Cloudkeel-DD finds drift, unmanaged resources and policy violations across Terraform, Kubernetes and cloud — from inside your own cluster. It never touches your cloud. That's the point.
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.0$ kubectl port-forward svc/dd-frontend 3000:3000
Public chart. No form, no account, no call.
A field that no longer matches the Terraform that declared it — the exact property, the old value, the new one.
Live infrastructure no Terraform state claims. The category terraform plan structurally cannot see.
Rules you define, evaluated against what is actually running rather than against the plan.
Best-effort attribution from cloud activity logs, within a lookback window.
Every finding carries severity, category, owner and history — not just "something changed." See the whole product →
The scanner never creates, updates or deletes, and never runs terraform apply. Remediation arrives as pull requests you review.
Everything runs in your environment under credentials you hold — the product and the engagements alike.
Comparison depth differs by resource type and by where your state lives. The table is generated from the code, not written by hand.
We are pre-launch: no customers yet, and no SOC 2. Where the software's depth ends is published and generated from the code.
Two paid engagements sit alongside the product. Neither is a trial of it and neither gates it — the install above is a complete path on its own.
Install it and get real findings from your own estate before you speak to anyone — or book a call and we will tell you whether an engagement is worth doing at all.