Compose key inventory
GENERATED by tools/scripts/generate/compose-key-inventory.py (SPRINT_20260905_003 CKG-1) — edit the generator, not this file. One line per devops/compose/docker-compose.*.y?ml.
Why. docker compose config exiting 0 proves the YAML composes; it cannot notice a deleted load-bearing key, a deleted mount, or a dead key that came back. Only a key-by-key assertion does. This inventory decides, per file, whether such an assertion is owed.
Method. (i) runtime config counts services that declare image/build and any of environment, env_file, volumes, command, secrets, configs — configuration a render cannot miss; a service with neither image nor build is an override fragment. (ii) asserted today is read from the architecture pack: only EvidenceConsolidationComposeConformanceTests and AdvisoryAiConsolidationConformanceTests render and assert per key; PacksRegistryDualMode, AppRootWritability assert specific mounts/keys; DatabaseOwnership asserts the connection-string key class on 17 files; every other compose reference in the pack is textual. (iii) disposition applies the ordered rules in the generator; gate = an entry in devops/compose/compose-key-expectations.json (the file rendered alone, hermetically, with --env-file empty and --no-interpolate), checked by ComposeKeyConformanceTests; gate-exists = a render-based per-key test already covers it; no-gate = the stated reason.
| Disposition | Files |
|---|---|
gate | 22 |
gate-exists | 4 |
no-gate | 135 |
| File | Services | Deployed | Runtime config | Long-lived | Asserted today | Disposition | Reason |
|---|---|---|---|---|---|---|---|
docker-compose.advisory-fixture-offline.override.yml | 1 | 1 | 0 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.advisoryai-knowledge-test.yml | 1 | 1 | 1 | 1 | DatabaseOwnership asserts the connection-string class | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.advisoryai.scratch.yml | 4 | 4 | 3 | 1 | AdvisoryAiConsolidationConformanceTests renders the scratch chain | gate-exists | AdvisoryAiConsolidationConformanceTests renders the scratch chain |
docker-compose.advisoryai.yml | 3 | 3 | 3 | 2 | AdvisoryAiConsolidationConformanceTests renders the family and asserts keys and mounts | gate-exists | AdvisoryAiConsolidationConformanceTests renders the family and asserts keys and mounts |
docker-compose.authority-image-pin-fnd9.override.yml | 1 | 1 | 0 | 0 | — | no-gate | one-shot tool / job definition (no restart policy); nothing long-lived to keep configured |
docker-compose.authority-image-pin.override.yml | 1 | 1 | 0 | 0 | — | no-gate | image-pin override (image only); nothing a key gate could lose |
docker-compose.authority-password-tool.yml | 1 | 1 | 1 | 0 | — | no-gate | one-shot tool / job definition (no restart policy); nothing long-lived to keep configured |
docker-compose.authority.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.auto-sbom-e2e.override.yml | 4 | 0 | 3 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.binary-fold.scratch.yml | 4 | 4 | 4 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.bl2.override.yml | 16 | 16 | 15 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.blue-green.yml | 4 | 4 | 3 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.bsim.yml | 2 | 2 | 2 | 2 | DatabaseOwnership asserts the connection-string class | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.cas.yaml | 6 | 6 | 6 | 4 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.cli.yml | 1 | 1 | 1 | 0 | — | no-gate | one-shot tool / job definition (no restart policy); nothing long-lived to keep configured |
docker-compose.compliance-china.yml | 9 | 0 | 9 | 0 | — | no-gate | regional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role |
docker-compose.compliance-eu.yml | 9 | 0 | 9 | 0 | — | no-gate | regional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role |
docker-compose.compliance-golden-path.override.yml | 18 | 15 | 11 | 0 | DatabaseOwnership asserts the connection-string class | no-gate | regional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role |
docker-compose.compliance-russia.yml | 9 | 0 | 9 | 0 | — | no-gate | regional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role |
docker-compose.connected-travel.override.yml | 1 | 0 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.cons-c1a-enable.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.console-audit.override.yml | 6 | 0 | 1 | 0 | DatabaseOwnership asserts the connection-string class | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.corpus.yml | 1 | 1 | 1 | 1 | DatabaseOwnership asserts the connection-string class | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.cra-assurance-produce.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.crypto-provider.crypto-sim.yml | 7 | 1 | 7 | 1 | — | no-gate | regional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role |
docker-compose.crypto-provider.cryptopro.yml | 7 | 1 | 7 | 1 | — | no-gate | regional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role |
docker-compose.crypto-provider.smremote.yml | 1 | 1 | 1 | 1 | — | no-gate | regional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role |
docker-compose.crypto-softtoken-eval.yml | 3 | 0 | 3 | 0 | — | no-gate | regional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role |
docker-compose.customer-deploy-fidelity.yml | 3 | 0 | 3 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.dev-ui.yml | 1 | 0 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.dev.yml | 6 | 6 | 6 | 5 | DatabaseOwnership asserts the connection-string class | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.e2e-analyzer-coverage.override.yml | 7 | 0 | 5 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.e2e-analyzer-coverage.yml | 2 | 2 | 2 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.e2e-notify-coverage.yml | 2 | 2 | 2 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.evidence.scratch.yml | 2 | 0 | 2 | 0 | EvidenceConsolidationComposeConformanceTests renders the scratch chain and asserts its isolation prefix and keys | gate-exists | EvidenceConsolidationComposeConformanceTests renders the scratch chain and asserts its isolation prefix and keys |
docker-compose.evidence.yml | 2 | 2 | 2 | 2 | EvidenceConsolidationComposeConformanceTests renders the evidence chain and asserts keys and mounts per role | gate-exists | EvidenceConsolidationComposeConformanceTests renders the evidence chain and asserts keys and mounts per role |
