SkillByAIOpen interactive version →

Lesson 12 / 25

Drift

When someone changes infrastructure by hand.

Detect and reconcile

Drift is a difference between real infrastructure and what Terraform last recorded, usually caused by manual console changes, other tools or incidents. Each plan refreshes state and proposes changes to bring reality back to the configuration. Decide whether the manual change was a mistake (let Terraform revert it) or should be kept (update the configuration). Run scheduled plans to detect drift early.

Detecting a hand-edited file, run

I ran this with Terraform 1.16.4 and the hashicorp/local 2.9.1 and hashicorp/random 3.9.1 providers, which manage local files and random values, so no cloud account was needed; each example starts from a fresh directory. After the file is edited outside Terraform, the next plan notices that the managed content no longer exists as recorded and plans to create it again. Cloud providers usually show such drift as in-place updates of the changed attributes instead.

echo "env=hacked" > out/shop-dev.conf   # someone edits the file by hand
terraform plan -no-color | grep -E "will be created|Plan:"

Output:

  # local_file.config will be created
Plan: 1 to add, 0 to change, 0 to destroy.

Run plans on a schedule

A nightly plan with -detailed-exitcode in CI alerts you to drift before it surprises the next deploy.

Quick check: What should you do when a plan shows drift from a deliberate manual change?

  • Ignore it forever
  • Update the configuration to match, so Terraform does not revert it
  • Delete the state file
  • Disable plans
Answer

Update the configuration to match, so Terraform does not revert it — Code must remain the source of truth.