Discover modules > cue.dev/x/dockercompose
v0.5.0
#Schema: ¶

Compose Specification

The Compose file is a YAML file defining a multi-containers based application.

"version"?: string ¶

declared for backward compatibility, ignored. Please remove it.

"name"?: string ¶

define the Compose project name, until user defines one explicitly.

"include"?: [...#include] ¶

compose sub-projects to be included.

[...]: #include
"services"?: ¶

The services that will be used by your application.

[=~"^[a-zA-Z0-9._-]+$"]: #service ¶
"develop"?: #development ¶
"watch"?:
click to see definition
[...close({
	// Patterns to exclude from watching.
	"ignore"?: #string_or_list

	// Patterns to include in watching.
	"include"?: #string_or_list

	// Path to watch for changes.
	"path"!: string

	// Action to take when a change is detected: rebuild the container, sync files,
	// restart the container, sync and restart, or sync and execute a command.
	"action"!: "rebuild" | "sync" | "restart" | "sync+restart" | "sync+exec"

	// Target path in the container for sync operations.
	"target"?: string

	// Command to execute when a change is detected and action is sync+exec.
	"exec"?: #service_hook

	// Ensure that an initial synchronization is done before starting watch mode for sync+x triggers
	"initial_sync"?: bool

	{[=~"^x-"]: _}
})]
¶

Configure watch mode for the service, which monitors file changes and performs actions in response.

[...]:
"ignore"?: #string_or_list

Patterns to exclude from watching.

"include"?: #string_or_list

Patterns to include in watching.

"path"!: string

Path to watch for changes.

"action"!: "rebuild" | "sync" | "restart" | "sync+restart" | "sync+exec"

Action to take when a change is detected: rebuild the container, sync files, restart the container, sync and restart, or sync and execute a command.

"target"?: string

Target path in the container for sync operations.

"exec"?: #service_hook

Command to execute when a change is detected and action is sync+exec.

"command"!: #command

Command to execute as part of the hook.

"user"?: string

User to run the command as.

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command.

"environment"?: #list_or_dict

Environment variables for the command.

[=~"^x-"]: _
"initial_sync"?: bool

Ensure that an initial synchronization is done before starting watch mode for sync+x triggers

[=~"^x-"]: _
[=~"^x-"]: _ ¶
"deploy"?: #deployment ¶
"mode"?: string ¶

Deployment mode for the service: 'replicated' (default) or 'global'.

"endpoint_mode"?: string ¶

Endpoint mode for the service: 'vip' (default) or 'dnsrr'.

"replicas"?: int | string ¶

Number of replicas of the service container to run.

"labels"?: #list_or_dict ¶

Labels to apply to the service.

"rollback_config"?: ¶

Configuration for rolling back a service update.

"parallelism"?: int | string ¶

The number of containers to rollback at a time. If set to 0, all containers rollback simultaneously.

"delay"?: string ¶

The time to wait between each container group's rollback (e.g., '1s', '1m30s').

"failure_action"?: string ¶

Action to take if a rollback fails: 'continue', 'pause'.

"monitor"?: string ¶

Duration to monitor each task for failures after it is created (e.g., '1s', '1m30s').

"max_failure_ratio"?: number | string ¶

Failure rate to tolerate during a rollback.

"order"?: "start-first" | "stop-first" ¶

Order of operations during rollbacks: 'stop-first' (default) or 'start-first'.

[=~"^x-"]: _ ¶
"update_config"?: ¶

Configuration for updating a service.

"parallelism"?: int | string ¶

The number of containers to update at a time.

"delay"?: string ¶

The time to wait between updating a group of containers (e.g., '1s', '1m30s').

"failure_action"?: string ¶

Action to take if an update fails: 'continue', 'pause', 'rollback'.

"monitor"?: string ¶

Duration to monitor each updated task for failures after it is created (e.g., '1s', '1m30s').

"max_failure_ratio"?: number | string ¶

Failure rate to tolerate during an update (0 to 1).

"order"?: "start-first" | "stop-first" ¶

Order of operations during updates: 'stop-first' (default) or 'start-first'.

[=~"^x-"]: _ ¶
"resources"?: ¶

Resource constraints and reservations for the service.

"limits"?: ¶

Resource limits for the service containers.

"cpus"?: number | string ¶

Limit for how much of the available CPU resources, as number of cores, a container can use.

"memory"?: string ¶

Limit on the amount of memory a container can allocate (e.g., '1g', '1024m').

"pids"?: int | string ¶

Maximum number of PIDs available to the container.

[=~"^x-"]: _ ¶
"reservations"?: ¶

Resource reservations for the service containers.

"cpus"?: number | string ¶

Reservation for how much of the available CPU resources, as number of cores, a container can use.

"memory"?: string ¶

Reservation on the amount of memory a container can allocate (e.g., '1g', '1024m').

"generic_resources"?: #generic_resources ¶

User-defined resources to reserve.

"devices"?: #devices ¶

Device reservations for the container.

[=~"^x-"]: _ ¶
[=~"^x-"]: _ ¶
"restart_policy"?: ¶

Restart policy for the service containers.

"condition"?: string ¶

Condition for restarting the container: 'none', 'on-failure', 'any'.

"delay"?: string ¶

Delay between restart attempts (e.g., '1s', '1m30s').

"max_attempts"?: int | string ¶

Maximum number of restart attempts before giving up.

"window"?: string ¶

Time window used to evaluate the restart policy (e.g., '1s', '1m30s').

[=~"^x-"]: _ ¶
"placement"?: ¶

Constraints and preferences for the platform to select a physical node to run service containers

"constraints"?: [...string] ¶

Placement constraints for the service (e.g., 'node.role==manager').

[...]: string
"preferences"?:
click to see definition
[...close({
	// Spread tasks evenly across values of the specified node label.
	"spread"?: string

	{[=~"^x-"]: _}
})]
¶

Placement preferences for the service.

[...]:
"spread"?: string

Spread tasks evenly across values of the specified node label.

[=~"^x-"]: _
"max_replicas_per_node"?: int | string ¶

Maximum number of replicas of the service.

[=~"^x-"]: _ ¶
[=~"^x-"]: _ ¶
"annotations"?: #list_or_dict ¶
"attach"?: bool | string ¶
"build"?:
click to see definition
matchN(1, [
	string,
	close({
		// Path to the build context. Can be a relative path or a URL.
		"context"?: string

		// Name of the Dockerfile to use for building the image.
		"dockerfile"?: string

		// Inline Dockerfile content to use instead of a Dockerfile from the build context.
		"dockerfile_inline"?: string

		// List of extra privileged entitlements to grant to the build process.
		"entitlements"?: [...string]

		// Build-time variables, specified as a map or a list of KEY=VAL pairs.
		"args"?: #list_or_dict

		// SSH agent socket or keys to expose to the build. Format is either a string or
		// a list of 'default|<id>[=<socket>|<key>[,<key>]]'.
		"ssh"?: #list_or_dict

		// Labels to apply to the built image.
		"labels"?: #list_or_dict

		// List of sources the image builder should use for cache resolution
		"cache_from"?: [...string]

		// Cache destinations for the build cache.
		"cache_to"?: [...string]

		// Do not use cache when building the image.
		"no_cache"?: bool | string

		// Do not use build cache for the specified stages.
		"no_cache_filter"?: #string_or_list

		// Additional build contexts to use, specified as a map of name to context path or URL.
		"additional_contexts"?: #list_or_dict

		// Network mode to use for the build. Options include 'default', 'none', 'host', or a network name.
		"network"?: string

		// Add a provenance attestation
		"provenance"?: bool | string

		// Add a SBOM attestation
		"sbom"?: bool | string

		// Always attempt to pull a newer version of the image.
		"pull"?: bool | string

		// Build stage to target in a multi-stage Dockerfile.
		"target"?: string

		// Size of /dev/shm for the build container. A string value can use suffix like
		// '2g' for 2 gigabytes.
		"shm_size"?: int | string

		// Add hostname mappings for the build container.
		"extra_hosts"?: #extra_hosts

		// Container isolation technology to use for the build process.
		"isolation"?: string

		// Give extended privileges to the build container.
		"privileged"?: bool | string

		// Secrets to expose to the build. These are accessible at build-time.
		"secrets"?: #service_config_or_secret

		// Additional tags to apply to the built image.
		"tags"?: [...string]

		// Override the default ulimits for the build container.
		"ulimits"?: #ulimits

		// Platforms to build for, e.g., 'linux/amd64', 'linux/arm64', or 'windows/amd64'.
		"platforms"?: [...string]

		{[=~"^x-"]: _}
	}),
])
¶

Configuration options for building the service's image.

"blkio_config"?: ¶

Block IO configuration for the service.

"device_read_bps"?: [...#blkio_limit] ¶

Limit read rate (bytes per second) from a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"device_read_iops"?: [...#blkio_limit] ¶

Limit read rate (IO per second) from a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"device_write_bps"?: [...#blkio_limit] ¶

Limit write rate (bytes per second) to a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"device_write_iops"?: [...#blkio_limit] ¶

Limit write rate (IO per second) to a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"weight"?: int | string ¶

Block IO weight (relative weight) for the service, between 10 and 1000.

"weight_device"?: [...#blkio_weight] ¶

Block IO weight (relative weight) for specific devices.

[...]: #blkio_weight
"path"?: string

Path to the device (e.g., '/dev/sda').

"weight"?: int | string

Relative weight for the device, between 10 and 1000.

"cap_add"?: list.UniqueItems() & [...string] ¶

Add Linux capabilities. For example, 'CAP_SYS_ADMIN', 'SYS_ADMIN', or 'NET_ADMIN'.

[...]: string
"cap_drop"?: list.UniqueItems() & [...string] ¶

Drop Linux capabilities. For example, 'CAP_SYS_ADMIN', 'SYS_ADMIN', or 'NET_ADMIN'.

[...]: string
"cgroup"?: "host" | "private" ¶

Specify the cgroup namespace to join. Use 'host' to use the host's cgroup namespace, or 'private' to use a private cgroup namespace.

"cgroup_parent"?: string ¶

Specify an optional parent cgroup for the container.

"command"?: #command ¶

Override the default command declared by the container image, for example 'CMD' in Dockerfile.

"configs"?: #service_config_or_secret ¶

Grant access to Configs on a per-service basis.

"container_name"?: =~"[a-zA-Z0-9][a-zA-Z0-9_.-]+" ¶

Specify a custom container name, rather than a generated default name.

"cpu_count"?: matchN(1, [string, int & >=0]) ¶

Number of usable CPUs.

"cpu_percent"?: matchN(1, [string, int & >=0 & <=100]) ¶

Percentage of CPU resources to use.

"cpu_shares"?: number | string ¶

CPU shares (relative weight) for the container.

"cpu_quota"?: number | string ¶

Limit the CPU CFS (Completely Fair Scheduler) quota.

"cpu_period"?: number | string ¶

Limit the CPU CFS (Completely Fair Scheduler) period.

"cpu_rt_period"?: number | string ¶

Limit the CPU real-time period in microseconds or a duration.

"cpu_rt_runtime"?: number | string ¶

Limit the CPU real-time runtime in microseconds or a duration.

"cpus"?: number | string ¶

Number of CPUs to use. A floating-point value is supported to request partial CPUs.

"cpuset"?: string ¶

CPUs in which to allow execution (0-3, 0,1).

