Was in same situation. Vault would have been ideal but not enough people believed it was worth the effort while many other things were behind schedule.
AWS Secrets Manager looked like it could do what was required with little set up.
GitCrypt was ok to start with.....