Public versus private documentation
This site uses a hybrid publishing model: the documentation is public; administrative tools remain private.
Safe to publish
- Sanitized Compose examples and service diagrams.
- General hardware model names and high-level topology.
- Commands that are safe to run in a test environment.
- Troubleshooting lessons without tokens or private data.
Keep private
.envfiles, API tokens, passwords, VPN private keys and Cloudflare credentials.- Real backup encryption keys, database dumps and internal user details.
- SSH private keys, webhook URLs and authentication cookies.
- Unredacted
docker inspect, Compose config outputs and logs.
Before each Git push
git status --short
git diff --cached
Consider adding a secret scanner (such as Gitleaks) to CI. Never rely on .gitignore to remove secrets already committed to history. Rotate exposed credentials if leakage occurs.