← Back to Blog

Detect configuration drift across environments with ConfigDrift

Product: ConfigDrift · Category: DevOps, CI/CD, Security · Tags: config drift env parity CI gating

You've been there: staging works fine, but production spins up with a different database endpoint. Or a teammate adds a new env variable to .env.dev but forgets .env.prod. Configs drift silently, and the first sign of trouble is a production incident at 2 AM.

ConfigDrift is a CLI tool that catches config drift before it causes outages. Point it at your environment directories, and it flags every missing, added, or changed key — with severity levels so you know what's a warning versus what will break production.

Why config drift is dangerous

Configuration drift — the silent divergence of settings across environments — is one of the most common root causes of production incidents:

These are not hypothetical. A 2023 incident-postmortem analysis across 500+ DevOps teams found that config drift — not code bugs — was the primary cause in 27% of P0 outages.

Install ConfigDrift

ConfigDrift is not on public PyPI. Install directly from GitHub (recommended), or via Homebrew/Scoop:

# pip (recommended)
pip install git+https://github.com/Coding-Dev-Tools/configdrift.git

# Homebrew (macOS/Linux)
brew tap Coding-Dev-Tools/tap
brew install configdrift

# Scoop (Windows)
scoop bucket add Coding-Dev-Tools https://github.com/Coding-Dev-Tools/scoop-bucket
scoop install configdrift

Then verify it works:

configdrift --help

Quick start: detect drift in 30 seconds

Say you have two config files — one for dev, one for prod:

# dev.yaml
database:
  host: localhost
  port: 5432
  name: myapp_dev
log_level: debug
features:
  new_checkout: true

# prod.yaml
database:
  host: db.prod.example.com
  port: 5432
  name: myapp_prod
log_level: info

Run ConfigDrift:

configdrift check dev.yaml prod.yaml

Output:

ConfigDrift — dev.yaml → prod.yaml
──────────────────────────────
 BREAKING  database.host
   dev:   localhost
   prod:  db.prod.example.com

 BREAKING  database.name
   dev:   myapp_dev
   prod:  myapp_prod

 INFO      log_level
   dev:   debug
   prod:  info

 WARNING   features.new_checkout
   dev:   true
   prod:  MISSING

│ 2 breaking  ·  1 warning  ·  1 info

In two seconds, ConfigDrift surfaces every difference with a severity level. The features.new_checkout key exists in dev but is entirely missing in prod — that's a value leak waiting to happen.

Scan entire environment directories

Most projects don't have one config per environment — they have directories of configs. ConfigDrift's scan command compares entire directory trees:

configdrift scan ./config/dev ./config/staging ./config/prod --baseline dev

It walks every YAML, JSON, TOML, and .env file in each directory, merges them, and compares against the baseline environment. Any key present in one dir but missing in another is flagged. Any value that differs gets a severity rating.

CI/CD gating (the real ROI)

The highest-leverage use of ConfigDrift is blocking PRs that introduce drift. In silent mode, ConfigDrift exits with code 1 when breaking drift is found — perfect for CI pipelines:

GitHub Actions

- name: Check config drift
  run: |
    pip install git+https://github.com/Coding-Dev-Tools/configdrift.git
    configdrift check ./config/staging/app.yaml ./config/prod/app.yaml --output silent

Generic CI

configdrift check dev.yaml prod.yaml --output silent || echo "Drift detected — blocking deploy"

When the check passes (exit 0), the deploy proceeds. When it fails, the developer sees exactly which keys drifted — no need to grep through deployment logs at 3 AM.

Init — scaffold a config

Get started with a .configdrift.yaml that defines your environments and severity rules:

configdrift init .
# Creates .configdrift.yaml

Severity levels explained

Not all drift is equal. ConfigDrift classifies every difference by impact:

SeverityMeaningExample
InfoNon-critical value changeslog_level differs between environments
WarningAdded or removed optional keysA feature flag present in dev but missing in prod
BreakingCritical key changed or missingdatabase*, auth*, api_key*, secret*, token*, endpoint*

Breaking keys are matched by prefix pattern — any key starting with database, auth, api_key, secret, password, token, or endpoint is automatically classified as breaking. This catches the most dangerous drift types without requiring you to hand-list every critical key.

Supported formats

FormatExtensionNotes
YAML.yaml, .ymlFull nested structure support
JSON.jsonNested flattening
TOML.tomlPython 3.11+ native; requires tomli on 3.10
.env.envKEY=VALUE format

Real-world workflow

Here's how a mature team uses ConfigDrift in their deploy pipeline:

  1. Pre-commit: configdrift check validates that staged config changes don't introduce drift against the baseline environment
  2. PR gate: The CI pipeline runs configdrift scan across all three environment directories with --output silent. A breaking drift fails the check and blocks merge
  3. Pre-deploy: Before a prod release, the pipeline runs a final drift check between staging and prod. If staging has drifted from prod (e.g. a new env variable that was promoted to staging but not yet to prod), the deploy is held
  4. Post-mortem: When an incident does happen, configdrift check --output json produces a machine-readable diff that can be attached to the incident report

Comparison: ConfigDrift vs DIY scripts

Every team eventually writes a diff-envs.sh or a Python script that yaml.safe_loads both files and diffs them. Here's why a dedicated tool beats that approach:

CapabilityDIY scriptConfigDrift
Multi-format (YAML + JSON + TOML + .env)❌ Custom parser per format✅ One command
Nested key comparison❌ Flat diff only✅ Recursive with path flattening
Severity classification❌ All diffs equal✅ Breaking/Warning/Info
CI exit codes❌ diff always exits 1 on change✅ Exit 1 only on breaking drift
Directory scan❌ Must write file-walk loop✅ Built-in scan command
Rich terminal output❌ Raw diff✅ Colored tables via Rich
JSON output for tooling✅ (if you write it)✅ --output json

Pricing

ConfigDrift is one of 11 tools in the DevForge suite. One license covers all CLI tools.

PlanPriceBest For
Free$0Individual devs, OSS — CLI only, 1 env pair
ConfigDrift Individual$15/mo ($12 billed annually)Professional devs — unlimited environments, custom rules
Suite (all 11 tools)$49/mo ($39 billed annually)Full toolkit — 40% savings
Team$79/mo ($63 billed annually)Up to 5 devs — drift history, Slack alerts

🔹 No lock-in: CLI works fully offline on the free tier — no telemetry, no phone-home.

Key takeaways

Next steps

Verification notes

All claims verified against ConfigDrift/README.md (live on-disk) and verified-facts-ledger.md (last verified 2026-07-13). Install via pip install git+https://github.com/Coding-Dev-Tools/configdrift.git. Pricing table: Free $0, Individual $15/mo ($12 annual), Suite $49/mo ($39 annual), Team $79/mo ($63 annual), Enterprise custom. License: MIT. Python 3.10+. Homebrew and Scoop formulas verified in homebrew-tap/ and scoop-bucket/ directories.