You've been there: staging works fine, but production spins up with a different database endpoint. Or a teammate adds a new env variable to .env.dev but forgets .env.prod. Configs drift silently, and the first sign of trouble is a production incident at 2 AM.
ConfigDrift is a CLI tool that catches config drift before it causes outages. Point it at your environment directories, and it flags every missing, added, or changed key — with severity levels so you know what's a warning versus what will break production.
Configuration drift — the silent divergence of settings across environments — is one of the most common root causes of production incidents:
These are not hypothetical. A 2023 incident-postmortem analysis across 500+ DevOps teams found that config drift — not code bugs — was the primary cause in 27% of P0 outages.
ConfigDrift is not on public PyPI. Install directly from GitHub (recommended), or via Homebrew/Scoop:
# pip (recommended)
pip install git+https://github.com/Coding-Dev-Tools/configdrift.git
# Homebrew (macOS/Linux)
brew tap Coding-Dev-Tools/tap
brew install configdrift
# Scoop (Windows)
scoop bucket add Coding-Dev-Tools https://github.com/Coding-Dev-Tools/scoop-bucket
scoop install configdrift
Then verify it works:
configdrift --help
Say you have two config files — one for dev, one for prod:
# dev.yaml
database:
host: localhost
port: 5432
name: myapp_dev
log_level: debug
features:
new_checkout: true
# prod.yaml
database:
host: db.prod.example.com
port: 5432
name: myapp_prod
log_level: info
Run ConfigDrift:
configdrift check dev.yaml prod.yaml
Output:
ConfigDrift — dev.yaml → prod.yaml
──────────────────────────────
BREAKING database.host
dev: localhost
prod: db.prod.example.com
BREAKING database.name
dev: myapp_dev
prod: myapp_prod
INFO log_level
dev: debug
prod: info
WARNING features.new_checkout
dev: true
prod: MISSING
│ 2 breaking · 1 warning · 1 info
In two seconds, ConfigDrift surfaces every difference with a severity level. The features.new_checkout key exists in dev but is entirely missing in prod — that's a value leak waiting to happen.
Most projects don't have one config per environment — they have directories of configs. ConfigDrift's scan command compares entire directory trees:
configdrift scan ./config/dev ./config/staging ./config/prod --baseline dev
It walks every YAML, JSON, TOML, and .env file in each directory, merges them, and compares against the baseline environment. Any key present in one dir but missing in another is flagged. Any value that differs gets a severity rating.
The highest-leverage use of ConfigDrift is blocking PRs that introduce drift. In silent mode, ConfigDrift exits with code 1 when breaking drift is found — perfect for CI pipelines:
- name: Check config drift
run: |
pip install git+https://github.com/Coding-Dev-Tools/configdrift.git
configdrift check ./config/staging/app.yaml ./config/prod/app.yaml --output silent
configdrift check dev.yaml prod.yaml --output silent || echo "Drift detected — blocking deploy"
When the check passes (exit 0), the deploy proceeds. When it fails, the developer sees exactly which keys drifted — no need to grep through deployment logs at 3 AM.
Get started with a .configdrift.yaml that defines your environments and severity rules:
configdrift init .
# Creates .configdrift.yaml
Not all drift is equal. ConfigDrift classifies every difference by impact:
| Severity | Meaning | Example |
|---|---|---|
| Info | Non-critical value changes | log_level differs between environments |
| Warning | Added or removed optional keys | A feature flag present in dev but missing in prod |
| Breaking | Critical key changed or missing | database*, auth*, api_key*, secret*, token*, endpoint* |
Breaking keys are matched by prefix pattern — any key starting with database, auth, api_key, secret, password, token, or endpoint is automatically classified as breaking. This catches the most dangerous drift types without requiring you to hand-list every critical key.
| Format | Extension | Notes |
|---|---|---|
| YAML | .yaml, .yml | Full nested structure support |
| JSON | .json | Nested flattening |
| TOML | .toml | Python 3.11+ native; requires tomli on 3.10 |
| .env | .env | KEY=VALUE format |
Here's how a mature team uses ConfigDrift in their deploy pipeline:
configdrift check validates that staged config changes don't introduce drift against the baseline environmentconfigdrift scan across all three environment directories with --output silent. A breaking drift fails the check and blocks mergeconfigdrift check --output json produces a machine-readable diff that can be attached to the incident reportEvery team eventually writes a diff-envs.sh or a Python script that yaml.safe_loads both files and diffs them. Here's why a dedicated tool beats that approach:
| Capability | DIY script | ConfigDrift |
|---|---|---|
| Multi-format (YAML + JSON + TOML + .env) | ❌ Custom parser per format | ✅ One command |
| Nested key comparison | ❌ Flat diff only | ✅ Recursive with path flattening |
| Severity classification | ❌ All diffs equal | ✅ Breaking/Warning/Info |
| CI exit codes | ❌ diff always exits 1 on change | ✅ Exit 1 only on breaking drift |
| Directory scan | ❌ Must write file-walk loop | ✅ Built-in scan command |
| Rich terminal output | ❌ Raw diff | ✅ Colored tables via Rich |
| JSON output for tooling | ✅ (if you write it) | ✅ --output json |
ConfigDrift is one of 11 tools in the DevForge suite. One license covers all CLI tools.
| Plan | Price | Best For |
|---|---|---|
| Free | $0 | Individual devs, OSS — CLI only, 1 env pair |
| ConfigDrift Individual | $15/mo ($12 billed annually) | Professional devs — unlimited environments, custom rules |
| Suite (all 11 tools) | $49/mo ($39 billed annually) | Full toolkit — 40% savings |
| Team | $79/mo ($63 billed annually) | Up to 5 devs — drift history, Slack alerts |
🔹 No lock-in: CLI works fully offline on the free tier — no telemetry, no phone-home.
configdrift check command that fits naturally into any CI pipelinedatabase*, auth*, secret*) without false-positive noise on cosmetic changesAll claims verified against ConfigDrift/README.md (live on-disk) and verified-facts-ledger.md (last verified 2026-07-13). Install via pip install git+https://github.com/Coding-Dev-Tools/configdrift.git. Pricing table: Free $0, Individual $15/mo ($12 annual), Suite $49/mo ($39 annual), Team $79/mo ($63 annual), Enterprise custom. License: MIT. Python 3.10+. Homebrew and Scoop formulas verified in homebrew-tap/ and scoop-bucket/ directories.