# Terraform state/vars are also ignored inside terraform/.gitignore; repeated here
# in case a stray file ever lands at repo root.
*.tfstate
*.tfstate.*
.terraform/
*.tfvars
!*.tfvars.example
crash.log
crash.*.log

# The SOPS+age private key must never be committed (deploy/secrets/*.yaml, the
# encrypted values, are meant to be committed).
age.key
*.age.key

.DS_Store

# lake-iceberg's pytest suite runs in place.
__pycache__/
*.pyc

# Host-side deploy state (deploy.sh): the live per-service image tags and the
# cross-repo deploy lock. Untracked on purpose -- they must survive the
# `git reset --hard` at the top of every deploy (deploy.sh's comments already
# assumed .image-tags.env was ignored; make it actually true so a stray
# `git clean` can't destroy the record of what's running).
deploy/.image-tags.env
deploy/.deploy.lock
deploy/.stack-image-tags.env

# LAN dev's mirror of the rendered secrets, for snap-confined Docker (see
# deploy-dev.sh / render-secrets.sh) -- plaintext, re-rendered every deploy.
deploy/dev-secrets.env
