# Local .terraform directories .terraform/ # .tfstate files *.tfstate *.tfstate.* # Crash log files crash.log crash.*.log # Exclude all .tfvars files, which are likely to contain sensitive data, such as # password, private keys, and other secrets. These should not be part of version # control as they are data points which are potentially sensitive and subject # to change depending on the environment. *.tfvars *.tfvars.json # Ignore override files as they are usually used to override resources locally and so # are not checked in override.tf override.tf.json *_override.tf *_override.tf.json # Ignore transient lock info files created by terraform apply .terraform.tfstate.lock.info # Include override files you do wish to add to version control using negated pattern # !example_override.tf # Include tfplan files to ignore the plan output of command: terraform plan -out=tfplan # example: *tfplan* # Ignore CLI configuration files .terraformrc terraform.rc # Optional: ignore graph output files generated by `terraform graph` # *.dot # Optional: ignore plan files saved before destroying Terraform configuration # Uncomment the line below if you want to ignore planout files. # planout **/.claude # ============================================ # Secrets — voir .sops.yaml # ============================================ # Les secrets vivent UNIQUEMENT dans des stacks/*/secrets.enc.yaml chiffrés, # consommés à la volée par `sops exec-env`. Aucun secret déchiffré ne doit # exister sur le filesystem : les règles ci-dessous sont une ceinture de # sécurité, pas un mode de fonctionnement. .env *.env *.dec.yaml *.decrypted.* # La configuration NON sensible de chaque stack vit dans un fichier nommé # `env_file` (sans extension) : il échappe donc volontairement aux règles # ci-dessus et reste versionné en clair. # Clés privées age (ne doivent jamais approcher le dépôt) *.agekey age-key.txt keys.txt # Le stockage ACME de Traefik : clé de compte Let's Encrypt et clés privées de # tous les certificats. Vit sur le serveur uniquement, jamais dans le dépôt. acme.json