"credential_spec"?: ¶

Configure the credential spec for managed service account.

"config"?: string ¶

The name of the credential spec Config to use.

"file"?: string ¶

Path to a credential spec file.

"registry"?: string ¶

Path to a credential spec in the Windows registry.

[=~"^x-"]: _ ¶
"depends_on"?:
click to see definition
matchN(1, [
	#list_of_strings,
	close({

		{
			[=~"^[a-zA-Z0-9._-]+$"]: close({

				{[=~"^x-"]: _}

				// Whether to restart dependent services when this service is restarted.
				"restart"?: bool | string

				// Whether the dependency is required for the dependent service to start.
				"required"?: bool

				// Condition to wait for. 'service_started' waits until the service has started,
				// 'service_healthy' waits until the service is healthy (as defined by its
				// healthcheck), 'service_completed_successfully' waits until the service has
				// completed successfully.
				"condition"!: "service_started" | "service_healthy" | "service_completed_successfully"
			})
		}}),
])
¶

Express dependency between services. Service dependencies cause services to be started in dependency order. The dependent service will wait for the dependency to be ready before starting.

"device_cgroup_rules"?: #list_of_strings ¶

Add rules to the cgroup allowed devices list.

"devices"?:
click to see definition
[...matchN(1, [
	string,
	close({
		// Path on the host to the device.
		"source"!: string

		// Path in the container where the device will be mapped.
		"target"?: string

		// Cgroup permissions for the device (rwm).
		"permissions"?: string

		{[=~"^x-"]: _}
	}),
])]
¶

List of device mappings for the container.

[...]:
click to see definition
matchN(1, [
	string,
	close({
		// Path on the host to the device.
		"source"!: string

		// Path in the container where the device will be mapped.
		"target"?: string

		// Cgroup permissions for the device (rwm).
		"permissions"?: string

		{[=~"^x-"]: _}
	}),
])
"dns"?: #string_or_list ¶

Custom DNS servers to set for the service container.

"dns_opt"?: list.UniqueItems() & [...string] ¶

Custom DNS options to be passed to the container's DNS resolver.

[...]: string
"dns_search"?: #string_or_list ¶

Custom DNS search domains to set on the service container.

"domainname"?: string ¶

Custom domain name to use for the service container.

"entrypoint"?: #command ¶

Override the default entrypoint declared by the container image, for example 'ENTRYPOINT' in Dockerfile.

"env_file"?: #env_file ¶

Add environment variables from a file or multiple files. Can be a single file path or a list of file paths.

"label_file"?: #label_file ¶

Add metadata to containers using files containing Docker labels.

"environment"?: #list_or_dict ¶

Add environment variables. You can use either an array or a list of KEY=VAL pairs.

"expose"?: list.UniqueItems() & [...number | string] ¶

Expose ports without publishing them to the host machine - they'll only be accessible to linked services.

[...]: number | string
"extends"?:
click to see definition
matchN(1, [
	string,
	close({
		// The name of the service to extend.
		"service"!: string

		// The file path where the service to extend is defined.
		"file"?: string
	}),
])
¶

Extend another service, in the current file or another file.

"provider"?: ¶

Specify a service which will not be manage by Compose directly, and delegate its management to an external provider.

"type"!: string ¶

External component used by Compose to manage setup and teardown lifecycle of the service.

"options"?: ¶

Provider-specific options.

[=~"^.+$"]: matchN(1, [bool | number | string, [...bool | number | string]])
[=~"^x-"]: _ ¶
"external_links"?: list.UniqueItems() & [...string] ¶

Link to services started outside this Compose application. Specify services as <service_name>:<alias>.

[...]: string
"extra_hosts"?: #extra_hosts ¶

Add hostname mappings to the container network interface configuration.

"gpus"?: #gpus ¶

Define GPU devices to use. Can be set to 'all' to use all GPUs, or a list of specific GPU devices.

"group_add"?: list.UniqueItems() & [...number | string] ¶

Add additional groups which user inside the container should be member of.

[...]: number | string
"healthcheck"?: #healthcheck ¶

Configure a health check for the container to monitor its health status.

"disable"?: bool | string ¶

Disable any container-specified healthcheck. Set to true to disable.

"interval"?: string ¶

Time between running the check (e.g., '1s', '1m30s'). Default: 30s.

"retries"?: number | string ¶

Number of consecutive failures needed to consider the container as unhealthy. Default: 3.

"test"?: matchN(1, [string, [...string]]) ¶

The test to perform to check container health. Can be a string or a list. The first item is either NONE, CMD, or CMD-SHELL. If it's CMD, the rest of the command is exec'd. If it's CMD-SHELL, the rest is run in the shell.

"timeout"?: string ¶

Maximum time to allow one check to run (e.g., '1s', '1m30s'). Default: 30s.

"start_period"?: string ¶

Start period for the container to initialize before starting health-retries countdown (e.g., '1s', '1m30s'). Default: 0s.

"start_interval"?: string ¶

Time between running the check during the start period (e.g., '1s', '1m30s'). Default: interval value.

[=~"^x-"]: _ ¶
"hostname"?: string ¶

Define a custom hostname for the service container.

"image"?: string ¶

Specify the image to start the container from. Can be a repository/tag, a digest, or a local image ID.

"init"?: bool | string ¶

Run as an init process inside the container that forwards signals and reaps processes.

"ipc"?: string ¶

IPC sharing mode for the service container. Use 'host' to share the host's IPC namespace, 'service:[service_name]' to share with another service, or 'shareable' to allow other services to share this service's IPC namespace.

"isolation"?: string ¶

Container isolation technology to use. Supported values are platform-specific.

"labels"?: #list_or_dict ¶

Add metadata to containers using Docker labels. You can use either an array or a list.

"links"?: list.UniqueItems() & [...string] ¶

Link to containers in another service. Either specify both the service name and a link alias (SERVICE:ALIAS), or just the service name.

[...]: string
"logging"?: ¶

Logging configuration for the service.

"driver"?: string ¶

Logging driver to use, such as 'json-file', 'syslog', 'journald', etc.

"options"?: ¶

Options for the logging driver.

[=~"^.+$"]: null | number | string
[=~"^x-"]: _ ¶
"mac_address"?: string ¶

Container MAC address to set.

"mem_limit"?: number | string ¶

Memory limit for the container. A string value can use suffix like '2g' for 2 gigabytes.

"mem_reservation"?: int | string ¶

Memory reservation for the container.

"mem_swappiness"?: int | string ¶

Container memory swappiness as percentage (0 to 100).

"memswap_limit"?: number | string ¶

Amount of memory the container is allowed to swap to disk. Set to -1 to enable unlimited swap.

"network_mode"?: string ¶

Network mode. Values can be 'bridge', 'host', 'none', 'service:[service name]', or 'container:[container name]'.

"models"?:
click to see definition
matchN(1, [
	#list_of_strings,
	{
		{
			[=~"^[a-zA-Z0-9._-]+$"]: matchN(1, [
				close({
					// Environment variable set to AI model endpoint.
					"endpoint_var"?: string

					// Environment variable set to AI model name.
					"model_var"?: string

					{[=~"^x-"]: _}
				}),
				null,
			])
		}
		...
	},
])
¶

AI Models to use, referencing entries under the top-level models key.

"networks"?:
click to see definition
matchN(1, [
	#list_of_strings,
	close({

		{
			[=~"^[a-zA-Z0-9._-]+$"]: matchN(1, [
				close({
					// Alternative hostnames for this service on the network.
					"aliases"?: #list_of_strings

					// Interface network name used to connect to network
					"interface_name"?: string

					// Specify a static IPv4 address for this service on this network.
					"ipv4_address"?: string

					// Specify a static IPv6 address for this service on this network.
					"ipv6_address"?: string

					// List of link-local IPs.
					"link_local_ips"?: #list_of_strings

					// Specify a MAC address for this service on this network.
					"mac_address"?: string

					// Driver options for this network.
					"driver_opts"?: {
						{[=~"^.+$"]: number | string}
						...
					}

					// Specify the priority for the network connection.
					"priority"?: number

					// Specify the gateway priority for the network connection.
					"gw_priority"?: number

					{[=~"^x-"]: _}
				}),
				null,
			])
		}}),
])
¶

Networks to join, referencing entries under the top-level networks key. Can be a list of network names or a mapping of network name to network configuration.

"oom_kill_disable"?: bool | string ¶

Disable OOM Killer for the container.

"oom_score_adj"?: matchN(1, [string, int & >=-1000 & <=1000]) ¶

Tune host's OOM preferences for the container (accepts -1000 to 1000).

"pid"?: null | string ¶

PID mode for container.

"pids_limit"?: number | string ¶

Tune a container's PIDs limit. Set to -1 for unlimited PIDs.

"platform"?: string ¶

Target platform to run on, e.g., 'linux/amd64', 'linux/arm64', or 'windows/amd64'.

"ports"?:
click to see definition
list.UniqueItems() & [...matchN(1, [
	number,
	string,
	close({
		// A human-readable name for this port mapping.
		"name"?: string

		// The port binding mode, either 'host' for publishing a host port or 'ingress' for load balancing.
		"mode"?: string

		// The host IP to bind to.
		"host_ip"?: string

		// The port inside the container.
		"target"?: int | string

		// The publicly exposed port.
		"published"?: int | string

		// The port protocol (tcp or udp).
		"protocol"?: string

		// Application protocol to use with the port (e.g., http, https, mysql).
		"app_protocol"?: string

		{[=~"^x-"]: _}
	}),
])]
¶

Expose container ports. Short format ([HOST:]CONTAINER[/PROTOCOL]).

[...]:
click to see definition
matchN(1, [
	number,
	string,
	close({
		// A human-readable name for this port mapping.
		"name"?: string

		// The port binding mode, either 'host' for publishing a host port or 'ingress' for load balancing.
		"mode"?: string

		// The host IP to bind to.
		"host_ip"?: string

		// The port inside the container.
		"target"?: int | string

		// The publicly exposed port.
		"published"?: int | string

		// The port protocol (tcp or udp).
		"protocol"?: string

		// Application protocol to use with the port (e.g., http, https, mysql).
		"app_protocol"?: string

		{[=~"^x-"]: _}
	}),
])
"pre_start"?: [...#pre_start_hook] ¶

Init containers to run to completion before the service container is started. Each step runs in its own ephemeral container, in declared order; a non-zero exit fails the bring-up of the service and its dependents.

[...]: #pre_start_hook
"command"?: #command

Command to execute. Optional when the chosen image's entrypoint already runs the intended command.

"image"?: string

Image used for the ephemeral container. If omitted, the parent service's image is used.

"user"?: string

User to run the command as. Defaults to the user declared in image (or to the service's user when image is omitted).

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command. Defaults to the service's working directory.

"environment"?: #list_or_dict

Environment variables for the command. Appended to or overriding the service environment.

"per_replica"?: bool | string

Whether the hook runs once per service replica (true), or once for the service as a whole before any replica starts (false, the default).

[=~"^x-"]: _
"post_start"?: [...#service_hook] ¶

Commands to run after the container starts. If any command fails, the container stops.

[...]: #service_hook
"command"!: #command

Command to execute as part of the hook.

"user"?: string

User to run the command as.

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command.

"environment"?: #list_or_dict

Environment variables for the command.

