# drift
The drift analyser breaches whenever its input is non-empty. It is designed to
pair with the file:drift fact: any drift content at
all is itself the assertion failure.
# Plugin fields
drift has no plugin-specific fields — there is nothing to configure beyond the
common ones below.
No inverse polarity
Unlike allowed:list or regex:match, drift has no toggle to invert the
assertion. Drift always means breach.
# Common fields
| Field | Description | Required | Default |
|---|---|---|---|
| name | The name of the policy - this is the yaml key in the config file when defining the policy. | Yes | - |
| description | The description of the policy - if specified, it will be used as the heading for the policy in the output. | No | "" |
| input | The input for the policy - used to select the fact plugin to use. | Yes | - |
| severity | The severity of the policy when breached (low, normal, high, critical) | No | normal |
| breach-format | The breach template for the policy. The table below shows the available fields. | No | Empty breach template |
| remediation | The remediation for the policy. The table below shows the available fields. | No | Empty remediation |
# Breach template
WARNING
TODO: Add information on how to use go template variables.
| Field | Description | Required | Default |
|---|---|---|---|
| type | The type of breach. | Yes | "" |
| key-label | The label for the key. | No | "" |
| key | The key. | No | "" |
| value-label | The label for the value. | No | "" |
| value | The value. | No | "" |
# Remediation
| Field | Description | Required | Default |
|---|---|---|---|
| plugin | The plugin to use for remediation. | No | "command" |
| msg | The message to display when remediation completes successfully. | No | "remediation successful" |
| ... | Any fields required by the plugin. | No | - |
# Example
analyse:
ci-matches-template:
drift:
description: CI workflow has not drifted from the project template
input: ci-drift
Source: examples/file-drift.yml — see also the
filediff recipe.
# Breach output
Breaches carry the full unified diff via KeyValuesBreach, legible in the
pretty, json and junit renderers. The table renderer does not wrap
multi-line breach values, so avoid it for drift checks.