Reference CLI
drift
Report Kix-managed resources whose applied fields have changed since the last deploy, and which tool changed them.
kix drift checks whether the fields Kix applied to each resource still hold
the values it applied. Every apply writes a kix.run/applied-hash annotation;
the check recomputes that hash from the live object and compares. It needs
only a kubeconfig: it evaluates no flake and builds nothing.
This page is hand-maintained. Check cli/kix-cli/src/cli.rs and
cli/kix-cli/src/commands/drift.rs when in doubt.
Synopsis
Section titled “Synopsis”kix drift [--cluster <CLUSTER>] [--context <CONTEXT>] [-o text|json] [-q]| Flag | Meaning |
|---|---|
--cluster <CLUSTER> | Check only this Kix cluster’s resources. Kix finds them through the cluster’s Activation records, so no flake is needed. Fails when the cluster has no records while other Kix clusters do. |
--context <CONTEXT> | Kubeconfig context to check. Defaults to the current context. |
-o, --output | text (default) or json. Other values print text. |
-q, --quiet | Omit the connection and count lines. |
--flake and --no-cache have no effect. See
Global flags.
Without --cluster, the check covers every resource carrying the Kix
managed-by label in the Kubernetes context, whichever Kix cluster deployed it.
Each report names the Kix clusters the resource belongs to, read from the
Activation records its kix.run/activations annotation names. Text output
shows them in brackets after the resource when the check found more than one
Kix cluster. With --cluster, the check covers that cluster’s resources,
including ones it shares with another cluster.
Only fields Kix owns through server-side apply are hashed. A field Kix never
set, such as one a controller adds, is not drift. A change made through the
/scale subresource, such as kubectl scale or an autoscaler, is drift when
Kix set the replica count.
Verdicts
Section titled “Verdicts”| Verdict | Text | JSON verdict | Meaning |
|---|---|---|---|
| In sync | in sync | in-sync | The applied fields match the stamp |
| Drifted | DRIFTED | drifted | The applied fields changed |
| Unstamped | unstamped | unstamped | No kix.run/applied-hash; the resource was applied before stamping existed. Not counted as drift. |
| Unreadable | no managedFields | no-fieldset | The object has no field ownership data, so the check cannot run |
For a drifted resource, text output names each changed field with the field
manager, operation and time Kubernetes recorded, in the form
<field> taken by <manager> (<operation>) at <time>. When no other manager
is recorded, Kix says so.
JSON output has a resources array (kind, namespace, name, verdict,
clusters, foreignOwners) and a summary object with inSync, drifted, unstamped
and noFieldset counts.
Examples
Section titled “Examples”❱ kix drift --context prod❱ kix drift --cluster prod -o json Exit status
Section titled “Exit status”| Code | Meaning |
|---|---|
0 | No resource drifted |
1 | At least one resource drifted, or the cluster could not be reached |