6538b09b7d
- providers/webrunner.yml: wrap loop_var under loop_control in all three provider provision tasks — Ansible was rejecting loop_var as a conflicting action statement alongside include_tasks - deployment_engine.py: strip _SECRET_KEYS (tokens, passwords, api keys) from create_extra_vars() — credentials are already set as env vars by set_provider_environment(), no need to pass them through --extra-vars where they end up in process listings and logs - deployment_engine.py: remove debug log line that dumped the full ansible-playbook command including all extra-vars JSON with live creds - deployment_engine.py: create deployment log files with 0o600 permissions instead of world-readable 0o644 - deploy_webrunner.py: remove load_vars_file() call that was pulling phishing module creds (SMTP password, gophish port, domain) into the webrunner config dict — all provider creds already collected by gather_provider_config() - deploy_webrunner.py: remove unused select_provider import - .gitignore: narrow 'deployment*' glob to specific artifact patterns so deployment_engine.py is no longer excluded from tracking