node_modules *.tsbuildinfo # Claude Code local state — per-operator settings + agent worktrees; never commit. .claude/ .env.local .env # Exception: tf/.env is committed — contains only op:// references to 1P items, # no literal secrets. Resolved at runtime by `op run --env-file=tf/.env -- ...`. !tf/.env !tf/pages/.env mise.local.toml dist/ packages/yuctl/resticbench/bench-agent-linux-amd64.gz packages/michael/michael # k3d/Tilt dev stack — Helm builds subchart snapshots on the fly; the .dev/ # directory holds persistent service data carried over from the compose flow. .dev/ charts/**/charts/ charts/**/tmpcharts-*/ charts/**/Chart.lock # air (Go live-reload) temp build output in michael package packages/michael/tmp/ # OpenTofu / Terraform # .terraform.lock.hcl IS committed for reproducibility **/.terraform/ **/terraform.tfstate **/terraform.tfstate.* **/*.tfvars.local # Secret material — never commit. App private keys + cluster credentials are # stored in 1Password and injected at runtime (TF_VAR / op run); these patterns # are a backstop so a downloaded key or fetched config can't be added by accident. *.pem *-private-key*.pem **/kubeconfig **/talosconfig *kubeconfig *talosconfig .private/ # terragrunt-generated backend.tf contains absolute per-operator paths **/backend.tf # Ansible runtime artifacts ansible/*/ansible.log ansible/*/ansible.*.log ansible/*/.ansible/ ansible/*/.ansible_facts_cache/ ansible/*/.venv/ # Working notes for the partition/region/ceph-cluster rework — local scratch. notes.md # Lens / decision-support artifacts are controller-local notes, not repo code. # Per-project: kept outside the repo (e.g., ~/Projects/immich/yucca-ceph-import/analysis/ # on operator workstation, but not tracked). analysis/ # prod deployment-stack terraform — locally-built providers + generated artifacts tf/.terraformrc.local .mise/.provider-bin/ .mise/.provider-mirror/ .mise/.hetzner-provider-src/ # self-built hetzner (mirror) makes this lock platform-specific; regenerated by init tf/deployment/prod/htz-fsn1/fabric/.terraform.lock.hcl # ansible/mgmt inventory is TF-generated at run time (tf/render/ansible-mgmt) — # Terraform is the source of truth, not these files. ansible/mgmt/inventories/*/hosts.yml ansible/mgmt/inventories/*/host_vars/ ansible/mgmt/inventories/*/group_vars/all/users.generated.yml # ephemeral local state for the render roots tf/render/*/.terraform/ tf/render/*/.terraform.lock.hcl tf/render/*/terraform.tfstate* .DS_Store # Local operator credential/token caches — NEVER commit. Tracked configs (tf/.env*) # reference secrets as op:// refs only; literal tokens live in the harness scratchpad # (outside the repo). These patterns are a belt-and-braces guard in case a cache is # ever written inside the tree. op_sa nb_pat nb_setup_key aws_key aws_secret robot_user robot_pass hcloud_token *.token *.secret env.local.sh