(for now, this is supported only in runtime action manifest inputs)
As an example BringYourOwn AWS credentials are read from app.config.yaml, although we support the $include directive, which would provide a mechanism to users to not commit the secret into app.config.yaml, it would be good to support reading those from env.
This would align with our recommendation to store secrets in .env