Back

Docker run to Compose converter

Developer tools

Loading

Loading tool

The tool is loaded only when you open it.

All processing for this tool happens in your browser. Your input is not sent to a server.

About this tool

Paste one literal docker run or docker container run command to create a single-service Compose YAML draft. The preview updates as you edit and uses the same content for copying and downloading. Every environment value is masked by default; editing the command resets any raw-value reveal. Conversion happens entirely in the browser without executing commands, accessing Docker, reading files or saving input history. Review warnings and deployment settings before using the result.

Common uses

  • Move a small, supported Docker run example into a reviewable Compose file without manually rewriting ports and mounts.
  • Check the mapping of an explicit entrypoint, command arguments, working directory, user, TTY and standard input settings.
  • Prepare a debugging example with environment values masked, then inspect arguments, paths and other visible fields before sharing.

How to use it

  1. 1.Paste a single POSIX-style Docker run command with literal values and a valid image. Use quotes for spaces and a backslash followed by a line break for continuation.
  2. 2.Review the current YAML and any errors or warnings. Correct unsupported options rather than assuming they will be silently ignored. Keep environment values masked unless you intentionally need them.
  3. 3.Copy the YAML or download compose.yaml. Replace masked placeholders securely, inspect all remaining fields, and validate the file with your own Compose installation before deployment.

Worked Docker conversion examples

Web server with a published port

docker run -d --name web -p 8080:80 --restart unless-stopped nginx:alpine
services:
  app:
    container_name: "web"
    restart: "unless-stopped"
    image: "nginx:alpine"
    ports:
      - "8080:80"
    network_mode: "bridge"

The service is named app in YAML; --name supplies container_name. The quoted port mapping keeps host port 8080 separate from container port 80. Restart policy is retained, -d is reported as an execution-time choice, and bridge networking is explicit.

Masked environment, named volume and external network

docker run --name database -e POSTGRES_PASSWORD=demo-only -e APP_MODE=first -e APP_MODE=final -v pgdata:/var/lib/postgresql/data --network app-net postgres:16
services:
  app:
    container_name: "database"
    networks:
      - "network_1"
    image: "postgres:16"
    volumes:
      - type: "volume"
        target: "/var/lib/postgresql/data"
        read_only: false
        source: "volume_1"
    environment:
      POSTGRES_PASSWORD: "[REDACTED]"
      APP_MODE: "[REDACTED]"
volumes:
  volume_1:
    name: "pgdata"
networks:
  network_1:
    name: "app-net"
    external: true

Both environment values are masked, and APP_MODE keeps its final assignment when revealed. The volume retains the Docker name pgdata. The app-net network is external and must already exist; conversion does not inspect database data or validate this image’s storage requirements.

Read-only bind with a literal shell argument

docker container run -it --mount type=bind,src=/srv/project,target=/app,readonly -w /app -u 1000:1000 --entrypoint /bin/sh alpine:3.20 -c 'printf %s "$HOME"'
services:
  app:
    stdin_open: true
    tty: true
    working_dir: "/app"
    user: "1000:1000"
    entrypoint:
      - "/bin/sh"
    image: "alpine:3.20"
    command:
      - "-c"
      - "printf %s \"$$HOME\""
    volumes:
      - type: "bind"
        target: "/app"
        read_only: true
        source: "/srv/project"
        bind:
          create_host_path: false
    network_mode: "bridge"

The --mount bind does not request creation of a missing host directory. The user, working directory, interactive input and TTY remain explicit. The outer single quotes make $HOME literal during parsing; Compose receives $$HOME so it does not interpolate the value before the container’s shell sees it.

Common conversion mistakes

  • Using -e NAME or --env-file: the tool cannot read your shell environment or local files. Supply explicit literal assignments in a supported command.
  • Pasting --rm, --privileged, resource limits or other unlisted flags: unsupported options fail the entire conversion instead of disappearing from the result.
  • Treating ./data:/data or C:\data:/data as a portable bind mount: use a supported absolute Linux source and inspect the target host yourself.
  • Running YAML with [REDACTED] values or sharing a raw export without review: replace placeholders securely and check secrets outside environment values.
  • Assuming a successful parse proves deployment will work: validate images, networks, volumes, host paths, permissions and Compose compatibility separately.

Limits and notes

  • Input is limited to 100,000 characters and 2,000 shell words. The parser accepts a conservative literal POSIX subset, not a full shell. It rejects sudo prefixes, shell expansion, substitutions, unescaped command separators, redirects, pipelines and PowerShell/CMD syntax. Quoted literal dollar signs are escaped for Compose.
  • Supported options are --name, -p/--publish, -v/--volume, --mount for bind or volume, -e/--env with explicit KEY=VALUE, --restart, --network/--net, -w/--workdir, -u/--user, --entrypoint, -d/--detach, -i/--interactive and -t/--tty. Unknown options, --rm, --env-file, environment lookups and restart retry counts are rejected. Options after the image are container command arguments.
  • Ports must be 1–65535, optionally with tcp, udp or sctp, an IPv4 host, and equal-length host/container ranges. Container-only ports are accepted. IPv6, port zero and empty host-port forms are unsupported. Host or none networking cannot be combined with published ports.
  • Bind paths must be absolute Linux paths; relative paths and Windows drive paths are rejected. Volume names require at least two supported characters; anonymous volumes are accepted. Mount targets must be absolute and cannot be /. --mount accepts only type, source/src, target/dst/destination and readonly/ro; it does not parse CSV-quoted commas or advanced mount options. The output explicitly uses network_mode: bridge when no network is supplied. Named networks are external, and named volumes retain their Docker names rather than acquiring a Compose project prefix. Docker resources, image defaults, runtime permissions and platform compatibility cannot be checked by this text-only converter.
  • Masking covers every environment value in the preview and exports, including empty values. It does not hide the input, variable names, command arguments, image names, mount paths or other fields. Masking is not complete secret detection, and a masked draft is not ready to deploy.

Frequently asked questions

Why does the YAML contain bridge networking?

Docker run uses the default bridge when no network is specified, while Compose normally creates a project network. The converter writes network_mode: bridge to preserve the original choice. Change it deliberately if your Compose setup needs service-name discovery or a project-specific network.

What happens to repeated environment variables and secrets?

Repeated assignments to the same variable keep the last value and produce a warning. The default YAML masks all environment values. Revealing values includes them in preview, copies and downloads; modifying the command restores masking. Secrets in other fields still need manual review.

Are existing volumes and networks renamed or created?

Named volumes receive generated Compose keys but retain their original Docker name through the name property. Compose can create a missing named volume; this tool does not check existing data. Named networks are declared external and must already exist. Bind mounts retain whether the original -v or --mount form allows creating a missing host directory. These volumes are Compose-managed rather than external, so docker compose down -v can remove them. Back up data and review lifecycle commands.

Why are -d and entrypoint handled differently?

Detached execution is a command-line choice, so -d becomes a warning rather than a service property. An explicit entrypoint is emitted as a list and clears the image’s default CMD when no command is supplied. Command arguments after the image are preserved as a list, including empty arguments.

Related tools