Coming soon · Join early access

AI wrote your Docker stack.
We check whether you should actually deploy it.

InfraVerdict is currently in validation and is not yet available as a paid service. When launched, upload your Docker Compose configuration and get a practical review of security, performance, reliability and Docker best practices – before you deploy.

Security · Performance & Resources · Reliability · Best Practices

One-time payment · No subscription

Need the checks a Compose file cannot answer? A planned Audit + Deployment Guide bundle is also available for early access.

  • Actionable findings
  • Severity prioritized
  • Human checks flagged
compose.yaml
1services:
2  api:
3    image: acme/api:latest
4    volumes:
5      - /var/run/docker.sock:/var/run/docker.sock
6  db:
7    ports: ["5432:5432"]
!
3 findings detectedReview before deployment
68/100

The gap

A Compose file can work and still be poorly configured.

AI tools like ChatGPT, Claude, Copilot and coding agents can generate a Docker stack in seconds. Reviewing whether the result follows sound production practices still requires infrastructure knowledge.

A stack that starts successfully is not necessarily a stack you should run in production. InfraVerdict reviews the configuration behind your services and highlights:

  • Security risks
  • Resource issues
  • Reliability problems
  • Common Compose mistakes

Example output

A report you can act on

InfraVerdict does not stop at identifying problems. Each finding explains what is wrong, why it matters and how to fix it – with an improved Docker Compose configuration you can copy and adapt as a starting point.

Audit Report

Prioritized findings tied to your configuration.

Deployment Verdict
68/100
⚠ Not ready
Security 72/100
Performance & Resources 64/100
Reliability 61/100
Best Practices 78/100
Critical
Docker socket mounted into container

A compromised container could gain control of the Docker host.

api.volumes
High
Database port publicly exposed

The database may be reachable beyond the private application network.

db.ports
Medium
No CPU limit configured

The service has no configuration-level CPU constraint.

api.deploy.resources
Medium
No memory limit configured

The service has no configuration-level memory constraint.

api.deploy.resources
Medium
Healthcheck missing

Service health cannot be determined from the Compose configuration.

api.healthcheck
Warning
Image uses :latest tag

Deployments can change without a corresponding configuration change.

api.image
Warning
Services share an unnecessarily broad network

The database is not isolated from public-facing network traffic.

networks
Pass
Persistent database volume configured

Database state is mapped to a named volume.

postgres-data
Improved Compose

A corrected configuration based on the audit findings.

improved-compose.yaml
services:
  app:
    image: ghcr.io/example/app:1.4.2
    restart: unless-stopped
    ports:
      - "127.0.0.1:8080:8080"
    environment:
      DATABASE_URL_FILE: /run/secrets/database_url
    secrets:
      - database_url
    deploy:
      resources:
        limits:
          cpus: "1.0"
          memory: 512M
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:8080/health"]
      interval: 30s
      timeout: 5s
      retries: 3
    security_opt:
      - no-new-privileges:true
    cap_drop:
      - ALL
    depends_on:
      db:
        condition: service_healthy
    networks:
      - frontend
      - backend

  db:
    image: postgres:17.6
    restart: unless-stopped
    environment:
      POSTGRES_PASSWORD_FILE: /run/secrets/postgres_password
    secrets:
      - postgres_password
    volumes:
      - postgres-data:/var/lib/postgresql/data
    healthcheck:
      test:
        - CMD-SHELL
        - pg_isready -U postgres
      interval: 30s
      timeout: 5s
      retries: 3
    security_opt:
      - no-new-privileges:true
    networks:
      - backend

volumes:
  postgres-data:

secrets:
  database_url:
    file: ./secrets/database_url

  postgres_password:
    file: ./secrets/postgres_password

networks:
  frontend:

  backend:
    internal: true

Review the generated configuration against your actual application and environment before deployment.

See what is wrong. Understand why. Copy the improved configuration.

Illustrative sample report and improved configuration. The audit product is currently in validation and is not yet available.

What we check

Four areas in one Docker Compose audit.

A focused Docker Compose review for production readiness – without pretending static analysis knows your entire infrastructure.

  • 01
    Security

    Docker Compose security checks for privileges, capabilities, exposed ports, secrets, mounts and container isolation.

  • 02
    Performance & Resources

    Configuration-level Docker Compose performance and resource checks covering CPU and memory configuration, resource limits, reservations and settings that may affect resource usage or contention. This includes Docker Compose CPU limits, Docker Compose memory limits and other Docker Compose resource limits.

