Cloudkeel-DD · self-hosted drift detection

Terraform tells you what should exist. We tell you what does.

You already diff Terraform on a schedule. That catches fields that changed on resources you declared. It misses the console change nobody merged back, the resource no state file mentions, and who made either; and it stops at one cloud. Cloudkeel-DD covers those, from inside your own cluster. It never touches your cloud. That's the point.

Read-only, alwaysRuns in your clusterAzure · AWS · GCP · K8s
quickstart
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.7$ kubectl port-forward svc/dd-frontend 3000:3000

Public chart. No form, no account, no call. Runs unmetered for 30 days, then settles onto the Free plan: 1 scope, 3 users, every feature, forever. Nothing stops, nothing is deleted.

200 resource types, fixture-verified · 3 real-cloud-proven (Azure, AWS, GCP) · Zero Cloudkeel-DD-operated endpoints · ~15 minutes to first finding

What your plan check misses.

Drift

The security group opened by hand during an incident, still open. The exact property, the old value, the new one.

Unmanaged resources

The contractor’s VM, the “temporary” bucket from 2024. Live infrastructure no state file claims: the category terraform plan structurally cannot see.

Policy violations

Rules you define, evaluated against what is actually running rather than against the plan.

Who changed it

The postmortem question that costs an afternoon in audit logs. Best-effort attribution from cloud activity logs, within a lookback window.

Every finding carries severity, category, owner and history, not just "something changed." See the whole product →

What you can count on.

Read-only by default

The scanner never creates, updates or deletes, and never runs terraform apply. Remediation arrives as pull requests you review.

Your credentials stay yours

Everything runs in your environment under credentials you hold: the product and the engagements alike.

We publish where the depth ends

Comparison depth differs by resource type and by where your state lives. The table is generated from the code, not written by hand.

Noise engineered out

Severity you define, by resource type and environment. Tag-only changes ignored by design. Suppressions need a reason, expire, and auto-reopen: a drift tool you won’t mute in week two.

We are pre-launch: no customers yet, and no SOC 2. Where the software's depth ends is published and generated from the code.

If you would rather not do it alone.

Two paid engagements sit alongside the product. Neither is a trial of it and neither gates it; the install above is a complete path on its own.

Both services, side by side →

See what your own estate is hiding.

Install it and get real findings from your own estate before you speak to anyone, or book a call and we will tell you whether an engagement is worth doing at all.

Install in 15 minutes