Open source · Cloud & Platform

Infrastructure Drift Snapshotter

Capture infrastructure state and compare drift between approved snapshots.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Offline, read-only comparison of two exported infrastructure snapshots. It never invokes Terraform/OpenTofu, reads live cloud state, provisions, changes, or deletes resources. The caller supplies complete approved and observed exports in one local JSON file. Snapshot completeness and sensitivity labeling are claims of the exporter; this tool cannot verify them against a provider.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/infra-drift-snapshotter.mjs --root examples --input passing.json
node bin/infra-drift-snapshotter.mjs --root examples --input failing.json
npm run check

Read the result

--root is the realpath-confined input directory; --input is a relative path within it. Optional --human prints one summary to stderr. Stdout contains only the JSON report. There is no output-file option; redirect stdout deliberately if a file is wanted. Unknown/duplicate options or missing root/input: exit 2 with empty stdout. Unreadable, non-UTF-8, malformed, or unsupported input: incomplete JSON on stdout, exit 2. A completed clean comparison exits 0; evaluated drift exits 1. --help prints usage.

Where this check stops

Maximum input/document size is 1,048,576 UTF-8 bytes, 100 resources per snapshot, JSON nesting depth 8 (root depth 0), and 5,000 ms wall time measured against an injectable library clock. Exact limits are accepted; N+1 is incomplete. Duplicate JSON object keys, including escaped spellings, are refused. UTF-8 decoding is fatal, not replacement-based. The CLI's file read also has a 5-second abort signal. No network or provider calls, no live plan execution, no auto-fix, no semantic interpretation of secrets. Sensitive key lists must be accurate; use an export pipeline that redacts secrets before handing it to this tool.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.