docker-compose.existing-networks.override.yml | 0 | 0 | 0 | 0 | — | no-gate | no services (network/volume declarations only) |
docker-compose.findings-dsse-dev.yml | 1 | 0 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.findings.scratch.yml | 3 | 1 | 1 | 1 | DatabaseOwnership asserts the connection-string class | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.findings.yml | 2 | 2 | 2 | 2 | AppRootWritabilityConformanceTests asserts the app-root mounts; DatabaseOwnership asserts the connection-string class | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.fixture-mode.yml | 7 | 0 | 7 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.gpu.yaml | 2 | 0 | 2 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.graph-api-image-pin.override.yml | 1 | 1 | 0 | 0 | — | no-gate | image-pin override (image only); nothing a key gate could lose |
docker-compose.graph.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.idp-testing.yml | 3 | 2 | 3 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.integration-fixtures.yml | 11 | 11 | 11 | 11 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.integrations.yml | 9 | 9 | 9 | 9 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.jobengine.yml | 1 | 1 | 1 | 1 | PacksRegistryDualModeComposeConformanceTests asserts the dual-mode keys and mounts; DatabaseOwnership asserts the connection-string class | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.lab-plugin-bundles.yml | 1 | 0 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.local-authority-rollback.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-authority.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-console-rollback.yml | 1 | 0 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-evidence.yml | 2 | 2 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-findings-web.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-graph-candidate.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-graph.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-integrations-web.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-jobengine-estate-worker.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-jobengine-web.yml | 2 | 2 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-notify-web.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-notify-worker.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-platform-login-rollback.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-platform-notify-rollback.yml | 1 | 0 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-platform-scope-rollback.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-platform.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-policy-engine-plc1.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-policy-engine-scn-candidate.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-policy-engine-scn-update.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-policy-engine.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-release-orchestrator-est7.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-release-orchestrator-scn-candidate.yml | 1 | 1 | 0 | 0 | — | no-gate | local image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain |
docker-compose.local-release-orchestrator.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-router-gateway-rollback.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-router-gateway.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-scanner-web.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-scanner-worker-baseline.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.local-scanner-worker-scn-candidate.yml | 1 | 1 | 1 | 0 | — | no-gate | machine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive |
docker-compose.notifier-mailpit.override.yml | 2 | 1 | 2 | 1 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.notify-activation.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.notify.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.offlinekit-consolidated.yml | 2 | 2 | 2 | 2 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.offlinekit-signer.yml | 2 | 0 | 2 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.openbao.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.operator-signing-liveproof.override.yml | 3 | 1 | 3 | 0 | — | no-gate | one-shot tool / job definition (no restart policy); nothing long-lived to keep configured |
docker-compose.osv-real.override.yml | 0 | 0 | 0 | 0 | — | no-gate | no services (network/volume declarations only) |
docker-compose.packsregistry-dual-mode.scratch.yml | 3 | 3 | 2 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.pg-tuning.override.yml | 1 | 0 | 1 | 0 | DatabaseOwnership asserts the connection-string class | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.platform-version.override.yml | 1 | 1 | 0 | 0 | — | no-gate | image-pin override (image only); nothing a key gate could lose |
docker-compose.plugins.bad-signature.yml | 6 | 0 | 6 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.crypto-eidas.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.crypto-fips-hsm.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.crypto-gost.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.crypto-sm-hsm.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.crypto-sm.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.execution-optional.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.execution.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.harness.yml | 11 | 0 | 11 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.integrations-runtime-host.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.integrations-scm-ci.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.integrations-secrets-optional.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.mounted-transport.yml | 17 | 0 | 17 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.notify-connectors.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.recommended.yml | 11 | 0 | 11 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.router-transport-rabbitmq.yml | 2 | 1 | 2 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.router-transport-tcp.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.router-transport-udp.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.scanner-full-analyzers.yml | 2 | 0 | 2 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.scanner-os.yml | 2 | 0 | 2 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.scheduler-ai.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.scheduler-estate-doctor.yml | 2 | 0 | 2 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.plugins.scheduler-feed.yml | 1 | 0 | 1 | 0 | — | no-gate | opt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set |
