Globbing, Quoting and Escaping

rm *.log never sees the *. Bash expands the pattern first and hands rm the finished list of names; when nothing matches, it passes the pattern through unchanged, which is why the error quotes a literal *.bak. * matches any run of characters, ? one character and [0-9] one from a set, and none of them match a leading dot, so * skips .htaccess. Brace expansion, {a,b}, generates text whether or not files exist.

Single quotes stop all expansion, which suits passwords and regular expressions. Double quotes keep $var and $(cmd) but protect spaces and globs; put them around almost every variable. A backslash escapes one character.

Watching the shell expand a pattern before the command runsShell
mkdir -p /tmp/g && cd /tmp/g && touch a.log b.log .hidden report.txt
echo *.log                 # the shell expands; echo only prints the result
echo *                     # the dotfile is not matched
rm *.bak                   # no match: rm receives the literal pattern
echo {dev,test,prod}.conf  # brace expansion invents names that need not exist
DIR="my files"; printf '[%s]\n' "$DIR"     # quoted: one argument
printf '[%s]\n' $DIR                       # unquoted: split into two
cd /tmp && rm -rf /tmp/g
Output
a.log b.log
a.log b.log report.txt
rm: cannot remove '*.bak': No such file or directory
dev.conf test.conf prod.conf
[my files]
[my]
[files]