Skip to main content

cisco-config-drift

Read-only configuration drift detection for Cisco IOS and IOS-XE. Save an approved baseline of every device's running-config, then check on a schedule and get a clean diff of anything that changed outside change control.

Why

Unauthorized or forgotten changes are a common root cause of outages and a common audit finding (NIST 800-53 CM-3 and CM-6, CIS Control 4, IEC 62443 SR 7.6). This tool answers "did anything change on the switches since the last approved state?" without touching the devices.

Safety

  • The only command sent to a device is show running-config. Nothing is ever pushed.
  • Credentials come from the DRIFT_USERNAME / DRIFT_PASSWORD environment variables or an interactive prompt. They are never written to disk.
  • Baselines and reports contain full configurations, which can include secrets. They are git-ignored by default; store them like any other sensitive config backup.

Install

pip install -r requirements.txt
cp inventory.example.csv inventory.csv   # then edit

inventory.csv columns: name,host,device_type (Netmiko device type, defaults to cisco_ios).

Usage

python drift.py snapshot          # save approved baselines to baselines/
python drift.py check             # compare running-config to baseline, diffs go to reports/<timestamp>/
python drift.py diff old.cfg new.cfg   # offline, no device access

Volatile lines (timestamps, Current configuration : N bytes, ntp clock-period) are ignored so only real changes are reported. Extend VOLATILE_PATTERNS at the top of drift.py.

Exit codes: 0 no drift, 1 drift found, 2 error. That makes it easy to alert from Task Scheduler, cron or CI.

Every run logs to logs/drift.log with one VERIFY or DRIFT line per device.

Tests

pip install pytest && python -m pytest

License

MIT. See LICENSE. Security reports: see SECURITY.md.

Metadata

Release files for cisco-config-drift 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cisco-config-drift 0.1.0
File Size Uploaded
cisco_config_drift-0.1.0.tar.gz 6.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cisco-config-drift 0.1.0
File Interpreter ABI Platform
cisco_config_drift-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 12.0 kB

Release files / cisco_config_drift-0.1.0.tar.gz

Download URL cisco_config_drift-0.1.0.tar.gz
Size 6.0 kB
Tags Source
SHA-256 checksum
How to use checksums
391d24b4b08802405d3f7f493ffab8d31eb40eaf63d4bc8a3fa3dc7a56a8386c
BLAKE2b-256 checksum
How to use checksums
73d6a109566651b3e1b554eb5e16f8056c37ce79ca0c62c6114ad2a2d993838c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / cisco_config_drift-0.1.0-py3-none-any.whl

Download URL cisco_config_drift-0.1.0-py3-none-any.whl
Size 6.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
eb504604da0f5e586ad9a02c2946a68a9b70221f7f9ece8a85e354d8230a9a95
BLAKE2b-256 checksum
How to use checksums
5c7c5cbbc74426e2d354111f63d62dd2bf6038fda010350843ef98acd4a737fd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page