Self-hosted configuration-drift detection

Know what's actually running.

Cloudkeel-DD finds drift, unmanaged resources, and policy violations across Terraform, Kubernetes, and cloud — from inside your own cluster. It never touches your cloud. That's the point.

Read-only, alwaysRuns in your clusterAzure · AWS · GCP · K8s
real-azure · dev
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.0
$ kubectl port-forward svc/dd-frontend 3000:3000
✓ scanning real-azure (24 resources)
! DRIFT  nsg/web-nsg  ingress 0.0.0.0/0 added — critical
! UNMANAGED  sg "temp-debug" — in no state file
✓ evidence recorded · owner notified

Terraform tells you what should exist. Not what does.

The incident fix

A console click during an outage that never made it back into code.

The test resource

A hand-made resource that outlived the test it was created for.

The widened rule

A security rule opened to unblock someone, and quietly left open.

The kubectl edit

A live edit to a running workload that Git never saw.

terraform plan only checks resources already in state, only when you run it — and it never sees unmanaged resources at all.

Three answers, continuously.

AWS
Azure
GCP
AKS
EKS
GKE

Every finding carries severity, category, owner, and history — not just "something changed."

Your credentials never leave your cluster.

No SaaS. No vendor holding keys to your estate. All findings and credentials stay in your PostgreSQL, encrypted with a key only your install holds.

  • Read-only, always — never creates, updates, or deletes; never runs terraform apply.
  • Least privilege, documented — the exact permissions per cloud are published.
  • Kubernetes Secret values are never read or diffed.

A drift tool you won't mute in week two.

Severity gating you control

You define what "serious" means — by resource type, environment, and property. Most-specific rule wins.

False drift, engineered out

Semantic comparison absorbs rule coalescing, protocol aliases, and defaulted fields. Tag-only changes are ignored.

Suppression with accountability

A reason is required, suppressions carry an expiry and auto-reopen, and maintenance windows are scoped in time.

Routed to the right team

Slack or webhook, filtered by severity, category, and owner — not one firehose channel.

One tool across the whole right side of your SDLC.

Code / Reviewpre-merge policy gate
Deploypost-deploy scan trigger
Operatedrift · unmanaged · policy
Respondwho changed it · revert plans
Back to Coderemediation + Codify import PRs
findings flow back into code as pull requests →

Pipeline scanners see code before it ships. Cloudkeel-DD sees reality after — and nothing else covers the after.

Honesty is a feature

Exactly where our depth ends.

200 resource types get a true field-level diff. How many you get depends on where your Terraform state lives, not on which cloud you run — so here are both answers.

Terraform Cloud68 Azure types, 59 GCP types, and AWS security groups — field-level.
Raw .tfstate77 Azure, 62 AWS, and 59 GCP types — field-level. S3, GCS, or Azure Blob. This is the path that unlocks AWS depth.
KubernetesDeployments, StatefulSets, DaemonSets, Services, ConfigMaps, Ingress — from Helm's own release records. No Argo or Flux required.
Everything elseDiscovered and tracked as clearly-labelled inventory — never assumed clean.

We'd rather show you the edge of our coverage than sell you the word "complete." See the full table →

One meter. No surprises.

Starter
$299/mo

5 scopes · 5 users · all connectors · CI/CD gates

most teams
Team
$799/mo

15 scopes · 15 users · priority support

Enterprise
from $20K/yr

Custom scopes · SLA · procurement

Pay per enabled scope — a subscription, account, project, or cluster. Dev scopes are half price, your first three free. No per-resource charges, ever. See pricing →

Two ways to see your own drift.

Install it yourself, or have us walk you through it — both end in real findings from your own estate.

Public chart · inspect first

Run it yourself

quickstart
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.0$ kubectl port-forward svc/dd-frontend 3000:3000
Install in 15 minutes

read-only credentials · runs in your cluster

Guided first step

Drift Audit

We install Cloudkeel-DD read-only alongside your team, scan your Terraform estate and clusters, and walk you through everything that's drifted.

  1. 01
    Deploy read-onlyone Helm chart, your cluster
  2. 02
    Scanstate and releases vs live cloud + K8s
  3. 03
    Report + walkthroughevery finding, severity, identity
Book your 20-minute scoping call

the report is yours to keep either way

Read-only, alwaysRuns in your clusterNo per-resource pricing
Install in 15 minutes