The strict version read in docker_config_migrate is what keeps a list-root config.yaml on the warn-and-continue path; only a probe covered it. Fold the list-root case into the existing invalid-YAML test (reverting to the tolerant read now goes red) and correct the comment about where the warning comes from.