  • 03
    Reliability

    Healthchecks, restart behaviour, persistence, service dependencies and operational resilience visible in the configuration.

  • 04
    Best Practices

    Image pinning, networking, maintainability and common Docker Compose anti-patterns.

What you would get

One configuration in. A practical review out.

01

Clear scores

Separate scores for security, performance & resources, reliability and best practices.

02

Prioritized issues

Every finding grouped by severity, with a plain-language explanation.

03

Concrete fixes

Actionable recommendations and YAML examples for possible corrections.

04

Honest limits

Anything that needs context or a human check is clearly marked for manual verification.

No false certainty

What the audit covers – and what comes next

InfraVerdict reviews everything that can be determined reliably from your Docker Compose configuration – including security, resource configuration, reliability and best practices.

Performance & Resources is based on CPU, memory and other settings defined in Compose. Real-world runtime performance and exact workload requirements require external testing.

Some production-readiness questions depend on the environment around your stack rather than the Compose file itself. These include:

  • Host firewall and operating-system hardening
  • Backup and restore procedures
  • External network topology and upstream access controls
  • DNS and TLS configuration
  • Secrets managed outside Docker Compose
  • Monitoring and alerting
  • Recovery objectives and availability requirements

The audit clearly identifies which areas require manual verification instead of making assumptions. For those checks, the Deployment Readiness Guide provides a practical checklist and guidance for completing the review beyond Docker Compose.

Deployment Readiness Guide

Take the review beyond Docker Compose.

The Deployment Readiness Guide helps you verify the parts of production readiness that depend on your host and surrounding infrastructure. It covers backups and restore testing, firewalling, host security, TLS and DNS, monitoring, patching, recovery planning and other operational checks that require verification beyond the Compose file.

Built as a short, practical extension to the automated audit.

AuditReviews what can be verified from your Docker Compose configuration

GuideCovers the surrounding deployment environment with a manual verification checklist

BundleCombines both approaches for a broader pre-deployment review

  • Host hardening
  • Firewall and exposed ports
  • Reverse proxy and TLS
  • DNS
  • Backup strategy
  • Restore testing
  • Secrets outside Compose
  • Monitoring and alerting
  • Patching and updates
  • Single points of failure
  • Availability and recovery
  • RPO / RTO basics
  • Operational documentation
Example checklist

Backup & Restore

  • Identify all persistent data
  • Define what must be backed up
  • Store backups separately from the server
  • Define retention
  • Test an actual restore
Why it mattersWhat to verifyRecommended minimum

Planned pricing

Choose the review you need.

Coming soon. Join early access now; no payment will be taken. The planned service uses one-time pricing with no subscription, seat pricing or sales call.

Docker Compose Audit

€19.90

One-time payment · No subscription

Review of security, resource configuration, reliability and Docker Compose best practices.

Includes:

  • Configuration analysis
  • Severity-ranked findings
  • Clear explanations
  • Concrete remediation suggestions
  • Deployment verdict
Currently validating demand. No payment will be taken.

Deployment Readiness Guide

€9.90

One-time payment · No subscription

A practical checklist for important production checks that cannot be determined from Compose alone.

Includes:

  • Host and firewall checks
  • Backup and restore guidance
  • TLS and DNS
  • Monitoring and alerting
  • Updates and patching
  • Recovery planning
Currently validating demand. No payment will be taken.

FAQ

Questions, answered.

Do I need an account?

The planned flow does not require an account: upload a configuration, pay once and receive the report.

Will my Compose file be stored?

We plan to process uploaded configuration only for the audit and avoid permanent storage. Final retention details will be documented before launch.

Is this a replacement for a security or infrastructure professional?

No. It is a focused first-pass review of what can be determined from Docker Compose configuration, not a penetration test, runtime performance benchmark, architecture review or compliance assessment.

What Docker Compose versions are supported?

We plan to support the current Compose Specification. Exact compatibility and validation rules will be published before launch.

Can I upload Dockerfiles too?

The first planned version focuses on Compose configuration. Dockerfile analysis may follow if there is enough demand.

Is this a subscription?

No. The planned price is €19.90 for one Docker stack audit, paid once.

Coming soon · Early access

Get another pair of eyes on your Compose file.

Early access

These products are not live yet, and no payment will be taken. Leave your email if you would like to hear when InfraVerdict is ready.

By joining early access, you agree that we may use your email address exclusively to contact you about the launch and availability of InfraVerdict. See our Privacy Policy. No spam; unsubscribe anytime.