Configuration Drift

· 1 min read · Terraform

Configuration drift happens when the real infrastructure no longer matches what the code and the Terraform state describe, usually because someone changed a resource manually in the console, or another tool modified it.

Detect it #

  • terraform plan refreshes the state and shows the differences. Run it on a schedule in CI/CD and alert when the result is not empty.
  • terraform plan -refresh-only shows only the drift, without proposing code changes.
  • AWS Config and CloudFormation drift detection serve the same purpose for other tools.

Fix it #

  1. Decide which side is right.
  2. If the manual change was wanted, update the code to match it.
  3. If not, run apply to restore the code definition.
  4. Remove the cause: restrict console write access and require changes through the pipeline.

Attributes that another system changes on purpose can be ignored with ignore_changes. See also best practices.

#Terraform #OpenTofu