# Git
.git
.gitignore
.gitmodules

# Python
__pycache__
*.py[cod]
*$py.class
*.so
.Python
*.egg-info/
dist/
build/

# Virtual environments
venv/
env/
ENV/

# Dependencies
node_modules
**/node_modules
.venv
**/.venv
.notebooklm-cli-venv/
.notebooklm-playwright/
.pip-cache/
.uv-cache/

# Built artifacts that are regenerated inside the image.  Excluded so local
# rebuilds on the developer's machine don't invalidate the npm-install layer
# that now depends on the full ui-tui/packages/subnaut-ink/ tree being present.
ui-tui/dist/
ui-tui/packages/subnaut-ink/dist/

# CI/CD
.github

# Environment files
.env
.env.*
# ...but keep the template: docker/stage2-hook.sh seeds $SUBNAUT_HOME/.env from
# /opt/subnaut/.env.example on first boot (OOF-285 — excluding it silently broke
# first-boot .env seeding and the API_SERVER_KEY generation that depends on it).
!.env.example

# IDE
.vscode/
.idea/
*.swp
*.swo

# Testing
.pytest_cache/
.coverage
htmlcov/

# Documentation
*.md

# Runtime data (bind-mounted at /opt/data; must not leak into build context)
data/
.subnaut-docker/
.notebooklm-home/

# ---------- Credential-bearing SUBNAUT_HOME state ----------
# The same set .gitignore refuses to commit. It lands in the checkout root
# whenever something runs with SUBNAUT_HOME pointing at the repo (an agent
# operating in its own tree, a dev export), and `COPY --chmod=a+rX . .` would
# bake transcripts, OAuth tokens and the session DB into an image layer that
# every user of the image can read. Root-anchored on purpose: Docker matches
# these against the path relative to the context root, so `hooks/` here means
# the checkout's own hooks/, never apps/desktop/src/**/hooks/.
# tests/test_dockerignore_covers_credentials.py holds the two files together.
sessions/
pairing/
memories/
hooks/
audio_cache/
image_cache/
mcp-tokens/
auth.json
.anthropic_oauth.json
cli-config.yaml
state.db*
.skills_prompt_snapshot.json
skills/.hub/
# These four are unanchored in .gitignore, so mirror them at every depth:
# a .dockerignore pattern without a leading **/ matches the context root only.
logs/
**/logs/
.subnaut/
**/.subnaut/
.op.env
**/.op.env
**/cli-config.yaml

# Private keys and certificates (.gitignore's set). Nothing tracked matches
# these, so excluding them costs the build nothing and stops a stray key in a
# developer's working tree from becoming a world-readable image layer.
**/release-signing-key*
**/*.ppk
**/*.pem
**/*.key
**/*.p12
**/*.pfx
**/id_rsa*

# Compose/profile runtime state (bind-mounted; avoid ownership/secret issues)
subnaut-config/
runtime/

# ---------- Not needed inside the Docker image ----------

# Desktop app source (Tauri/Electron); never installed in the container.
# apps/shared is the shared websocket helper and is linked from
# ui-tui/package.json as a file: workspace dep — keep it in the build context.
apps/
!apps/shared/
!apps/shared/**

# Test suite — not shipped in production images
tests/

# Documentation site (Docusaurus) and supplementary docs
website/
docs/

# Assets only used by the GitHub README
assets/

# Nix / Homebrew / AUR packaging metadata — irrelevant to Docker
nix/
flake.nix
flake.lock
packaging/

# Design and planning documents
plans/
.plans/

# Repo-level dotfiles that are git-only or dev-tooling config
.envrc
.gitattributes
.hadolint.yaml
.mailmap

# Debug/export artifacts — must never reach image layers (COPY . .)
/log.txt
/sqlite_leak_fix.png
/*.png.bak
*.tar.gz
*.tgz
