# Nix build results
result*

# Tailscale authkey (unencrypted, should NOT be committed)
hosts/richmond-server/tailscale_authkey.txt
hosts/richmond-server/mcf-notices.env
hosts/richmond-server/castopod-container.env
hosts/richmond-server/castopod-api.env
hosts/richmond-server/pihole.env

# Local sops age keys (generated per-machine at deploy time)
# The public key goes in .sops.yaml, encrypted secrets go in secrets.yaml
/root/.config/sops/age/
/var/lib/sops-nix/

# Decrypted temporary sops files
.*decrypted*

extra-files/
extra-files/**
extra-files/
extra-files/**
