# Build artifacts
/target/
/dist/
/REMAPPING/meridian-admin-web/dist/

# lefthook-generated hook scripts (machine-specific)
.hooks/

# Environment files (may contain secrets)
.env
.env.local
.env.*.local
# Editor/tool backups of the above carry the same secrets and were NOT matched
# by the rules above — `.env.bak` is a real thing tooling writes.
.env.bak
.env.*.bak
.env.save
# ...but keep the committed templates.
!.env.example

# Fetched snapshot of the live GitLab wiki. Regenerate with
# `python3 .settings/gitlab/wiki/scripts/wiki-pull.py`. Committing it would make
# every unrelated wiki edit show up as a diff here.
.settings/gitlab/wiki/live/

# Python bytecode — the .settings/gitlab/ tooling is plain scripts, and importing
# one writes a cache dir beside it.
__pycache__/
*.pyc
!.env.local.example
# IHLC local TAG env — required by REMAPPING/cicd compose quickstart
!REMAPPING/cicd/.env.local

# Local credential drop. The `artifacts-s3` compose profile bind-mounts this
# directory read-only for the ReductStore Pro licence key.
.secrets/

# Machine-specific Compose overrides. Compose auto-loads this file, so it must
# never be committed — it would silently rewrite everyone else's ports.
docker-compose.override.yml
docker-compose.override.yml.disabled
!docker-compose.override.yml.example

# ./run.sh scratch state: backups of the override layers it rewrites, plus logs
# and pidfiles for the processes it starts in the background.
.meridian-run/

# Editor / IDE
.idea/
.vscode/*
!.vscode/settings.json
*.swp
*.swo
*~
.*.sw?

# OS artifacts
.DS_Store
Thumbs.db

# Scratch / working files (AI reviews, notes, drafts)
.scratch/

# Playwright artifacts
playwright-report/
test-results/
blob-report/
.playwright-mcp/

# Node modules (pnpm workspace hoists to root)
node_modules/

# Root npm lockfiles are accidental; desktop uses pnpm in /desktop.
/package-lock.json

# sqlx offline query data (generated, not portable)
.sqlx/

# SQLite database (created by relay in CWD)
meridian.db
meridian.db-wal
meridian.db-shm

# Docker volumes (if mounted locally)
mysql-data/
typesense-data/

# Hermit (toolchain manager cache)
.hermit/
doc/
/repos/

# Local identity files
identity.key
**/identity.key

# Claude Code worktrees
.claude/worktrees/

# mesh-llm build cache
.cache/

# Helm dependency tarballs — regenerable from Chart.lock via `helm dependency build`
deploy/charts/*/charts/*.tgz

# Beads / Dolt files (added by bd init)
.dolt/
*.db
.beads-credential-key

# Local relay-operator key for `just control-plane` (never commit)
.control-plane/

# Third-party checkouts read while writing the parity docs in
# .settings/features/. Each is a full clone with its own .git, so committing
# them would add gitlinks to repos nobody else can resolve. Local-only: the
# docs quote what matters, and a reader who wants the source clones it.
.settings/reference-code/

# Source PDFs read while writing the distillations in .settings/reference-docs/.
# Some carry owner-gated / pre-circulation markings, so the binaries stay local
# and only the derived Markdown is committed. Same rule as reference-code above:
# the distillation quotes what matters.
.settings/reference-docs/**/*.pdf
# Upstream machine-readable sources fetched alongside them (the NIP registry's
# schema.yaml, and anything like it). `.settings/AGENTS.md` allows only derived
# Markdown out of this directory, and a vendored upstream file is the opposite:
# unreviewable, stale the day it lands, and read by nothing in the tree.
.settings/reference-docs/**/*.yaml
.settings/reference-docs/**/*.yml
.settings/reference-docs/**/*.json

# Cluster credentials — never commit (added while deploying to R2D2).
.settings/kubeconfig.*

# Scratch tree for gate logs and tool caches. `just check`/`just ci` write their
# per-gate logs here (`desktop-typecheck.log`, `mobile-check.log`, …) and Node's
# jiti/compile caches land beside them, so it is 600+ files of machine-local
# build residue that reads as source in `git status`.
.tmp/
