Lesson 2 of 5 ยท Terraform State & Drift Detection

Why infrastructure drift happens

Drift happens when a cloud resource changes outside the Terraform workflow. A console edit during an incident, a manual deletion, another automation, a provider-managed default, or a second state file can all create a mismatch. The important question is not only what changed, but whether the change was approved and who owns the resource now.

Example

# Desired configuration
resource "aws_security_group" "app" {
  # intended rules live here
}

# A console rule added later can create drift.

Step by step

  1. Find the resource and attribute that changed.
  2. Check who made the change and why.
  3. Decide whether the cloud change is now approved intent.
  4. Document the ownership boundary before the next apply.

Common mistakes to avoid

  • Assuming all drift is malicious or accidental.
  • Letting several tools manage the same resource.
  • Applying a plan before understanding an out-of-band change.