I've put together a script, git-dot that wraps git and git-crypt, allowing in-place dotfile management without symlinks that allows sensitive files to be encrypted.
I'm using it myself. It's had limited testing but just mentioning it in case anyone would like to try it. Feedback welcome.
http://git-dot.johnlane.ie