Skip to main content

Public versus private documentation

This site uses a hybrid publishing model: the documentation is public; administrative tools remain private.

Safe to publish​

  • Sanitized Compose examples and service diagrams.
  • General hardware model names and high-level topology.
  • Commands that are safe to run in a test environment.
  • Troubleshooting lessons without tokens or private data.

Keep private​

  • .env files, API tokens, passwords, VPN private keys and Cloudflare credentials.
  • Real backup encryption keys, database dumps and internal user details.
  • SSH private keys, webhook URLs and authentication cookies.
  • Unredacted docker inspect, Compose config outputs and logs.

Before each Git push​

git status --short
git diff --cached

Consider adding a secret scanner (such as Gitleaks) to CI. Never rely on .gitignore to remove secrets already committed to history. Rotate exposed credentials if leakage occurs.