drift
Catch console click-ops before they surprise you: compare live AWS state against Terraform, locally on demand or daily in CI with automatic GitHub Issues.
What it does
Section titled “What it does”driftrunsterraform init+terraform plan -detailed-exitcodeinterraform/and reports✅ No infrastructure drift detected(exit0),⚠ Infrastructure drift detected!with a resource summary (exit2), or a plan failure (exit1).drift --setup(alias:drift init) scaffolds.github/workflows/drift.ymlinto an existing project, reusing your deploy workflow’s OIDC role — no extra secrets needed.--setup-ci-driftscaffolds the same workflow duringgradascaffolding.- The scheduled workflow runs daily at 06:00 UTC (plus a manual
workflow_dispatchtrigger): on drift it opens (or updates, without spamming) a GitHub Issue labelediac-driftwith the plan diff; when drift resolves it comments✅ Drift resolvedand closes the issue. - Set a
SLACK_WEBHOOK_URLrepository secret to also post drift alerts to Slack. - Emits a
drift_runtelemetry event recording the action and outcome.
npx grada-run driftnpx grada-run drift --setupnpx grada-run drift --setup --forcenpx grada-run --setup-ci-drift| Flag | Description |
|---|---|
--setup |
Scaffold .github/workflows/drift.yml instead of running a local check. |
--force |
Overwrite an existing drift.yml on --setup. |
--region <region> |
Explicit AWS region override. |
--project-name <name> |
Explicit project name override (defaults to the name in terraform/main.tf, then the directory name). |
Requires a project initialized with grada (terraform/main.tf must exist) and the Terraform CLI installed for local checks.