Solutionunvalidated
only the service account should be able to read the file (`400` permission). — Running on a managed platform like a Cloud, or even a self managed Kubernetes. Tension: you would have to secure access to the encryption key with yet another password in a file. Outcome: you can use the identity given to your application when it is started by the platform.
48a251c2-fe79-462b-96e4-6ee5a0335744
only the service account should be able to read the file (400 permission). — Running on a managed platform like a Cloud, or even a self managed Kubernetes. Tension: you would have to secure access to the encryption key with yet another password in a file. Outcome: you can use the identity given to your application when it is started by the platform.