AWSCRITICAL
aws_s3_bucket.customer_exports
declaredacl private+ actualacl public-readchanged_byiam::…:user/j.doe · 14:32 UTC
Bucket opened to public reads
drift · who changed it
You already diff Terraform on a schedule. That catches fields that changed on resources you declared. It misses the console change nobody merged back, the resource no state file mentions, and who made either, and it stops at one cloud. Cloudkeel-DD covers those, from inside your own cluster. It never touches your cloud. That's the point.
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.7 $ kubectl port-forward svc/dd-frontend 3000:3000 ✓ scanning real-azure (24 resources) ! DRIFT nsg/web-nsg ingress 0.0.0.0/0 added — critical ! UNMANAGED sg "temp-debug" — in no state file ✓ evidence recorded · owner notified
A console click during an outage that never made it back into code.
A hand-made resource that outlived the test it was created for.
A security rule opened to unblock someone, and quietly left open.
A live edit to a running workload that Git never saw.
And each cloud’s own answer stops at its border: Azure Policy, AWS Config and GCP Asset Inventory are each scoped to one cloud, each with their own query language, and none of them speak Terraform, so the check becomes a wiki page that reads differently for every cloud and is stale for all of them. Cloudkeel-DD is one lens and one finding format across all three, plus Kubernetes.
Every finding carries severity, category, owner, and history, not just "something changed."
No SaaS. No vendor holding keys to your estate. All findings and credentials stay in your PostgreSQL, encrypted with a key only your install holds.
You define what "serious" means: by resource type, environment, and property. Most-specific rule wins.
Semantic comparison absorbs rule coalescing, protocol aliases, and defaulted fields. Tag-only changes are ignored.
A reason is required, suppressions carry an expiry and auto-reopen, and maintenance windows are scoped in time.
Slack or webhook, filtered by severity, category, and owner, not one firehose channel.
Pipeline scanners see code before it ships. Cloudkeel-DD sees reality after, and nothing else covers the after.
Coverage is not one number, and we publish where it ends. 200 resource types get a true field-level diff; how many you get depends on where your Terraform state lives, not on which cloud you run, so here are both answers.
We'd rather show you the edge of our coverage than sell you the word "complete." See the full table →
1 scope · 3 users · every feature · no key needed
2–20 scopes · 25 users · every feature · email support
Custom scopes · priority support · procurement
Pay per enabled scope: a subscription, account, project, or cluster. No per-resource charges, ever. See pricing →
Install it yourself, or have us walk you through it; both end in real findings from your own estate.
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.7$ kubectl port-forward svc/dd-frontend 3000:3000
read-only credentials · runs in your cluster
We install Cloudkeel-DD read-only alongside your team, scan your Terraform estate and clusters, and walk you through everything that's drifted.
the report is yours to keep either way