Know when something changes outside the panel.
Servers drift. Someone SSHs in to fix a typo, a deploy script overwrites nginx.conf, an unattended-upgrade lands a new openssl version. Cloudnan tracks every resource it installs and tells you the moment something diverges — with the diff, the timestamp, and a one-click reconcile.
Configuration Drift
Differences between Cloudnan's expected state and what's currently on this server.
/etc/nginx/sites-available/web.cloudnan.dev
Config filehigh3 min agoopenssl 3.0.13-0ubuntu3.4
Packagecritical14 min agodocker / nginx:1.27-alpine
Containermedium42 min agoufw allow 5432/tcp
Firewallhigh1 h ago/etc/fail2ban/jail.d/nginx-auth.conf
Config filelow3 h agophp8.2-fpm / systemd unit
Resolved
Servicemedium6 h ago—
What's tracked
Six surfaces, continuously.
Drift detection isn't a snapshot of every byte on disk — that'd be expensive and noisy. We track exactly the surface area Cloudnan installed or registered, plus anything you opt in.
Packages
Every apt / dpkg / rpm install, upgrade, removal — version pinned at install time.
Services
systemd unit files, enabled state, override fragments, drop-ins.
Containers
Docker images, image tags + digests, exposed ports, volume mounts.
Firewall rules
UFW rules, fail2ban jails, modsecurity rule sets, sshd_config.
Config files
nginx, php-fpm, mysql, redis, custom files registered for tracking.
Cron + supervisor
crontab entries, systemd timers, supervisor program definitions.
How it works
Snapshot. Re-scan. Diff. Alert. Decide.
- 01
Snapshot at install
Whenever Cloudnan installs or modifies anything, it records the precise state — package version, file hash, config bytes — to the control plane.
- 02
Continuous re-scan
The agent re-hashes the tracked surface on a schedule (default every 15 min). Cheap — only file mtimes + small metadata.
- 03
Diff against expected
Anything that diverged from the snapshot — a package upgrade, a config edit, a new firewall rule — surfaces as a drift finding.
- 04
Alert with context
You get a notification: what changed, when, what the previous and current values are. Email / Telegram / Slack / Discord — whichever channel you wired.
- 05
You decide
Reconcile to the expected state, accept the drift (updates the snapshot), or investigate. Each action is a click and audit-logged.
- 06
History stays forever
Every snapshot, every diff, every reconcile decision persists. Replay months later for compliance or post-incident review.
Why this matters
Four production scenarios drift detection unblocks.
"Why is the site down?"
Drift detection caught it: nginx.conf was edited 47 minutes ago by a deploy script that wasn't supposed to touch production. One-click reconcile.
"Did anyone install software on prod?"
`apt install cron-bash-shell-shock` — drift detection flags the package, you see the new dependency, you remove it before it runs.
"Has the WAF config changed?"
modsecurity.conf is part of the tracked surface. Whether it changed via SSH, via a deploy hook, or via a panicked 3am edit — the panel knows.
"Compliance audit starts Monday."
Export the drift history for the past 12 months. Every change to tracked config, who triggered it, whether it was reconciled — in one CSV.
The two actions
Reconcile, or update the baseline.
Reconcile
Restore the resource to the snapshotted state. Cloudnan rewrites the file, downgrades the package, removes the unauthorised firewall rule. Always shows you exactly what will change before confirming.
Accept drift
The current state IS the new baseline. Updates the snapshot so future scans don't re-alert. Useful when you intentionally edited something and want Cloudnan to remember the change.
FAQ
Common questions about drift.
Does drift detection slow down my server?
What counts as "drift"?
Can I disable detection for a specific file?
What happens when I "Reconcile"?
What about "Accept drift"?
How does this compare to a config-management tool like Ansible / Puppet?
Related capabilities
AI Operations Assistant
Ask the AI to investigate a drift finding — it can read context across the fleet.
ReadWeb Application Firewall
WAF config is part of the tracked surface — drift catches unauthorised rule edits.
ReadNotifications & Alerts
Route drift alerts to email, Telegram, Slack, Discord, or webhooks.
ReadYour fleet deserves better.
Get started in minutes.
Deploy agents on your servers, connect securely, and take full control. Start free, upgrade when ready.
- 7-day free trial
- No credit card
- Cancel anytime
