node_modules
*.tsbuildinfo

.env.local
.env

# Exception: tf/.env is committed — contains only op:// references to 1P items,
# no literal secrets. Resolved at runtime by `op run --env-file=tf/.env -- ...`.
!tf/.env

mise.local.toml

dist/
packages/michael/michael

# k3d/Tilt dev stack — Helm builds subchart snapshots on the fly; the .dev/
# directory holds persistent service data carried over from the compose flow.
.dev/
charts/**/charts/
charts/**/tmpcharts-*/
charts/**/Chart.lock

# air (Go live-reload) temp build output in michael package
packages/michael/tmp/

# OpenTofu / Terraform
# .terraform.lock.hcl IS committed for reproducibility
**/.terraform/
**/terraform.tfstate
**/terraform.tfstate.*
**/*.tfvars.local

# Secret material — never commit. App private keys + cluster credentials are
# stored in 1Password and injected at runtime (TF_VAR / op run); these patterns
# are a backstop so a downloaded key or fetched config can't be added by accident.
*.pem
*-private-key*.pem
**/kubeconfig
**/talosconfig
*kubeconfig
*talosconfig
.private/
# terragrunt-generated backend.tf contains absolute per-operator paths
**/backend.tf

# Ansible runtime artifacts
ansible/*/ansible.log
ansible/*/ansible.*.log
ansible/*/.ansible/
ansible/*/.ansible_facts_cache/
ansible/*/.venv/

# Lens / decision-support artifacts are controller-local notes, not repo code.
# Per-project: kept outside the repo (e.g., ~/Projects/immich/yucca-ceph-import/analysis/
# on operator workstation, but not tracked).
analysis/

# fabric (Junos/JTAF) terraform — generated artifacts
tf/.terraformrc.fabric
.mise/.fabric-provider-bin/
.mise/.fabric-provider-mirror/
# self-built junos-qfx (mirror) makes this lock platform-specific; regenerated by init
tf/deployment/prod/htz-fsn1/.terraform.lock.hcl
