- Remove sensitive files from git tracking (kubeconfig, secrets.yaml.backup, talosconfig.backup) and update .gitignore - Fix installer version drift: v1.12.4 -> v1.12.6 across all talos configs - Fix grubUseUKICmdline + extraKernelArgs conflict on CP configs - Remove tailscale extension from stock installer CP configs (won't work) - Add nameservers to controlplane and per-node configs - Add time servers to all per-node worker configs - Fix HostnameConfig auto: stable in base templates - Clean up doc drift (README.md, CLAUDE.md) for worker count and storage - Remove all Longhorn references (worker configs, documentation) - Migrate Cloudflare provider v4 -> v5 with full resource refactoring: cloudflare_record -> cloudflare_dns_record, zone_settings_override -> zone_setting, block -> attribute syntax for rulesets, data, and tunnel configs - Fix firewall expression (not http.user_agent ne '' -> not exists)
14 lines
266 B
Text
14 lines
266 B
Text
# Talos secrets and sensitive files
|
|
secrets.yaml
|
|
secrets.yaml.backup
|
|
talosconfig
|
|
talosconfig.backup
|
|
kubeconfig
|
|
|
|
# Per-node configs contain full cluster PKI — track with care
|
|
# Consider externalizing secrets from these files
|
|
|
|
# Temporary files
|
|
*.tmp
|
|
*.bak
|
|
*.backup
|