Lesson 2 of 5 ยท Terraform State & Drift Detection
Why infrastructure drift happens
Drift happens when a cloud resource changes outside the Terraform workflow. A console edit during an incident, a manual deletion, another automation, a provider-managed default, or a second state file can all create a mismatch. The important question is not only what changed, but whether the change was approved and who owns the resource now.
Example
# Desired configuration
resource "aws_security_group" "app" {
# intended rules live here
}
# A console rule added later can create drift.Step by step
- Find the resource and attribute that changed.
- Check who made the change and why.
- Decide whether the cloud change is now approved intent.
- Document the ownership boundary before the next apply.
Common mistakes to avoid
- Assuming all drift is malicious or accidental.
- Letting several tools manage the same resource.
- Applying a plan before understanding an out-of-band change.