Driftmorning
A lightweight infrastructure-as-code drift sentinel that compares authorized declared and observed state, correlates changes to audit principals and events, estimates affected dependencies, and sends a redacted morning review with evidence, uncertainty, and separately approved remediation options.
Small platform teams want to know when live infrastructure diverges from declared configuration without adopting a full management platform. Driftmorning collects a bounded snapshot and produces a concise review brief. Difference does not always mean unauthorized drift: provider defaults, computed fields, imports, moved resources, version changes, partial coverage, failed refresh, state lag, or an approved emergency action can explain it. An audit principal is not necessarily the human who intended the change, blast radius is an estimate, and a generated apply or revert command is not safe to execute without a fresh plan, review, and normal change authority. Declared state, backend state, observed resource, audit event, principal, drift candidate, security hypothesis, reviewer disposition, approved change, provider acknowledgment, readback, rollback, incident, and correction remain distinct.
A solo platform engineer, cloud owner, security-conscious engineering lead, managed service provider, or small infrastructure team that uses declared configuration but does not want a broader platform migration.
Recent open projects and a current practitioner specification validate demand without a hard deadline.
Scheduled collection, normalization, correlation, and reports are software-scalable once provider and state semantics are supported.
No cross-reference, inbound connection, or direct connection makes internal convergence weak despite external project repetition.
A specific lightweight buyer request, confirmed heavyweight platforms, an archived prior open tool, a new command-line replacement, and multiple independently built attribution-plus-email projects support real unmet demand for a polished email-first service.
There are no cross-references, inbound, or direct connections; stage one verified no interfaces; the moat is explicitly thin; multi-cloud state and audit correlation are hard; generated remediation can be dangerous; and platforms, open projects, or cloud providers can copy the morning report.
Discussion
No comments yet — be the first to weigh in.
