Find which services fight over a host port
Paste the port lists from your compose file and every host:container entry is expanded into one row, then services sharing a host port are named in pairs. Ranges are expanded port by port before comparing, and a mapping with no host port is assigned one at run time, so it is left out of the clash check. The same number on a different protocol is not a clash.
Bind addresses count too. With no address the port opens on all interfaces, which covers the same number written for a specific address, while two different specific addresses do not collide. The difference between ports and expose is in the table below. Notation follows the Compose file specification, as of October 2026.
The tool does not parse a whole compose file. Long-form port blocks, variable substitution, profiles and host network mode are out of scope, and a host range whose length differs from the container range is reported as an error. Confirm the ports actually bound after the stack starts.
Frequently Asked Questions
If you write only the container port, the host port is assigned from the free range at run time. Because the number is not fixed in advance, the tool leaves it out of the clash check and counts it separately.
That counts as a clash. With no address the port opens on all interfaces, which overlaps the same number opened on a specific address. Two different specific addresses do not overlap.
ports opens a host port so clients outside can connect, while expose uses no host port and only containers on the same network reach the service. That is why expose alone never causes a host port clash.