Fixes #224
also ensure to initialize kms before the dataprovider, it could be needed to downgrade secret from cloud kms providers
Fixes #226
Fixes #233
also gcs credentials are now encrypted, both on disk and inside the provider. Data provider is automatically migrated and load data will accept old format too but you should upgrade to the new format to avoid future issues