docker / docker/cli

Bug when merging when TCP and UDP on the same published port

Open
#6,223 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

area/stack kind/bug status/0-triage
Dominant language
Go
Stars
6.1k
Forks
2.2k
Avg merge
1d 15h
Merged PRs (30d)
43

Description

Description

When merging multiple stack Compose files where one defines a service exposing TCP and UDP on the same published port (e.g., 443), the resulting merged configuration silently drops the first port entry. Even if the override doesn't specify ports. The only work-around I've found is to change the merge order but that's only a viable solution if you're not relying on overriding other values.

This violates the expected behavior where the ports array should remain unchanged if not explicitly overridden.

Reproduce

Given the following files:

# compose.yaml
services:
  web:
    image: caddy
    ports:
      - "80:80"
      - "443:443" # adding /tcp here makes no difference
      - "443:443/udp"
# compose.override.yaml
services:
  web:
    environment:
      FOO: bar

Running the following command:

docker stack config -c compose.yaml -c compose.override.yaml

Returns the following:

version: "3.13"
services:
  web:
    environment:
      FOO: bar
    image: caddy
    ports:
      - mode: ingress
        target: 80
        published: 80
        protocol: tcp
      - mode: ingress
        target: 443
        published: 443
        protocol: udp

Note that the 443 tcp entry is now gone.
The same is true when using long syntax.
Reversing the merge order leaves the ports array intact:

docker stack config -c compose.override.yaml -c compose.yaml

Returns the following:

version: "3.13"
services:
  web:
    environment:
      FOO: bar
    image: caddy
    ports:
      - mode: ingress
        target: 80
        published: 80
        protocol: tcp
      - mode: ingress
        target: 443
        published: 443
        protocol: tcp
      - mode: ingress
        target: 443
        published: 443
        protocol: udp

I've found that merging on a service that uses the same port for both tcp and udp only work as expected if the ports array is only defined in the last file.

Expected behavior

I expect the resulting ports array to be the same (untouched) in the examples above.

docker version
Client: Docker Engine - Community
 Version:           28.0.0
 API version:       1.48
 Go version:        go1.24.0
 Git commit:        f9ced58158
 Built:             Wed Feb 19 22:05:47 2025
 OS/Arch:           darwin/arm64
 Context:           desktop-linux

Server: Docker Desktop 4.43.2 (199162)
 Engine:
  Version:          28.3.2
  API version:      1.51 (minimum version 1.24)
  Go version:       go1.24.5
  Git commit:       e77ff99
  Built:            Wed Jul  9 16:13:56 2025
  OS/Arch:          linux/arm64
  Experimental:     true
 containerd:
  Version:          1.7.27
  GitCommit:        05044ec0a9a75232cad458027ca83437aae3f4da
 runc:
  Version:          1.2.5
  GitCommit:        v1.2.5-0-g59923ef
 docker-init:
  Version:          0.19.0
  GitCommit:        de40ad0
docker info
Client: Docker Engine - Community
 Version:    28.0.0
 Context:    desktop-linux
 Debug Mode: false
Additional Info

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the issue with compose.yaml and compose.override.yaml, then run docker stack config with both merge orders. Trace the Docker CLI's Compose-file merge handling for service ports, including short and long syntax. Done means the merged output preserves both TCP and UDP entries on published port 443 when the override does not define ports.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, go
Domain
cli
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.