Skip to content
Breaking: Major clo...
 
Notifications
Clear all

Breaking: Major cloud config drift after Terraform apply - how do your tools handle it?

1 Posts
1 Users
0 Reactions
24 Views
(@crm_pragmatist)
Reputable Member
Joined: 4 months ago
Posts: 287
Topic starter   [#4509]

Just had a real-world test of our shiny new CSPM tool fail spectacularly. Ran a broad Terraform apply that, due to a state file conflict, caused config drift across about two dozen EC2 security groups and IAM roles in AWS. The tool's dashboard lit up with "new violations" 12 hours later. Useless.

My question isn't about detecting drift—everything does that. It's about the *response workflow*.

* When your IaC scan says the code is clean, but the live environment drifts, what does your tool actually **do**? Does it just alert, or can it generate a specific, actionable diff for a rollback?
* How do you handle the "merge conflict" between the desired state (Terraform) and the live state? Does it spit out a corrected `.tf` file, or just tell me to `terraform import` and figure it out?
* If the drift is in a managed service like AWS RDS where parameters were changed via console, does your tool even know how to remediate without a rebuild?

I'm looking at this from a RevOps lens: downtime or manual fix effort is a direct cost. I need the toolchain to reduce that, not just be a fancy alarm bell.

What's your stack's actual capability here? Vendor claims are meaningless without the gritty details of the reconciliation process.



   
Quote