# Install driftctl with Homebrew, MacPorts, Nix

Detect, track and alert on infrastructure drift. Version 0.40.0 via Homebrew; verified from local package data. Also installable with nix: nix profile install nixpkgs#driftctl.

## Install

```sh
sudo av install brew:driftctl
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install driftctl
```

  Evidence: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install driftctl
```

  Evidence: MacPorts ports tree: sysutils/driftctl/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#driftctl
```

  Evidence: nixpkgs package indexes: pkgs/by-name/dr/driftctl/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

## Package facts

- **Package key:** brew:driftctl
- **Package manager:** Homebrew
- **Package manager page:** <https://formulae.brew.sh/formula/driftctl>
- **Version:** 0.40.0
- **Source summary:** Detect, track and alert on infrastructure drift
- **Homepage:** <https://github.com/snyk/driftctl>
- **Repository:** <https://github.com/snyk/driftctl>
- **Upstream docs:** <https://docs.driftctl.com/>
- **License:** Apache-2.0
- **Source archive:** <https://github.com/snyk/driftctl/archive/refs/tags/v0.40.0.tar.gz>
- **Generated:** 2026-07-26T07:20:29+00:00

## Executables

- driftctl (cli)
- driftctl (alias)

## Build dependencies

- go

## Install behavior

- Post-install hook: not defined
- Bottle: available on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## Freshness

- Page generated: 2026-07-26
- Package-manager version: 0.40.0
- Local data: ok
- Upstream repository: https://github.com/snyk/driftctl
- Upstream latest detected: v0.40.0 (current)
- info: No package-manager update timestamp was available.
## Project history and usage

driftctl is a Snyk-maintained infrastructure-drift scanner for Terraform-era IaC workflows. It measures how much cloud infrastructure is covered by code and reports unmanaged or drifted resources.

### Project history

The public repository was created in September 2020 and the official docs describe the tool as a CLI for measuring infrastructure-as-code coverage and tracking drift. Its README now states that the project is in maintenance mode, which makes the package historically important as a snapshot of the early standalone drift-detection tooling wave.

### Adoption history

driftctl was adopted by infrastructure and DevSecOps users because it filled a gap between Terraform state and actual cloud-provider state. The official installation docs list direct binaries, Docker, Homebrew, and MacPorts, while the README shows badges for release downloads and Docker pulls, reflecting distribution beyond source builds.

### How it is used

Typical use centers on driftctl scan, with Terraform state supplied locally, from S3, from multiple state files, or by glob. The docs also show AWS credential usage through environment variables, named profiles, and Docker mounts for ~/.aws and ~/.driftctl.

### Why package nerds care

For package nerds, driftctl is a neat example of a Go-style single-binary cloud CLI that shipped through releases, Docker, Homebrew, MacPorts, and distro package indexes. It also marks a moment when IaC drift moved from an enterprise-platform feature into a small installable tool.

### Timeline

- 2020: Public snyk/driftctl repository created.
- 2020: Early v0.1.x tags appear in the public repository.
- 2023: v0.40.0 release published and documented as the stable Homebrew version.
- 2026: README identifies the project as being in maintenance mode.

### Related projects

- Terraform is the primary IaC system referenced by driftctl docs and examples.
- Snyk is the maintaining organization for the repository and documentation.
- The official Docker image snyk/driftctl is documented as an alternate installation and execution path.

### Sources

- <https://github.com/snyk/driftctl>
- <https://raw.githubusercontent.com/snyk/driftctl/main/README.md>
- <https://docs.driftctl.com/0.40.0/>
- <https://raw.githubusercontent.com/snyk/driftctl-docs/main/versioned_docs/version-0.40.0/intro.mdx>
- <https://raw.githubusercontent.com/snyk/driftctl-docs/main/versioned_docs/version-0.40.0/installation.mdx>
- <https://raw.githubusercontent.com/snyk/driftctl-docs/main/versioned_docs/version-0.40.0/usage.mdx>
- <https://formulae.brew.sh/formula/driftctl>


## Security Notes

infrastructure mutation or orchestration signal.

- **Geiger risk:** orange / medium
- infrastructure mutation or orchestration signal

## Source Database Details

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** driftctl
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## Other Package-Manager Records

- Nix - driftctl: normalized package name match | nixpkgs package indexes: pkgs/by-name/dr/driftctl/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- MacPorts - driftctl: normalized package name match | MacPorts ports tree: sysutils/driftctl/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1


## Related links

- [Cloud CLI packages](https://www.automicvault.com/pkg/cloud-clis/) - Belongs to a cloud or infrastructure command family.
- [Source-control packages](https://www.automicvault.com/pkg/source-control-tools/) - Belongs to a source-control command family.
- [Secret-risk packages](https://www.automicvault.com/pkg/secret-risk-packages/) - Has protected-tool coverage, approval-gate, or non-low Geiger security signals.
- [Terminal utility packages](https://www.automicvault.com/pkg/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [go](https://www.automicvault.com/pkg/brew/go/) - Build dependency declared by Homebrew.
- [aztfexport](https://www.automicvault.com/pkg/brew/aztfexport/) - Shares av.db curated category or tags: azure, cli, cloud-infrastructure, iac, infrastructure-as-code.
- [aws-cdk](https://www.automicvault.com/pkg/brew/aws-cdk/) - Shares av.db curated category or tags: aws, cli, cloud-infrastructure, infrastructure-as-code.
- [c7n](https://www.automicvault.com/pkg/brew/c7n/) - Shares av.db curated category or tags: aws, azure, cli, cloud-infrastructure, gcp.
- [org-formation](https://www.automicvault.com/pkg/brew/org-formation/) - Shares av.db curated category or tags: aws, cli, cloud-infrastructure, infrastructure-as-code.
- [pug](https://www.automicvault.com/pkg/brew/pug/) - Shares av.db curated category or tags: cli, cloud-infrastructure, infrastructure-as-code, terraform.
- [rain](https://www.automicvault.com/pkg/brew/rain/) - Shares av.db curated category or tags: aws, cli, cloud-infrastructure, infrastructure-as-code.
- [sceptre](https://www.automicvault.com/pkg/brew/sceptre/) - Shares av.db curated category or tags: aws, cli, cloud-infrastructure, infrastructure-as-code.
- [terracognita](https://www.automicvault.com/pkg/brew/terracognita/) - Shares av.db curated category or tags: aws, azure, cli, cloud-infrastructure, infrastructure-as-code.

## Combined YAML source

View the package source record on GitHub. [combined/driftctl.yml](https://github.com/automic-vault/db/blob/main/combined/driftctl.yml)


## Sources

- Nucleus package database
- Geiger risk classifier
- package-page enrichment
- curated package history
- package version freshness
- av.db category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
