# Ignore all files related to services
**/services

# Allow docker-compose.yml
!**/docker-compose.yml
!/*

# Don't allow .env files, just env-exmaple files
!.env-example

# Secrets generated at deploy time (e.g. services/dev/Runners/.env, holding the
# live Gitea Actions registration token) - never committed, regardless of the
# services/docker-compose.yml carve-out above.
**/.env

# Variables set through control.sh's "Set variables" menu (HCLOUD_TOKEN,
# BACKUP_S3_*, etc.) - never committed.
.control.env

### Ansible ###
*.retry

### Terraform ###
# Local .terraform directories
**/.terraform/*

# .tfstate files
*.tfstate
*.tfstate.*

# Crash log files
crash.log
crash.*.log

# Exclude all .tfvars files, which are likely to contain sensitive data, such as
# password, private keys, and other secrets. These should not be part of version
# control as they are data points which are potentially sensitive and subject
# to change depending on the environment.
*.tfvars
*.tfvars.json

# Ignore override files as they are usually used to override resources locally and so
# are not checked in
override.tf
override.tf.json
*_override.tf
*_override.tf.json

# Include override files you do wish to add to version control using negated pattern
# !example_override.tf

# Include tfplan files to ignore the plan output of command: terraform plan -out=tfplan
# example: *tfplan*

# Ignore CLI configuration files
.terraformrc
terraform.rc