Skip to content

Check live resources for drift

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

Use kix drift to find changes made to fields Kix manages after the resources were deployed.

Run the command without a cluster name:

Run in kix-examples/
❱ kix drift
Connecting to cluster...
16 kix-managed resources

  ✓ Activation/how-to-application-aq1zdgf9gsnb         in sync
  ✓ ConfigMap/preview@how-to-app                       in sync
  ✓ ConfigMap/production@how-to-app                    in sync
  ✓ ConfigMap/production-health-script@how-to-app      in sync
  ✓ CustomResourceDefinition/activations.kix.run       in sync
  ✓ CustomResourceDefinition/packageinstances.kix.run  in sync
  ✓ Deployment/preview@how-to-app                      in sync
  ✗ Deployment/production@how-to-app                   DRIFTED
      spec.replicas taken by kubectl (Update via /scale) at unknown time
  ✓ Job/production-health@how-to-app                   in sync
  ✓ Namespace/how-to-app                               in sync
  ✓ Namespace/kube-system                              in sync
  ✓ PackageInstance/preview@how-to-app                 in sync
  ✓ PackageInstance/production@how-to-app              in sync
  ✓ PackageInstance/platform-dns@kube-system           in sync
  ✓ Service/preview@how-to-app                         in sync
  ✓ Service/production@how-to-app                      in sync

Drift: 15 in sync, 1 drifted
(exit code: 1)

The captured example has one deliberate change: the production Deployment was scaled from two replicas to one with kubectl. The output identifies spec.replicas as drifted and names kubectl as the field manager that changed it.

drift reads Kix-managed resources from the selected Kubernetes context. It does not need a source checkout, cluster name, or Nix evaluation because each deployed resource carries the information needed for the comparison.

The complete output assigns each managed resource one of four verdicts:

VerdictMeaning
in-syncThe fields managed by Kix still match their applied content
driftedOne or more managed fields changed
unstampedThe resource predates drift stamps and cannot yet be compared
no-fieldsetKubernetes did not retain the managed-field data needed for the check

When possible, a drifted result names the other field manager, operation, subresource, time, and field paths involved. A result containing any drifted resource exits with status 1.

Pass --context to inspect a context other than the current one:

❱ kix drift --context kind-kix-demo

Use JSON when another program will process or store the report:

❱ kix drift --output json > drift.json

kix drift checks field content. Use Check cluster health when you need to verify that the active dependency graph is still intact.