Terraform drift

Terraform Drift Detection

Terraform tells you what should exist. It never tells you what does. Cloudkeel-DD reads your Terraform desired state and the live cloud independently, on a schedule, and diffs them field by field, wherever your state actually lives.

Where a plan runs, and where drift actually happens

terraform plan and terraform apply happen when someone runs them. Drift happens continuously, between applies, and nobody is watching in between unless something is.

Desired state, read from wherever it lives

Terraform Cloud / Enterprise

Reads the workspace’s plan JSON over the API, including resources Terraform’s own refresh already found drifted.

Raw .tfstate

S3, a GCS bucket, or an Azure Storage account. The state file itself is the desired-state source, read directly.

A local plan file

terraform plan -out=plan.tfplan, uploaded once, read the same way as the hosted path.

What a clean plan output does not tell you

"terraform plan came back clean"

A plan only compares resources already in state. A console click, a script, or an automation that never touched Terraform leaves no trace for it to see.

"we don’t know what changed, or who"

Plan output says a field differs. It never says which engineer, which service account, or when. Cloudkeel-DD reads the cloud’s own audit log (Azure Activity Log, AWS CloudTrail, GCP Audit Logs) on a best-effort basis to answer that.

"our state is split across three places"

Real estates keep Terraform Cloud workspaces, raw state in a bucket, and a plan file someone runs by hand, all at once. Detection that assumes one workspace system misses the other two by construction.

The gap that matters most is what never entered state at all. A resource nobody declared in Terraform is invisible to terraform plan by construction, not by bug: there is nothing in state to compare it against. That is a separate detection mechanism (unmanaged resource discovery), not a deeper Terraform diff.

Further reading

How other Terraform drift tools compare

Every comparison below is sourced from the other vendor’s own pricing page or documentation.

Install in 15 minutes