Unfortunately I don't think there's a nice way to do that. You can retrieve secrets from pass (albeit with quite a bit of working around the intended evaluation model) but I don't see a good way to actually deploy the secrets without just putting the plain text into the Nix store (unless you also use a big server management thing like NixOps, as the author of that blog is, but in the time since blog was written NixOps has decided people shouldn't be using it anymore... so it's a bit of a mess). You'd really want something like sops-nix or agenix for that.
You can of course decide you don't care about the secrets being in the Nix store. It "just" means that every local user on the system can read them, as can anyone booting a live USB if the disk isn't encrypted. And, while this almost certainly isn't relevant to you right now, if you use the system as a binary cache for other systems those can get the plaintext secrets too. But you might not actually actually care about any of these.