DRIFT DETECTION

Know when something changes outside the panel.

Servers drift. Someone SSHs in to fix a typo, a deploy script overwrites nginx.conf, an unattended-upgrade lands a new openssl version. Cloudnan tracks every resource it installs and tells you the moment something diverges — with the diff, the timestamp, and a one-click reconcile.

cloudnan.com / dashboard / agents / web-01 / drift

Configuration Drift

Differences between Cloudnan's expected state and what's currently on this server.

1 critical2 high1 medium1 low
All severities
ResourceTypeSeverityDetected
  • /etc/nginx/sites-available/web.cloudnan.dev

    Config file
    high3 min ago
  • openssl 3.0.13-0ubuntu3.4

    Package
    critical14 min ago
  • docker / nginx:1.27-alpine

    Container
    medium42 min ago
  • ufw allow 5432/tcp

    Firewall
    high1 h ago
  • /etc/fail2ban/jail.d/nginx-auth.conf

    Config file
    low3 h ago
  • php8.2-fpm / systemd unit

    Resolved

    Service
    medium6 h ago
    —
web-01.cloudnan.devLast scan ran 2 min ago · next scheduled in 13 min

What's tracked

Six surfaces, continuously.

Drift detection isn't a snapshot of every byte on disk — that'd be expensive and noisy. We track exactly the surface area Cloudnan installed or registered, plus anything you opt in.

Packages

Every apt / dpkg / rpm install, upgrade, removal — version pinned at install time.

Services

systemd unit files, enabled state, override fragments, drop-ins.

Containers

Docker images, image tags + digests, exposed ports, volume mounts.

Firewall rules

UFW rules, fail2ban jails, modsecurity rule sets, sshd_config.

Config files

nginx, php-fpm, mysql, redis, custom files registered for tracking.

Cron + supervisor

crontab entries, systemd timers, supervisor program definitions.

How it works

Snapshot. Re-scan. Diff. Alert. Decide.

  1. 01

    Snapshot at install

    Whenever Cloudnan installs or modifies anything, it records the precise state — package version, file hash, config bytes — to the control plane.

  2. 02

    Continuous re-scan

    The agent re-hashes the tracked surface on a schedule (default every 15 min). Cheap — only file mtimes + small metadata.

  3. 03

    Diff against expected

    Anything that diverged from the snapshot — a package upgrade, a config edit, a new firewall rule — surfaces as a drift finding.

  4. 04

    Alert with context

    You get a notification: what changed, when, what the previous and current values are. Email / Telegram / Slack / Discord — whichever channel you wired.

  5. 05

    You decide

    Reconcile to the expected state, accept the drift (updates the snapshot), or investigate. Each action is a click and audit-logged.

  6. 06

    History stays forever

    Every snapshot, every diff, every reconcile decision persists. Replay months later for compliance or post-incident review.

Why this matters

Four production scenarios drift detection unblocks.

"Why is the site down?"

Drift detection caught it: nginx.conf was edited 47 minutes ago by a deploy script that wasn't supposed to touch production. One-click reconcile.

"Did anyone install software on prod?"

`apt install cron-bash-shell-shock` — drift detection flags the package, you see the new dependency, you remove it before it runs.

"Has the WAF config changed?"

modsecurity.conf is part of the tracked surface. Whether it changed via SSH, via a deploy hook, or via a panicked 3am edit — the panel knows.

"Compliance audit starts Monday."

Export the drift history for the past 12 months. Every change to tracked config, who triggered it, whether it was reconciled — in one CSV.

The two actions

Reconcile, or update the baseline.

Reconcile

Restore the resource to the snapshotted state. Cloudnan rewrites the file, downgrades the package, removes the unauthorised firewall rule. Always shows you exactly what will change before confirming.

Accept drift

The current state IS the new baseline. Updates the snapshot so future scans don't re-alert. Useful when you intentionally edited something and want Cloudnan to remember the change.

FAQ

Common questions about drift.

Does drift detection slow down my server?
Negligible. The default scan re-hashes a few hundred small files and reads systemd / dpkg metadata — typically <1 sec per cycle, every 15 min. Configurable lower or higher per server.
What counts as "drift"?
Anything that diverges from the state Cloudnan recorded the last time it touched (or accepted) that resource. New package version. New file hash. New systemd override. New firewall rule. The diff explains exactly what changed.
Can I disable detection for a specific file?
Yes — every tracked resource has a "watch / unwatch" toggle. Useful for log files that change constantly and shouldn't trigger alerts, or directories owned by an external tool.
What happens when I "Reconcile"?
The agent restores the file / package / rule to the snapshotted state. If a config got edited outside the panel, reconciling rolls it back. Always shows a preview of what will change before you confirm.
What about "Accept drift"?
Updates the snapshot to the current observed state — telling Cloudnan "this is the new expected baseline." Use this when you intentionally edited something outside the panel and want to stop alerting on it.
How does this compare to a config-management tool like Ansible / Puppet?
Different goal. Ansible / Puppet enforce state on a schedule and overwrite drift. Cloudnan's drift detection observes and alerts — it tells you something changed and asks what you want to do. They compose well: run Ansible to converge, run Cloudnan to know when convergence broke.

Your fleet deserves better.

Get started in minutes.

Deploy agents on your servers, connect securely, and take full control. Start free, upgrade when ready.

  • 7-day free trial
  • No credit card
  • Cancel anytime