Configuration Drift
Configuration drift happens when the real infrastructure no longer matches what the code and the Terraform state describe, usually because someone changed a resource manually in the console, or another tool modified it.
Detect it #
terraform planrefreshes the state and shows the differences. Run it on a schedule in CI/CD and alert when the result is not empty.terraform plan -refresh-onlyshows only the drift, without proposing code changes.- AWS Config and CloudFormation drift detection serve the same purpose for other tools.
Fix it #
- Decide which side is right.
- If the manual change was wanted, update the code to match it.
- If not, run
applyto restore the code definition. - Remove the cause: restrict console write access and require changes through the pipeline.
Attributes that another system changes on purpose can be ignored with ignore_changes. See also best practices.