Repository navigation
Expand file tree
/
Copy path.gitignore
More file actions
49 lines (39 loc) · 2.16 KB
/
Copy path.gitignore
File metadata and controls
49 lines (39 loc) · 2.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
# ─────────────────────────────────────────────────────────────────────────────
# Secrets & generated state — NEVER commit these.
# The repo ships *.example templates for secret files; the real secrets are generated
# on the host by the Ansible role tasks and live under /etc and /var/lib. Non-secret
# config (e.g. ansible host_vars/<node>/main.yml) is committed directly.
# These patterns are defense-in-depth in case anyone copies generated files in.
# ─────────────────────────────────────────────────────────────────────────────
# Environment files (may hold secrets)
.env
**/.env
!**/.env.example
# Private keys & certs (defense-in-depth; real keystores live under /etc on the host)
**/cert.pem
**/*.pem
# Encrypted node backups (`make backup`); they belong with the operator, not in git
*.tar.age
# Local, per-developer Claude Code settings (not shared)
.claude/settings.local.json
# KICS security-scan output (`make security`; CI uploads it as an artifact)
kics-results/
# Galaxy collection build output (`make build`/`galaxy-check`; CI uploads the
# tarball as an artifact). The collection is staged + built under ansible/build/.
# galaxy-importer drops importer_result.json in its cwd (ansible/) when validating.
ansible/build/
*.tar.gz
ansible/importer_result.json
# ansible-compat scaffolding (a .lock plus empty modules/collections/roles dirs),
# created in the project root by ansible-lint and molecule — so `make lint-ansible`
# and `make molecule` both leave one behind. Regenerated on every run.
.ansible/
# Python bytecode (e.g. from the molecule stub daemon or any local tooling)
__pycache__/
*.pyc
# Pinned third-party binaries downloaded by the test harnesses (`make lint-alloy`
# caches the verified Grafana Alloy release here so repeat runs skip the fetch).
ansible/.cache/
# Release packaging output (the release workflow builds into dist/)
dist/
release-notes.md