- kind
- CLI
- status
- released
- version
- 0.1.0
- released
- 2026-10-01
- language
- Go 1.24
- licence
- MIT
- platforms
- Linux, macOS, Windows
amd64, arm64 - binary
- static, ~3 MB
- deps
- yaml.v3
confdriftCompares configuration files across environments and tells you what drifted, before you deploy. Staging works, production doesn't, and somewhere between the two a key went missing or a timeout lost a zero.
SYNOPSIS
confdrift [flags] FILE FILE [FILE...]
INSTALL
go install github.com/eduardofrafre/confdrift@latestor a prebuilt binary, Linux amd64 shown:
curl -sL https://github.com/eduardofrafre/confdrift/releases/download/v0.1.0/confdrift_0.1.0_linux_amd64.tar.gz | tar xzBuilds for Linux, macOS and Windows on amd64 and arm64, with checksums, are on the releases page.
DESCRIPTION
confdrift never compares text. It reads each file into a flat list of key paths and typed values, then lines every key up across all the files at once, two environments or ten. Ordering, indentation and format stop mattering; only real differences are left. A key is the same, changed, or missing somewhere.
- dotenv:
.env,.env.production,prod.env. Quotes,export, comments and multi-line values.${VARS}are not expanded. - YAML and JSON flatten the same way, to paths like
db.pool.maxorservers[0], so a YAML file compares with a JSON one. - Kubernetes ConfigMaps compare by their
datakeys.helm templateandkustomize buildoutput works as is.
Types count: 5432 and "5432" differ. Values of keys that look like credentials print as <redacted>, and are still compared, so a rotated secret still shows up.
EXAMPLE
$ confdrift staging/configmap.yaml production/configmap.yaml
DATABASE_URL changed
staging "postgres://checkout:<redacted>@db.staging.example.com:5432/checkout"
production "postgres://checkout:<redacted>@db.prod.example.com:5432/checkout"
FEATURE_NEW_CART missing from production
staging "true"
production (not set)
LOG_LEVEL changed
staging "debug"
production "info"
PAYMENTS_TIMEOUT_MS changed
staging "3000"
production "300"
STRIPE_API_KEY changed
staging <redacted>
production <redacted>
5 of 6 keys drifted across 2 files (1 missing, 4 changed).
OPTIONS
| --keys-only | Report only keys missing somewhere, not value differences. Usually what CI wants. |
| --ignore PATTERN | Skip keys matching PATTERN, * as wildcard. Repeatable. |
| --format text|json | Output for people, or for scripts and bots. |
| --show-secrets | Print the values of keys that look like credentials. |
| --version | Print the version and exit. |
EXIT STATUS
| 0 | The files agree. |
| 1 | Drift found. |
| 2 | Bad input: unreadable file, parse error, unknown flag. |
SEE ALSO
The confdrift page runs the real engine, compiled to WebAssembly, on your own files in the browser, and covers CI and per-platform install. Bugs and formats it should read go to the issue tracker.