[=~"^x-"]: _
"pre_stop"?: [...#service_hook] ¶

Commands to run before the container stops. If any command fails, the container stop is aborted.

[...]: #service_hook
"command"!: #command

Command to execute as part of the hook.

"user"?: string

User to run the command as.

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command.

"environment"?: #list_or_dict

Environment variables for the command.

[=~"^x-"]: _
"privileged"?: bool | string ¶

Give extended privileges to the service container.

"profiles"?: #list_of_strings ¶

List of profiles for this service. When profiles are specified, services are only started when the profile is activated.

"pull_policy"?: =~"always|never|build|if_not_present|missing|refresh|daily|weekly|every_([0-9]+[wdhms])+" ¶

Policy for pulling images. Options include: 'always', 'never', 'if_not_present', 'missing', 'build', or time-based refresh policies.

"pull_refresh_after"?: string ¶

Time after which to refresh the image. Used with pull_policy=refresh.

"read_only"?: bool | string ¶

Mount the container's filesystem as read only.

"restart"?: string ¶

Restart policy for the service container. Options include: 'no', 'always', 'on-failure', and 'unless-stopped'.

"runtime"?: string ¶

Runtime to use for this container, e.g., 'runc'.

"scale"?: int | string ¶

Number of containers to deploy for this service.

"security_opt"?: list.UniqueItems() & [...string] ¶

Override the default labeling scheme for each container.

[...]: string
"shm_size"?: number | string ¶

Size of /dev/shm. A string value can use suffix like '2g' for 2 gigabytes.

"secrets"?: #service_config_or_secret ¶

Grant access to Secrets on a per-service basis.

"sysctls"?: #list_or_dict ¶

Kernel parameters to set in the container. You can use either an array or a list.

"stdin_open"?: bool | string ¶

Keep STDIN open even if not attached.

"stop_grace_period"?: string ¶

Time to wait for the container to stop gracefully before sending SIGKILL (e.g., '1s', '1m30s').

"stop_signal"?: string ¶

Signal to stop the container (e.g., 'SIGTERM', 'SIGINT').

"storage_opt"?: {...} ¶

Storage driver options for the container.

"tmpfs"?: #string_or_list ¶

Mount a temporary filesystem (tmpfs) into the container. Can be a single value or a list.

"tty"?: bool | string ¶

Allocate a pseudo-TTY to service container.

"ulimits"?: #ulimits ¶

Override the default ulimits for a container.

"use_api_socket"?: bool ¶

Bind mount Docker API socket and required auth.

"user"?: string ¶

Username or UID to run the container process as.

"uts"?: string ¶

UTS namespace to use. 'host' shares the host's UTS namespace.

"userns_mode"?: string ¶

User namespace to use. 'host' shares the host's user namespace.

"volumes"?:
click to see definition
list.UniqueItems() & [...matchN(1, [
	string,
	close({
		// The mount type: bind for mounting host directories, volume for named volumes,
		// tmpfs for temporary filesystems, cluster for cluster volumes, npipe for
		// named pipes, or image for mounting from an image.
		"type"!: "bind" | "volume" | "tmpfs" | "cluster" | "npipe" | "image"

		// The source of the mount, a path on the host for a bind mount, a docker image
		// reference for an image mount, or the name of a volume defined in the
		// top-level volumes key. Not applicable for a tmpfs mount.
		"source"?: string

		// The path in the container where the volume is mounted.
		"target"?: string

		// Flag to set the volume as read-only.
		"read_only"?: bool | string

		// The consistency requirements for the mount. Available values are platform specific.
		"consistency"?: string

		// Configuration specific to bind mounts.
		"bind"?: close({
			// The propagation mode for the bind mount: 'shared', 'slave', 'private',
			// 'rshared', 'rslave', or 'rprivate'.
			"propagation"?: string

			// Create the host path if it doesn't exist.
			"create_host_path"?: bool | string

			// Recursively mount the source directory.
			"recursive"?: "enabled" | "disabled" | "writable" | "readonly"

			// SELinux relabeling options: 'z' for shared content, 'Z' for private unshared content.
			"selinux"?: "z" | "Z"

			{[=~"^x-"]: _}
		})

		// Configuration specific to volume mounts.
		"volume"?: close({
			// Labels to apply to the volume.
			"labels"?: #list_or_dict

			// Flag to disable copying of data from a container when a volume is created.
			"nocopy"?: bool | string

			// Path within the volume to mount instead of the volume root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		// Configuration specific to tmpfs mounts.
		"tmpfs"?: close({
			// Size of the tmpfs mount in bytes.
			"size"?: matchN(1, [int & >=0, string])

			// File mode of the tmpfs in octal.
			"mode"?: number | string

			{[=~"^x-"]: _}
		})

		// Configuration specific to image mounts.
		"image"?: close({
			// Path within the image to mount instead of the image root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		{[=~"^x-"]: _}
	}),
])]
¶

Mount host paths or named volumes accessible to the container. Short syntax (VOLUME:CONTAINER_PATH[:MODE])

[...]:
click to see definition
matchN(1, [
	string,
	close({
		// The mount type: bind for mounting host directories, volume for named volumes,
		// tmpfs for temporary filesystems, cluster for cluster volumes, npipe for
		// named pipes, or image for mounting from an image.
		"type"!: "bind" | "volume" | "tmpfs" | "cluster" | "npipe" | "image"

		// The source of the mount, a path on the host for a bind mount, a docker image
		// reference for an image mount, or the name of a volume defined in the
		// top-level volumes key. Not applicable for a tmpfs mount.
		"source"?: string

		// The path in the container where the volume is mounted.
		"target"?: string

		// Flag to set the volume as read-only.
		"read_only"?: bool | string

		// The consistency requirements for the mount. Available values are platform specific.
		"consistency"?: string

		// Configuration specific to bind mounts.
		"bind"?: close({
			// The propagation mode for the bind mount: 'shared', 'slave', 'private',
			// 'rshared', 'rslave', or 'rprivate'.
			"propagation"?: string

			// Create the host path if it doesn't exist.
			"create_host_path"?: bool | string

			// Recursively mount the source directory.
			"recursive"?: "enabled" | "disabled" | "writable" | "readonly"

			// SELinux relabeling options: 'z' for shared content, 'Z' for private unshared content.
			"selinux"?: "z" | "Z"

			{[=~"^x-"]: _}
		})

		// Configuration specific to volume mounts.
		"volume"?: close({
			// Labels to apply to the volume.
			"labels"?: #list_or_dict

			// Flag to disable copying of data from a container when a volume is created.
			"nocopy"?: bool | string

			// Path within the volume to mount instead of the volume root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		// Configuration specific to tmpfs mounts.
		"tmpfs"?: close({
			// Size of the tmpfs mount in bytes.
			"size"?: matchN(1, [int & >=0, string])

			// File mode of the tmpfs in octal.
			"mode"?: number | string

			{[=~"^x-"]: _}
		})

		// Configuration specific to image mounts.
		"image"?: close({
			// Path within the image to mount instead of the image root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		{[=~"^x-"]: _}
	}),
])
"volumes_from"?: list.UniqueItems() & [...string] ¶

Mount volumes from another service or container. Optionally specify read-only access (ro) or read-write (rw).

[...]: string
"working_dir"?: string ¶

The working directory in which the entrypoint or command will be run

[=~"^x-"]: _ ¶
"models"?: ¶

Language models that will be used by your application.

[=~"^[a-zA-Z0-9._-]+$"]: #model ¶
"name"?: string ¶

Custom name for this model.

"model"!: string ¶

Language Model to run.

"context_size"?: int ¶
"runtime_flags"?: [...string] ¶

Raw runtime flags to pass to the inference engine.

[...]: string
[=~"^x-"]: _ ¶
"networks"?: ¶

Networks that are shared among multiple services.

[=~"^[a-zA-Z0-9._-]+$"]: #network ¶
"name"?: string ¶

Custom name for this network.

"driver"?: string ¶

Specify which driver should be used for this network. Default is 'bridge'.

"driver_opts"?: ¶

Specify driver-specific options defined as key/value pairs.

[=~"^.+$"]: number | string
"ipam"?: ¶

Custom IP Address Management configuration for this network.

"driver"?: string ¶

Custom IPAM driver, instead of the default.

"config"?:
click to see definition
[...close({
	// Subnet in CIDR format that represents a network segment.
	"subnet"?: string

	// Range of IPs from which to allocate container IPs.
	"ip_range"?: string

	// IPv4 or IPv6 gateway for the subnet.
	"gateway"?: string

	// Auxiliary IPv4 or IPv6 addresses used by Network driver.
	"aux_addresses"?: close({

		{[=~"^.+$"]: string}})

	{[=~"^x-"]: _}
})]
¶

List of IPAM configuration blocks.

[...]:
"subnet"?: string

Subnet in CIDR format that represents a network segment.

"ip_range"?: string

Range of IPs from which to allocate container IPs.

"gateway"?: string

IPv4 or IPv6 gateway for the subnet.

"aux_addresses"?:

Auxiliary IPv4 or IPv6 addresses used by Network driver.

[=~"^.+$"]: string
[=~"^x-"]: _
"options"?: ¶

Driver-specific options for the IPAM driver.

[=~"^.+$"]: string
[=~"^x-"]: _ ¶
"external"?:
click to see definition
bool |
	string |
	close({
		// Specifies the name of the external network. Deprecated: use the 'name' property instead.
		"name"?: string @deprecated()

		{[=~"^x-"]: _}
	})
¶

Specifies that this network already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external network. Deprecated: use the 'name' property instead.

[=~"^x-"]: _ ¶
"internal"?: bool | string ¶

Create an externally isolated network.

"enable_ipv4"?: bool | string ¶

Enable IPv4 networking.

"enable_ipv6"?: bool | string ¶

Enable IPv6 networking.

"attachable"?: bool | string ¶

If true, standalone containers can attach to this network.

"labels"?: #list_or_dict ¶

Add metadata to the network using labels.

[=~"^x-"]: _ ¶
"volumes"?: ¶

Named volumes that are shared among multiple services.

[=~"^[a-zA-Z0-9._-]+$"]: #volume ¶
"name"?: string ¶

Custom name for this volume.

"driver"?: string ¶

Specify which volume driver should be used for this volume.

"driver_opts"?: ¶

Specify driver-specific options.

[=~"^.+$"]: number | string
"external"?:
click to see definition
bool |
	string |
	close({
		// Specifies the name of the external volume. Deprecated: use the 'name' property instead.
		"name"?: string @deprecated()

		{[=~"^x-"]: _}
	})
¶

Specifies that this volume already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external volume. Deprecated: use the 'name' property instead.

[=~"^x-"]: _ ¶
"labels"?: #list_or_dict ¶

Add metadata to the volume using labels.

[=~"^x-"]: _ ¶
"secrets"?: ¶

Secrets that are shared among multiple services.

[=~"^[a-zA-Z0-9._-]+$"]: #secret ¶
"name"?: string ¶

Custom name for this secret.

"environment"?: string ¶

Name of an environment variable from which to get the secret value.

"file"?: string ¶

Path to a file containing the secret value.

"external"?:
click to see definition
bool | string | {
	// Specifies the name of the external secret.
	"name"?: string
	...
}
¶

Specifies that this secret already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external secret.

"labels"?: #list_or_dict ¶

Add metadata to the secret using labels.

"driver"?: string ¶

Specify which secret driver should be used for this secret.

