# ansible/group_vars/all/vault.yml is now ANSIBLE-VAULT ENCRYPTED and IS committed.
# The password lives in ../.vault_pass (gitignored at the repo root) and a copy is
# in OpenBao at kv/infra/ansible-vault.
# ⚠ If you ever `ansible-vault decrypt` it, DO NOT commit until re-encrypted.
ansible/inventory/hosts.local.yml
ansible/*.retry
.vault_pass
