tfstate-drift-inspector

Nightly Terraform drift detection with Slack alerts and auto remediation PRs. Find silent drift before it causes outages.

Terminal — nightly scan
$ drift-inspector scan-all workspace.json
Scanning 3 workspaces...
 
infra-prod — 0 drift items
infra-staging — 3 drift items
    🔴 aws_security_group.bastion — deleted (security risk)
    🟠 aws_instance.worker — instance_type changed t3→m5
    🟡 aws_s3_bucket.logs — tags modified
 
Sent alert to #infra-alerts • Created PR #442
Critical
High
Medium
Low
🔍

Nightly Drift Scans

Automated terraform plan against every workspace. Detects resources added, removed, or changed outside IaC.

🔴

Smart Severity

Security groups, IAM, and databases flagged as critical. Tags and metadata filtered out automatically.

💬

Slack Alerts

Structured notifications with severity counts, top items, and direct links to the affected resources.

🔀

Auto Remediation PRs

One-click PR creation with full drift analysis, terraform plan output, and remediation checklist.

📊

Drift History

Track drift trends over time. Identify workspaces that drift most and root cause recurring issues.

🔒

GitHub App Auth

Install as a GitHub App on your org. No personal tokens to rotate. Scoped to specific repos.

GitHub Webhook │ ▼ ┌─────────────────────────────────────────────────────┐ │ FastAPI Server │ │ https://drift.yourdomain.com │ ├─────────────────────────────────────────────────────┤ │ /scan │ /scan-all │ /history │ /webhook/gh │ └────┬────┴──────┬──────┴─────┬──────┴───────┬───────┘ │ │ │ │ ▼ ▼ │ │ ┌──────────────────────┐ │ │ │ DriftEngine │ │ │ │ (terraform plan + │ │ │ │ parse + classify) │ │ │ └──────┬───────────────┘ │ │ │ │ │ ┌───┼───┐ │ │ ▼ ▼ ▼ │ ┌──────┐ ┌────────┐ ┌────────────┐ │ │Slack │ │GitHub │ │ PostgreSQL │◀──────┘ │Alert │ │PR │ │ History │ └──────┘ └────────┘ └────────────┘
Free
$0
forever
  • 3 workspaces
  • Weekly scans
  • Email alerts
  • Community support
Get Started
Business
$499
/month
  • Unlimited workspaces
  • Real-time (webhook) scans
  • Slack + Teams
  • Auto PRs + approvals
  • Unlimited history
  • SOC2 evidence export
  • SSO / SAML
  • Dedicated support
Contact Sales