Skip to content

Manual console changes, configuration drift and broken state files

Terraform drift remediation and infrastructure as code

Bring console-created resources under Terraform or OpenTofu, split monolithic state, and run every infrastructure change through a reviewed plan in CI.

Symptoms

Signs your platform has this problem

If several of these sound familiar, the plan below is where we would start.

01

Console changes breaking Terraform

Manual tweaks in the cloud console that make terraform apply fail or fight the console.

02

One huge state file

State lock contention and slow plans from a single monolithic configuration.

03

No reviewed plans

Infrastructure changes applied from laptops without peer review.

Remediation plan

How we fix it, step by step

Each phase ends with a measurement, so you can see what changed before the next one starts.

01

Resource discovery

Scanning cloud accounts for unmanaged resources and drift.

02

Modules and state splitting

Splitting monolithic state into isolated modules (network, cluster, databases), for example with Terragrunt.

03

Importing existing resources

Bringing existing resources into code with terraform import, without recreating or destroying them.

04

Plan and apply in CI

Atlantis or GitHub Actions showing plans on pull requests, with OIDC credentials.

Technical checklist

Remediation checklist

What we check before a change goes to production:

  • Import every console-created resource into Terraform
  • Split monolithic state into modular directories
  • Use OIDC instead of static credentials for CI deployments
  • Run a daily drift-detection plan that alerts on differences

What we measure

We take a baseline first and report the same measurements after each change, from your own monitoring — evidence, not promised results.

Managed resources
Resources under Terraform vs found by discovery
Drift alerts
Drift detected by the daily plan, per week
Plan time
terraform plan duration per state, before and after

Related service

Cloud & DevOps

Cloud cost optimization, Kubernetes platforms, and CI/CD that make deploys boring — savings and reliability measured in your dashboards, not our deck.

Explore Cloud & DevOps

Questions

Questions about this remediation

We write matching resource definitions, run terraform import, and confirm with terraform plan that nothing will be destroyed or replaced before anything is applied.

Separate states for networking, compute and data limit the blast radius of a change, remove lock contention between teams and make plans faster.

Want an engineer to look at this with you?

Send us the symptoms and any metrics you have. We'll reply within one business day, set up a call and agree what to measure before anything changes.