# Secrets — names are documented in .env.example, values never committed
.env
.env.*
!.env.example

# Python
__pycache__/
*.py[cod]
*.egg-info/
dist/
build/
.venv/
.mypy_cache/
.pytest_cache/
.ruff_cache/
.coverage
coverage.xml
htmlcov/

# Eval artifacts — generated, never committed (reports are reproducible)
evals/results/

# Local index data. SQLite runs in WAL mode (ADR-0002), so a store is three
# files rather than one and the `-wal`/`-shm` sidecars outlive any open
# connection — without them the sidecars are the only part of an index
# directory that shows up as untracked.
*.lance/
*.sqlite3
*.sqlite3-shm
*.sqlite3-wal

# The default index directory `grk` writes when `--index-dir` is not given.
# Listed as well as the globs above so a future artifact type inside it is
# ignored by placement, not only by extension.
.groundkit/

# Local AI-agent context file (solo-dev machine convenience, not shipped repo
# content). SPEC.md, KNOWN_LIMITATIONS.md and docs/adr/ are the tracked source
# of truth; a fresh clone is governed by those.
CLAUDE.md

# External review scratch — build scripts and rendered artifacts produced by
# agent review runs against this repo. Not repo content, and not held to its
# gates: `ruff check .` walks it otherwise and reports errors from code this
# project neither owns nor ships.
.codex-artifacts/

# Local MCP client config: machine-specific absolute paths, generated by
# whichever client registered the server. docs/guides/mcp-clients.md is the
# tracked source for client configuration.
.mcp.json

# Editors / OS
.idea/
.vscode/
.vs/
*.swp
Thumbs.db
.DS_Store
# Word/Excel owner-lock files, written beside an open document.
~$*

# Docs build
site/

# Terraform working state (infra/terraform/**). `.terraform/` is a provider
# cache, and `.terraform.lock.hcl` belongs to a ROOT module — this repo ships a
# reusable module, whose consumers own their own lock. Committing one here would
# pin every consumer to whatever provider version happened to resolve on the
# machine that ran `init`. `*.tfvars` is ignored because that is where a real
# deployment's account-specific values land, and `.tfvars.example` is the
# documented-names counterpart, matching the `.env` / `.env.example` rule above.
.terraform/
.terraform.lock.hcl
*.tfstate
*.tfstate.*
*.tfplan
crash.log
*.tfvars
!*.tfvars.example

# Internal design documents kept alongside the repo but never published
# with it (they are not part of the package and carry no license header).
*.docx
