Inline compose-file contents (mutates the documents). The agent expects
either a path that exists on the device or base64:<encoded yaml> it
materializes into the workload working directory. Stack files reference
local paths, so we resolve them relative to the stack file's directory and
embed the bytes here — otherwise the agent looks at a path that doesn't
exist on the remote device.
Every set of bytes that passes through here is also structurally inspected
(collectComposeFindings) — the only point in the client that reads a
compose file from disk, and the reason services: "this is not a mapping"
used to ship unnoticed. The findings are returned as WARNINGS and never
throw: this function is on the path of stack status, diff, teardown
and validate as well as deploy, and none of those ship a compose byte.
The hard failure lives on the shipping path instead
(assertComposeWorkloadsValid, called by StacksClient.deploy), so a
broken compose file can still be inspected and torn down.
Embedding erases the path from the document, so when the caller passes
composeSources every path-backed workload's resolved path is recorded
there — that is how the shipping gate later names the offending FILE
rather than <embedded compose document>.
Inline compose-file contents (mutates the documents). The agent expects either a path that exists on the device or
base64:<encoded yaml>it materializes into the workload working directory. Stack files reference local paths, so we resolve them relative to the stack file's directory and embed the bytes here — otherwise the agent looks at a path that doesn't exist on the remote device.Every set of bytes that passes through here is also structurally inspected (collectComposeFindings) — the only point in the client that reads a compose file from disk, and the reason
services: "this is not a mapping"used to ship unnoticed. The findings are returned as WARNINGS and never throw: this function is on the path ofstack status,diff,teardownandvalidateas well asdeploy, and none of those ship a compose byte. The hard failure lives on the shipping path instead (assertComposeWorkloadsValid, called byStacksClient.deploy), so a broken compose file can still be inspected and torn down.Embedding erases the path from the document, so when the caller passes
composeSourcesevery path-backed workload's resolved path is recorded there — that is how the shipping gate later names the offending FILE rather than<embedded compose document>.