# Configuration Drift

> Configuration drift is the difference between the real infrastructure and its Terraform code or state, caused by manual changes. Learn how to detect and fix it.

- Source: https://www.itwonderlab.com/terraform-drift/
- Published: 2026-08-08
- Updated: 2026-08-08
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**Configuration drift** happens when the real infrastructure no longer matches what the code and the [Terraform state](https://www.itwonderlab.com/terraform-state/) describe, usually because someone changed a resource manually in the console, or another tool modified it.

### Detect it

- `terraform plan` refreshes the state and shows the differences. Run it on a schedule in [CI/CD](https://www.itwonderlab.com/terraform-github-actions-aws-oidc/) and alert when the result is not empty.
- `terraform plan -refresh-only` shows only the drift, without proposing code changes.
- AWS Config and CloudFormation drift detection serve the same purpose for other tools.

### Fix it

1. Decide which side is right.
2. If the manual change was wanted, update the code to match it.
3. If not, run `apply` to restore the code definition.
4. Remove the cause: restrict console write access and require changes through the pipeline.

Attributes that another system changes on purpose can be ignored with [`ignore_changes`](https://www.itwonderlab.com/terraform-lifecycle-meta-argument/). See also [best practices](https://www.itwonderlab.com/terraform-best-practices/).