"driver_opts"?: ¶

Specify driver-specific options.

[=~"^.+$"]: number | string
"template_driver"?: string ¶

Driver to use for templating the secret's value.

[=~"^x-"]: _ ¶
"configs"?: ¶

Configurations that are shared among multiple services.

[=~"^[a-zA-Z0-9._-]+$"]: #config ¶
"name"?: string ¶

Custom name for this config.

"content"?: string ¶

Inline content of the config.

"environment"?: string ¶

Name of an environment variable from which to get the config value.

"file"?: string ¶

Path to a file containing the config value.

"external"?:
click to see definition
bool | string | {
	// Specifies the name of the external config. Deprecated: use the 'name' property instead.
	"name"?: string @deprecated()
	...
}
¶

Specifies that this config already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external config. Deprecated: use the 'name' property instead.

"labels"?: #list_or_dict ¶

Add metadata to the config using labels.

"template_driver"?: string ¶

Driver to use for templating the config's value.

[=~"^x-"]: _ ¶
[=~"^x-"]: _ ¶
#blkio_limit: ¶

Block IO limit for a specific device.

"path"?: string ¶

Path to the device (e.g., '/dev/sda').

"rate"?: int | string ¶

Rate limit in bytes per second or IO operations per second.

#blkio_weight: ¶

Block IO weight for a specific device.

"path"?: string ¶

Path to the device (e.g., '/dev/sda').

"weight"?: int | string ¶

Relative weight for the device, between 10 and 1000.

#command: matchN(1, [null, string, [...string]]) ¶

Command to run in the container, which can be specified as a string (shell form) or array (exec form).

#config: ¶

Config configuration for the Compose application.

"name"?: string ¶

Custom name for this config.

"content"?: string ¶

Inline content of the config.

"environment"?: string ¶

Name of an environment variable from which to get the config value.

"file"?: string ¶

Path to a file containing the config value.

"external"?:
click to see definition
bool | string | {
	// Specifies the name of the external config. Deprecated: use the 'name' property instead.
	"name"?: string @deprecated()
	...
}
¶

Specifies that this config already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external config. Deprecated: use the 'name' property instead.

"labels"?: #list_or_dict ¶

Add metadata to the config using labels.

"template_driver"?: string ¶

Driver to use for templating the config's value.

[=~"^x-"]: _ ¶
#deployment:
click to see definition
null | close({
	// Deployment mode for the service: 'replicated' (default) or 'global'.
	"mode"?: string

	// Endpoint mode for the service: 'vip' (default) or 'dnsrr'.
	"endpoint_mode"?: string

	// Number of replicas of the service container to run.
	"replicas"?: int | string

	// Labels to apply to the service.
	"labels"?: #list_or_dict

	// Configuration for rolling back a service update.
	"rollback_config"?: close({
		// The number of containers to rollback at a time. If set to 0, all containers
		// rollback simultaneously.
		"parallelism"?: int | string

		// The time to wait between each container group's rollback (e.g., '1s', '1m30s').
		"delay"?: string

		// Action to take if a rollback fails: 'continue', 'pause'.
		"failure_action"?: string

		// Duration to monitor each task for failures after it is created (e.g., '1s', '1m30s').
		"monitor"?: string

		// Failure rate to tolerate during a rollback.
		"max_failure_ratio"?: number | string

		// Order of operations during rollbacks: 'stop-first' (default) or 'start-first'.
		"order"?: "start-first" | "stop-first"

		{[=~"^x-"]: _}
	})

	// Configuration for updating a service.
	"update_config"?: close({
		// The number of containers to update at a time.
		"parallelism"?: int | string

		// The time to wait between updating a group of containers (e.g., '1s', '1m30s').
		"delay"?: string

		// Action to take if an update fails: 'continue', 'pause', 'rollback'.
		"failure_action"?: string

		// Duration to monitor each updated task for failures after it is created (e.g., '1s', '1m30s').
		"monitor"?: string

		// Failure rate to tolerate during an update (0 to 1).
		"max_failure_ratio"?: number | string

		// Order of operations during updates: 'stop-first' (default) or 'start-first'.
		"order"?: "start-first" | "stop-first"

		{[=~"^x-"]: _}
	})

	// Resource constraints and reservations for the service.
	"resources"?: close({
		// Resource limits for the service containers.
		"limits"?: close({
			// Limit for how much of the available CPU resources, as number of cores, a container can use.
			"cpus"?: number | string

			// Limit on the amount of memory a container can allocate (e.g., '1g', '1024m').
			"memory"?: string

			// Maximum number of PIDs available to the container.
			"pids"?: int | string

			{[=~"^x-"]: _}
		})

		// Resource reservations for the service containers.
		"reservations"?: close({
			// Reservation for how much of the available CPU resources, as number of cores, a container can use.
			"cpus"?: number | string

			// Reservation on the amount of memory a container can allocate (e.g., '1g', '1024m').
			"memory"?: string

			// User-defined resources to reserve.
			"generic_resources"?: #generic_resources

			// Device reservations for the container.
			"devices"?: #devices

			{[=~"^x-"]: _}
		})

		{[=~"^x-"]: _}
	})

	// Restart policy for the service containers.
	"restart_policy"?: close({
		// Condition for restarting the container: 'none', 'on-failure', 'any'.
		"condition"?: string

		// Delay between restart attempts (e.g., '1s', '1m30s').
		"delay"?: string

		// Maximum number of restart attempts before giving up.
		"max_attempts"?: int | string

		// Time window used to evaluate the restart policy (e.g., '1s', '1m30s').
		"window"?: string

		{[=~"^x-"]: _}
	})

	// Constraints and preferences for the platform to select a physical node to run service containers
	"placement"?: close({
		// Placement constraints for the service (e.g., 'node.role==manager').
		"constraints"?: [...string]

		// Placement preferences for the service.
		"preferences"?: [...close({
			// Spread tasks evenly across values of the specified node label.
			"spread"?: string

			{[=~"^x-"]: _}
		})]

		// Maximum number of replicas of the service.
		"max_replicas_per_node"?: int | string

		{[=~"^x-"]: _}
	})

	{[=~"^x-"]: _}
})
¶

Deployment configuration for the service.

"mode"?: string ¶

Deployment mode for the service: 'replicated' (default) or 'global'.

"endpoint_mode"?: string ¶

Endpoint mode for the service: 'vip' (default) or 'dnsrr'.

"replicas"?: int | string ¶

Number of replicas of the service container to run.

"labels"?: #list_or_dict ¶

Labels to apply to the service.

"rollback_config"?: ¶

Configuration for rolling back a service update.

"parallelism"?: int | string ¶

The number of containers to rollback at a time. If set to 0, all containers rollback simultaneously.

"delay"?: string ¶

The time to wait between each container group's rollback (e.g., '1s', '1m30s').

"failure_action"?: string ¶

Action to take if a rollback fails: 'continue', 'pause'.

"monitor"?: string ¶

Duration to monitor each task for failures after it is created (e.g., '1s', '1m30s').

"max_failure_ratio"?: number | string ¶

Failure rate to tolerate during a rollback.

"order"?: "start-first" | "stop-first" ¶

Order of operations during rollbacks: 'stop-first' (default) or 'start-first'.

[=~"^x-"]: _ ¶
"update_config"?: ¶

Configuration for updating a service.

"parallelism"?: int | string ¶

The number of containers to update at a time.

"delay"?: string ¶

The time to wait between updating a group of containers (e.g., '1s', '1m30s').

"failure_action"?: string ¶

Action to take if an update fails: 'continue', 'pause', 'rollback'.

"monitor"?: string ¶

Duration to monitor each updated task for failures after it is created (e.g., '1s', '1m30s').

"max_failure_ratio"?: number | string ¶

Failure rate to tolerate during an update (0 to 1).

"order"?: "start-first" | "stop-first" ¶

Order of operations during updates: 'stop-first' (default) or 'start-first'.

[=~"^x-"]: _ ¶
"resources"?: ¶

Resource constraints and reservations for the service.

"limits"?: ¶

Resource limits for the service containers.

"cpus"?: number | string ¶

Limit for how much of the available CPU resources, as number of cores, a container can use.

"memory"?: string ¶

Limit on the amount of memory a container can allocate (e.g., '1g', '1024m').

"pids"?: int | string ¶

Maximum number of PIDs available to the container.

[=~"^x-"]: _ ¶
"reservations"?: ¶

Resource reservations for the service containers.

"cpus"?: number | string ¶

Reservation for how much of the available CPU resources, as number of cores, a container can use.

"memory"?: string ¶

Reservation on the amount of memory a container can allocate (e.g., '1g', '1024m').

"generic_resources"?: #generic_resources ¶

User-defined resources to reserve.

"devices"?: #devices ¶

Device reservations for the container.

[=~"^x-"]: _ ¶
[=~"^x-"]: _ ¶
"restart_policy"?: ¶

Restart policy for the service containers.

"condition"?: string ¶

Condition for restarting the container: 'none', 'on-failure', 'any'.

"delay"?: string ¶

Delay between restart attempts (e.g., '1s', '1m30s').

"max_attempts"?: int | string ¶

Maximum number of restart attempts before giving up.

"window"?: string ¶

Time window used to evaluate the restart policy (e.g., '1s', '1m30s').

[=~"^x-"]: _ ¶
"placement"?: ¶

Constraints and preferences for the platform to select a physical node to run service containers

"constraints"?: [...string] ¶

Placement constraints for the service (e.g., 'node.role==manager').

[...]: string
"preferences"?:
click to see definition
[...close({
	// Spread tasks evenly across values of the specified node label.
	"spread"?: string

	{[=~"^x-"]: _}
})]
¶

Placement preferences for the service.

[...]:
"spread"?: string

Spread tasks evenly across values of the specified node label.

[=~"^x-"]: _
"max_replicas_per_node"?: int | string ¶

Maximum number of replicas of the service.

[=~"^x-"]: _ ¶
[=~"^x-"]: _ ¶
#development:
click to see definition
null | close({
	// Configure watch mode for the service, which monitors file changes and
	// performs actions in response.
	"watch"?: [...close({
		// Patterns to exclude from watching.
		"ignore"?: #string_or_list

		// Patterns to include in watching.
		"include"?: #string_or_list

		// Path to watch for changes.
		"path"!: string

		// Action to take when a change is detected: rebuild the container, sync files,
		// restart the container, sync and restart, or sync and execute a command.
		"action"!: "rebuild" | "sync" | "restart" | "sync+restart" | "sync+exec"

		// Target path in the container for sync operations.
		"target"?: string

		// Command to execute when a change is detected and action is sync+exec.
		"exec"?: #service_hook

		// Ensure that an initial synchronization is done before starting watch mode for sync+x triggers
		"initial_sync"?: bool

		{[=~"^x-"]: _}
	})]

	{[=~"^x-"]: _}
})
¶

Development configuration for the service, used for development workflows.

"watch"?:
click to see definition
[...close({
	// Patterns to exclude from watching.
	"ignore"?: #string_or_list

	// Patterns to include in watching.
	"include"?: #string_or_list

	// Path to watch for changes.
	"path"!: string

	// Action to take when a change is detected: rebuild the container, sync files,
	// restart the container, sync and restart, or sync and execute a command.
	"action"!: "rebuild" | "sync" | "restart" | "sync+restart" | "sync+exec"

	// Target path in the container for sync operations.
	"target"?: string

	// Command to execute when a change is detected and action is sync+exec.
	"exec"?: #service_hook

	// Ensure that an initial synchronization is done before starting watch mode for sync+x triggers
	"initial_sync"?: bool

	{[=~"^x-"]: _}
})]
¶

Configure watch mode for the service, which monitors file changes and performs actions in response.

