# ---------------------------------------------------------------------------
# Owner documents. Held back deliberately for now, not permanently.
# Note that agents cloning this repo will not receive AGENTS.md while it is
# listed here, so they have to be handed the rules another way.
# ---------------------------------------------------------------------------
AGENTS.md
PLAN.md

# ---------------------------------------------------------------------------
# Secrets and credentials. Nothing in this block ever reaches the repository.
# ---------------------------------------------------------------------------
.env
.env.*
!.env.example
*.env

# private keys and certificates
*.pem
*.key
*.p12
*.pfx
*.jks
id_rsa*
id_ecdsa*
id_ed25519*
!*.pub

# cluster and cloud credentials
*.kubeconfig
kubeconfig
.kube/
.netrc
.npmrc
credentials
credentials.json
service-account*.json

# sealed-secrets private key backups. Losing this file means losing every
# sealed secret, so it is backed up outside the repo and never inside it.
*sealed-secrets-key*.yaml

# Plaintext inputs to Sealed Secrets. The sealed output (*-sealed.yaml) is
# encrypted and IS meant to be committed, so it is not ignored here.
deploy/secrets/*.plain.yaml
deploy/secrets/*.unsealed.yaml

# ---------------------------------------------------------------------------
# AI assistants, IDEs, editors. Local tooling, not part of the project.
# ---------------------------------------------------------------------------
.claude/
.codex/
.cursor/
.aider*
.continue/
.windsurf/
.github-copilot/
CLAUDE.local.md

.vscode/
.idea/
*.iml
.fleet/
.zed/
.helix/
.nvim.lua
.nvimrc
*.sublime-project
*.sublime-workspace
.vim/
*.swp
*.swo
*~
.\#*
\#*\#

.direnv/
.envrc
.ci/

# ---------------------------------------------------------------------------
# Terraform. The lock file is committed on purpose; state never is.
# ---------------------------------------------------------------------------
.terraform/
*.tfstate
*.tfstate.*
*.tfvars
!*.tfvars.example
terraform/**/inventory.yml
crash.log
crash.*.log
override.tf
override.tf.json

# ---------------------------------------------------------------------------
# Build output and local scratch
# ---------------------------------------------------------------------------
bin/
dist/
apps/api/api
apps/loadgen/loadgen
node_modules/
*.test
*.out
coverage.*
vendor/
!apps/web/vendor/
!apps/web/vendor/leaflet.css
!apps/web/vendor/leaflet.js
!apps/web/vendor/LEAFLET-LICENSE

# ---------------------------------------------------------------------------
# OS noise
# ---------------------------------------------------------------------------
.DS_Store
Thumbs.db
desktop.ini
