# Local runtime configuration .env .tls-renewal.env # Runtime TLS artifacts (never commit private keys/certs) nginx/ssl/*.crt nginx/ssl/*.key nginx/ssl/*.pem nginx/ssl/letsencrypt/ # Runtime logs logs/