# Docker Compose Change Review — sample fixtures

Companion download for **[Docker Compose Change Review: Find Configuration
Regressions Before Deployment](https://devopsaitoolkit.com/blog/docker-compose-change-review-configuration-regressions/)**.

These are **synthetic** fixtures for a small demo app (`api` + `db` + `web`). They
exist to practice reviewing a *change* between two Compose configurations.

| File | What it is |
|---|---|
| `baseline.compose.yaml` | The currently-deployed configuration (reasonably hardened). |
| `proposed.compose.yaml` | A proposed change with **deliberate, labeled regressions**. |
| `reviewed.compose.yaml` | The proposed change after review, with each regression fixed. |
| `.env.example` | Template for the untracked `.env` the reviewed file references. |
| `release-review-worksheet.md` | A checklist to run against any Compose diff. |

## ⚠️ Do not deploy `proposed.compose.yaml`

It intentionally contains insecure settings — `privileged: true`, a mounted Docker
socket, a hardcoded password, a publicly-bound database, and a floating `latest`
tag — so a review can catch them. Never run it, and never point it at a real
Docker context, production secrets, or a public host.

## How to use these

1. Diff the change: `diff -u baseline.compose.yaml proposed.compose.yaml`
2. Validate syntax with the Docker CLI (does not start anything):
   `docker compose -f proposed.compose.yaml config -q`
3. Run **both** files through the free
   [Docker Production Readiness Auditor](https://devopsaitoolkit.com/tools/docker-production-readiness-auditor/)
   and compare the scores and findings.
4. Work through `release-review-worksheet.md`, then confirm your fixes against
   `reviewed.compose.yaml`.

## What the auditor reports (engine v1.0.0, verified 2026-09-16)

Running each file through the auditor:

| File | Score | Band | Critical | High |
|---|---|---|---|---|
| `baseline.compose.yaml` | 94 | Production Ready | 0 | 0 |
| `proposed.compose.yaml` | 74 | Needs Improvement | 2 | 5 |
| `reviewed.compose.yaml` | 94 | Production Ready | 0 | 0 |

The proposed change introduces: `privileged` (DPA-SEC-101, critical), Docker
socket mount (DPA-SEC-102, critical), `SYS_ADMIN` capability (DPA-SEC-106),
hardcoded secrets ×2 (DPA-SEC-108), a published database port (DPA-SEC-109), and a
`latest` image tag (DPA-SUPPLY-101). A static review also **cannot** catch some
things — e.g. that `backend` dropped `internal: true` is only partially reflected
(via the published-port finding); treat network-scope changes as a manual check.

Scores are a static configuration signal, not a certification of security or
correctness. Verify runtime behavior separately in a non-production environment.
