.git .gitignore .next node_modules coverage storage prod.log update.log .pm2 # Only the pnpm lockfile is used. Ignore other lockfile formats and stray # package managers so they never taint the build context by accident. package-lock.json yarn.lock bun.lockb .npmrc.bak # Installation secrets must never enter any image layer (including migrations). .env .env.* **/.env **/.env.* !.env.example *.pem *.key *.tsbuildinfo # Runtime write targets; bound as RW volumes at runtime (see docker-compose.yml) public/nitro-assets public/swf .deploy.lock logs # Other installation data and local tool artifacts public/cache public/tmp db_backup_*.sql *.log .codex .agents .docker-install .docker-install.tmp.* .env.install.*