drift migrate
Move off another cloud. Every step runs locally, with your own provider login, Drift never holds your credentials or your data. The first provider is Azure; see the migration guide for the whole story.
| Command | Description |
|---|---|
drift migrate azure estimate -g <rg> [--json] [--csv] [--dry-run] | Read-only: map an Azure resource group's cost to the equivalent Drift slice |
drift migrate azure snapshot -g <rg> -o <dir> [--deref-secrets] [--source app=dir] | Read-only: pull function source, Cosmos documents, blobs, queue messages, $web sites, and app settings into a vendor-neutral folder |
drift migrate azure transform -i <dir> -o <dir> | Offline: rewrite the export into a deployable Drift project (validated Driftfile + scaffolds) |
drift migrate azure apply -i <dir> [--accept-refusals] | Deploy the workspace; hard-refuses anything in REFUSED.md unless --accept-refusals |
The first two are read-only against your provider, and transform touches no network at all so you can run the whole assessment before deciding anything.
estimate --dry-run prints the az commands it would run and fetches nothing; --json/--csv change only the output format. snapshot writes app settings as secret names, never values, unless --deref-secrets asks for the plaintext too, in which case it lands on disk mode 0600, unencrypted. --source <app>=<dir> skips live retrieval for a function app you already have a local copy of, which works regardless of plan type. snapshot also needs mongoexport on your machine to read a Cosmos account's data, and squashfs-tools for Linux Consumption source; a missing one fails loudly with the command that installs it.
Nothing deploys while REFUSED.md still has entries.
transform writes it listing what it would not translate, and apply refuses to deploy while anything is on it. That is deliberate: a migration that silently drops a resource is worse than one that stops and names it.