by the app.yaml configuration files documentation, its allows env variables like:
runtime: nodejs16 # or another supported version
instance_class: F2
env_variables:
BUCKET_NAME: "example-gcs-bucket"
DB_PASSWORD: "my_secret_pw"
However some of those variables may contain sensitive data like DB_PASSWORD.
The deployment yaml file is in the repository and the CI pipeline reffers it to deploy to the GCP App Engine service.
How can i secure the those variable value and prevent that anyone with repository acesses be able to see them?