Sign inSign up

hardikaws/driftlens

By hardikaws

•Updated 3 months ago

Image
Security
Monitoring & observability
0

253

hardikaws/driftlens repository overview

⁠driftlens

Recursively scan a directory tree for Terraform or Terragrunt root modules, run init + plan across them in parallel, and report which modules have drifted from their recorded state — as a console table, JSON, HTML, or PDF report.

Built for CI gating and local audits. This image bundles driftlens, terraform, and terragrunt on PATH — no local toolchain needed.

⁠Quick start

Mount the directory you want to scan and run:

docker pull hardikaws/driftlens:latest

# scan ./infra (Terraform)
docker run --rm -v "$PWD:/work" -w /work hardikaws/driftlens ./infra

Write reports back to the host:

docker run --rm -v "$PWD:/work" -w /work \
  hardikaws/driftlens --report=both --report-dir=/work/report ./infra

Terragrunt trees (state access needs cloud credentials, e.g. AWS):

docker run --rm -v "$PWD:/work" -w /work \
  -v "$HOME/.aws:/root/.aws:ro" -e AWS_PROFILE \
  hardikaws/driftlens --tool=terragrunt ./live

Machine-readable output for a CI gate:

docker run --rm -v "$PWD:/work" -w /work \
  hardikaws/driftlens --format=json ./infra > drift.json

⁠Exit codes

Mirrors Terraform's -detailed-exitcode, aggregated across all modules:

CodeMeaning
0All modules clean
2At least one module drifted (no errors)
1At least one module errored (or bad flags / unreadable path)

Precedence: any error → 1, else any drift → 2, else 0.

⁠Common flags

FlagDefaultDescription
--toolterraformterraform or terragrunt
--parallelism4Concurrent workers
--detailedfalseList each drifted resource (auto-on for file reports)
--plugin-cache-dir(off)Shared provider cache; download providers once, not per module
--formatconsolestdout format: console or json
--reporthtmlfile report: none, html, pdf, or both
--report-dirreportdirectory for report files
--timeout10mper-directory init+plan timeout
--versionprint version and exit

Run docker run --rm hardikaws/driftlens --help for the full flag list.

⁠Reports

  • Console / JSON → stdout (--format). JSON is an object { "elapsed_seconds": <float>, "results": [...] }.
  • HTML → interactive: per-resource search + status filter, and for terragrunt a layered dependency-graph SVG colored by drift status.
  • PDF → landscape A4, pure-Go engine (no external binary), static.

Every run reports total wall-clock time (Completed in …).

⁠Reproduce the image

Built by GoReleaser during the release workflow. To build locally from source:

git clone https://github.com/hardik-aws/driftlens
cd driftlens
docker build -t driftlens .
docker run --rm -v "$PWD:/work" -w /work driftlens ./infra

⁠License

See the repository⁠ for license and full documentation.

Tag summary

Content type

Image

Digest

sha256:bad3214aa…

Size

70.1 MB

Last updated

3 months ago

docker pull hardikaws/driftlens