// the find
Kong/deck
decK: Configuration management and drift detection for Kong
decK is Kong's own CLI for declarative configuration management of Kong Gateway and Konnect — it exports the live Admin API state to YAML, diffs that against a config file, and syncs either direction. It's for teams running Kong who want GitOps-style config instead of manual Admin API calls or clicking through a dashboard.
Diff/sync is bidirectional — it detects drift when someone makes a manual change directly against the Admin API, not just one-way push from file to server. It also ships kong2kic and kong2tf subcommands to convert existing Kong config into Kubernetes Ingress/Gateway API CRDs or Terraform, which is a real escape hatch if you're migrating off Kong's own Admin API model. Integration tests run against live Kong instances across several Kong versions (OSS, Enterprise, Konnect), which is more rigorous than most config-management CLIs bother with.
It's a first-party Kong Inc. tool, so Konnect (the commercial SaaS control plane) features get priority over community asks — expect the roadmap to track Kong's product strategy, not generic GitOps needs. The convert/rulesets directory (280-to-340, 310-to-314, etc.) shows how much of the codebase is version-migration glue tied to Kong's own schema churn, which is inherent fragility you inherit as a dependency. Auth to the Admin API is just custom headers you inject yourself — there's no built-in support for anything beyond that, so you're on your own for token rotation or more complex auth setups. The binary also does a lot: declarative sync, drift detection, and three separate format converters (KIC, Terraform, OpenAPI) bolted onto one CLI, which is more surface area than you need if you only care about diff/sync.