Recursively scan a directory tree for Terraform or Terragrunt root
modules, run init + plan across them in parallel, and report which modules
have drifted from their recorded state — as a console table, JSON, HTML, or
PDF report.
Built for CI gating and local audits. This image bundles driftlens,
terraform, and terragrunt on PATH — no local toolchain needed.
Mount the directory you want to scan and run:
docker pull hardikaws/driftlens:latest
# scan ./infra (Terraform)
docker run --rm -v "$PWD:/work" -w /work hardikaws/driftlens ./infra
Write reports back to the host:
docker run --rm -v "$PWD:/work" -w /work \
hardikaws/driftlens --report=both --report-dir=/work/report ./infra
Terragrunt trees (state access needs cloud credentials, e.g. AWS):
docker run --rm -v "$PWD:/work" -w /work \
-v "$HOME/.aws:/root/.aws:ro" -e AWS_PROFILE \
hardikaws/driftlens --tool=terragrunt ./live
Machine-readable output for a CI gate:
docker run --rm -v "$PWD:/work" -w /work \
hardikaws/driftlens --format=json ./infra > drift.json
Mirrors Terraform's -detailed-exitcode, aggregated across all modules:
| Code | Meaning |
|---|---|
0 | All modules clean |
2 | At least one module drifted (no errors) |
1 | At least one module errored (or bad flags / unreadable path) |
Precedence: any error → 1, else any drift → 2, else 0.
| Flag | Default | Description |
|---|---|---|
--tool | terraform | terraform or terragrunt |
--parallelism | 4 | Concurrent workers |
--detailed | false | List each drifted resource (auto-on for file reports) |
--plugin-cache-dir | (off) | Shared provider cache; download providers once, not per module |
--format | console | stdout format: console or json |
--report | html | file report: none, html, pdf, or both |
--report-dir | report | directory for report files |
--timeout | 10m | per-directory init+plan timeout |
--version | print version and exit |
Run docker run --rm hardikaws/driftlens --help for the full flag list.
--format). JSON is an object
{ "elapsed_seconds": <float>, "results": [...] }.Every run reports total wall-clock time (Completed in …).
Built by GoReleaser during the release workflow. To build locally from source:
git clone https://github.com/hardik-aws/driftlens
cd driftlens
docker build -t driftlens .
docker run --rm -v "$PWD:/work" -w /work driftlens ./infra
See the repository for license and full documentation.
Content type
Image
Digest
sha256:bad3214aa…
Size
70.1 MB
Last updated
3 months ago
docker pull hardikaws/driftlens