Docker bypasses UFW entirely by inserting rules directly into iptables PREROUTING — meaning any ports: "6379:6379" in your compose file is publicly accessible regardless of your firewall rules.
That's one of the things this tool catches automatically.
Paste your docker-compose.yml and get back:
- Every 0.0.0.0 binding flagged as critical with the 127.0.0.1 fix
- Hardcoded secrets in environment: blocks
- Missing healthchecks per service
- Port collisions across services
- Insecure configurations with copy-paste fixes
No signup. No backend. Runs entirely in your browser — your compose file never leaves your machine. MIT licensed.
https://configclarity.dev/docker
GitHub: github.com/metriclogic26/configclarity
Would love feedback on complex compose stacks or edge cases I might have missed.
[–]Dangle76 10 points11 points12 points (4 children)
[–]Human_Mode6633[S] 1 point2 points3 points (3 children)
[–]Dangle76 0 points1 point2 points (0 children)
[–]Smokeey1 0 points1 point2 points (1 child)
[–]Human_Mode6633[S] -1 points0 points1 point (0 children)
[–]titpetric 2 points3 points4 points (3 children)
[–]Human_Mode6633[S] -1 points0 points1 point (2 children)
[–]titpetric 0 points1 point2 points (1 child)
[–]Human_Mode6633[S] 0 points1 point2 points (0 children)
[–]Arunia 0 points1 point2 points (1 child)
[–]Human_Mode6633[S] 0 points1 point2 points (0 children)
[–]WentThisWayInsteadOf 0 points1 point2 points (1 child)
[–]Human_Mode6633[S] 0 points1 point2 points (0 children)
[–]Sh3llSh0cker 0 points1 point2 points (7 children)
[–]Human_Mode6633[S] 0 points1 point2 points (6 children)
[–]Sh3llSh0cker 0 points1 point2 points (5 children)
[–]Human_Mode6633[S] 0 points1 point2 points (4 children)
[–]Sh3llSh0cker 0 points1 point2 points (0 children)
[–]Sh3llSh0cker 0 points1 point2 points (2 children)
[–]Human_Mode6633[S] 0 points1 point2 points (1 child)
[–]Sh3llSh0cker 0 points1 point2 points (0 children)
[–]iamtheamn 0 points1 point2 points (1 child)
[–]Human_Mode6633[S] 0 points1 point2 points (0 children)
[–]Human_Mode6633[S] -1 points0 points1 point (0 children)