Skip to content
kix /docs
Install the CLI

Reference CLI

drift

Report Kix-managed resources whose applied fields have changed since the last deploy, and which tool changed them.

kix drift checks whether the fields Kix applied to each resource still hold the values it applied. Every apply writes a kix.run/applied-hash annotation; the check recomputes that hash from the live object and compares. It needs only a kubeconfig: it evaluates no flake and builds nothing.

This page is hand-maintained. Check cli/kix-cli/src/cli.rs and cli/kix-cli/src/commands/drift.rs when in doubt.

kix drift [--cluster <CLUSTER>] [--context <CONTEXT>] [-o text|json] [-q]
FlagMeaning
--cluster <CLUSTER>Check only this Kix cluster’s resources. Kix finds them through the cluster’s Activation records, so no flake is needed. Fails when the cluster has no records while other Kix clusters do.
--context <CONTEXT>Kubeconfig context to check. Defaults to the current context.
-o, --outputtext (default) or json. Other values print text.
-q, --quietOmit the connection and count lines.

--flake and --no-cache have no effect. See Global flags.

Without --cluster, the check covers every resource carrying the Kix managed-by label in the Kubernetes context, whichever Kix cluster deployed it. Each report names the Kix clusters the resource belongs to, read from the Activation records its kix.run/activations annotation names. Text output shows them in brackets after the resource when the check found more than one Kix cluster. With --cluster, the check covers that cluster’s resources, including ones it shares with another cluster.

Only fields Kix owns through server-side apply are hashed. A field Kix never set, such as one a controller adds, is not drift. A change made through the /scale subresource, such as kubectl scale or an autoscaler, is drift when Kix set the replica count.

VerdictTextJSON verdictMeaning
In syncin syncin-syncThe applied fields match the stamp
DriftedDRIFTEDdriftedThe applied fields changed
UnstampedunstampedunstampedNo kix.run/applied-hash; the resource was applied before stamping existed. Not counted as drift.
Unreadableno managedFieldsno-fieldsetThe object has no field ownership data, so the check cannot run

For a drifted resource, text output names each changed field with the field manager, operation and time Kubernetes recorded, in the form <field> taken by <manager> (<operation>) at <time>. When no other manager is recorded, Kix says so.

JSON output has a resources array (kind, namespace, name, verdict, clusters, foreignOwners) and a summary object with inSync, drifted, unstamped and noFieldset counts.

❱ kix drift --context prod
❱ kix drift --cluster prod -o json
CodeMeaning
0No resource drifted
1At least one resource drifted, or the cluster could not be reached