Self-hosted configuration-drift detection

Know what's actually running.

You already diff Terraform on a schedule. That catches fields that changed on resources you declared. It misses the console change nobody merged back, the resource no state file mentions, and who made either, and it stops at one cloud. Cloudkeel-DD covers those, from inside your own cluster. It never touches your cloud. That's the point.

Read-only, alwaysRuns in your clusterAzure · AWS · GCP · K8s
real-azure · dev
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.7
$ kubectl port-forward svc/dd-frontend 3000:3000
✓ scanning real-azure (24 resources)
! DRIFT  nsg/web-nsg  ingress 0.0.0.0/0 added — critical
! UNMANAGED  sg "temp-debug" — in no state file
✓ evidence recorded · owner notified

Terraform tells you what should exist. Not what does.

The incident fix

A console click during an outage that never made it back into code.

The test resource

A hand-made resource that outlived the test it was created for.

The widened rule

A security rule opened to unblock someone, and quietly left open.

The kubectl edit

A live edit to a running workload that Git never saw.

terraform plan only checks resources already in state, only when you run it, and it never sees unmanaged resources at all.

And each cloud’s own answer stops at its border: Azure Policy, AWS Config and GCP Asset Inventory are each scoped to one cloud, each with their own query language, and none of them speak Terraform, so the check becomes a wiki page that reads differently for every cloud and is stale for all of them. Cloudkeel-DD is one lens and one finding format across all three, plus Kubernetes.

The three questions your IaC cannot answer.

AWS
Azure
GCP
AKS
EKS
GKE

Every finding carries severity, category, owner, and history, not just "something changed."

Your credentials never leave your cluster.

No SaaS. No vendor holding keys to your estate. All findings and credentials stay in your PostgreSQL, encrypted with a key only your install holds.

  • Read-only, always: never creates, updates, or deletes; never runs terraform apply.
  • Least privilege, documented: the exact permissions per cloud are published.
  • Kubernetes Secret values are never read or diffed.

A signal you won't mute in week two.

Severity gating you control

You define what "serious" means: by resource type, environment, and property. Most-specific rule wins.

False drift, engineered out

Semantic comparison absorbs rule coalescing, protocol aliases, and defaulted fields. Tag-only changes are ignored.

Suppression with accountability

A reason is required, suppressions carry an expiry and auto-reopen, and maintenance windows are scoped in time.

Routed to the right team

Slack or webhook, filtered by severity, category, and owner, not one firehose channel.

One tool across the whole right side of your SDLC.

Code / Reviewpre-merge policy gate
Deploypost-deploy scan trigger
Operatedrift · unmanaged · policy
Respondwho changed it · revert plans
Back to Coderemediation + Codify import PRs
findings flow back into code as pull requests →

Pipeline scanners see code before it ships. Cloudkeel-DD sees reality after, and nothing else covers the after.

Honesty is a feature

Exactly where our depth ends.

Coverage is not one number, and we publish where it ends. 200 resource types get a true field-level diff; how many you get depends on where your Terraform state lives, not on which cloud you run, so here are both answers.

Terraform Cloud68 Azure types, 59 GCP types, and AWS security groups (field-level).
Raw .tfstate77 Azure, 62 AWS, and 59 GCP types (field-level). S3, GCS, or Azure Blob. This is the path that unlocks AWS depth.
KubernetesDeployments, StatefulSets, DaemonSets, Services, ConfigMaps, Ingress: from Helm's own release records. No Argo or Flux required.
Everything elseDiscovered and tracked as clearly-labelled inventory, never assumed clean.

We'd rather show you the edge of our coverage than sell you the word "complete." See the full table →

One meter. No surprises.

Free
$0forever

1 scope · 3 users · every feature · no key needed

most teams
Team
$79/ scope / mo

2–20 scopes · 25 users · every feature · email support

Enterprise
from $20K/yr

Custom scopes · priority support · procurement

Pay per enabled scope: a subscription, account, project, or cluster. No per-resource charges, ever. See pricing →

Two ways to see your own estate.

Install it yourself, or have us walk you through it; both end in real findings from your own estate.

Public chart · inspect first

Run it yourself

quickstart
$ helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.7$ kubectl port-forward svc/dd-frontend 3000:3000
Install in 15 minutes

read-only credentials · runs in your cluster

Guided first step

Drift Audit

We install Cloudkeel-DD read-only alongside your team, scan your Terraform estate and clusters, and walk you through everything that's drifted.

  1. 01
    Deploy read-onlyone Helm chart, your cluster
  2. 02
    Scanstate and releases vs live cloud + K8s
  3. 03
    Report + walkthroughevery finding, severity, identity
Book your 20-minute scoping call

the report is yours to keep either way

Read-only, alwaysRuns in your clusterNo per-resource pricing
Install in 15 minutes