[...]:
"ignore"?: #string_or_list

Patterns to exclude from watching.

"include"?: #string_or_list

Patterns to include in watching.

"path"!: string

Path to watch for changes.

"action"!: "rebuild" | "sync" | "restart" | "sync+restart" | "sync+exec"

Action to take when a change is detected: rebuild the container, sync files, restart the container, sync and restart, or sync and execute a command.

"target"?: string

Target path in the container for sync operations.

"exec"?: #service_hook

Command to execute when a change is detected and action is sync+exec.

"command"!: #command

Command to execute as part of the hook.

"user"?: string

User to run the command as.

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command.

"environment"?: #list_or_dict

Environment variables for the command.

[=~"^x-"]: _
"initial_sync"?: bool

Ensure that an initial synchronization is done before starting watch mode for sync+x triggers

[=~"^x-"]: _
[=~"^x-"]: _ ¶
#devices:
click to see definition
[...close({
	// List of capabilities the device needs to have (e.g., 'gpu', 'compute', 'utility').
	"capabilities"!: #list_of_strings

	// Number of devices of this type to reserve.
	"count"?: int | string

	// List of specific device IDs to reserve.
	"device_ids"?: #list_of_strings

	// Device driver to use (e.g., 'nvidia').
	"driver"?: string

	// Driver-specific options for the device.
	"options"?: #list_or_dict

	{[=~"^x-"]: _}
})]
¶

Device reservations for containers, allowing services to access specific hardware devices.

[...]:
"capabilities"!: #list_of_strings

List of capabilities the device needs to have (e.g., 'gpu', 'compute', 'utility').

"count"?: int | string

Number of devices of this type to reserve.

"device_ids"?: #list_of_strings

List of specific device IDs to reserve.

"driver"?: string

Device driver to use (e.g., 'nvidia').

"options"?: #list_or_dict

Driver-specific options for the device.

[=~"^x-"]: _
#env_file:
click to see definition
matchN(1, [
	string,
	[...matchN(1, [
		string,
		close({
			// Path to the environment file.
			"path"!: string

			// Format attribute lets you to use an alternative file formats for env_file.
			// When not set, env_file is parsed according to Compose rules.
			"format"?: string

			// Whether the file is required. If true and the file doesn't exist, an error will be raised.
			"required"?: bool | string
		}),
	])],
])
¶
#extra_hosts: matchN(1, [close({{[=~".+"]: matchN(1, [string, [...string]])}}), list.UniqueItems() & [...string]]) ¶

Additional hostnames to be defined in the container's /etc/hosts file.

#generic_resources:
click to see definition
[...close({
	// Specification for discrete (countable) resources.
	"discrete_resource_spec"?: close({
		// Type of resource (e.g., 'GPU', 'FPGA', 'SSD').
		"kind"?: string

		// Number of resources of this kind to reserve.
		"value"?: number | string

		{[=~"^x-"]: _}
	})

	{[=~"^x-"]: _}
})]
¶

User-defined resources for services, allowing services to reserve specialized hardware resources.

[...]:
"discrete_resource_spec"?:

Specification for discrete (countable) resources.

"kind"?: string

Type of resource (e.g., 'GPU', 'FPGA', 'SSD').

"value"?: number | string

Number of resources of this kind to reserve.

[=~"^x-"]: _
[=~"^x-"]: _
#gpus:
click to see definition
matchN(1, [
	"all",
	[...{
		// List of capabilities the GPU needs to have (e.g., 'compute', 'utility').
		"capabilities"?: #list_of_strings

		// Number of GPUs to use.
		"count"?: int | string

		// List of specific GPU device IDs to use.
		"device_ids"?: #list_of_strings

		// GPU driver to use (e.g., 'nvidia').
		"driver"?: string

		// Driver-specific options for the GPU.
		"options"?: #list_or_dict
		...
	}],
])
¶
#healthcheck: ¶

Configuration options to determine whether the container is healthy.

"disable"?: bool | string ¶

Disable any container-specified healthcheck. Set to true to disable.

"interval"?: string ¶

Time between running the check (e.g., '1s', '1m30s'). Default: 30s.

"retries"?: number | string ¶

Number of consecutive failures needed to consider the container as unhealthy. Default: 3.

"test"?: matchN(1, [string, [...string]]) ¶

The test to perform to check container health. Can be a string or a list. The first item is either NONE, CMD, or CMD-SHELL. If it's CMD, the rest of the command is exec'd. If it's CMD-SHELL, the rest is run in the shell.

"timeout"?: string ¶

Maximum time to allow one check to run (e.g., '1s', '1m30s'). Default: 30s.

"start_period"?: string ¶

Start period for the container to initialize before starting health-retries countdown (e.g., '1s', '1m30s'). Default: 0s.

"start_interval"?: string ¶

Time between running the check during the start period (e.g., '1s', '1m30s'). Default: interval value.

[=~"^x-"]: _ ¶
#include:
click to see definition
matchN(1, [
	string,
	close({
		// Path to the Compose application or sub-project files to include.
		"path"?: #string_or_list

		// Path to the environment files to use to define default values when
		// interpolating variables in the Compose files being parsed.
		"env_file"?: #string_or_list

		// Path to resolve relative paths set in the Compose file
		"project_directory"?: string
	}),
])
¶

Compose application or sub-projects to be included.

#label_file: matchN(1, [string, [...string]]) ¶
#list_of_strings: list.UniqueItems() & [...string] ¶

A list of unique string values.

[...]: string
#list_or_dict: matchN(1, [close({{[=~".+"]: null | bool | number | string}}), list.UniqueItems() & [...string]]) ¶

Either a dictionary mapping keys to values, or a list of strings.

#model: ¶

Language Model for the Compose application.

"name"?: string ¶

Custom name for this model.

"model"!: string ¶

Language Model to run.

"context_size"?: int ¶
"runtime_flags"?: [...string] ¶

Raw runtime flags to pass to the inference engine.

[...]: string
[=~"^x-"]: _ ¶
#network:
click to see definition
null | close({
	// Custom name for this network.
	"name"?: string

	// Specify which driver should be used for this network. Default is 'bridge'.
	"driver"?: string

	// Specify driver-specific options defined as key/value pairs.
	"driver_opts"?: {
		{[=~"^.+$"]: number | string}
		...
	}

	// Custom IP Address Management configuration for this network.
	"ipam"?: close({
		// Custom IPAM driver, instead of the default.
		"driver"?: string

		// List of IPAM configuration blocks.
		"config"?: [...close({
			// Subnet in CIDR format that represents a network segment.
			"subnet"?: string

			// Range of IPs from which to allocate container IPs.
			"ip_range"?: string

			// IPv4 or IPv6 gateway for the subnet.
			"gateway"?: string

			// Auxiliary IPv4 or IPv6 addresses used by Network driver.
			"aux_addresses"?: close({

				{[=~"^.+$"]: string}})

			{[=~"^x-"]: _}
		})]

		// Driver-specific options for the IPAM driver.
		"options"?: close({

			{[=~"^.+$"]: string}})

		{[=~"^x-"]: _}
	})

	// Specifies that this network already exists and was created outside of Compose.
	"external"?: bool |
		string |
		close({
			// Specifies the name of the external network. Deprecated: use the 'name' property instead.
			"name"?: string @deprecated()

			{[=~"^x-"]: _}
		})

	// Create an externally isolated network.
	"internal"?: bool | string

	// Enable IPv4 networking.
	"enable_ipv4"?: bool | string

	// Enable IPv6 networking.
	"enable_ipv6"?: bool | string

	// If true, standalone containers can attach to this network.
	"attachable"?: bool | string

	// Add metadata to the network using labels.
	"labels"?: #list_or_dict

	{[=~"^x-"]: _}
})
¶

Network configuration for the Compose application.

"name"?: string ¶

Custom name for this network.

"driver"?: string ¶

Specify which driver should be used for this network. Default is 'bridge'.

"driver_opts"?: ¶

Specify driver-specific options defined as key/value pairs.

[=~"^.+$"]: number | string
"ipam"?: ¶

Custom IP Address Management configuration for this network.

"driver"?: string ¶

Custom IPAM driver, instead of the default.

"config"?:
click to see definition
[...close({
	// Subnet in CIDR format that represents a network segment.
	"subnet"?: string

	// Range of IPs from which to allocate container IPs.
	"ip_range"?: string

	// IPv4 or IPv6 gateway for the subnet.
	"gateway"?: string

	// Auxiliary IPv4 or IPv6 addresses used by Network driver.
	"aux_addresses"?: close({

		{[=~"^.+$"]: string}})

	{[=~"^x-"]: _}
})]
¶

List of IPAM configuration blocks.

[...]:
"subnet"?: string

Subnet in CIDR format that represents a network segment.

"ip_range"?: string

Range of IPs from which to allocate container IPs.

"gateway"?: string

IPv4 or IPv6 gateway for the subnet.

"aux_addresses"?:

Auxiliary IPv4 or IPv6 addresses used by Network driver.

[=~"^.+$"]: string
[=~"^x-"]: _
"options"?: ¶

Driver-specific options for the IPAM driver.

[=~"^.+$"]: string
[=~"^x-"]: _ ¶
"external"?:
click to see definition
bool |
	string |
	close({
		// Specifies the name of the external network. Deprecated: use the 'name' property instead.
		"name"?: string @deprecated()

		{[=~"^x-"]: _}
	})
¶

Specifies that this network already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external network. Deprecated: use the 'name' property instead.

[=~"^x-"]: _ ¶
"internal"?: bool | string ¶

Create an externally isolated network.

"enable_ipv4"?: bool | string ¶

Enable IPv4 networking.

"enable_ipv6"?: bool | string ¶

Enable IPv6 networking.

"attachable"?: bool | string ¶

If true, standalone containers can attach to this network.

"labels"?: #list_or_dict ¶

Add metadata to the network using labels.

[=~"^x-"]: _ ¶
#pre_start_hook: ¶

Configuration for a pre_start init container, run to completion before the service container starts.

"command"?: #command ¶

Command to execute. Optional when the chosen image's entrypoint already runs the intended command.

"image"?: string ¶

Image used for the ephemeral container. If omitted, the parent service's image is used.

"user"?: string ¶

User to run the command as. Defaults to the user declared in image (or to the service's user when image is omitted).

"privileged"?: bool | string ¶

Whether to run the command with extended privileges.

"working_dir"?: string ¶

Working directory for the command. Defaults to the service's working directory.

"environment"?: #list_or_dict ¶

Environment variables for the command. Appended to or overriding the service environment.

"per_replica"?: bool | string ¶

Whether the hook runs once per service replica (true), or once for the service as a whole before any replica starts (false, the default).

[=~"^x-"]: _ ¶
#secret: ¶

Secret configuration for the Compose application.

"name"?: string ¶

Custom name for this secret.

"environment"?: string ¶

Name of an environment variable from which to get the secret value.

"file"?: string ¶

Path to a file containing the secret value.

