chore(git): harden ignore rules for env backups, wiki snapshot and scratch

Four gaps, each of which put machine-local or regenerable files in front of a
reviewer as though they were source:

- `.env.bak` / `.env.*.bak` / `.env.save` carry the same secrets as `.env`
  and were matched by none of the existing rules — editors and shell tooling
  write them without asking.
- `.settings/gitlab/wiki/live/` is a fetched snapshot of the live wiki
  (`wiki-pull.py`); committing it turns every unrelated wiki edit into a diff
  here.
- `__pycache__/` and `*.pyc` — the `.settings/gitlab/` tooling is plain
  scripts, and importing one writes a cache dir beside it.
- `.tmp/` holds the per-gate logs `just check` writes plus Node's jiti and
  compile caches: 611 files of build residue.

`REMAPPING/.gitignore` was still the PhpStorm template it was generated from.
Replaced with rules for what that tree actually builds (env, build output,
clients), and `REMAPPING/cicd/.env.local` is re-allowed because the compose
quickstart there requires it.

Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
This commit is contained in:
Josh Belke 2026-08-19 13:13:51 -04:00
commit e2c5f19cc6
2 changed files with 82 additions and 112 deletions

23
.gitignore vendored
View file

@ -10,9 +10,26 @@
.env
.env.local
.env.*.local
# Editor/tool backups of the above carry the same secrets and were NOT matched
# by the rules above — `.env.bak` is a real thing tooling writes.
.env.bak
.env.*.bak
.env.save
# ...but keep the committed templates.
!.env.example
# Fetched snapshot of the live GitLab wiki. Regenerate with
# `python3 .settings/gitlab/wiki/scripts/wiki-pull.py`. Committing it would make
# every unrelated wiki edit show up as a diff here.
.settings/gitlab/wiki/live/
# Python bytecode — the .settings/gitlab/ tooling is plain scripts, and importing
# one writes a cache dir beside it.
__pycache__/
*.pyc
!.env.local.example
# IHLC local TAG env — required by REMAPPING/cicd compose quickstart
!REMAPPING/cicd/.env.local
# Local credential drop. The `artifacts-s3` compose profile bind-mounts this
# directory read-only for the ReductStore Pro licence key.
@ -115,3 +132,9 @@ deploy/charts/*/charts/*.tgz
# Cluster credentials — never commit (added while deploying to R2D2).
.settings/kubeconfig.*
# Scratch tree for gate logs and tool caches. `just check`/`just ci` write their
# per-gate logs here (`desktop-typecheck.log`, `mobile-check.log`, …) and Node's
# jiti/compile caches land beside them, so it is 600+ files of machine-local
# build residue that reads as source in `git status`.
.tmp/

161
REMAPPING/.gitignore vendored
View file

@ -1,117 +1,64 @@
# Created by https://www.toptal.com/developers/gitignore/api/phpstorm
# Edit at https://www.toptal.com/developers/gitignore?templates=phpstorm
# Ignore rules for this tree as the working root. Do not inherit a parent
# checkout's ignore file.
### PhpStorm ###
# Covers JetBrains IDEs: IntelliJ, RubyMine, PhpStorm, AppCode, PyCharm, CLion, Android Studio, WebStorm and Rider
# Reference: https://intellij-support.jetbrains.com/hc/en-us/articles/206544839
# Environment (may contain secrets). Keep the committed templates.
.env
.env.local
# dotenvx private keys — the whole point of committing encrypted env files
.env.keys
*.env.keys
.env.*.local
!.env.example
!.env.local.example
# IHLC local TAG env — required by cicd compose quickstart
!cicd/.env.local
# User-specific stuff
.idea/**/workspace.xml
.idea/**/tasks.xml
.idea/**/usage.statistics.xml
.idea/**/dictionaries
.idea/**/shelf
# Build artifacts
target/
dist/
**/src-tauri/target/
meridian-admin-web/dist/
meridian-web/dist/
meridian-desktop/dist/
meridian-mobile/build/
meridian-mobile/.dart_tool/
meridian-mobile/.flutter-plugins
meridian-mobile/.flutter-plugins-dependencies
# AWS User-specific
.idea/**/aws.xml
# Node / pnpm
node_modules/
.pnpm-store/
# Generated files
.idea/**/contentModel.xml
# Playwright
playwright-report/
test-results/
blob-report/
# Sensitive or high-churn files
.idea/**/dataSources/
.idea/**/dataSources.ids
.idea/**/dataSources.local.xml
.idea/**/sqlDataSources.xml
.idea/**/dynamic.xml
.idea/**/uiDesigner.xml
.idea/**/dbnavigator.xml
# Gradle
.idea/**/gradle.xml
.idea/**/libraries
# Gradle and Maven with auto-import
# When using Gradle or Maven with auto-import, you should exclude module files,
# since they will be recreated, and may cause churn. Uncomment if using auto-import.
.idea/artifacts
.idea/compiler.xml
.idea/jarRepositories.xml
.idea/modules.xml
.idea/*.iml
.idea/modules
*.iml
*.ipr
# CMake
cmake-build-*/
# Mongo Explorer plugin
.idea/**/mongoSettings.xml
# File-based project format
*.iws
# IntelliJ
out/
.idea/encodings.xml
# mpeltonen/sbt-idea plugin
.idea_modules/
# JIRA plugin
atlassian-ide-plugin.xml
# Cursive Clojure plugin
.idea/replstate.xml
# Crashlytics plugin (for Android Studio and IntelliJ)
com_crashlytics_export_strings.xml
crashlytics.properties
crashlytics-build.properties
fabric.properties
# Editor-based Rest Client
.idea/httpRequests
# Android studio 3.1+ serialized cache file
.idea/caches/build_file_checksums.ser
### PhpStorm Patch ###
# Comment Reason: https://github.com/joeblau/gitignore.io/issues/186#issuecomment-215987721
# *.iml
# modules.xml
# .idea/misc.xml
# *.ipr
# Sonarlint plugin
# https://plugins.jetbrains.com/plugin/7973-sonarlint
.idea/**/sonarlint/
# SonarQube Plugin
# https://plugins.jetbrains.com/plugin/7238-sonarqube-community-plugin
.idea/**/sonarIssues.xml
# Markdown Navigator plugin
# https://plugins.jetbrains.com/plugin/7896-markdown-navigator-enhanced
.idea/**/markdown-navigator.xml
.idea/**/markdown-navigator-enh.xml
.idea/**/markdown-navigator/
# Cache file creation bug
# See https://youtrack.jetbrains.com/issue/JBR-2257
.idea/$CACHE_FILE$
# CodeStream plugin
# https://plugins.jetbrains.com/plugin/12206-codestream
.idea/codestream.xml
# End of https://www.toptal.com/developers/gitignore/api/phpstorm
#Visual Studio Code
# Editor / OS
.idea/
.vscode/*
!.vscode/settings.json
!.vscode/tasks.json
!.vscode/launch.json
!.vscode/extensions.json
.DS_Store
Thumbs.db
*.swp
*.swo
*~
.*.sw?
# Local identity / secrets
identity.key
**/identity.key
.secrets/
.control-plane/
# Scratch
.scratch/
.meridian-run/
.cache/
.hermit/
# Helm dependency tarballs — regenerable from Chart.lock via `helm dependency build`
cicd/charts/*/charts/*.tgz