Skip to content

Drift Detection

Terraform's drift detection and remediation capabilities are essential for maintaining alignment between your infrastructure as code (IaC) configuration and the actual state of your cloud environment. Drift occurs when the real infrastructure deviates from the Terraform state file, often due to manual changes or external processes. This section explains how to use terraform apply with the -replace flag to detect and correct such drift. terraform destroy is used for deleting all managed resources, not for replacing specific ones.


Detecting Drift with terraform plan

Before remediation, you must first identify drift. Use terraform plan with the -detailed-explanation flag to get granular insights into resource mismatches:

terraform plan -detailed-explanation

This command highlights resources that are out of sync with the state file, such as incorrect attributes or missing resources. For example, if an EC2 instance has been manually modified, the output will show discrepancies like unexpected tags or security group changes.


Correcting Drift with terraform apply -replace

When drift is detected, use terraform apply with the -replace flag to force Terraform to replace specific resources, ensuring the state file is updated to match the actual infrastructure. This is particularly useful when a resource's attributes can't be updated in place (e.g., due to API limitations or configuration changes):

terraform apply -replace="aws_instance.example"

Key considerations: - Resource replacement creates a new resource and updates the state file to reflect the new resource ID. - Use -replace sparingly, as it can lead to unexpected costs or downtime. Always verify the impact of replacements in a test environment first.


Remediation with terraform destroy

In some cases, drift may involve resources that are no longer needed or cannot be reconciled. For example, if a manually created resource conflicts with your Terraform configuration, you may need to destroy it explicitly. terraform destroy deletes all resources managed by Terraform. For targeted destruction (e.g., removing a single S3 bucket), use -replace in combination with a terraform apply to ensure the state is updated before deletion:

terraform apply -replace="aws_s3_bucket.example"
terraform destroy -force

Note: terraform destroy is not used with -replace. It is strictly for deleting all managed resources. Always confirm the scope of destruction to avoid unintended resource removal.


Best Practices for Drift Remediation

  1. Automate drift detection using CI/CD pipelines and regular terraform plan checks.
  2. Isolate replacements to minimize risks—test -replace in non-production environments first.
  3. Document manual changes to avoid future drift, and ensure they are reflected in your Terraform configuration.
  4. Use state locking to prevent concurrent modifications that could introduce drift.

Key takeaways

  • Use terraform plan -detailed-explanation to identify drift and understand resource mismatches.
  • Apply terraform apply -replace to force replacements of problematic resources, ensuring state alignment.
  • Use terraform destroy to remove resources that cannot be reconciled, but prioritize targeted actions over full destruction.
  • Combine drift detection with automation and state management to maintain infrastructure consistency.