Deploy a read-only IAM role in your AWS account using our one-click CloudFormation template or Terraform module. IaCRadar uses cross-account role assumption with a unique External ID — the same security pattern used by Datadog, CloudHealth, and every serious AWS monitoring tool. We can never write to your account.
Tell IaCRadar where your Terraform state files live. Paste your S3 bucket name and the path to your terraform.tfstate file. You can add as many workspaces as your plan allows — one per Terraform state file.
IaCRadar scans your Terraform state against live AWS every hour and sends an alert the moment it detects something changed outside of Terraform. Every alert tells you exactly what changed, which resource, and how severe it is.
Every check runs against your live AWS infrastructure — not just your state file.
🔴 Terraform Drift Detected
IaCRadar | 2026-06-21 14:32 UTC
Critical · IAM Role: prod-deploy-role
🔴 Policy added: AmazonEC2ReadOnlyAccess
Critical · Security Group: prod-api-sg
🔴 Inbound rule added: Port 22-22 (tcp) from 0.0.0.0/0
⚡ Action required — review and apply Terraform or revert manual changes
14-day free trial. No credit card required.