Container Build Graph
This local, bounded analyzer reads a Dockerfile as text. It links stages referenced by FROM and COPY --from, checks local COPY/ADD sources against the effective context file list you enter, and shows which stages are dependencies of a selected target. A changed listed file highlights a conservative downstream impact path. External image and named-context references remain unverified; it never builds an image, runs RUN, reads your filesystem, contacts a registry or certifies Docker behavior.
Key features
- Resolve named and numeric stage references for FROM/AS and COPY --from
- Show target reachability and unused stages as a visual graph and accessible edge table
- Check literal and simple * / ? local sources against a user-supplied effective context list
- Flag missing listed sources, invalid numeric stages, forward aliases, duplicate aliases and cycles
- Trace a listed changed file through direct context copies and dependent stages
- Download a bounded JSON report or Graphviz DOT without executing the Dockerfile
How to use
- Load the three-stage example or paste a bounded Dockerfile.
- List files actually available in the effective build context, one path per line; optionally name a changed listed file.
- Analyze, then choose a target stage to update reachability and inspect errors, warnings, graph edges and possible impact.
- Download JSON or DOT for a local review; verify real builds separately with Docker.
Use cases
- Review whether a final stage depends on a builder stage
- Spot a missing context file before attempting a local COPY
- See why changing src/index.ts may affect build and runtime but not deps
- Distinguish an external COPY image from an invalid numeric stage reference
Frequently asked questions
Does this run docker build or any RUN line?
No. The parser only reads text in the browser. It never builds an image, executes instructions, fetches an image or sends the Dockerfile to a tool API.
Is an unknown COPY --from name always a missing stage?
No. Docker can copy from an external image or named context. This tool marks an unresolved name as an unverified external source. A numeric stage index outside earlier stages or an alias defined later is diagnosed separately.
What does the context list mean?
Enter effective files available to the build after any ignore rules. The tool does not inspect local folders or evaluate .dockerignore. An empty list makes local source checks unverified rather than missing.
Does the impact path predict exact Docker cache hits?
No. It is a conservative static dependency path from a selected listed file. Actual cache checks depend on content, metadata, build arguments, base images, mounts, COPY flags and builder version.
Why do some Dockerfiles show unsupported syntax warnings?
The parser handles a documented subset of default-escape Dockerfiles. Dynamic variables, complex globs, heredocs, ONBUILD, RUN mounts and unusual COPY options cannot be fully interpreted here; review them with Docker.
Privacy
Dockerfile text and context paths remain in browser memory. JSON/DOT are created only when you click download. The report omits raw RUN commands. No upload, registry lookup or command execution occurs.
Comments & questions