Solutions · Configuration drift

Notice when provider configuration changes behind your back

Configuration is right on the day you set it up. Then someone edits a dashboard setting, an old resource lingers, or an environment changes, and the stack quietly stops matching what you approved. Drift detection answers one question: did anything change from the state I expect?

How drift happens

Almost never on purpose:

  • A quick fix made directly in a provider's dashboard that never gets written down.
  • An old resource or project left running after the app moved on.
  • An environment that was copied once and has since diverged.
  • A teammate or a script changing a setting the app depends on.

How Ahena detects it

  1. Record the expected state

    ahena lock reads every connected provider and writes ahena.lock, a git-safe record of the values Ahena manages. Ahena's own changes update it, so they're never reported as drift.

  2. Compare live values

    ahena drift compares what providers report now with ahena.lock and lists each changed value with its severity.

  3. Decide per change

    Accept the new value, fix it back to what ahena.config.ts declares (through the usual plan and approval), or ignore it for 7 days, recorded so teammates and CI see the same decision.

  4. Without your laptop

    Continuous Doctor runs Doctor and drift on a schedule per environment, from the lock the CLI last shared, and emails findings. ahena deploy-check fails on high-severity drift.

Recording and checking

$ ahena lock && git add ahena.lock # the state you expect
$ ahena drift -e production # what changed outside Ahena
$ ahena drift --accept # keep the change: update ahena.lock

Good to know

  • Drift covers the values each provider integration records (each integration page lists them); AI providers have no drift tracking.
  • Drift tells you what changed, not who changed it at the provider: provider dashboards keep that history.
  • Local providers (Ollama) are checked by the CLI on your machine, not by Ahena's servers.

Questions

How do I detect configuration drift across SaaS providers?

Record the expected state with ahena lock, then run ahena drift (or turn on Continuous Doctor) to compare each provider's live settings with it. Each change is reported with its severity and can be accepted, fixed through an approved plan, or ignored for a week.

How is drift different from Doctor?

Doctor asks whether the configuration is correct; drift asks whether it changed from the recorded state. A setting can be correct and drifted (someone improved it by hand), or unchanged and wrong.