Developer Tools
Check a Docker Compose file for errors and exposed secrets
Upload up to 20 Compose files. Each finding names the file and the key: a missing services section, or a key such as POSTGRES_PASSWORD or API_TOKEN with a password written in plain text. Nothing is executed and no container is started.
or drop it here
- YAML / YML
- Up to 20 documents
- Free jobs: 3 files, 10 MB each
- Free account needed
What you upload
compose.yaml
services:db:image: postgres:16environment:POSTGRES_PASSWORD: s3cret-localflaggedapi:image: example/api:1.4environment:- API_TOKEN=${API_TOKEN}variable, skipped- JWT_SECRET=change-meflagged
compose.override.yaml
x-logging:no services keydriver: json-file
What the check reports
- error
INLINE_SECRETcompose.yaml: POSTGRES_PASSWORD has a literal inline value - error
INLINE_SECRETcompose.yaml: JWT_SECRET has a literal inline value - error
ROOT_KEY_MISSINGcompose.override.yaml document 1: services
Line 9 is not reported: ${API_TOKEN} is a variable reference, not a password in the file.
On screen: the summary (2 documents, 2 sources) and the first three findings. In the download: findings.csv with every finding, normalized-source.yaml and manifest.json.
Three steps from file to findings
- 1
Add your Compose files
Sign in with a free account and choose up to 20 YAML or YML documents. Formats and limits are shown before the upload.
- 2
Run the check
There are no settings to choose. Nothing is executed and no referenced file is opened.
- 3
Read the findings
The first three findings appear on screen. Download the package for findings.csv with the full list.
What the Compose check flags
Every finding has a severity, a code and the file it came from. There are three codes:
- INLINE_SECRET · errorA key whose name ends in password, passwd, token, secret or api_key (upper or lower case) holds a literal value. Both forms are read:
POSTGRES_PASSWORD: valueand- POSTGRES_PASSWORD=value. An unquoted${VAR}or<placeholder>value is skipped. A quoted"${VAR}"and a bare$VARare reported, so check those by hand. A key such asPOSTGRES_PASSWORD_FILEthat points to a Docker secret is not flagged. - ROOT_KEY_MISSING · errorA document has no services key. Files with several documents separated by
---are checked document by document. - MULTILINE_VALUE · reviewThe file contains a block scalar written with
|or>. It is marked for a manual look, once per file.
Findings and a normalized copy
findings.csv lists severity, code and evidence for each finding. normalized-source.yaml is one copy of all the YAML you supplied, with each file marked by its name and Windows line endings changed to Unix ones. manifest.json records which files were checked, their checksums and the summary. Your uploaded files stay as they were. Read each finding against your own file before you change anything.
What this screen leaves open
Findings name the file and the key, not the line number, so search your file for the key. Variables are left exactly as written, so a secret hidden behind interpolation is not inspected. An include or extends reference is not followed, and extension fields, profiles and host-mounted paths are not resolved. A clean report does not mean the stack is ready to deploy, because service behaviour is never tested. Afterwards, run Docker's own configuration command for your version and keep your normal deployment review.
Questions before you run it
What does the preflight actually look for?
Two things in the YAML text: whether each document has a services key, and whether a key ending in password, passwd, token, secret or api_key holds a literal value. Block scalars written with | or > are marked for a manual look. It is an early structural screen, not a Compose schema validation.
Do I need an account?
Yes, a free account. It includes 3 free jobs a day, and failed jobs are not counted. Pro allows up to 200 jobs a day for €12.99 a month or €89.99 a year.
Does a finding show the line number?
No. Each finding names the file and the key, for example compose.yaml: JWT_SECRET has a literal inline value. Search the file for that key to find the line.
Does it expand variable interpolation or read my env file?
No. Variables are left exactly as written. A value written as ${VAR} is not reported, and the value behind it is never inspected. Extension fields, profiles and host-mounted paths are not resolved either.
What happens to an include or extends reference?
It is not followed. The referenced file is never opened, so its contents are not checked. No image is built and no container is started.
How many Compose files fit in one job?
Up to 20 YAML or YML documents per job. Free jobs take up to 3 files of up to 10 MB each. A larger set is rejected instead of partly processed.
Does a clean report mean the stack is ready to deploy?
No. Service behaviour is never exercised and nothing runs. Follow this screen with the version-matched Docker configuration command and a normal deployment review.