Securing Vault Agent / Consul Template Secret Caching

I am a bit troubled by the writing of secrets to disk*memory where they can be read in clear text when enabling cache’ing. What are Best Practices does Hashicorp advise to ensure these are not available to someone with shell access.