forgejo-mcp/.gitignore
Christoph Görn b63095f211
chore: 🔥 remove stale secrets/ + point at op1st-emea-b4mad as normative cosign pub
The op1st Tekton release pipeline signs with the cosign-signing-key
Secret in op1st-pipelines, provisioned upstream from op1st-emea-b4mad
GitOps. The in-repo secrets/cosign.pub diverged from that key (sha256
0c945708... vs 377836e4...) — verifying Tekton-signed releases against
the local key would fail. Local material was never the source of truth
and is now removed.

Removed:
- secrets/cosign.pub (stale, wrong key)
- secrets/cosign-signing-key.enc.yaml (SOPS-encrypted local copy, redundant with op1st-gitops)
- secrets/.gitkeep
- scripts/cosign-keygen.sh (helper for the removed local material)
- .gitignore allowlist for secrets/* (replaced with full secrets/ ignore)

Updated:
- README "Verifying Releases" → fetch cosign.pub from op1st-emea-b4mad
  at manifests/applications/op1st-pipelines-tokens/cosign-signing-key.pub.
  Both branch-tip and commit-pinned (8a3c55e5...) variants.
- ADR + runbook: operator precondition now references the op1st-emea-b4mad
  path instead of secrets/cosign.pub.

Refs: forgejo-mcp-a2y, forgejo-mcp-d4b
2026-05-25 13:35:31 +02:00

45 lines
601 B
Text

*.log
# Build output
build/
dist/
forgejo-mcp
# Environment variables
.env
.env.local
.env.development.local
.env.test.local
.env.production.local
.envrc
# IDE and editor files
.idea/
.vscode/
*.swp
*.swo
*~
# OS files
.DS_Store
Thumbs.db
# Claude Code settings
.claude/settings.local.json
.claude/scheduled_tasks.lock
.social-media/
# Beads / Dolt files (added by bd init)
.dolt/
*.db
.beads-credential-key
# Python bytecode cache
__pycache__/
worktrees/
.claude/scheduled_tasks.lock
# Defense-in-depth: catch SOPS scratch files and any future secrets/ usage.
secrets/
.~decrypted*.enc.yaml