DevOps

Infrastructure Drift Checker

An infrastructure drift checker compares the configuration you declared (Terraform, YAML, JSON or .env) with the state actually running, and reports every attribute that was added by hand, removed, or changed. It is a genuine key-by-key diff, and it highlights the changes that touch security: network exposure, encryption, IAM and sizing.

Last reviewed by the Radiatus Cloud team

Want this automated for your stack?

We build CI/CD, Kubernetes & IaC pipelines that scale.

Talk to an engineer

What drift is and why it matters

Drift is the gap between what your code says infrastructure should be and what it actually is, created when someone changes a setting in the console instead of in code. It is dangerous because the change is invisible to review: a security group opened to the world, an instance resized, encryption switched off, none of it shows up in a pull request. The next terraform apply may silently revert it, or preserve it, depending on how the code is written.

How the diff works

The tool parses key/value attributes out of both sides, handling Terraform resource blocks, YAML indentation, .env lines and JSON. It then compares the two flattened maps and classifies each attribute as changed, unmanaged (present in reality but not in code), or missing (in code but not observed). Case and quote differences can be ignored so that "t3.large" and t3.large are treated as equal.

The security highlight

Rows whose attribute or value touches public access, 0.0.0.0/0, security groups, ingress, encryption, KMS, IAM, policies, passwords, secrets, instance sizing or replica counts are highlighted, because those are the changes that turn drift into an incident. An unmanaged security_group_open_world attribute is exactly the finding this is built to surface.

Scope

It compares text you paste; it does not connect to your cloud. Generate the observed state with terraform plan, terraform show, or your provider's describe commands, paste both sides, and read the diff. Everything stays in the browser.

Related tools

  • Config Drift Compare — Compare baseline vs current config.
  • K8s Manifest Auditor — A new tool extracted from the codebase.
  • Chmod Calculator — Toggle read, write and execute for owner, group and others to get the octal chmod number, the symbolic string and the ready command. Understand what each permission actually allows.
  • YAML JSON Converter — Convert YAML to JSON and JSON to YAML in your browser. Handles anchors, multi-line strings and the classic YAML type-coercion traps.

Frequently Asked Questions

Does it connect to my cloud account?

No. It diffs two blocks of text you paste. Produce the observed state with terraform plan or show, or your cloud provider's describe or get commands, and paste it against your declared configuration.

What formats can it parse?

Terraform HCL resource blocks, YAML, JSON and .env-style key=value lines. It flattens each into attribute paths and compares them, so mixed formats on the two sides still diff.

What does unmanaged mean in the results?

An attribute present in the observed state but absent from your code, meaning someone set it by hand. These are the drift items most likely to be reverted unexpectedly or to hide a manual security change.

Why are some rows highlighted?

Because their attribute or value touches security: public access, security groups, encryption, IAM, secrets or sizing. Those are the changes where drift becomes a real exposure, so they are marked for attention.

Can it ignore formatting differences?

Yes. With the case-and-quotes option on, values that differ only in quoting or capitalisation are treated as equal, so you see real configuration changes rather than cosmetic ones.

Privacy & Security

Comparison done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.