__pycache__/
*.pyc
.venv/
venv/
.env
.env.*
*-key.json
# Slice 16 moved dashboard accounts into the users table and deleted this file,
# so nothing reads it any more. The ignore stays because DASHBOARD.md tells an
# upgrading deployment to put one here for the one-shot --import-file, and for
# the length of that window it is a file of live password hashes sitting at a
# stageable path in a directory the release step bulk-adds.
config/dashboard-users.yaml
.pytest_cache/
.ruff_cache/
.superpowers/

# graphify knowledge graph outputs. Regenerated by /graphify from the tree
# itself, and it carries an extraction cache keyed on file hashes, so it is
# derived state rather than source.
graphify-out/

# Deployment-level config is per installation. The committed file is
# deployment.yaml.example.
config/deployment.yaml

# The fleet receiver's own SQLite file. Local runtime state, not source, and
# it lives on the receiver's own infrastructure rather than in the repo.
# DEFAULT_DB resolves to this exact path at the repo root when
# ANCHORPOINT_FLEET_DB is unset, so this is where a local run actually
# writes it. The three sibling files SQLite leaves beside it in rollback
# journal or WAL mode are runtime state too, not a second copy of anything.
fleet.sqlite3
fleet.sqlite3-journal
fleet.sqlite3-wal
fleet.sqlite3-shm

# The console's dependencies and its built bundle. The bundle is produced by
# the Dockerfile's node stage at build time and by `npm run build` locally, so
# committing it would be committing a build output that goes stale silently.
console/node_modules/
anchorpoint/dashboard/static/
console/*.tsbuildinfo

# The npm client's dependencies. Its compiler, not a runtime dependency: the
# package declares none. Its build output needs no line here, because the
# dist/ below matches at any depth.
npm-connect/node_modules/

# Release bundles. Hundreds of megabytes of image tarball per release
# (S358), built into dist/ by scripts/build-release.py and carried to a
# client by hand or by a link. Never committed.
dist/

# The alias package has no dependencies of its own to install, but a
# stray npm install in it would leave a tree behind.
npm-alias/node_modules/
npm-alias/*.tgz

# A demo enterprise's record of which invoices it has already reviewed, written
# beside its runner after every run. Output rather than configuration, despite
# living under config/: it carries timestamps, task and session ids and per-run
# spend, it is rewritten on every invoice of every night, and a second machine's
# copy would describe a different week. The runner refuses a file it cannot
# read rather than starting fresh, so losing one is recoverable by hand; a
# committed one that disagrees with the deployment it is restored beside is not.
config/demo-enterprises/*/run-state.json