"external"?:
click to see definition
bool | string | {
	// Specifies the name of the external secret.
	"name"?: string
	...
}
¶

Specifies that this secret already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external secret.

"labels"?: #list_or_dict ¶

Add metadata to the secret using labels.

"driver"?: string ¶

Specify which secret driver should be used for this secret.

"driver_opts"?: ¶

Specify driver-specific options.

[=~"^.+$"]: number | string
"template_driver"?: string ¶

Driver to use for templating the secret's value.

[=~"^x-"]: _ ¶
#service: ¶

Configuration for a service.

"develop"?: #development ¶
"watch"?:
click to see definition
[...close({
	// Patterns to exclude from watching.
	"ignore"?: #string_or_list

	// Patterns to include in watching.
	"include"?: #string_or_list

	// Path to watch for changes.
	"path"!: string

	// Action to take when a change is detected: rebuild the container, sync files,
	// restart the container, sync and restart, or sync and execute a command.
	"action"!: "rebuild" | "sync" | "restart" | "sync+restart" | "sync+exec"

	// Target path in the container for sync operations.
	"target"?: string

	// Command to execute when a change is detected and action is sync+exec.
	"exec"?: #service_hook

	// Ensure that an initial synchronization is done before starting watch mode for sync+x triggers
	"initial_sync"?: bool

	{[=~"^x-"]: _}
})]
¶

Configure watch mode for the service, which monitors file changes and performs actions in response.

[...]:
"ignore"?: #string_or_list

Patterns to exclude from watching.

"include"?: #string_or_list

Patterns to include in watching.

"path"!: string

Path to watch for changes.

"action"!: "rebuild" | "sync" | "restart" | "sync+restart" | "sync+exec"

Action to take when a change is detected: rebuild the container, sync files, restart the container, sync and restart, or sync and execute a command.

"target"?: string

Target path in the container for sync operations.

"exec"?: #service_hook

Command to execute when a change is detected and action is sync+exec.

"command"!: #command

Command to execute as part of the hook.

"user"?: string

User to run the command as.

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command.

"environment"?: #list_or_dict

Environment variables for the command.

[=~"^x-"]: _
"initial_sync"?: bool

Ensure that an initial synchronization is done before starting watch mode for sync+x triggers

[=~"^x-"]: _
[=~"^x-"]: _ ¶
"deploy"?: #deployment ¶
"mode"?: string ¶

Deployment mode for the service: 'replicated' (default) or 'global'.

"endpoint_mode"?: string ¶

Endpoint mode for the service: 'vip' (default) or 'dnsrr'.

"replicas"?: int | string ¶

Number of replicas of the service container to run.

"labels"?: #list_or_dict ¶

Labels to apply to the service.

"rollback_config"?: ¶

Configuration for rolling back a service update.

"parallelism"?: int | string ¶

The number of containers to rollback at a time. If set to 0, all containers rollback simultaneously.

"delay"?: string ¶

The time to wait between each container group's rollback (e.g., '1s', '1m30s').

"failure_action"?: string ¶

Action to take if a rollback fails: 'continue', 'pause'.

"monitor"?: string ¶

Duration to monitor each task for failures after it is created (e.g., '1s', '1m30s').

"max_failure_ratio"?: number | string ¶

Failure rate to tolerate during a rollback.

"order"?: "start-first" | "stop-first" ¶

Order of operations during rollbacks: 'stop-first' (default) or 'start-first'.

[=~"^x-"]: _ ¶
"update_config"?: ¶

Configuration for updating a service.

"parallelism"?: int | string ¶

The number of containers to update at a time.

"delay"?: string ¶

The time to wait between updating a group of containers (e.g., '1s', '1m30s').

"failure_action"?: string ¶

Action to take if an update fails: 'continue', 'pause', 'rollback'.

"monitor"?: string ¶

Duration to monitor each updated task for failures after it is created (e.g., '1s', '1m30s').

"max_failure_ratio"?: number | string ¶

Failure rate to tolerate during an update (0 to 1).

"order"?: "start-first" | "stop-first" ¶

Order of operations during updates: 'stop-first' (default) or 'start-first'.

[=~"^x-"]: _ ¶
"resources"?: ¶

Resource constraints and reservations for the service.

"limits"?: ¶

Resource limits for the service containers.

"cpus"?: number | string ¶

Limit for how much of the available CPU resources, as number of cores, a container can use.

"memory"?: string ¶

Limit on the amount of memory a container can allocate (e.g., '1g', '1024m').

"pids"?: int | string ¶

Maximum number of PIDs available to the container.

[=~"^x-"]: _ ¶
"reservations"?: ¶

Resource reservations for the service containers.

"cpus"?: number | string ¶

Reservation for how much of the available CPU resources, as number of cores, a container can use.

"memory"?: string ¶

Reservation on the amount of memory a container can allocate (e.g., '1g', '1024m').

"generic_resources"?: #generic_resources ¶

User-defined resources to reserve.

"devices"?: #devices ¶

Device reservations for the container.

[=~"^x-"]: _ ¶
[=~"^x-"]: _ ¶
"restart_policy"?: ¶

Restart policy for the service containers.

"condition"?: string ¶

Condition for restarting the container: 'none', 'on-failure', 'any'.

"delay"?: string ¶

Delay between restart attempts (e.g., '1s', '1m30s').

"max_attempts"?: int | string ¶

Maximum number of restart attempts before giving up.

"window"?: string ¶

Time window used to evaluate the restart policy (e.g., '1s', '1m30s').

[=~"^x-"]: _ ¶
"placement"?: ¶

Constraints and preferences for the platform to select a physical node to run service containers

"constraints"?: [...string] ¶

Placement constraints for the service (e.g., 'node.role==manager').

[...]: string
"preferences"?:
click to see definition
[...close({
	// Spread tasks evenly across values of the specified node label.
	"spread"?: string

	{[=~"^x-"]: _}
})]
¶

Placement preferences for the service.

[...]:
"spread"?: string

Spread tasks evenly across values of the specified node label.

[=~"^x-"]: _
"max_replicas_per_node"?: int | string ¶

Maximum number of replicas of the service.

[=~"^x-"]: _ ¶
[=~"^x-"]: _ ¶
"annotations"?: #list_or_dict ¶
"attach"?: bool | string ¶
"build"?:
click to see definition
matchN(1, [
	string,
	close({
		// Path to the build context. Can be a relative path or a URL.
		"context"?: string

		// Name of the Dockerfile to use for building the image.
		"dockerfile"?: string

		// Inline Dockerfile content to use instead of a Dockerfile from the build context.
		"dockerfile_inline"?: string

		// List of extra privileged entitlements to grant to the build process.
		"entitlements"?: [...string]

		// Build-time variables, specified as a map or a list of KEY=VAL pairs.
		"args"?: #list_or_dict

		// SSH agent socket or keys to expose to the build. Format is either a string or
		// a list of 'default|<id>[=<socket>|<key>[,<key>]]'.
		"ssh"?: #list_or_dict

		// Labels to apply to the built image.
		"labels"?: #list_or_dict

		// List of sources the image builder should use for cache resolution
		"cache_from"?: [...string]

		// Cache destinations for the build cache.
		"cache_to"?: [...string]

		// Do not use cache when building the image.
		"no_cache"?: bool | string

		// Do not use build cache for the specified stages.
		"no_cache_filter"?: #string_or_list

		// Additional build contexts to use, specified as a map of name to context path or URL.
		"additional_contexts"?: #list_or_dict

		// Network mode to use for the build. Options include 'default', 'none', 'host', or a network name.
		"network"?: string

		// Add a provenance attestation
		"provenance"?: bool | string

		// Add a SBOM attestation
		"sbom"?: bool | string

		// Always attempt to pull a newer version of the image.
		"pull"?: bool | string

		// Build stage to target in a multi-stage Dockerfile.
		"target"?: string

		// Size of /dev/shm for the build container. A string value can use suffix like
		// '2g' for 2 gigabytes.
		"shm_size"?: int | string

		// Add hostname mappings for the build container.
		"extra_hosts"?: #extra_hosts

		// Container isolation technology to use for the build process.
		"isolation"?: string

		// Give extended privileges to the build container.
		"privileged"?: bool | string

		// Secrets to expose to the build. These are accessible at build-time.
		"secrets"?: #service_config_or_secret

		// Additional tags to apply to the built image.
		"tags"?: [...string]

		// Override the default ulimits for the build container.
		"ulimits"?: #ulimits

		// Platforms to build for, e.g., 'linux/amd64', 'linux/arm64', or 'windows/amd64'.
		"platforms"?: [...string]

		{[=~"^x-"]: _}
	}),
])
¶

Configuration options for building the service's image.

"blkio_config"?: ¶

Block IO configuration for the service.

"device_read_bps"?: [...#blkio_limit] ¶

Limit read rate (bytes per second) from a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"device_read_iops"?: [...#blkio_limit] ¶

Limit read rate (IO per second) from a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"device_write_bps"?: [...#blkio_limit] ¶

Limit write rate (bytes per second) to a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"device_write_iops"?: [...#blkio_limit] ¶

Limit write rate (IO per second) to a device.

[...]: #blkio_limit
"path"?: string

Path to the device (e.g., '/dev/sda').

"rate"?: int | string

Rate limit in bytes per second or IO operations per second.

"weight"?: int | string ¶

Block IO weight (relative weight) for the service, between 10 and 1000.

"weight_device"?: [...#blkio_weight] ¶

Block IO weight (relative weight) for specific devices.

[...]: #blkio_weight
"path"?: string

Path to the device (e.g., '/dev/sda').

"weight"?: int | string

Relative weight for the device, between 10 and 1000.

"cap_add"?: list.UniqueItems() & [...string] ¶

Add Linux capabilities. For example, 'CAP_SYS_ADMIN', 'SYS_ADMIN', or 'NET_ADMIN'.

[...]: string
"cap_drop"?: list.UniqueItems() & [...string] ¶

Drop Linux capabilities. For example, 'CAP_SYS_ADMIN', 'SYS_ADMIN', or 'NET_ADMIN'.

[...]: string
"cgroup"?: "host" | "private" ¶

Specify the cgroup namespace to join. Use 'host' to use the host's cgroup namespace, or 'private' to use a private cgroup namespace.

"cgroup_parent"?: string ¶

Specify an optional parent cgroup for the container.

"command"?: #command ¶

Override the default command declared by the container image, for example 'CMD' in Dockerfile.

"configs"?: #service_config_or_secret ¶

Grant access to Configs on a per-service basis.

"container_name"?: =~"[a-zA-Z0-9][a-zA-Z0-9_.-]+" ¶

Specify a custom container name, rather than a generated default name.

"cpu_count"?: matchN(1, [string, int & >=0]) ¶

Number of usable CPUs.

"cpu_percent"?: matchN(1, [string, int & >=0 & <=100]) ¶

Percentage of CPU resources to use.

"cpu_shares"?: number | string ¶

CPU shares (relative weight) for the container.

"cpu_quota"?: number | string ¶

Limit the CPU CFS (Completely Fair Scheduler) quota.

"cpu_period"?: number | string ¶

Limit the CPU CFS (Completely Fair Scheduler) period.

"cpu_rt_period"?: number | string ¶

Limit the CPU real-time period in microseconds or a duration.

"cpu_rt_runtime"?: number | string ¶

Limit the CPU real-time runtime in microseconds or a duration.

