Compose key inventory

GENERATED by tools/scripts/generate/compose-key-inventory.py (SPRINT_20260905_003 CKG-1) — edit the generator, not this file. One line per devops/compose/docker-compose.*.y?ml.

Why. docker compose config exiting 0 proves the YAML composes; it cannot notice a deleted load-bearing key, a deleted mount, or a dead key that came back. Only a key-by-key assertion does. This inventory decides, per file, whether such an assertion is owed.

Method. (i) runtime config counts services that declare image/build and any of environment, env_file, volumes, command, secrets, configs — configuration a render cannot miss; a service with neither image nor build is an override fragment. (ii) asserted today is read from the architecture pack: only EvidenceConsolidationComposeConformanceTests and AdvisoryAiConsolidationConformanceTests render and assert per key; PacksRegistryDualMode, AppRootWritability assert specific mounts/keys; DatabaseOwnership asserts the connection-string key class on 17 files; every other compose reference in the pack is textual. (iii) disposition applies the ordered rules in the generator; gate = an entry in devops/compose/compose-key-expectations.json (the file rendered alone, hermetically, with --env-file empty and --no-interpolate), checked by ComposeKeyConformanceTests; gate-exists = a render-based per-key test already covers it; no-gate = the stated reason.

DispositionFiles
gate22
gate-exists4
no-gate135
FileServicesDeployedRuntime configLong-livedAsserted todayDispositionReason
docker-compose.advisory-fixture-offline.override.yml1100no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.advisoryai-knowledge-test.yml1111DatabaseOwnership asserts the connection-string classno-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.advisoryai.scratch.yml4431AdvisoryAiConsolidationConformanceTests renders the scratch chaingate-existsAdvisoryAiConsolidationConformanceTests renders the scratch chain
docker-compose.advisoryai.yml3332AdvisoryAiConsolidationConformanceTests renders the family and asserts keys and mountsgate-existsAdvisoryAiConsolidationConformanceTests renders the family and asserts keys and mounts
docker-compose.authority-image-pin-fnd9.override.yml1100no-gateone-shot tool / job definition (no restart policy); nothing long-lived to keep configured
docker-compose.authority-image-pin.override.yml1100no-gateimage-pin override (image only); nothing a key gate could lose
docker-compose.authority-password-tool.yml1110no-gateone-shot tool / job definition (no restart policy); nothing long-lived to keep configured
docker-compose.authority.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.auto-sbom-e2e.override.yml4030no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.binary-fold.scratch.yml4440no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.bl2.override.yml1616150no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.blue-green.yml4430no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.bsim.yml2222DatabaseOwnership asserts the connection-string classno-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.cas.yaml6664gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.cli.yml1110no-gateone-shot tool / job definition (no restart policy); nothing long-lived to keep configured
docker-compose.compliance-china.yml9090no-gateregional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role
docker-compose.compliance-eu.yml9090no-gateregional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role
docker-compose.compliance-golden-path.override.yml1815110DatabaseOwnership asserts the connection-string classno-gateregional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role
docker-compose.compliance-russia.yml9090no-gateregional compliance profile; asserted by its compliance lane (EvidenceConsolidationCompose renders the EU chain), not a standing estate role
docker-compose.connected-travel.override.yml1010no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.cons-c1a-enable.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.console-audit.override.yml6010DatabaseOwnership asserts the connection-string classno-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.corpus.yml1111DatabaseOwnership asserts the connection-string classno-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.cra-assurance-produce.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.crypto-provider.crypto-sim.yml7171no-gateregional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role
docker-compose.crypto-provider.cryptopro.yml7171no-gateregional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role
docker-compose.crypto-provider.smremote.yml1111no-gateregional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role
docker-compose.crypto-softtoken-eval.yml3030no-gateregional crypto-provider profile rendered by EvidenceConsolidationComposeConformanceTests in its regional chains; opt-in, not a standing estate role
docker-compose.customer-deploy-fidelity.yml3030no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.dev-ui.yml1010no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.dev.yml6665DatabaseOwnership asserts the connection-string classno-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.e2e-analyzer-coverage.override.yml7050no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.e2e-analyzer-coverage.yml2220no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.e2e-notify-coverage.yml2220no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.evidence.scratch.yml2020EvidenceConsolidationComposeConformanceTests renders the scratch chain and asserts its isolation prefix and keysgate-existsEvidenceConsolidationComposeConformanceTests renders the scratch chain and asserts its isolation prefix and keys
docker-compose.evidence.yml2222EvidenceConsolidationComposeConformanceTests renders the evidence chain and asserts keys and mounts per rolegate-existsEvidenceConsolidationComposeConformanceTests renders the evidence chain and asserts keys and mounts per role
