Lesson 4 of 5 ยท Terraform State & Drift Detection
Reconcile drift with clear ownership
After you identify drift, make an explicit decision. If the live change is correct, update Terraform configuration through review so it records the approved design. If the change was temporary or unsafe, use a reviewed plan to return the cloud resource to configuration. Direct state edits should not be the default answer because they can hide a real ownership or security problem.
Example
# Example: make an approved live change visible in configuration
resource "aws_s3_bucket_versioning" "assets" {
bucket = aws_s3_bucket.assets.id
versioning_configuration { status = "Enabled" }
}Step by step
- Write down whether configuration or cloud reality is the approved source of truth.
- Make the smallest reviewable configuration change required.
- Review the plan for replacement, deletion, access, and data risk.
- Use Drift Explorer again to confirm the reconciliation story.
Common mistakes to avoid
- Silencing drift by editing state without a decision.
- Leaving an approved emergency change undocumented.
- Using a second Terraform state to take over an existing resource.