You can use any of the various Secrets Management Tools.
You can store your secrets in code in your SCM IF they are encrypted. You still need to deliver a secret securely at deploy time (or have it available at startup) to be able to decrypt the secrets (password, credentials, secrets, certs) that have been deployed. That is where the Secrets Management Tool (such a Vault) comes in. The tool will allow you to securely retrieve your secret for use in decryption of the secrets when it's needed.
The other way is to actually store all secrets, certificates etc. outside of the SCM in the Secret Management Tool itself and retrieve them at deploy / startup time.
But obviously both these methods have their own pros and cons.
Ready to Build the Future of IT? Start with Our DevOps Engineer Course!
Also, Transform Your Career with a PGP in DevOps!