Q: A critical infrastructure configuration was manually modified via the AWS Console at 3 AM to fix an outage (Configuration Drift). The next morning, a CI pipeline runs `terraform apply` for an unrelated change. What happens and how do you reconcile this?
Because Terraform is declarative, it compares the desired state (the code) with the actual state (the AWS environment). When terraform ap...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
Because Terraform is declarative, it compares the desired state (the code) with the actual state (the AWS environment). When terraform apply runs, it will detect the 3 AM manual CLI/Console change, mark it as drift, and destroy the manual fix to revert the infrastructure back to exactly what is defined in the .tf files. To reconcile this: The manual change must be codified *before* anyone runs apply. A developer needs to write the equivalent Terraform code matching the manual 3 AM fix, run terraform plan to ensure zero changes are pending (meaning the code now perfectly matches reality), and then merge that code to main.
- Immediate Triage: Because Terraform is declarative, it compares the desired state (the code) with the actual stat
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.