
AWS Bites 131. What do you do about CloudFormation Drift?
Sep 19, 2024
Explore the intriguing concept of CloudFormation drift, where actual resource states diverge from configured templates. Discover various causes, including manual changes and third-party tools, that can lead to this phenomenon. Learn about built-in drift detection features and how to implement alarms for better monitoring. Strategies like change sets and parallel stacks are discussed to effectively reconcile drift while minimizing downtime. Maintain integrity in your infrastructure with actionable insights on managing CloudFormation drift.
AI Snips
Chapters
Transcript
Episode notes
CloudFormation Drift
- CloudFormation drift occurs when your infrastructure's actual state deviates from your template.
- This can happen with any IaC tool, not just CloudFormation.
Manual Changes and Drift
- Manually tweaking EC2 settings or security groups can cause drift.
- Luciano highlighted that changing Fargate service's task numbers is a common cause.
Mitigating Drift
- Avoid manual changes unless absolutely necessary, and update IaC promptly.
- Use IaC consistently; avoid mixing manual and IaC management for the same resources.
