I think it’s overkill for homelab and over complex/additional failure points.
I use sops encrypted, published in my public git. When I apply my nix config, they are pulled and unencrypted on apply on the local machine.
Keeps it as simple as I can think of, with few moving parts.
Looks a lot likehttps://github.com/open-webui/open-webui
I’m using it with open router, helps me claw back a little privacy