Automic VaultAutomic Vault

brew

Install driftctl with Homebrew, MacPorts, Nix

Detect, track and alert on infrastructure drift. Version 0.40.0 via Homebrew; verified from local package data. Also installable with nix: nix profile install nixpkgs#driftctl.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install driftctl

local Homebrew formula metadata

MacPortsverified · 94%
sudo port install driftctl

MacPorts ports tree · sysutils/driftctl/Portfile · source: api.github.com

Linux

Nixverified · 92%
nix profile install nixpkgs#driftctl

nixpkgs package indexes · pkgs/by-name/dr/driftctl/package.nix · source: api.github.com

overview

Package summary

Detect, track and alert on infrastructure drift

Commands and aliases

  • driftctl

history

Project history and usage

driftctl is a Snyk-maintained infrastructure-drift scanner for Terraform-era IaC workflows. It measures how much cloud infrastructure is covered by code and reports unmanaged or drifted resources.

Project history

The public repository was created in September 2020 and the official docs describe the tool as a CLI for measuring infrastructure-as-code coverage and tracking drift. Its README now states that the project is in maintenance mode, which makes the package historically important as a snapshot of the early standalone drift-detection tooling wave.

Adoption history

driftctl was adopted by infrastructure and DevSecOps users because it filled a gap between Terraform state and actual cloud-provider state. The official installation docs list direct binaries, Docker, Homebrew, and MacPorts, while the README shows badges for release downloads and Docker pulls, reflecting distribution beyond source builds.

How it is used

Typical use centers on driftctl scan, with Terraform state supplied locally, from S3, from multiple state files, or by glob. The docs also show AWS credential usage through environment variables, named profiles, and Docker mounts for ~/.aws and ~/.driftctl.

Why package nerds care

For package nerds, driftctl is a neat example of a Go-style single-binary cloud CLI that shipped through releases, Docker, Homebrew, MacPorts, and distro package indexes. It also marks a moment when IaC drift moved from an enterprise-platform feature into a small installable tool.

Timeline

  • 2020: Public snyk/driftctl repository created.
  • 2020: Early v0.1.x tags appear in the public repository.
  • 2023: v0.40.0 release published and documented as the stable Homebrew version.
  • 2026: README identifies the project as being in maintenance mode.

Related projects

  • Terraform is the primary IaC system referenced by driftctl docs and examples.
  • Snyk is the maintaining organization for the repository and documentation.
  • The official Docker image snyk/driftctl is documented as an alternate installation and execution path.

security posture

Risk level: orange

infrastructure mutation or orchestration signal.

Risk classifier

orange risk · medium confidence · infrastructure

Why

  • infrastructure mutation or orchestration signal

Signals

  • text:infrastructure

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
driftctlcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version0.40.0
manager updated
local dataok
upstreamcurrent
latest detectedv0.40.0

https://github.com/snyk/driftctl

  • infoNo package-manager update timestamp was available.low confidence

install metadata

Package metadata

Package keybrew:driftctl
Version0.40.0
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/driftctl
Homepagehttps://github.com/snyk/driftctl
Repositoryhttps://github.com/snyk/driftctl
Upstream docshttps://docs.driftctl.com/
LicenseApache-2.0
Source archivehttps://github.com/snyk/driftctl/archive/refs/tags/v0.40.0.tar.gz
Build dependenciesgo
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namedriftctl
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

driftctl

nix profile install nixpkgs#driftctl
  • normalized package name match
  • Matched by: Driftctl
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/dr/driftctl/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
MacPorts95%

driftctl

sudo port install driftctl
  • normalized package name match
  • Matched by: Driftctl
MacPorts ports tree · api.github.com · MacPorts ports tree: sysutils/driftctl/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment