Study notes · 9% of the exam

Docker Compose

Compose v2 (`docker compose`) runs a multi-container app from one model. Know how it names and connects resources, how it orders startup, how environment values are resolved, and how multiple files merge.

Key points

  1. 1

    Every project gets a <project>_default network. Services reach each other by service name on the container port; published ports are only for clients outside the network, and expose never publishes.

  2. 2

    The project name (from -p, then COMPOSE_PROJECT_NAME, then top-level name:, then the folder name) prefixes containers, networks and named volumes. Renaming the folder means new, empty volumes.

  3. 3

    depends_on short syntax only orders startup. Add a healthcheck and condition: service_healthy to wait for readiness, or service_completed_successfully for one-shot jobs such as migrations.

  4. 4

    The .env file feeds interpolation of the Compose file; it is not injected into containers. Interpolation precedence: shell, then --env-file, then .env. Container precedence: run --env, then environment, then env_file, then image ENV.

  5. 5

    Without -f, Compose merges compose.override.yaml onto compose.yaml. With -f, only the listed files are merged, in order: mappings merge, sequences append, command and entrypoint are replaced, and ports and volumes merge by their unique key. Use !reset to clear inherited values.

  6. 6

    docker compose run doesn't publish ports unless you pass --service-ports. down keeps named volumes unless you add -v, and never removes external resources or bind-mounted host folders.

  7. 7

    Compose Watch keeps dev containers in step with source: sync for hot-reloaded files, rebuild for dependency manifests, sync+restart for config read at startup. It only tracks services with a build section.

Common traps

  • ${VAR-default} and ${VAR?err} treat an empty value as set; only the colon forms ${VAR:-default} and ${VAR:?err} catch blank values like DB_PASSWORD=.

  • With both image and build and no pull_policy, Compose pulls the image first and only builds if it's missing, so a registry tag can silently replace your local code.

  • Write $$ in the Compose file when a $VAR must be expanded by the container's shell (for example in a healthcheck), otherwise Compose substitutes it at load time.

Test yourself on Docker Compose

Ten questions, with the answer and explanation after each one.