Skip to content

Terraform and OpenTofu drift monitors

A drift monitor schedules read-only Terraform or OpenTofu checks for one existing instance. It reuses the instance’s published template version, environment, resolved inputs, connections, and managed-state context. It does not create a second deployment target.

A monitor detects and records drift. It does not silently change infrastructure. Convergence is a separate, feature-gated request that follows the drift convergence workflow.

Confirm that:

  • the instance points to the published template version you want to compare;
  • its environment has the drift_monitoring.enabled feature gate;
  • the worker pool can execute the required Terraform or OpenTofu version;
  • connections, secret bindings, and managed state are usable for a read-only check; and
  • the cadence and dedupe window match the operational noise and provider limits you can support.

A disabled environment gate blocks monitor creation or execution. It does not delete the monitor configuration or its history.

Choose the instance, cadence, dedupe window, and whether a detected finding should automatically request approval for the next supported workflow. The monitor’s configuration state is explicit:

State Scheduling behavior
draft Configuration is saved but never scheduled.
active Checks are eligible at the configured cadence.
paused Scheduling stops temporarily while configuration and history remain available.
disabled The monitor is deactivated and schedules no new checks.

Saving an edit does not silently activate a draft. Pause or disable a monitor when its credentials, provider access, instance, or expected configuration is under change.

Parameter Value
Minimum interval 60 seconds
Maximum interval 7 days
Default interval 4 hours

After an active monitor completes, Forgeplane calculates its next due time from the configured cadence. Draft, paused, and disabled monitors are not scheduled. A due monitor creates a non-mutating drift run; the worker compares the instance context with live infrastructure and reports the result.

Configuration state and the latest check result are separate. A monitor can be active while its most recent check failed, or paused while retaining a prior drift_detected result.

Status Meaning
idle No check is running.
running A drift run is active.
no_drift The latest check found no drift.
drift_detected The latest check produced drift evidence.
failed The latest check failed.

consecutive_failures resets after a successful check. Repeated failures can indicate credential, provider, worker-capability, or reachability problems; they are not evidence of drift by themselves.

When a check finds drift, Forgeplane records evidence and reuses an active finding when its fingerprint and scope match. The dedupe window throttles repeated automatic approval requests; it does not group findings. See the drift observation workflow for the distinction.

Review the finding’s evidence, severity, observation history, and current instance context before requesting a response. See Drift detection for finding states and supported resolution types.

A monitor may automatically request approval for a supported follow-up. That option prepares the review step; it never approves or applies a change by itself.

Today, only revert_live convergence is executable. accept_live and codify_live are represented in the data model but their requests fail with a conflict. Any executable convergence remains subject to the environment’s feature gates and the normal review and evidence checks.

For run status, logs, cancellation, and follow-up operations, see Run operations.