For most self-hosted deployments the better answer is the volume: LUKS, an encrypted EBS volume, a storage class that does it transparently. Reach for this when the storage itself is what you do not trust: a shared NAS, a bucket somebody else operates, a disk you will one day return under warranty.
The key is a file path, never the key itself: a key in an environment variable is in the pod spec, in docker inspect, and in every log that dumps the environment. Rotation is a new line at the top of the file. Compression runs first when both are on.
It does not protect against anyone who has the running server, because that process holds the key by construction.