Everyone is wrong about Configuration Drift

2 davletdzh 1 8/21/2025, 8:44:21 AM davletd.medium.com ↗

Comments (1)

HelloNurse · 4h ago

  > Instead of only offering the traditional “overwrite cloud with IaC” fix, we built the reverse. A back-sync.

  > No diff. No surprises. Just your IaC, in sync with reality.
This is obviously bad because, even if there was a good reason for manually altering something, the reconciliation between "reality" and the written configuration should force someone to review the changes. Otherwise sooner or later bad changes will be made by accident and automatically adopted as official.

  > What if that drift was a deliberate, urgent hotfix made under fire to keep production alive? What if the organization is still in that messy transition between ClickOps and IaC, where already swamped teams simply cannot afford to be slowed down by more process police?
Until the authoritative IaC sources have been updated and tested, the hotfix is not done.

Shortcuts to repair a production environment slightly faster are extra effort that can be worthwhile, but pretending to be unable to afford a sustainable process is a terrible attitude and being actually "swamped" is a worse problem than a software malfunction.