Terraform tells you what should exist. It never tells you what does. Cloudkeel-DD reads your Terraform desired state and the live cloud independently, on a schedule, and diffs them field by field, wherever your state actually lives.
terraform plan and terraform apply happen when someone runs them. Drift happens continuously, between applies, and nobody is watching in between unless something is.
Reads the workspace’s plan JSON over the API, including resources Terraform’s own refresh already found drifted.
S3, a GCS bucket, or an Azure Storage account. The state file itself is the desired-state source, read directly.
terraform plan -out=plan.tfplan, uploaded once, read the same way as the hosted path.
A plan only compares resources already in state. A console click, a script, or an automation that never touched Terraform leaves no trace for it to see.
Plan output says a field differs. It never says which engineer, which service account, or when. Cloudkeel-DD reads the cloud’s own audit log (Azure Activity Log, AWS CloudTrail, GCP Audit Logs) on a best-effort basis to answer that.
Real estates keep Terraform Cloud workspaces, raw state in a bucket, and a plan file someone runs by hand, all at once. Detection that assumes one workspace system misses the other two by construction.
terraform plan by construction, not by bug: there is nothing in state to compare it against. That is a separate detection mechanism (unmanaged resource discovery), not a deeper Terraform diff.Every comparison below is sourced from the other vendor’s own pricing page or documentation.