"cpus"?: number | string ¶

Number of CPUs to use. A floating-point value is supported to request partial CPUs.

"cpuset"?: string ¶

CPUs in which to allow execution (0-3, 0,1).

"credential_spec"?: ¶

Configure the credential spec for managed service account.

"config"?: string ¶

The name of the credential spec Config to use.

"file"?: string ¶

Path to a credential spec file.

"registry"?: string ¶

Path to a credential spec in the Windows registry.

[=~"^x-"]: _ ¶
"depends_on"?:
click to see definition
matchN(1, [
	#list_of_strings,
	close({

		{
			[=~"^[a-zA-Z0-9._-]+$"]: close({

				{[=~"^x-"]: _}

				// Whether to restart dependent services when this service is restarted.
				"restart"?: bool | string

				// Whether the dependency is required for the dependent service to start.
				"required"?: bool

				// Condition to wait for. 'service_started' waits until the service has started,
				// 'service_healthy' waits until the service is healthy (as defined by its
				// healthcheck), 'service_completed_successfully' waits until the service has
				// completed successfully.
				"condition"!: "service_started" | "service_healthy" | "service_completed_successfully"
			})
		}}),
])
¶

Express dependency between services. Service dependencies cause services to be started in dependency order. The dependent service will wait for the dependency to be ready before starting.

"device_cgroup_rules"?: #list_of_strings ¶

Add rules to the cgroup allowed devices list.

"devices"?:
click to see definition
[...matchN(1, [
	string,
	close({
		// Path on the host to the device.
		"source"!: string

		// Path in the container where the device will be mapped.
		"target"?: string

		// Cgroup permissions for the device (rwm).
		"permissions"?: string

		{[=~"^x-"]: _}
	}),
])]
¶

List of device mappings for the container.

[...]:
click to see definition
matchN(1, [
	string,
	close({
		// Path on the host to the device.
		"source"!: string

		// Path in the container where the device will be mapped.
		"target"?: string

		// Cgroup permissions for the device (rwm).
		"permissions"?: string

		{[=~"^x-"]: _}
	}),
])
"dns"?: #string_or_list ¶

Custom DNS servers to set for the service container.

"dns_opt"?: list.UniqueItems() & [...string] ¶

Custom DNS options to be passed to the container's DNS resolver.

[...]: string
"dns_search"?: #string_or_list ¶

Custom DNS search domains to set on the service container.

"domainname"?: string ¶

Custom domain name to use for the service container.

"entrypoint"?: #command ¶

Override the default entrypoint declared by the container image, for example 'ENTRYPOINT' in Dockerfile.

"env_file"?: #env_file ¶

Add environment variables from a file or multiple files. Can be a single file path or a list of file paths.

"label_file"?: #label_file ¶

Add metadata to containers using files containing Docker labels.

"environment"?: #list_or_dict ¶

Add environment variables. You can use either an array or a list of KEY=VAL pairs.

"expose"?: list.UniqueItems() & [...number | string] ¶

Expose ports without publishing them to the host machine - they'll only be accessible to linked services.

[...]: number | string
"extends"?:
click to see definition
matchN(1, [
	string,
	close({
		// The name of the service to extend.
		"service"!: string

		// The file path where the service to extend is defined.
		"file"?: string
	}),
])
¶

Extend another service, in the current file or another file.

"provider"?: ¶

Specify a service which will not be manage by Compose directly, and delegate its management to an external provider.

"type"!: string ¶

External component used by Compose to manage setup and teardown lifecycle of the service.

"options"?: ¶

Provider-specific options.

[=~"^.+$"]: matchN(1, [bool | number | string, [...bool | number | string]])
[=~"^x-"]: _ ¶
"external_links"?: list.UniqueItems() & [...string] ¶

Link to services started outside this Compose application. Specify services as <service_name>:<alias>.

[...]: string
"extra_hosts"?: #extra_hosts ¶

Add hostname mappings to the container network interface configuration.

"gpus"?: #gpus ¶

Define GPU devices to use. Can be set to 'all' to use all GPUs, or a list of specific GPU devices.

"group_add"?: list.UniqueItems() & [...number | string] ¶

Add additional groups which user inside the container should be member of.

[...]: number | string
"healthcheck"?: #healthcheck ¶

Configure a health check for the container to monitor its health status.

"disable"?: bool | string ¶

Disable any container-specified healthcheck. Set to true to disable.

"interval"?: string ¶

Time between running the check (e.g., '1s', '1m30s'). Default: 30s.

"retries"?: number | string ¶

Number of consecutive failures needed to consider the container as unhealthy. Default: 3.

"test"?: matchN(1, [string, [...string]]) ¶

The test to perform to check container health. Can be a string or a list. The first item is either NONE, CMD, or CMD-SHELL. If it's CMD, the rest of the command is exec'd. If it's CMD-SHELL, the rest is run in the shell.

"timeout"?: string ¶

Maximum time to allow one check to run (e.g., '1s', '1m30s'). Default: 30s.

"start_period"?: string ¶

Start period for the container to initialize before starting health-retries countdown (e.g., '1s', '1m30s'). Default: 0s.

"start_interval"?: string ¶

Time between running the check during the start period (e.g., '1s', '1m30s'). Default: interval value.

[=~"^x-"]: _ ¶
"hostname"?: string ¶

Define a custom hostname for the service container.

"image"?: string ¶

Specify the image to start the container from. Can be a repository/tag, a digest, or a local image ID.

"init"?: bool | string ¶

Run as an init process inside the container that forwards signals and reaps processes.

"ipc"?: string ¶

IPC sharing mode for the service container. Use 'host' to share the host's IPC namespace, 'service:[service_name]' to share with another service, or 'shareable' to allow other services to share this service's IPC namespace.

"isolation"?: string ¶

Container isolation technology to use. Supported values are platform-specific.

"labels"?: #list_or_dict ¶

Add metadata to containers using Docker labels. You can use either an array or a list.

"links"?: list.UniqueItems() & [...string] ¶

Link to containers in another service. Either specify both the service name and a link alias (SERVICE:ALIAS), or just the service name.

[...]: string
"logging"?: ¶

Logging configuration for the service.

"driver"?: string ¶

Logging driver to use, such as 'json-file', 'syslog', 'journald', etc.

"options"?: ¶

Options for the logging driver.

[=~"^.+$"]: null | number | string
[=~"^x-"]: _ ¶
"mac_address"?: string ¶

Container MAC address to set.

"mem_limit"?: number | string ¶

Memory limit for the container. A string value can use suffix like '2g' for 2 gigabytes.

"mem_reservation"?: int | string ¶

Memory reservation for the container.

"mem_swappiness"?: int | string ¶

Container memory swappiness as percentage (0 to 100).

"memswap_limit"?: number | string ¶

Amount of memory the container is allowed to swap to disk. Set to -1 to enable unlimited swap.

"network_mode"?: string ¶

Network mode. Values can be 'bridge', 'host', 'none', 'service:[service name]', or 'container:[container name]'.

"models"?:
click to see definition
matchN(1, [
	#list_of_strings,
	{
		{
			[=~"^[a-zA-Z0-9._-]+$"]: matchN(1, [
				close({
					// Environment variable set to AI model endpoint.
					"endpoint_var"?: string

					// Environment variable set to AI model name.
					"model_var"?: string

					{[=~"^x-"]: _}
				}),
				null,
			])
		}
		...
	},
])
¶

AI Models to use, referencing entries under the top-level models key.

"networks"?:
click to see definition
matchN(1, [
	#list_of_strings,
	close({

		{
			[=~"^[a-zA-Z0-9._-]+$"]: matchN(1, [
				close({
					// Alternative hostnames for this service on the network.
					"aliases"?: #list_of_strings

					// Interface network name used to connect to network
					"interface_name"?: string

					// Specify a static IPv4 address for this service on this network.
					"ipv4_address"?: string

					// Specify a static IPv6 address for this service on this network.
					"ipv6_address"?: string

					// List of link-local IPs.
					"link_local_ips"?: #list_of_strings

					// Specify a MAC address for this service on this network.
					"mac_address"?: string

					// Driver options for this network.
					"driver_opts"?: {
						{[=~"^.+$"]: number | string}
						...
					}

					// Specify the priority for the network connection.
					"priority"?: number

					// Specify the gateway priority for the network connection.
					"gw_priority"?: number

					{[=~"^x-"]: _}
				}),
				null,
			])
		}}),
])
¶

Networks to join, referencing entries under the top-level networks key. Can be a list of network names or a mapping of network name to network configuration.

"oom_kill_disable"?: bool | string ¶

Disable OOM Killer for the container.

"oom_score_adj"?: matchN(1, [string, int & >=-1000 & <=1000]) ¶

Tune host's OOM preferences for the container (accepts -1000 to 1000).

"pid"?: null | string ¶

PID mode for container.

"pids_limit"?: number | string ¶

Tune a container's PIDs limit. Set to -1 for unlimited PIDs.

"platform"?: string ¶

Target platform to run on, e.g., 'linux/amd64', 'linux/arm64', or 'windows/amd64'.

"ports"?:
click to see definition
list.UniqueItems() & [...matchN(1, [
	number,
	string,
	close({
		// A human-readable name for this port mapping.
		"name"?: string

		// The port binding mode, either 'host' for publishing a host port or 'ingress' for load balancing.
		"mode"?: string

		// The host IP to bind to.
		"host_ip"?: string

		// The port inside the container.
		"target"?: int | string

		// The publicly exposed port.
		"published"?: int | string

		// The port protocol (tcp or udp).
		"protocol"?: string

		// Application protocol to use with the port (e.g., http, https, mysql).
		"app_protocol"?: string

		{[=~"^x-"]: _}
	}),
])]
¶

Expose container ports. Short format ([HOST:]CONTAINER[/PROTOCOL]).

[...]:
click to see definition
matchN(1, [
	number,
	string,
	close({
		// A human-readable name for this port mapping.
		"name"?: string

		// The port binding mode, either 'host' for publishing a host port or 'ingress' for load balancing.
		"mode"?: string

		// The host IP to bind to.
		"host_ip"?: string

		// The port inside the container.
		"target"?: int | string

		// The publicly exposed port.
		"published"?: int | string

		// The port protocol (tcp or udp).
		"protocol"?: string

		// Application protocol to use with the port (e.g., http, https, mysql).
		"app_protocol"?: string

		{[=~"^x-"]: _}
	}),
])
"pre_start"?: [...#pre_start_hook] ¶

Init containers to run to completion before the service container is started. Each step runs in its own ephemeral container, in declared order; a non-zero exit fails the bring-up of the service and its dependents.

[...]: #pre_start_hook
"command"?: #command

Command to execute. Optional when the chosen image's entrypoint already runs the intended command.

"image"?: string

Image used for the ephemeral container. If omitted, the parent service's image is used.

"user"?: string

User to run the command as. Defaults to the user declared in image (or to the service's user when image is omitted).

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command. Defaults to the service's working directory.

"environment"?: #list_or_dict

Environment variables for the command. Appended to or overriding the service environment.

"per_replica"?: bool | string

Whether the hook runs once per service replica (true), or once for the service as a whole before any replica starts (false, the default).

[=~"^x-"]: _
"post_start"?: [...#service_hook] ¶

Commands to run after the container starts. If any command fails, the container stops.

[...]: #service_hook
"command"!: #command

Command to execute as part of the hook.

"user"?: string

User to run the command as.

