Terraform State & Drift · Terraform systems note
Terraform Drift Detection Is Not the Same Thing as Drift Repair
A normal plan refreshes reality before calculating changes. Refresh-only mode updates Terraform's recorded view without changing infrastructure. The real decision is which side is authoritative.
Drift means configuration, state and remote reality disagree. Detecting that difference is easier than deciding how to resolve it.
Normal plan usually reconciles toward code
Terraform refreshes managed objects before planning and then proposes changes that make remote infrastructure match configuration.
Refresh-only reconciles state toward reality
terraform plan -refresh-only shows state changes Terraform would record from the remote system without proposing remote modifications. apply -refresh-only commits that view.
This is useful when an external change was intentional and Terraform should accept it.
The old terraform refresh command is risky
HashiCorp deprecates the standalone command because it effectively applies state refresh without giving you the same review workflow. Wrong credentials can make objects appear missing and update state in dangerous ways.
Repeated drift is an ownership problem
If an autoscaler or managed service legitimately owns one attribute, the solution may be an explicit ownership boundary rather than endless reconciliation. If humans keep editing production manually, the solution is process and access control.
A drift workflow should answer: what changed, who owns that field, and whether code or remote reality should win.