node_modules
*.tsbuildinfo

# Claude Code local state — per-operator settings + agent worktrees; never commit.
.claude/

.env.local
.env

# Exception: tf/.env is committed — contains only op:// references to 1P items,
# no literal secrets. Resolved at runtime by `op run --env-file=tf/.env -- ...`.
!tf/.env

mise.local.toml

dist/
packages/yuctl/internal/bench/bench-agent-linux-amd64.gz
packages/michael/michael

# k3d/Tilt dev stack — Helm builds subchart snapshots on the fly; the .dev/
# directory holds persistent service data carried over from the compose flow.
.dev/
charts/**/charts/
charts/**/tmpcharts-*/
charts/**/Chart.lock

# air (Go live-reload) temp build output in michael package
packages/michael/tmp/

# OpenTofu / Terraform
# .terraform.lock.hcl IS committed for reproducibility
**/.terraform/
**/terraform.tfstate
**/terraform.tfstate.*
**/*.tfvars.local

# Secret material — never commit. App private keys + cluster credentials are
# stored in 1Password and injected at runtime (TF_VAR / op run); these patterns
# are a backstop so a downloaded key or fetched config can't be added by accident.
*.pem
*-private-key*.pem
**/kubeconfig
**/talosconfig
*kubeconfig
*talosconfig
.private/
# terragrunt-generated backend.tf contains absolute per-operator paths
**/backend.tf

# Ansible runtime artifacts
ansible/*/ansible.log
ansible/*/ansible.*.log
ansible/*/.ansible/
ansible/*/.ansible_facts_cache/
ansible/*/.venv/

# Working notes for the partition/region/ceph-cluster rework — local scratch.
notes.md

# Lens / decision-support artifacts are controller-local notes, not repo code.
# Per-project: kept outside the repo (e.g., ~/Projects/immich/yucca-ceph-import/analysis/
# on operator workstation, but not tracked).
analysis/

# prod deployment-stack terraform — locally-built providers + generated artifacts
tf/.terraformrc.local
.mise/.provider-bin/
.mise/.provider-mirror/
.mise/.hetzner-provider-src/
# self-built hetzner (mirror) makes this lock platform-specific; regenerated by init
tf/deployment/prod/htz-fsn1/fabric/.terraform.lock.hcl

# ansible/mgmt inventory is TF-generated at run time (tf/render/ansible-mgmt) —
# Terraform is the source of truth, not these files.
ansible/mgmt/inventories/*/hosts.yml
ansible/mgmt/inventories/*/host_vars/
ansible/mgmt/inventories/*/group_vars/all/users.generated.yml
# ephemeral local state for the render roots
tf/render/*/.terraform/
tf/render/*/.terraform.lock.hcl
tf/render/*/terraform.tfstate*
.DS_Store

# Local operator credential/token caches — NEVER commit. Tracked configs (tf/.env*)
# reference secrets as op:// refs only; literal tokens live in the harness scratchpad
# (outside the repo). These patterns are a belt-and-braces guard in case a cache is
# ever written inside the tree.
op_sa
nb_pat
nb_setup_key
aws_key
aws_secret
robot_user
robot_pass
hcloud_token
*.token
*.secret
env.local.sh
