# Task 2 report — root Compose startup Status: DONE Implemented the root Compose defaults and the single bundle declaration: - added `.env.example` with automatic Compose defaults (`COMPOSE_FILE=compose.yaml`, an empty profile, and the relative `THT_SECRETS_FILE` path); - removed the mandatory `external` profile from `core` and `frontend`; - mounted `deploy/secrets/thothii.secrets` at `/run/secrets/thothii.secrets` and passed only the mounted path into the core container; - changed the production overlay to inherit that bundle instead of declaring per-secret mounts; - removed the local overlay's legacy `env_file` dependency; - added the versioned bundle template and `.gitignore` exception; - updated deployment security checks and added `scripts/test-default-compose.sh`. Focused verification: ```text ./scripts/test-default-compose.sh # default Compose contract passed. ./scripts/test-container-deployment.sh # container deployment security contract passed. ./scripts/test-preprocess-compose-config.sh # preprocess compose config: ok docker compose --env-file .env.example config --quiet (with a temporary mode-0600 bundle via THT_SECRETS_FILE) git diff --check ``` The local-vector and preprocess service secret declarations remain for Task 3, which converts those services to the same bundle helper. Documentation and smoke command migration is reserved for Task 4.