I want.
I havent used both, but if you can use python or Js at all, you can put whole code blocks into node red, I have used cgpt to make filters and json parsers for me before. It is quite easy to use in general and handles all my backend piping / logic for HA. I have devices from like 20 different vendors all playing perfect in node red, then HA just shows the nice dashboard essentially.
pi
pi3
pi3v2
space
fusion
magnet
qdivision