# Keep the build context small and NEVER bake secrets or host-built artifacts into the image.

# Secrets — must never enter the image (env is injected by Dokploy at runtime).
.env
.env.*
!.env.example

# Dependencies + build outputs (reinstalled / rebuilt inside the image).
node_modules
**/node_modules
apps/web/dist
apps/api/dist
dist
build
.turbo
.cache
coverage

# VCS / CI / editor / OS noise.
.git
.gitignore
.github
.vscode
.idea
.DS_Store
Thumbs.db

# Logs and legacy Plesk/Passenger runtime scratch.
*.log
logs
tmp

# Local-only storage dirs (documents live in Spaces).
storage
uploads

# Tests aren't needed in the runtime image.
apps/api/test
**/*.test.ts

# Note: certs/ is intentionally NOT ignored — the Postgres CA cert (if committed) is baked in
# so production TLS verification works. See DEPLOY-DOKPLOY.md.
