Configuration Drift
The gap that opens between the infrastructure your code describes and the infrastructure that actually exists.
Drift is created by the emergency at 3 AM: someone raises a limit, opens a security group, resizes an instance to stop the bleeding, and the fix never returns to the repository. It is created by consoles that make one-click changes easy, by autoscalers and controllers that legitimately mutate resources, and by cloud providers changing defaults underneath you.
The damage is delayed and specific. The next apply silently reverts the emergency fix and re-opens the incident, or refuses to run at all. Disaster recovery from code rebuilds an environment that was never the one you were running. And the code stops being trustworthy as documentation, which is most of its value.
Detection is the practical control: a scheduled plan or drift check that reports differences without applying them, reported as an operational signal rather than noise. GitOps reconciliation takes the stronger position of correcting drift continuously.
The nuance worth stating: not all drift is unwanted. Replica counts under an autoscaler and provider-managed tags will always differ from source, and the tooling needs to be told to ignore them, or the alert becomes noise and gets muted — after which real drift hides in it.