Comparison

Cloudkeel-DD vs Terracotta AI

Terracotta audits every Terraform and Kubernetes pull request for security, cost, and drift; PR-time governance, not estate inspection. It doesn't claim unmanaged-resource discovery, and its Kubernetes check never touches a live cluster. Every claim here is sourced from Terracotta's own site.

Terracotta is the closest competitor on this site, and it competes on a different axis than the other two comparisons here. Firefly and Spacelift both do drift detection the same way we do: read the live cloud, compare it to something declared. Terracotta’s headline motion is different: every pull request audited for security, cost, compliance and drift, delivered as PR comments and committable fixes before anything merges. This page says where that axis genuinely overlaps ours, and where it does not.

Every claim about Terracotta below is from their own pricing page and product pages, linked at the bottom.

What actually overlaps

More than we expected going in. Terracotta’s Drift Detection is not limited to PR review; it runs scheduled, continuous scans (hourly, daily or weekly per repo) that compare Terraform state against the live cloud on AWS, GCP and Azure, the same category of check we run. Their coverage page claims 1,618 AWS resource types in their comparison engine.

Their drift lifecycle also mirrors ours more closely than we expected: findings move through Active → Acknowledged → Suppressed → Resolved, and a suppression carries a configurable expiry (7/30/90 days, or indefinite), the same “suppress with an expiry, not a permanent mute” shape our own suppression model uses.

And neither tool auto-applies a fix to your live cloud without a human in the loop. Terracotta’s “Fix All” and “Committable fix” actions land as a commit suggestion on the pull request. You still merge it. Ours land as a pull request you review. Different mechanics, same posture: a person merges the change, always.

Where we actually differ

Where that leaves you

Cloudkeel-DDTerracotta AI
Drift on managed resourcesYes: AWS, Azure, GCP, scheduled scansYes: AWS, Azure, GCP, scheduled scans, 1,618 AWS types claimed
Unmanaged resource discoveryYes: AWS, Azure, GCPNot claimed on any page read
KubernetesLive cluster read: Helm, ArgoCD, Flux, sixteen kindsPR-time manifest/Helm/Kustomize scan by content, no cluster access
Change attribution: who made itBest-effort, native cloud audit logs, within a lookback windowNot documented on the pages we read
Cloud write accessNone: read-only, enforced in codeNot documented as writing to the cloud; fixes commit to the PR branch
Remediation modelReviewed pull request, alwaysCommittable PR suggestion, “Fix All” on grouped root causes
Cost governanceNonePer-resource estimates, budget enforcement, plain-English guardrails
DeploymentSelf-hosted Helm chart, the only modeSaaS (GitHub/GitLab app); self-hosted/VPC is Enterprise-only
Compliance certificationsNoneSOC 2 Type II, HIPAA
Entry pricingFree forever: 1 scope, 3 users, every featureFree: 1 private repo (20 PRs/mo), 5 seats, drift on 1 repo
Next tierTeam: $79/enabled scope/mo (annual) or $99 month-to-monthPlatform: $49/engineer/mo, unlimited repos and seats

The difference that actually matters

Terracotta governs the change. Cloudkeel-DD inspects the estate.

Even with its scheduled drift scans, Terracotta’s model still starts from something declared: a Terraform resource, a Kubernetes manifest in a repo it watches. A resource nobody ever wrote code for, or a workload someone kubectl apply’d by hand outside any pipeline, has no PR and no declared state for Terracotta to compare against or govern. That is the entire category Cloudkeel-DD leads with, and it is structural: PR-time governance cannot reach infrastructure that never went through a PR.

The cost is real, and it is the same cost we named on the other two comparison pages: Terracotta ships cost governance, plain-English policies, and two compliance certifications we do not have. If a regulated buyer’s actual blocker is “we need SOC 2 before we can even evaluate a vendor,” Terracotta clears that bar today and we do not.

Where Terracotta is ahead

Said plainly, because a comparison that only lists our wins is an advert.

What we do not do

The limits, in the same breath as the claims:

Which one to pick

Choose Terracotta if your primary pain is PR-time governance (catching a bad Terraform or Kubernetes change, its cost, and its policy violations before it merges) and you want cost estimation, plain-English guardrails, and SOC 2 / HIPAA compliance without running anything yourself.

Choose Cloudkeel-DD if you want to know what is actually running in your cloud right now, including the resource nobody wrote a PR for and the console change nobody merged back, entirely inside infrastructure you already control, without sending credentials to a SaaS vendor to get it.

What about the clouds’ own tools?

Azure Policy, AWS Config and GCP Asset Inventory each answer part of this: inside their own cloud, in their own query language, without reference to your Terraform. If your estate is one cloud, evaluate them first; they are already paid for. If it spans clouds, the check becomes three different checks, and none of them can say “this resource is in no Terraform state”, because that comparison needs your state, which is the input they do not take.

Read more

Sources

Read 2026-08-28. If any of this has changed, tell us and we will correct it: a comparison that goes stale is worse than none.