Given the PyPI supply chain attack, I recommend keeping a canary in the coalmine:
I have a bitcoin private key containing $100 of BTC in my .bashrc. It's clearly labelled.
If my system is ever compromised by some bad package, the BTC will get stolen, and I'll see the move on-chain. And that'll tell me that I need to rotate every single other secret.
There are even services that will send you an alert (text, email, whatsapp...) if a given bitcoin address moves funds. It's good to have a burglar alarm, especially when time is of the essence.