WoluTools

Developer Tools

Check a Docker Compose file for errors and exposed secrets

Upload up to 20 Compose files. Each finding names the file and the key: a missing services section, or a key such as POSTGRES_PASSWORD or API_TOKEN with a password written in plain text. Nothing is executed and no container is started.

or drop it here

YAML, YML · Up to 20 documents
Free account needed for your 3 free jobs a day

No file at hand? See an example result

Standard toolIncluded · 3 free jobs a dayFree: 3 jobs a dayPro: up to 200 jobs a day · €12.99/month or €89.99/year
  • YAML / YML
  • Up to 20 documents
  • Free jobs: 3 files, 10 MB each
  • Free account needed
Example result · fictional filesTwo Compose files in, three findings out

What you upload

compose.yaml

  1. services:
  2. db:
  3. image: postgres:16
  4. environment:
  5. POSTGRES_PASSWORD: s3cret-localflagged
  6. api:
  7. image: example/api:1.4
  8. environment:
  9. - API_TOKEN=${API_TOKEN}variable, skipped
  10. - JWT_SECRET=change-meflagged

compose.override.yaml

  1. x-logging:no services key
  2. driver: json-file

What the check reports

  • errorINLINE_SECRETcompose.yaml: POSTGRES_PASSWORD has a literal inline value
  • errorINLINE_SECRETcompose.yaml: JWT_SECRET has a literal inline value
  • errorROOT_KEY_MISSINGcompose.override.yaml document 1: services

Line 9 is not reported: ${API_TOKEN} is a variable reference, not a password in the file.

On screen: the summary (2 documents, 2 sources) and the first three findings. In the download: findings.csv with every finding, normalized-source.yaml and manifest.json.

BringYAML, YML
Getfindings.csv, normalized-source.yaml, manifest.json
PrivacyEncrypted source · 24-hour result

Three steps from file to findings

  1. 1

    Add your Compose files

    Sign in with a free account and choose up to 20 YAML or YML documents. Formats and limits are shown before the upload.

  2. 2

    Run the check

    There are no settings to choose. Nothing is executed and no referenced file is opened.

  3. 3

    Read the findings

    The first three findings appear on screen. Download the package for findings.csv with the full list.

What the Compose check flags

Every finding has a severity, a code and the file it came from. There are three codes:

Findings and a normalized copy

findings.csv lists severity, code and evidence for each finding. normalized-source.yaml is one copy of all the YAML you supplied, with each file marked by its name and Windows line endings changed to Unix ones. manifest.json records which files were checked, their checksums and the summary. Your uploaded files stay as they were. Read each finding against your own file before you change anything.

What this screen leaves open

Findings name the file and the key, not the line number, so search your file for the key. Variables are left exactly as written, so a secret hidden behind interpolation is not inspected. An include or extends reference is not followed, and extension fields, profiles and host-mounted paths are not resolved. A clean report does not mean the stack is ready to deploy, because service behaviour is never tested. Afterwards, run Docker's own configuration command for your version and keep your normal deployment review.

Questions before you run it

What does the preflight actually look for?

Two things in the YAML text: whether each document has a services key, and whether a key ending in password, passwd, token, secret or api_key holds a literal value. Block scalars written with | or > are marked for a manual look. It is an early structural screen, not a Compose schema validation.

Do I need an account?

Yes, a free account. It includes 3 free jobs a day, and failed jobs are not counted. Pro allows up to 200 jobs a day for €12.99 a month or €89.99 a year.

Does a finding show the line number?

No. Each finding names the file and the key, for example compose.yaml: JWT_SECRET has a literal inline value. Search the file for that key to find the line.

Does it expand variable interpolation or read my env file?

No. Variables are left exactly as written. A value written as ${VAR} is not reported, and the value behind it is never inspected. Extension fields, profiles and host-mounted paths are not resolved either.

What happens to an include or extends reference?

It is not followed. The referenced file is never opened, so its contents are not checked. No image is built and no container is started.

How many Compose files fit in one job?

Up to 20 YAML or YML documents per job. Free jobs take up to 3 files of up to 10 MB each. A larger set is rejected instead of partly processed.

Does a clean report mean the stack is ready to deploy?

No. Service behaviour is never exercised and nothing runs. Follow this screen with the version-matched Docker configuration command and a normal deployment review.