Ravindra BagaleCourses & study guides

Chapter 2: Git Fundamentals

2.6 .gitignore — keep junk and secrets out

A .gitignore file lists patterns Git should not track. Untracked ignored files stay on disk but never enter commits.

Why. node_modules, Python __pycache__, build folders and .env files are large or secret. They must not land in GitHub.

Create a .gitignore in the repo root, for example:

# secrets and local env
.env
.env.*
*.pem

# dependencies and caches
node_modules/
__pycache__/
*.pyc
.venv/

# OS / editor noise
.DS_Store
Thumbs.db
.idea/
.vscode/

Steps — add ignore rules before secrets appear

  1. Create .gitignore with at least .env, *.pem and your language's dependency folder.
  2. Run git status — .gitignore itself should show as untracked (you do want to commit it).
  3. git add .gitignore and commit: git commit -m "Add gitignore for env and dependencies"
  4. Create a fake .env with DEMO_SECRET=not-real — it must not appear as a file to add.

What you see: git status ignores .env. If a secret was already committed earlier, deleting it now is not enough — the history still has it. Rotate the secret and ask a trainer for history-cleanup guidance; do not invent unsafe "force push" steps on shared repos alone.

Never commit real keys

No AWS access keys, database passwords, or .pem private keys in Git. Use fake values in labs. Later chapters show safer CI secret stores.

Ravindra Bagale's Tip

Interview madhe vichartaat: "Repo madhe .env commit zala tar kay?" — Answer: rotate the secret, remove from future commits via gitignore, clean history with a known process, and treat the old secret as leaked. Panic delete on disk only is not enough. Dhyan rakho!