diff --git a/.gitignore b/.gitignore
index 3707f1b..acf6ee8 100644
--- a/.gitignore
+++ b/.gitignore
@@ -11,6 +11,7 @@ composer.lock
/web/sites/*/settings.php
/web/sites/*/settings.local.php
/web/sites/*/services*.yml
+/web/sites/*/*.services.yml
# Ignore Drupal's file directory
/web/sites/*/files/
diff --git a/config/sync/.htaccess b/config/sync/.htaccess
new file mode 100644
index 0000000..25776a3
--- /dev/null
+++ b/config/sync/.htaccess
@@ -0,0 +1,24 @@
+# Deny all requests from Apache 2.4+.
+
+ Require all denied
+
+
+# Deny all requests from Apache 2.0-2.2.
+
+ Deny from all
+
+
+# Turn off all options we don't need.
+Options -Indexes -ExecCGI -Includes -MultiViews
+
+# Set the catch-all handler to prevent scripts from being executed.
+SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006
+
+ # Override the handler again if we're run later in the evaluation list.
+ SetHandler Drupal_Security_Do_Not_Remove_See_SA_2013_003
+
+
+# If we know how to do it safely, disable the PHP engine entirely.
+
+ php_flag engine off
+
\ No newline at end of file