docker-compose.existing-networks.override.yml0000no-gateno services (network/volume declarations only)
docker-compose.findings-dsse-dev.yml1010no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.findings.scratch.yml3111DatabaseOwnership asserts the connection-string classno-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.findings.yml2222AppRootWritabilityConformanceTests asserts the app-root mounts; DatabaseOwnership asserts the connection-string classgatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.fixture-mode.yml7070no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.gpu.yaml2020no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.graph-api-image-pin.override.yml1100no-gateimage-pin override (image only); nothing a key gate could lose
docker-compose.graph.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.idp-testing.yml3230no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.integration-fixtures.yml11111111no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.integrations.yml9999gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.jobengine.yml1111PacksRegistryDualModeComposeConformanceTests asserts the dual-mode keys and mounts; DatabaseOwnership asserts the connection-string classgatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.lab-plugin-bundles.yml1010no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.local-authority-rollback.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-authority.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-console-rollback.yml1010no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-evidence.yml2200no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-findings-web.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-graph-candidate.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-graph.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-integrations-web.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-jobengine-estate-worker.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-jobengine-web.yml2210no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-notify-web.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-notify-worker.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-platform-login-rollback.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-platform-notify-rollback.yml1010no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-platform-scope-rollback.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-platform.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-policy-engine-plc1.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-policy-engine-scn-candidate.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-policy-engine-scn-update.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-policy-engine.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-release-orchestrator-est7.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-release-orchestrator-scn-candidate.yml1100no-gatelocal image-pin partial (image only); the healthcheck guard counts pins by shape and the rar/scn/overlay manifests own the chain
docker-compose.local-release-orchestrator.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-router-gateway-rollback.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-router-gateway.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-scanner-web.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-scanner-worker-baseline.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.local-scanner-worker-scn-candidate.yml1110no-gatemachine-local runtime partial governed by its manifest owner (local-runtime-chains.json / local-scn-runtime.json / local-overlay-chains.json); its keys are the deploy receipt, superseded on the next re-derive
docker-compose.notifier-mailpit.override.yml2121no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.notify-activation.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.notify.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.offlinekit-consolidated.yml2222gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.offlinekit-signer.yml2020no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.openbao.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.operator-signing-liveproof.override.yml3130no-gateone-shot tool / job definition (no restart policy); nothing long-lived to keep configured
docker-compose.osv-real.override.yml0000no-gateno services (network/volume declarations only)
docker-compose.packsregistry-dual-mode.scratch.yml3320no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.pg-tuning.override.yml1010DatabaseOwnership asserts the connection-string classno-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.platform-version.override.yml1100no-gateimage-pin override (image only); nothing a key gate could lose
docker-compose.plugins.bad-signature.yml6060no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.crypto-eidas.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.crypto-fips-hsm.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.crypto-gost.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.crypto-sm-hsm.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.crypto-sm.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.execution-optional.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.execution.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.harness.yml110110no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.integrations-runtime-host.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.integrations-scm-ci.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.integrations-secrets-optional.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.mounted-transport.yml170170no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.notify-connectors.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.recommended.yml110110no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.router-transport-rabbitmq.yml2120no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.router-transport-tcp.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.router-transport-udp.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.scanner-full-analyzers.yml2020no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.scanner-os.yml2020no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.scheduler-ai.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.scheduler-estate-doctor.yml2020no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.plugins.scheduler-feed.yml1010no-gateopt-in plugin bundle mount overlay; the lane that brings it up asserts the bundle, and the healthcheck/plugin guards own the mounted set
