Reorganize the brownfield repository, remove retired and generated artifacts, harden ignore rules, and record the GitOps/IaC redesign.
8 lines
349 B
Plaintext
8 lines
349 B
Plaintext
# ansible/group_vars/all/vault.yml is now ANSIBLE-VAULT ENCRYPTED and IS committed.
|
|
# The password lives in ../.vault_pass (gitignored at the repo root) and a copy is
|
|
# in OpenBao at kv/infra/ansible-vault.
|
|
# ⚠ If you ever `ansible-vault decrypt` it, DO NOT commit until re-encrypted.
|
|
ansible/inventory/hosts.local.yml
|
|
ansible/*.retry
|
|
.vault_pass
|