IaC Modules & Drift
Reusable infrastructure modules, state ownership, and detecting what changed out of band.
4 to work through
-
beginner
You run `terraform plan` on a production workspace where nothing has been committed for three weeks. The plan proposes 23 changes. Nobody has touched the console. Why does this happen, and what should you do about each kind?
3 min answer -
intermediate
An organisation's infrastructure code has become a sprawl of copied configurations. What module strategy works, and how is drift handled?
2 min answer -
intermediate
Your infrastructure drift detection fires 200 alerts a day. The team has muted it. How do you make it useful again?
2 min answer -
advanced
One Terraform state file holds 4,000 resources across networking, databases, Kubernetes and DNS for production. A plan takes 14 minutes, every change risks unrelated resources, and four teams contend for the lock. You must split it into per-domain states without destroying anything. What is the sequence?
4 min answer
3 terms in this topic
Configuration Drift
The gap that opens between the infrastructure your code describes and the infrastructure that actually exists.
practiceConfiguration Drift Detection
Continuously comparing declared infrastructure against what actually exists, so out-of-band change is found on a Tuesday rather than during a rebuild.
practiceInfrastructure State Partition
Splitting one infrastructure state file into several along ownership and lifecycle boundaries, so plans are fast and a mistaken apply cannot reach un…
Neighbouring topics
Delivery & Release Engineering
General material on getting a change from commit to production safely and often.
Pipeline Architecture
Stages, fan-out, caching, and the difference between a pipeline and a long script.
Build Reproducibility
Pinned inputs and hermetic builds, so one commit cannot produce two different artifacts.
Artifact Management
Immutable versioned outputs, promotion between repositories, and retention policy.
Environment Strategy
How many environments earn their cost, what each proves, and what none of them prove.
Branching Models
GitFlow, trunk and release branches as delivery constraints rather than Git preferences.
Continuous Integration Discipline
Integrating to the mainline daily, and the test speed and review culture that requires.
Deployment Strategies
Rolling, blue-green, canary and shadow, and the traffic and state each one assumes.
Progressive Delivery
Separating deploy from release, and exposing a change to users in controlled increments.
Rollback & Forward Fix
When reversing is genuinely possible, and designing so that it usually is.
Database Migration Under CD
Expand-contract, backwards-compatible schema change, and migrations that cannot roll back.
GitOps
Declared desired state in version control, with a reconciler closing the gap continuously.
Policy as Code
Encoding standards as automated admission and plan-time checks instead of review comments.
Pipeline Secrets
Short-lived credentials, workload identity, and why the CI system is a prime target.
Supply-Chain Provenance
SBOMs, signed artifacts, attestation, and knowing what actually went into a build.
Deployment Gates
Automated verification between stages, and the difference between a gate and a delay.
Flow Metrics
Work in progress, flow time and flow efficiency — where a change waits rather than moves.
Change Management vs CD
Reconciling CAB-era controls with continuous delivery without pretending either away.
Multi-Region Rollout
Ordering regions, bake time, and stopping a bad change before it becomes global.