docker-compose.policy-catalog-replica.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.policy-db.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.qa-fixtures.override.yml1010no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.rdt6-watch-proof.yml1000no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.reachability-gate.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.reachability.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.registry.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.release-orchestrator.yml2221gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.replay.yml1111AppRootWritabilityConformanceTests asserts the app-root mountsgatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.sbom-runtime-preservation.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.sbomservice-image-pin.override.yml1100no-gateimage-pin override (image only); nothing a key gate could lose
docker-compose.sbomservice.yml1111DatabaseOwnership asserts the connection-string classgatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.scanner-poe-dev.yml2020no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.scanner-surface-fix.override.yml2020no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.scanner.yml3332gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.sealed-ci.yml5555DatabaseOwnership asserts the connection-string classno-gatesealed-CI variant whose three pinned digests no longer resolve from the registry (CKG-2 R-CKG2-1); owner to re-derive before any gate is meaningful
docker-compose.secret-providers.override.yml3030no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.secret-providers.vault-local.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.secret-providers.vault-northwind.override.yml3030no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.signals.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.signer.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.skip-missing.override.yml1000no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.sm-remote.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.sprint028-agent-runtime.yml1110no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.sprint028-verify.yml1110no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.sprint051-smoke.override.yml1010no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.sprint057-smoke.override.yml2020no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.stella-infra.yml6663DatabaseOwnership asserts the postgres role wiring; ScannerConsolidation references it textuallygatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.stella-ops.yml0000no-gateinclude-only root; every included file is inventoried on its own line
docker-compose.stella-services.yml26262623DatabaseOwnership asserts the connection-string class per service; no per-key gate over the 39 servicesgatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.telemetry-federation-peer.override.yml1010no-gateoptional third-party observability side stack (opt-in profile); registered as such in the healthcheck exemption register
docker-compose.telemetry-offline.yml5555no-gateoptional third-party observability side stack (opt-in profile); registered as such in the healthcheck exemption register
docker-compose.telemetry.yml5555no-gateoptional third-party observability side stack (opt-in profile); registered as such in the healthcheck exemption register
docker-compose.tester.yml1111no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.testing.yml1313135DatabaseOwnership asserts the connection-string classno-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.tile-proxy.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.timeline-image-pin.override.yml1100no-gateimage-pin override (image only); nothing a key gate could lose
docker-compose.timeline.yml1111gatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.unknowns.yml1111DatabaseOwnership asserts the connection-string classgatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone
docker-compose.vex-cap-enable.override.yml2020no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.vex-disposition-live.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.vex-full-corpus-optin.override.yml0000no-gateno services (network/volume declarations only)
docker-compose.vex-ingest-ceiling.override.yml0000no-gateno services (network/volume declarations only)
docker-compose.vex-ingest-live.override.yml0000no-gateno services (network/volume declarations only)
docker-compose.vex-ingest-paused.override.yml0000no-gateno services (network/volume declarations only)
docker-compose.vexhub-deploy.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.vulnerabilities-web-image-pin.override.yml1100no-gateimage-pin override (image only); nothing a key gate could lose
docker-compose.vulnerabilities.binary-corpus.override.yml1010no-gateQA / development / fixture profile: exists for the lane that uses it, whose run is the assertion; not a standing estate role
docker-compose.vulnerabilities.g2.override.yml1010no-gateoverride fragment (no image/build): configures a service defined in a gated family file; its effect is only observable through the chain that applies it and that chain’s deploy receipt
docker-compose.vulnerabilities.yml2222AppRootWritabilityConformanceTests asserts the app-root mounts; DatabaseOwnership asserts the connection-string classgatedeployed estate role(s) with load-bearing runtime configuration and no render-based per-key gate; entry in compose-key-expectations.json, rendered alone