AWSCRITICAL
aws_s3_bucket.customer_exports
declaredacl private+ actualacl public-readchanged_byiam::…:user/j.doe · 14:32 UTC
Bucket opened to public reads
drift · who changed it
Cloudkeel-DD finds drift, unmanaged resources, and policy violations across Terraform, Kubernetes, and cloud — from inside your own cluster. It never touches your cloud. That's the point.
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.0 $ kubectl port-forward svc/dd-frontend 3000:3000 ✓ scanning real-azure (24 resources) ! DRIFT nsg/web-nsg ingress 0.0.0.0/0 added — critical ! UNMANAGED sg "temp-debug" — in no state file ✓ evidence recorded · owner notified
A console click during an outage that never made it back into code.
A hand-made resource that outlived the test it was created for.
A security rule opened to unblock someone, and quietly left open.
A live edit to a running workload that Git never saw.
Every finding carries severity, category, owner, and history — not just "something changed."
No SaaS. No vendor holding keys to your estate. All findings and credentials stay in your PostgreSQL, encrypted with a key only your install holds.
You define what "serious" means — by resource type, environment, and property. Most-specific rule wins.
Semantic comparison absorbs rule coalescing, protocol aliases, and defaulted fields. Tag-only changes are ignored.
A reason is required, suppressions carry an expiry and auto-reopen, and maintenance windows are scoped in time.
Slack or webhook, filtered by severity, category, and owner — not one firehose channel.
Pipeline scanners see code before it ships. Cloudkeel-DD sees reality after — and nothing else covers the after.
200 resource types get a true field-level diff. How many you get depends on where your Terraform state lives, not on which cloud you run — so here are both answers.
We'd rather show you the edge of our coverage than sell you the word "complete." See the full table →
5 scopes · 5 users · all connectors · CI/CD gates
15 scopes · 15 users · priority support
Custom scopes · SLA · procurement
Pay per enabled scope — a subscription, account, project, or cluster. Dev scopes are half price, your first three free. No per-resource charges, ever. See pricing →
Install it yourself, or have us walk you through it — both end in real findings from your own estate.
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.0$ kubectl port-forward svc/dd-frontend 3000:3000
read-only credentials · runs in your cluster
We install Cloudkeel-DD read-only alongside your team, scan your Terraform estate and clusters, and walk you through everything that's drifted.
the report is yours to keep either way