IaCRadarIaCRadar
  • Pricing
Sign In
Sign Up
IaCRadarIaCRadar

Alerts your team the moment a manual change causes drift — know before it breaks something.

© 2026 IACRADAR. All rights reserved.

Get Started
  • Sign In
  • Sign Up
Product
  • How it works
  • Pricing
  • Changelog
Company
  • Contact
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy

From signup to first drift alert in 10 minutes

No agent to install. No workflow changes. No platform migration. Just connect your existing S3 state bucket and go.

1

Connect your AWS account

Deploy a read-only IAM role in your AWS account using our one-click CloudFormation template or Terraform module. IaCRadar uses cross-account role assumption with a unique External ID — the same security pattern used by Datadog, CloudHealth, and every serious AWS monitoring tool. We can never write to your account.

2

Add your Terraform state bucket

Tell IaCRadar where your Terraform state files live. Paste your S3 bucket name and the path to your terraform.tfstate file. You can add as many workspaces as your plan allows — one per Terraform state file.

3

Get Slack or Teams alerts

IaCRadar scans your Terraform state against live AWS every hour and sends an alert the moment it detects something changed outside of Terraform. Every alert tells you exactly what changed, which resource, and how severe it is.

What IaCRadar monitors

Every check runs against your live AWS infrastructure — not just your state file.

🔴 Critical
security incidents
  • IAM role policies — detects policies attached or removed outside Terraform
  • IAM trust relationships — detects changes to who can assume your roles
  • IAM user access keys — detects credentials created outside Terraform
  • Security group ingress — detects ports opened manually
  • Security group egress — detects outbound rules added
  • S3 bucket policies — detects policy statements added
  • S3 public access block — detects public access enabled
  • KMS key policies — detects encryption key policy changes
🟡 Warning
operational impact
  • EC2 instance type — detects resizes outside Terraform
  • RDS instance class — detects database resizes
  • EKS node groups — detects manual scaling events
  • EKS cluster version — detects version upgrades
  • Lambda timeout and memory — detects config changes
  • Auto Scaling Group capacity — detects manual scaling
  • ALB listener rules — detects routing changes
  • Route53 DNS records — detects manual DNS changes
🔵 Info
compliance and cost
  • EC2 tags — detects tag changes
  • S3 bucket tags — detects tag changes
  • CloudWatch alarm thresholds — detects monitoring changes

What alerts look like

🔴 Terraform Drift Detected

IaCRadar | 2026-06-21 14:32 UTC


Critical · IAM Role: prod-deploy-role

🔴 Policy added: AmazonEC2ReadOnlyAccess

Critical · Security Group: prod-api-sg

🔴 Inbound rule added: Port 22-22 (tcp) from 0.0.0.0/0


⚡ Action required — review and apply Terraform or revert manual changes

Ready to catch drift before it causes incidents?

Start free trial →

14-day free trial. No credit card required.