Metadata-Version: 2.5
Name: driftsentry
Version: 0.3.0
Summary: Your infrastructure's immune system — detect IaC drift, attribute blame, auto-remediate with PRs.
Project-URL: Homepage, https://github.com/hemanthkp98/driftsentry
Project-URL: Documentation, https://github.com/hemanthkp98/driftsentry#readme
Project-URL: Repository, https://github.com/hemanthkp98/driftsentry
Project-URL: Issues, https://github.com/hemanthkp98/driftsentry/issues
Author: Hemanth KP
License-Expression: Apache-2.0
License-File: LICENSE
Keywords: aws,cloud,devsecops,drift,iac,infrastructure-as-code,opentofu,remediation,security,terraform
Classifier: Development Status :: 3 - Alpha
Classifier: Environment :: Console
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: System Administrators
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Security
Classifier: Topic :: System :: Systems Administration
Classifier: Typing :: Typed
Requires-Python: >=3.11
Requires-Dist: boto3>=1.35.0
Requires-Dist: deepdiff>=7.0.0
Requires-Dist: jinja2>=3.1.0
Requires-Dist: pydantic>=2.0.0
Requires-Dist: pygithub>=2.0.0
Requires-Dist: pyyaml>=6.0
Requires-Dist: rich>=13.0.0
Requires-Dist: typer>=0.12.0
Provides-Extra: ai
Requires-Dist: anthropic>=0.40.0; extra == 'ai'
Requires-Dist: google-genai>=1.0.0; extra == 'ai'
Provides-Extra: dev
Requires-Dist: boto3-stubs[essential]>=1.35.0; extra == 'dev'
Requires-Dist: moto[all]>=5.0.0; extra == 'dev'
Requires-Dist: mypy>=1.10.0; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.23.0; extra == 'dev'
Requires-Dist: pytest-cov>=5.0.0; extra == 'dev'
Requires-Dist: pytest>=8.0.0; extra == 'dev'
Requires-Dist: ruff>=0.5.0; extra == 'dev'
Requires-Dist: types-pyyaml>=6.0; extra == 'dev'
Description-Content-Type: text/markdown

# DriftSentry

Infrastructure-as-Code (IaC) drift detection, CloudTrail actor attribution, and AI-powered automated remediation engine for Terraform and OpenTofu.

[![CI](https://github.com/hemanthkp98/driftsentry/actions/workflows/ci.yml/badge.svg)](https://github.com/hemanthkp98/driftsentry/actions/workflows/ci.yml)
[![PyPI](https://img.shields.io/pypi/v/driftsentry.svg)](https://pypi.org/project/driftsentry/)
[![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](LICENSE)

---

## Why It Exists

Cloud environments continuously drift away from committed Terraform code due to emergency console hotfixes, uncoordinated script executions, and out-of-band updates. DriftSentry detects configuration discrepancies between live AWS infrastructure and your state files, pinpoints the exact IAM identity responsible using CloudTrail history, and generates production-ready HCL patches or Pull Requests with zero human intervention.

---

## Quickstart

```bash
# 1. Install DriftSentry with AI smart remediation
pip install "driftsentry[ai]"

# 2. Scan live AWS infrastructure against your state file
driftsentry scan --state-file ./terraform.tfstate

# 3. Generate an interactive HTML drift report
driftsentry report --format html --output drift-report.html

# 4. Auto-remediate and open a Pull Request with AI root-cause analysis
driftsentry remediate --ai --create-pr --repo "myorg/infra-repo"
```

---

## Documentation

- [Getting Started](docs/getting-started.md) — Installation options, AWS credentials setup, running first scans, and Docker usage.
- [Multi-Account & Multi-Region](docs/multi-account-multi-region.md) — Enterprise AWS Organizations setup, role templates, dynamic region discovery, and parallel execution.
- [Configuration](docs/configuration.md) — `.driftsentry.yaml` schema, environment variables, and recommended read-only IAM policy.
- [CLI Reference](docs/api.md) — Complete command options, flags, and exit codes for `scan`, `report`, and `remediate`.
- [Architecture & Internals](docs/architecture.md) — 5-stage pipeline design, diff engine algorithms, and CloudTrail correlation.
- [AI Smart Remediation](docs/ai-remediation.md) — Claude and Gemini LLM setup, prompt guardrails, and auto-generated HCL blocks.
- [Policy as Code](docs/policy-as-code.md) — Severity classification rules, noise suppression, and CI/CD threshold controls.
- [Deployment & CI/CD](docs/deployment.md) — Scheduled scans in GitHub Actions and GitLab CI with automated Slack alerting.
- [Custom Resources](docs/custom-resources.md) — Pluggable zero-code YAML schema and Python collector plugins for AWS resources.
- [Development](docs/development.md) — Local development workflow, running test suites, and linting.

---

## Architecture

DriftSentry processes infrastructure drift through an automated 5-stage pipeline:

```
IaC State (.tfstate) ──┐
                       ├──► Deep Diff Engine ──► CloudTrail Attribution ──► LLM Remediation & PR
Live AWS Cloud API  ───┘
```

For complete state reader abstractions, attribution lookups, and sequence diagrams, see [Architecture](docs/architecture.md).

---

## Contributing & License

- Development setup and PR checklists are in [CONTRIBUTING.md](CONTRIBUTING.md).
- Distributed under the [Apache License 2.0](LICENSE).
