Drift Prevention

Catch drift when reality stops matching code.

ops0 compares live infrastructure against state and code on a schedule, classifies what changed and why it matters, and routes reconciliation through review instead of guesswork.

Live state vs code
Scheduled scans
Before and after values
Blast radius before reconciling

ops0 brings your clouds, runtime, infrastructure code, and workflows into one operating context. Drift prevention compares live cloud state against Terraform state and code on a schedule, classifies severity and blast radius, and routes reconciliation through review instead of silent console edits.

ops0.ai/use-cases/drift-prevention
ops0 discovery snapshot: discovered live cloud state compared against code, with drift and unmanaged resources surfaced before they cause an incident

Your code says one thing. Your cloud quietly does another. ops0 catches the moment they split. 

Live vs state vs codeField-level diffsScheduled checksReviewed fixes
Code vs live
01 / 04 · In sync

Code and cloud agree.

Terraform says what the security group allows. The live cloud matches.

CODELIVEsg-payments-db-admin-prodINGRESS_PORT54325432INGRESS_CIDR10.0.0.0/1610.0.0.0/160.0.0.0/0EGRESS_CIDR0.0.0.0/00.0.0.0/0OWNERpayments-platformpayments-platformREGIONus-east-1us-east-1SECURITY-SENSITIVEcheckout-svcledger-apifraud-workerPR #842
1
field drifted
3
exposed
Going deeper

Every drift event, from first flag to reviewed fix.

Reality Check

Drift starts when production stops matching the record.

Live state compared against Terraform state and code.
Field-level before and after values.
Compared
3
sources checked
Drifted
2
resources
Scans
48
this week
Unmanaged
5
found
Live statecheckout-prod-eks
Compared againstTerraform state + code
Last scan14 minutes ago
Under the hood

Checked against three sources, every time.

Compared
Live state, state file, and code.
Live cloud statecheckout-prod-eks
Terraform statein sync
Codesg-payments-db-admin-prod.tf

48 scans this week. Last scan 14 minutes ago, so drift is caught between deploys, not just at release.

Severity
Security-sensitive, called out.
High severityingress_cidr
Routinetags
Blast radius
Dependency context before you react.
checkout-svc
ledger-api
fraud-worker
Unmanaged
Resources outside code surface too.
5

found this week, never written in Terraform

Cost
Cost-impacting drift stays visible.
+$210/mo

flagged alongside the drift, not in a separate report

Kiwi in Slack
Ask what drifted and why.
@ops0 what drifted this week?
One security-sensitive change, two routine ones. The ledger security group is the one to review.

Compare code, Terraform state, and live resources before deciding whether to restore the intended configuration or accept an approved change. Follow the infrastructure drift guide for a worked investigation and reviewed fix.

Common questions

Infrastructure drift happens when live cloud resources no longer match the code, state, or expected configuration used to manage them.

Keep production
honest against code.

Drift gets caught early. The reviewed reconciliation path is what keeps it from coming back.