.env
.env.*
bench/results/
bench/sample_10s.wav
__pycache__/
*.pyc
.venv/
!.env.example
# The website's two API origins, which are `PUBLIC_` — compiled into the bundle and readable in the
# page source of the deployed site — so there is nothing to keep out of the repository, and without
# them `cd web && npm run build` fails on a fresh clone (D314). Nothing secret goes in that file.
!web/.env
target/
.sqlx/
sdk/dist/
runner/dist/
studio/dist/

# The Railway IaC SDK. `.railway/railway.ts` imports `railway/iac`, and `railway config
# plan` cannot evaluate it without the package; `package.json` pins the version so the
# plan is the same one everywhere. `npm install` at the repository root is the setup step.
node_modules/
sdk/.venv/
.pytest_cache/
.ruff_cache/

# Claude Code session state and agent worktrees
.claude/

# per-user Claude Code permissions
.claude/settings.local.json

# Native CLI release payloads are built in CI and staged into the static site, never committed.
web/static/cli/latest
web/static/cli/latest.json
web/static/cli/*/

# Evidence (run logs, renders, probes) goes to the bucket, never git (D361). Some of it has held
# live credentials: output/h100-deployment-2026-09-26/bootstrap-h100.sh carries a Tailscale key.
output/

# macOS Finder metadata.
.DS_Store
**/.DS_Store

# Customer gateway declarations (`examples/<tenant>/gateway.py`): a tenant's own model names,
# provider endpoints and the *names* of its credential variables. No value is in them, but they
# are one customer's configuration and not the platform's, so they stay out of the tree.
examples/