docker-compose.policy-catalog-replica.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.policy-db.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.qa-fixtures.override.yml | 1 | 0 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.rdt6-watch-proof.yml | 1 | 0 | 0 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.reachability-gate.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.reachability.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.registry.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.release-orchestrator.yml | 2 | 2 | 2 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.replay.yml | 1 | 1 | 1 | 1 | AppRootWritabilityConformanceTests asserts the app-root mounts | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.sbom-runtime-preservation.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.sbomservice-image-pin.override.yml | 1 | 1 | 0 | 0 | — | no-gate | image-pin override (image only); nothing a key gate could lose |
docker-compose.sbomservice.yml | 1 | 1 | 1 | 1 | DatabaseOwnership asserts the connection-string class | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.scanner-poe-dev.yml | 2 | 0 | 2 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.scanner-surface-fix.override.yml | 2 | 0 | 2 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.scanner.yml | 3 | 3 | 3 | 2 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.sealed-ci.yml | 5 | 5 | 5 | 5 | DatabaseOwnership asserts the connection-string class | no-gate | sealed-CI variant whose three pinned digests no longer resolve from the registry (CKG-2 R-CKG2-1); owner to re-derive before any gate is meaningful |
docker-compose.secret-providers.override.yml | 3 | 0 | 3 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.secret-providers.vault-local.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.secret-providers.vault-northwind.override.yml | 3 | 0 | 3 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.signals.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.signer.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.skip-missing.override.yml | 1 | 0 | 0 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.sm-remote.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.sprint028-agent-runtime.yml | 1 | 1 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.sprint028-verify.yml | 1 | 1 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.sprint051-smoke.override.yml | 1 | 0 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.sprint057-smoke.override.yml | 2 | 0 | 2 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.stella-infra.yml | 6 | 6 | 6 | 3 | DatabaseOwnership asserts the postgres role wiring; ScannerConsolidation references it textually | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.stella-ops.yml | 0 | 0 | 0 | 0 | — | no-gate | include-only root; every included file is inventoried on its own line |
docker-compose.stella-services.yml | 26 | 26 | 26 | 23 | DatabaseOwnership asserts the connection-string class per service; no per-key gate over the 39 services | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.telemetry-federation-peer.override.yml | 1 | 0 | 1 | 0 | — | no-gate | optional third-party observability side stack (opt-in profile); registered as such in the healthcheck exemption register |
docker-compose.telemetry-offline.yml | 5 | 5 | 5 | 5 | — | no-gate | optional third-party observability side stack (opt-in profile); registered as such in the healthcheck exemption register |
docker-compose.telemetry.yml | 5 | 5 | 5 | 5 | — | no-gate | optional third-party observability side stack (opt-in profile); registered as such in the healthcheck exemption register |
docker-compose.tester.yml | 1 | 1 | 1 | 1 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.testing.yml | 13 | 13 | 13 | 5 | DatabaseOwnership asserts the connection-string class | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.tile-proxy.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.timeline-image-pin.override.yml | 1 | 1 | 0 | 0 | — | no-gate | image-pin override (image only); nothing a key gate could lose |
docker-compose.timeline.yml | 1 | 1 | 1 | 1 | — | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.unknowns.yml | 1 | 1 | 1 | 1 | DatabaseOwnership asserts the connection-string class | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
docker-compose.vex-cap-enable.override.yml | 2 | 0 | 2 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.vex-disposition-live.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.vex-full-corpus-optin.override.yml | 0 | 0 | 0 | 0 | — | no-gate | no services (network/volume declarations only) |
docker-compose.vex-ingest-ceiling.override.yml | 0 | 0 | 0 | 0 | — | no-gate | no services (network/volume declarations only) |
docker-compose.vex-ingest-live.override.yml | 0 | 0 | 0 | 0 | — | no-gate | no services (network/volume declarations only) |
docker-compose.vex-ingest-paused.override.yml | 0 | 0 | 0 | 0 | — | no-gate | no services (network/volume declarations only) |
docker-compose.vexhub-deploy.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.vulnerabilities-web-image-pin.override.yml | 1 | 1 | 0 | 0 | — | no-gate | image-pin override (image only); nothing a key gate could lose |
docker-compose.vulnerabilities.binary-corpus.override.yml | 1 | 0 | 1 | 0 | — | no-gate | QA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role |
docker-compose.vulnerabilities.g2.override.yml | 1 | 0 | 1 | 0 | — | no-gate | override fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt |
docker-compose.vulnerabilities.yml | 2 | 2 | 2 | 2 | AppRootWritabilityConformanceTests asserts the app-root mounts; DatabaseOwnership asserts the connection-string class | gate | deployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone |
