Update the git-sync secret-exposure solution doc with today's operational lesson: untracking an already-committed secret under a live bidirectional sync. Covers the direction:both force-push-revert trap, the freeze-every- server-first sequence, audit-before-reset (authoritative secret in env/), the stale origin/main ref + sparse-checkout gotchas, and the ignore:-field mechanism. Add Makefile targets that supported the fix: - remote-secrets-audit: secret-safe (existence + size + git ls-files, never contents) audit of config/ vs env/<host>/config secret locations - remote-content-status: also show the .gitignore diff git-sync regenerates Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
docs/
If you're Mischa
Doing something operational? → guides/
- Posting a journal entry
- Managing GPX files
- Switching to a new trip
- Rebuilding local dev from scratch
Checking project status? → working/
Design or architecture decisions? → reference/
If you're Claude
Always-loaded project rules → CLAUDE.md (repo root)
Active specs and plans → working/specs/ and working/plans/
Stable facts → reference/
Raw research input → research/