# Python
__pycache__/
*.py[cod]
*$py.class
*.egg-info/
dist/
build/
.eggs/
*.egg
.venv/
venv/

# Runtime
.ordel/

# IDE
.vscode/
.idea/
*.swp
*.swo

# OS
.DS_Store
Thumbs.db

# Environment
.env
# Local deploy secrets (Slack webhook etc) - never committed.
.deploy.env
.env.*
!.env.example
!.env.prod.example

# Terraform
**/.terraform/*
*.tfstate
*.tfstate.*
*.tfvars
!*.tfvars.example
tfplan
*.tfplan
crash.log
crash.*.log

# Stray root-level node_modules (e.g. an npm install run from the repo root,
# or the rrweb-dom-stream poc pulling deps up) — never committed.
/node_modules/
# Local trace-capture scratch (Langfuse/OTel dumps) — throwaway.
/scratchpad_traces/

# Node (web/)
web/node_modules/
web/.next/
# Stale build caches moved aside during repairs (e.g. the Kestrel→Ordel
# rename Turbopack fix). Local-only, safe to delete.
web/.next.*/
web/out/
web/.pnp
web/.pnp.*
# TypeScript incremental build cache — local-only, regenerates on each build.
web/tsconfig.tsbuildinfo

# Node runner (node-runner/) — local Playwright run output
node-runner/runs/
node-runner/artifacts/
node-runner/node_modules/
# ...and the same path as a SYMLINK. A trailing slash matches directories
# only, so a worktree that links node_modules at the main checkout's copy
# (which is how a git worktree avoids a second 700MB install) showed it as
# an untracked file and offered it up to every `git add -A`.
node-runner/node_modules

# Testing
.coverage
htmlcov/
.pytest_cache/
.ruff_cache/
.mypy_cache/
test-results/
web/test-results/
# Video-recording overlay's output (playwright.video.config.ts) - same reason
# as test-results/: large binary run artifacts, regenerated on demand.
web/test-results-video/
# GAP-3067: the per-test video archive - the last clip of every test,
# ~150-200MB steady-state across the suite. Local artifact, never committed.
web/video-archive/
# Per-purpose Playwright output dirs (--output=test-results-<x>) - same class.
web/test-results-*/
web/playwright-report/
backend/test-results/

# Playwright
.playwright-cli/
.playwright-mcp/
.playwright/

# storageState files — contain live auth tokens; regenerated each run
web/tests/.auth/
web/**/.auth/

# Worktrees
.worktrees/

# Brainstorm sessions
.superpowers/

# Claude Code config
.claude.json
.claude/worktrees/
*.debug

# Backups (local only)
backups/

# Local dev notes (credentials, scratch)
draft-keep.txt

# Binary artifacts
*.docx

# Test artifacts (manual playtest screenshots + recorder session captures)
# Live snapshots end up next to whatever directory the tester ran from;
# pin specific names rather than a blanket *.png so legit UI assets in
# web/public/ + docs/ don't get caught.
/*.png
/web/*.png
/backend/*.png
/qa-suite/modules/_session-*.spec.ts
/backend/bugs.md

# Backend runtime artifact storage (POM persist / local-FS dev mirror)
/backend/storage/

# Archived docs (historical plans, sessions, completed milestones — not for review)
docs/archive/

# =============================================================
# Reference / experimental code (kept locally, not in repo)
# =============================================================

# Performance testing reference implementation (Phase 2)
Perf_Flow/
Perf_Flow.zip

# Archived v1 components (replaced by v2)
web/components/scripts/archived/

# Unused shared components (experimental)
web/components/shared/approval-batch.tsx
web/components/shared/coverage-ring.tsx
web/components/shared/inline-approval.tsx
web/components/shared/onboarding-tour.tsx

# Unused studio components (experimental)
web/components/studio/ArtifactCard.tsx
web/components/studio/BrowserPreview.tsx
web/components/studio/NewSessionModal.tsx

# Unused layout components (replaced)
web/components/layout/app-sidebar.tsx
web/components/layout/header.tsx
.claude/scheduled_tasks.lock

# =============================================================
# Per-developer tool output (regenerable, don't commit)
# =============================================================

# Antigravity CLI: home-dir symlinks to ~/.gemini/config/projects/*
.antigravitycli/

# Understand-Anything: knowledge graph cache (regenerate with /understand)
# Keep the .understandignore input config so all devs share the same graph scope.
.understand-anything/*
!.understand-anything/.understandignore

# Local install / runtime logs (uvicorn, npm, pip, alembic, bootstrap, etc.)
*.log
*.err
backend/.secrets/
*.pem
.secrets/

# Workflow/agent scratch scripts (throwaway)
.wf-*
backend/.wf-*
# Ad-hoc scratch/verify scripts — SEC-3191: these leaked a live prod refresh
# token when tracked. Keep throwaway prod-probe scripts OUT of the repo.
/scratch/

# Stale: web/e2e was renamed to web/tests long ago — keep the leftover out
web/e2e/
docs/conference/demo-video/
scratchpad-video/
.overmind.env

# Private/internal ops docs (prod-access cheat-sheets with infra IDs) — never commit
docs/deployment/*.local.md
osprey-repo.zip
web/video-archive.partial-regression-only-20260825-070136/
# Generated by `npm run test:unit:cov` - 31 MB of HTML that polluted every
# editor search (589 files, tracked until 2026-08-29).
web/coverage/
packages/ordel-graph-poc/graph.json
regress.env
artifacts/regress/

# Run artifacts and tool caches that were showing up as ~230 pending files
# (~560 MB): Playwright videos/traces/screenshots from QA export runs, the
# pre-commit tool cache, and executor output dirs. All regenerated on demand.
/docs/qa/exports/wo21/
/.precommit-cache/
/output/
/backend/output/
/node-runner/artifacts/

# Per-developer agent tooling and scratch (2026-09-14). These are machine-local
# by nature: .codex/ carries an approval/sandbox policy that must never become
# anyone else's default, and .agents/ + documents/ are a seat's own skills and
# working notes. Ignored, not deleted - they stay on the developer's disk.
.codex/
.agents/
.mcp.json
documents/

# Scratch diagnostics. A file whose name says temp/diag is a working artifact,
# not a test the suite should own; nothing references these two.
web/tests/**/_diag-*.spec.ts
web/tests/**/_minimal_*_diag*.test.tsx
scripts/h3_experiment.py

# Per-run test results (JUnit XML). Generated by scripts/regress-*.sh, one
# timestamped folder per run - history, not source.
artifacts/regress-results/
# testboard's own database, rebuilt from the run folders at any time.
artifacts/testboard.db
artifacts/testboard.db-wal
artifacts/testboard.db-shm
artifacts/testboard-rerun.txt

# Dashboard binary - a released upstream build, not our source.
ops/olivetin/bin/

# runner/lifecycle drivers keep a PAT and a machine token here; never commit
backend/artifacts/osprey-lifecycle/
backend/artifacts/explore-ab/

# Design-system sync tooling and its compiled bundle - local build artifacts
# (node_modules, screenshots, ~60MB), regenerated by the sync scripts.
.ds-sync/
ds-bundle/

# Daily cron output of scripts/qa/backup_testcase_status.py (07:00): dated copies and the log stay local; latest.csv is the tracked view.
/docs/qa/exports/status-snapshots/20*.csv
/docs/qa/exports/status-snapshots/cron.log
