Clear scores
Separate scores for security, performance & resources, reliability and best practices.
InfraVerdict is currently in validation and is not yet available as a paid service. When launched, upload your Docker Compose configuration and get a practical review of security, performance, reliability and Docker best practices – before you deploy.
Security · Performance & Resources · Reliability · Best Practices
Need the checks a Compose file cannot answer? A planned Audit + Deployment Guide bundle is also available for early access.
1services:
2 api:
3 image: acme/api:latest
4 volumes:
5 - /var/run/docker.sock:/var/run/docker.sock
6 db:
7 ports: ["5432:5432"]
The gap
AI tools like ChatGPT, Claude, Copilot and coding agents can generate a Docker stack in seconds. Reviewing whether the result follows sound production practices still requires infrastructure knowledge.
A stack that starts successfully is not necessarily a stack you should run in production. InfraVerdict reviews the configuration behind your services and highlights:
Example output
InfraVerdict does not stop at identifying problems. Each finding explains what is wrong, why it matters and how to fix it – with an improved Docker Compose configuration you can copy and adapt as a starting point.
Prioritized findings tied to your configuration.
A compromised container could gain control of the Docker host.
api.volumesThe database may be reachable beyond the private application network.
db.portsThe service has no configuration-level CPU constraint.
api.deploy.resourcesThe service has no configuration-level memory constraint.
api.deploy.resourcesService health cannot be determined from the Compose configuration.
api.healthcheck:latest tagDeployments can change without a corresponding configuration change.
api.imageThe database is not isolated from public-facing network traffic.
networksDatabase state is mapped to a named volume.
postgres-dataA corrected configuration based on the audit findings.
services:
app:
image: ghcr.io/example/app:1.4.2
restart: unless-stopped
ports:
- "127.0.0.1:8080:8080"
environment:
DATABASE_URL_FILE: /run/secrets/database_url
secrets:
- database_url
deploy:
resources:
limits:
cpus: "1.0"
memory: 512M
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8080/health"]
interval: 30s
timeout: 5s
retries: 3
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
depends_on:
db:
condition: service_healthy
networks:
- frontend
- backend
db:
image: postgres:17.6
restart: unless-stopped
environment:
POSTGRES_PASSWORD_FILE: /run/secrets/postgres_password
secrets:
- postgres_password
volumes:
- postgres-data:/var/lib/postgresql/data
healthcheck:
test:
- CMD-SHELL
- pg_isready -U postgres
interval: 30s
timeout: 5s
retries: 3
security_opt:
- no-new-privileges:true
networks:
- backend
volumes:
postgres-data:
secrets:
database_url:
file: ./secrets/database_url
postgres_password:
file: ./secrets/postgres_password
networks:
frontend:
backend:
internal: trueReview the generated configuration against your actual application and environment before deployment.
See what is wrong. Understand why. Copy the improved configuration.
Illustrative sample report and improved configuration. The audit product is currently in validation and is not yet available.
What we check
A focused Docker Compose review for production readiness – without pretending static analysis knows your entire infrastructure.
Docker Compose security checks for privileges, capabilities, exposed ports, secrets, mounts and container isolation.
Configuration-level Docker Compose performance and resource checks covering CPU and memory configuration, resource limits, reservations and settings that may affect resource usage or contention. This includes Docker Compose CPU limits, Docker Compose memory limits and other Docker Compose resource limits.
Healthchecks, restart behaviour, persistence, service dependencies and operational resilience visible in the configuration.
Image pinning, networking, maintainability and common Docker Compose anti-patterns.
What you would get
Separate scores for security, performance & resources, reliability and best practices.
Every finding grouped by severity, with a plain-language explanation.
Actionable recommendations and YAML examples for possible corrections.
Anything that needs context or a human check is clearly marked for manual verification.
No false certainty
InfraVerdict reviews everything that can be determined reliably from your Docker Compose configuration – including security, resource configuration, reliability and best practices.
Performance & Resources is based on CPU, memory and other settings defined in Compose. Real-world runtime performance and exact workload requirements require external testing.
Some production-readiness questions depend on the environment around your stack rather than the Compose file itself. These include:
The audit clearly identifies which areas require manual verification instead of making assumptions. For those checks, the Deployment Readiness Guide provides a practical checklist and guidance for completing the review beyond Docker Compose.
Deployment Readiness Guide
The Deployment Readiness Guide helps you verify the parts of production readiness that depend on your host and surrounding infrastructure. It covers backups and restore testing, firewalling, host security, TLS and DNS, monitoring, patching, recovery planning and other operational checks that require verification beyond the Compose file.
Built as a short, practical extension to the automated audit.
AuditReviews what can be verified from your Docker Compose configuration
GuideCovers the surrounding deployment environment with a manual verification checklist
BundleCombines both approaches for a broader pre-deployment review
Planned pricing
Coming soon. Join early access now; no payment will be taken. The planned service uses one-time pricing with no subscription, seat pricing or sales call.
FAQ
The planned flow does not require an account: upload a configuration, pay once and receive the report.
We plan to process uploaded configuration only for the audit and avoid permanent storage. Final retention details will be documented before launch.
No. It is a focused first-pass review of what can be determined from Docker Compose configuration, not a penetration test, runtime performance benchmark, architecture review or compliance assessment.
We plan to support the current Compose Specification. Exact compatibility and validation rules will be published before launch.
The first planned version focuses on Compose configuration. Dockerfile analysis may follow if there is enough demand.
No. The planned price is €19.90 for one Docker stack audit, paid once.
Coming soon · Early access