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command.

"environment"?: #list_or_dict

Environment variables for the command.

[=~"^x-"]: _
"pre_stop"?: [...#service_hook] ¶

Commands to run before the container stops. If any command fails, the container stop is aborted.

[...]: #service_hook
"command"!: #command

Command to execute as part of the hook.

"user"?: string

User to run the command as.

"privileged"?: bool | string

Whether to run the command with extended privileges.

"working_dir"?: string

Working directory for the command.

"environment"?: #list_or_dict

Environment variables for the command.

[=~"^x-"]: _
"privileged"?: bool | string ¶

Give extended privileges to the service container.

"profiles"?: #list_of_strings ¶

List of profiles for this service. When profiles are specified, services are only started when the profile is activated.

"pull_policy"?: =~"always|never|build|if_not_present|missing|refresh|daily|weekly|every_([0-9]+[wdhms])+" ¶

Policy for pulling images. Options include: 'always', 'never', 'if_not_present', 'missing', 'build', or time-based refresh policies.

"pull_refresh_after"?: string ¶

Time after which to refresh the image. Used with pull_policy=refresh.

"read_only"?: bool | string ¶

Mount the container's filesystem as read only.

"restart"?: string ¶

Restart policy for the service container. Options include: 'no', 'always', 'on-failure', and 'unless-stopped'.

"runtime"?: string ¶

Runtime to use for this container, e.g., 'runc'.

"scale"?: int | string ¶

Number of containers to deploy for this service.

"security_opt"?: list.UniqueItems() & [...string] ¶

Override the default labeling scheme for each container.

[...]: string
"shm_size"?: number | string ¶

Size of /dev/shm. A string value can use suffix like '2g' for 2 gigabytes.

"secrets"?: #service_config_or_secret ¶

Grant access to Secrets on a per-service basis.

"sysctls"?: #list_or_dict ¶

Kernel parameters to set in the container. You can use either an array or a list.

"stdin_open"?: bool | string ¶

Keep STDIN open even if not attached.

"stop_grace_period"?: string ¶

Time to wait for the container to stop gracefully before sending SIGKILL (e.g., '1s', '1m30s').

"stop_signal"?: string ¶

Signal to stop the container (e.g., 'SIGTERM', 'SIGINT').

"storage_opt"?: {...} ¶

Storage driver options for the container.

"tmpfs"?: #string_or_list ¶

Mount a temporary filesystem (tmpfs) into the container. Can be a single value or a list.

"tty"?: bool | string ¶

Allocate a pseudo-TTY to service container.

"ulimits"?: #ulimits ¶

Override the default ulimits for a container.

"use_api_socket"?: bool ¶

Bind mount Docker API socket and required auth.

"user"?: string ¶

Username or UID to run the container process as.

"uts"?: string ¶

UTS namespace to use. 'host' shares the host's UTS namespace.

"userns_mode"?: string ¶

User namespace to use. 'host' shares the host's user namespace.

"volumes"?:
click to see definition
list.UniqueItems() & [...matchN(1, [
	string,
	close({
		// The mount type: bind for mounting host directories, volume for named volumes,
		// tmpfs for temporary filesystems, cluster for cluster volumes, npipe for
		// named pipes, or image for mounting from an image.
		"type"!: "bind" | "volume" | "tmpfs" | "cluster" | "npipe" | "image"

		// The source of the mount, a path on the host for a bind mount, a docker image
		// reference for an image mount, or the name of a volume defined in the
		// top-level volumes key. Not applicable for a tmpfs mount.
		"source"?: string

		// The path in the container where the volume is mounted.
		"target"?: string

		// Flag to set the volume as read-only.
		"read_only"?: bool | string

		// The consistency requirements for the mount. Available values are platform specific.
		"consistency"?: string

		// Configuration specific to bind mounts.
		"bind"?: close({
			// The propagation mode for the bind mount: 'shared', 'slave', 'private',
			// 'rshared', 'rslave', or 'rprivate'.
			"propagation"?: string

			// Create the host path if it doesn't exist.
			"create_host_path"?: bool | string

			// Recursively mount the source directory.
			"recursive"?: "enabled" | "disabled" | "writable" | "readonly"

			// SELinux relabeling options: 'z' for shared content, 'Z' for private unshared content.
			"selinux"?: "z" | "Z"

			{[=~"^x-"]: _}
		})

		// Configuration specific to volume mounts.
		"volume"?: close({
			// Labels to apply to the volume.
			"labels"?: #list_or_dict

			// Flag to disable copying of data from a container when a volume is created.
			"nocopy"?: bool | string

			// Path within the volume to mount instead of the volume root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		// Configuration specific to tmpfs mounts.
		"tmpfs"?: close({
			// Size of the tmpfs mount in bytes.
			"size"?: matchN(1, [int & >=0, string])

			// File mode of the tmpfs in octal.
			"mode"?: number | string

			{[=~"^x-"]: _}
		})

		// Configuration specific to image mounts.
		"image"?: close({
			// Path within the image to mount instead of the image root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		{[=~"^x-"]: _}
	}),
])]
¶

Mount host paths or named volumes accessible to the container. Short syntax (VOLUME:CONTAINER_PATH[:MODE])

[...]:
click to see definition
matchN(1, [
	string,
	close({
		// The mount type: bind for mounting host directories, volume for named volumes,
		// tmpfs for temporary filesystems, cluster for cluster volumes, npipe for
		// named pipes, or image for mounting from an image.
		"type"!: "bind" | "volume" | "tmpfs" | "cluster" | "npipe" | "image"

		// The source of the mount, a path on the host for a bind mount, a docker image
		// reference for an image mount, or the name of a volume defined in the
		// top-level volumes key. Not applicable for a tmpfs mount.
		"source"?: string

		// The path in the container where the volume is mounted.
		"target"?: string

		// Flag to set the volume as read-only.
		"read_only"?: bool | string

		// The consistency requirements for the mount. Available values are platform specific.
		"consistency"?: string

		// Configuration specific to bind mounts.
		"bind"?: close({
			// The propagation mode for the bind mount: 'shared', 'slave', 'private',
			// 'rshared', 'rslave', or 'rprivate'.
			"propagation"?: string

			// Create the host path if it doesn't exist.
			"create_host_path"?: bool | string

			// Recursively mount the source directory.
			"recursive"?: "enabled" | "disabled" | "writable" | "readonly"

			// SELinux relabeling options: 'z' for shared content, 'Z' for private unshared content.
			"selinux"?: "z" | "Z"

			{[=~"^x-"]: _}
		})

		// Configuration specific to volume mounts.
		"volume"?: close({
			// Labels to apply to the volume.
			"labels"?: #list_or_dict

			// Flag to disable copying of data from a container when a volume is created.
			"nocopy"?: bool | string

			// Path within the volume to mount instead of the volume root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		// Configuration specific to tmpfs mounts.
		"tmpfs"?: close({
			// Size of the tmpfs mount in bytes.
			"size"?: matchN(1, [int & >=0, string])

			// File mode of the tmpfs in octal.
			"mode"?: number | string

			{[=~"^x-"]: _}
		})

		// Configuration specific to image mounts.
		"image"?: close({
			// Path within the image to mount instead of the image root.
			"subpath"?: string

			{[=~"^x-"]: _}
		})

		{[=~"^x-"]: _}
	}),
])
"volumes_from"?: list.UniqueItems() & [...string] ¶

Mount volumes from another service or container. Optionally specify read-only access (ro) or read-write (rw).

[...]: string
"working_dir"?: string ¶

The working directory in which the entrypoint or command will be run

[=~"^x-"]: _ ¶
#service_config_or_secret:
click to see definition
[...matchN(1, [
	string,
	close({
		// Name of the config or secret as defined in the top-level configs or secrets section.
		"source"?: string

		// Path in the container where the config or secret will be mounted. Defaults to
		// /<source> for configs and /run/secrets/<source> for secrets.
		"target"?: string

		// UID of the file in the container. Default is 0 (root).
		"uid"?: string

		// GID of the file in the container. Default is 0 (root).
		"gid"?: string

		// File permission mode inside the container, in octal. Default is 0444 for
		// configs and 0400 for secrets.
		"mode"?: number | string

		{[=~"^x-"]: _}
	}),
])]
¶

Configuration for service configs or secrets, defining how they are mounted in the container.

[...]:
click to see definition
matchN(1, [
	string,
	close({
		// Name of the config or secret as defined in the top-level configs or secrets section.
		"source"?: string

		// Path in the container where the config or secret will be mounted. Defaults to
		// /<source> for configs and /run/secrets/<source> for secrets.
		"target"?: string

		// UID of the file in the container. Default is 0 (root).
		"uid"?: string

		// GID of the file in the container. Default is 0 (root).
		"gid"?: string

		// File permission mode inside the container, in octal. Default is 0444 for
		// configs and 0400 for secrets.
		"mode"?: number | string

		{[=~"^x-"]: _}
	}),
])
#service_hook: ¶

Configuration for service lifecycle hooks, which are commands executed at specific points in a container's lifecycle.

"command"!: #command ¶

Command to execute as part of the hook.

"user"?: string ¶

User to run the command as.

"privileged"?: bool | string ¶

Whether to run the command with extended privileges.

"working_dir"?: string ¶

Working directory for the command.

"environment"?: #list_or_dict ¶

Environment variables for the command.

[=~"^x-"]: _ ¶
#string_or_list: matchN(1, [string, #list_of_strings]) ¶

Either a single string or a list of strings.

#ulimits: ¶

Container ulimit options, controlling resource limits for processes inside the container.

[=~"^[a-z]+$"]:
click to see definition
matchN(1, [
	int | string,
	close({
		// Hard limit for the ulimit type. This is the maximum allowed value.
		"hard"!: int | string

		// Soft limit for the ulimit type. This is the value that's actually enforced.
		"soft"!: int | string

		{[=~"^x-"]: _}
	}),
])
¶
#volume:
click to see definition
null | close({
	// Custom name for this volume.
	"name"?: string

	// Specify which volume driver should be used for this volume.
	"driver"?: string

	// Specify driver-specific options.
	"driver_opts"?: {
		{[=~"^.+$"]: number | string}
		...
	}

	// Specifies that this volume already exists and was created outside of Compose.
	"external"?: bool |
		string |
		close({
			// Specifies the name of the external volume. Deprecated: use the 'name' property instead.
			"name"?: string @deprecated()

			{[=~"^x-"]: _}
		})

	// Add metadata to the volume using labels.
	"labels"?: #list_or_dict

	{[=~"^x-"]: _}
})
¶

Volume configuration for the Compose application.

"name"?: string ¶

Custom name for this volume.

"driver"?: string ¶

Specify which volume driver should be used for this volume.

"driver_opts"?: ¶

Specify driver-specific options.

[=~"^.+$"]: number | string
"external"?:
click to see definition
bool |
	string |
	close({
		// Specifies the name of the external volume. Deprecated: use the 'name' property instead.
		"name"?: string @deprecated()

		{[=~"^x-"]: _}
	})
¶

Specifies that this volume already exists and was created outside of Compose.

"name"?: string ¶

Specifies the name of the external volume. Deprecated: use the 'name' property instead.

[=~"^x-"]: _ ¶
"labels"?: #list_or_dict ¶

Add metadata to the volume using labels.

[=~"^x-"]: _ ¶

Source files

  • schema.cue