Spacelift orchestrates Terraform runs. Cloudkeel-DD reads what your Terraform does not declare. Both do drift detection on resources you declared, and diverge on everything either side of it, so the comparison is only useful if it says which job you are actually hiring for.
Every claim about Spacelift below is from their own pricing page or documentation, linked at the bottom. Where they are ahead, it says so.
Start with the gap
A scheduled plan check catches fields that changed on resources you declared. Two things sit outside it entirely:
-
Resources no state file mentions.
terraform planstructurally cannot see them, because they are absent from state. Spacelift’s pricing page lists Unmanaged Resources as coming soon, on Enterprise+. We ship it today for AWS, Azure and GCP, with a caveat below. -
The cluster. Workloads that no chart or application owns. We read the live cluster across Helm, ArgoCD and Flux; Spacelift reaches Kubernetes through IaC orchestration rather than as a cluster-native lens.
-
Who made it. A plan diff says what changed, never who. We read the native cloud audit logs (Azure Activity Log, AWS CloudTrail, GCP Audit Logs) on a best-effort basis within a lookback window. Spacelift’s drift documentation names external actors as a cause of drift and gives no way to identify them.
Where they differ
Ordered by the gap first, then by what each tool is allowed to do about it.
| Cloudkeel-DD | Spacelift | |
|---|---|---|
| Unmanaged resource discovery | Yes (AWS, Azure, GCP) | Listed as “Unmanaged Resources (coming soon)”, Enterprise+ |
| Kubernetes | Live cluster read: Helm, ArgoCD, Flux, sixteen kinds | Via IaC orchestration, not a Kubernetes-native lens |
| Change attribution: who made it | Best-effort, all three clouds, within a lookback window | Not mentioned in their drift documentation |
| Drift on managed resources | Yes | Yes, Starter and above (private workers only) |
| Cloud write access | None (read-only, enforced in code) | Applies runs |
| Remediation | Reviewed pull request, never an unattended write | Apply |
| Deployment | Self-hosted Helm chart, standalone | SaaS; self-hosted on Enterprise+ only |
| Entry price | Not set (pilot stage) | Free tier; Starter and above from $20,000/yr |
The difference that actually matters
Spacelift applies. We do not.
That is not a limitation we are apologising for. A tool that can apply needs
credentials that can write to your cloud, and that is the thing a security
review spends its time on. Cloudkeel-DD holds read-only credentials, in your
own cluster, and the read-only guarantee is enforced in code rather than
promised in a policy document: "apply" sits in a denied-prefix list, checked
both at runtime and by a static gate.
The cost is real: we cannot fix anything for you. Remediation ships as a pull request against your repository, which your engineers review and merge on your schedule. If you want drift corrected automatically, Spacelift does that and we never will.
Where Spacelift is ahead
Said plainly, because a comparison that only lists our wins is an advert.
- They orchestrate; we observe. If your problem is “our Terraform runs are chaotic”, Spacelift addresses it directly and we do not address it at all.
- They have a free tier and public pricing. We are pre-launch and our pricing is not set.
- They are an established product with public customers. We have none, and no SOC 2. Against a regulated buyer that is a procurement blocker, and no amount of self-hosting substitutes for it.
- Their onboarding is lighter. Spacelift is a SaaS signup. Ours is
helm install, three generated secrets, then per-integration credential wiring. That is materially more work on day one.
What we do not do
The limits, in the same breath as the claims:
- Unmanaged detection needs a Terraform state source. Something has to define “managed”. A cloud credential on its own produces nothing.
- Attribution is best-effort and can fail quietly. If the IAM permission it needs is missing, the actor is simply absent and nothing on screen says why.
- Kubernetes coverage is sixteen kinds, not arbitrary custom resources.
- Codify emits a Terraform
import{}block only, never a resource body. - No PDF export. CSV exists, is generated in the browser, and carries aggregate report metrics only; there is no per-finding export in any format.
- No cost governance and no pull-request-time gate. If your actual pain is “someone merged an oversized instance”, we do not help.
- Scans are point-in-time, on a schedule you set. This is not a live feed and we will not describe it as one.
- Nothing phones home: no telemetry, no analytics, no licence server, and it runs air-gapped. But three paths do carry finding data outward when you configure them: notification webhooks, and the GitHub and GitLab integrations that open remediation pull requests. We will not tell you nothing leaves your environment, because that would not be true.
Which one to pick
Choose Spacelift if you want your Terraform runs orchestrated and gated in one place, and you are comfortable with a platform that holds apply-capable credentials.
Choose Cloudkeel-DD if you need to know what your cloud is actually running (including the parts Terraform never declared) without granting write access to anything, and you would rather run it yourself than send your estate to a vendor.
They are not mutually exclusive. Nothing about running Spacelift stops you reading your own estate.
What about the clouds’ own tools?
Azure Policy, AWS Config and GCP Asset Inventory each answer part of this: inside their own cloud, in their own query language, without reference to your Terraform. If your estate is one cloud, evaluate them first; they are already paid for. If it spans clouds, the check becomes three different checks, and none of them can say “this resource is in no Terraform state”, because that comparison needs your state, which is the input they do not take.
Read more
- What Cloudkeel-DD is: the product page
- Exactly where the depth ends: coverage, generated from the engine
- Install it yourself: no call, no account
Sources
- Spacelift pricing tiers and “Unmanaged Resources (coming soon)”: spacelift.io/pricing
- Spacelift drift mechanism, proposed runs, private-workers requirement: docs.spacelift.io/concepts/stack/drift-detection
Read 2026-07-31; re-read for change attribution 2026-08-15. If any of this has changed, tell us and we will correct it: a comparison that goes stale is worse than none.