# Never commit the rendered TSIG key material or a populated .env. secrets.conf
# holds the shared secrets every node's AXFR/NOTIFY authenticates with; leaking
# it lets anyone transfer -- or spoof a NOTIFY for -- every zone in the estate.
secrets.conf
.env
