# Python
__pycache__/
*.py[cod]
*$py.class
*.so

# Distribution / packaging
build/
dist/
*.egg-info/
.installed.cfg
*.egg

# Testing
.pytest_cache/
.coverage
htmlcov/

# Environment
# Every .env variant carries secrets — the deploy-generated .env.users
# included. Two carry none and are therefore committed: .env.example, the
# documented variable list, and .env.shared, the deployment's shared defaults
# (`.env` beside it holds this host's own values, and wins on any key set in
# both).
.env*
!.env.example
!.env.shared
.venv
env/
venv/
ENV/

# IDE
.idea/
.vscode/
*.swp
*.swo

# OS
.DS_Store
Thumbs.db

# Runtime-minted material `osprey up` writes into the data tree — today the
# Bluesky document-plane CURVE certificates (data/.runtime/<lane>_curve/).
# The *.key_secret files are private keys, and the public halves are bearer
# material too (holding the manager's public key is enough to reach its
# control socket), so the whole directory stays out of version control —
# same treatment as .env above. The build-drift fingerprint reserves this
# subpath for exactly such material and never treats it as build input.
#
# Leading slash on purpose: this anchors the pattern to the project root, so
# it matches only the directory `osprey up` writes. An unanchored
# `.runtime/` would match a directory of that name ANYWHERE in the tree,
# and git would then silently skip such a path on `git add` — the failure mode
# is a file that looks committed but never was.
/data/.runtime/

# The compose document a deploy merges at the repo root when the container
# runtime needs a single file. Machine-written, rewritten by every `osprey up`
# and removed by `osprey reset`, so it is never committed.
#
# Leading slash for the same reason as above: it must match this one root file
# and nothing of that name deeper in the tree.
/.osprey-compose.yml

# STATE zone — the agent's memory, sessions and audit log. Durable,
# host-local, and nobody else's business. Tracks `agent_data.base_dir` in
# config.yml; a path outside it would be committed on the first run.
var/

# Logs
*.log
*.pid

# Temporary
tmp/
temp/

# Claude Code local settings (personal, not shared)
.claude/settings.local.json
CLAUDE.local.md
