Terraform and OpenTofu drift monitors
A drift monitor schedules read-only Terraform or OpenTofu checks for one existing instance. It reuses the instance’s published template version, environment, resolved inputs, connections, and managed-state context. It does not create a second deployment target.
A monitor detects and records drift. It does not silently change infrastructure. Convergence is a separate, feature-gated request that follows the drift convergence workflow.
Before creating a monitor
Section titled “Before creating a monitor”Confirm that:
- the instance points to the published template version you want to compare;
- its environment has the
drift_monitoring.enabledfeature gate; - the worker pool can execute the required Terraform or OpenTofu version;
- connections, secret bindings, and managed state are usable for a read-only check; and
- the cadence and dedupe window match the operational noise and provider limits you can support.
A disabled environment gate blocks monitor creation or execution. It does not delete the monitor configuration or its history.
Create and activate a monitor
Section titled “Create and activate a monitor”Choose the instance, cadence, dedupe window, and whether a detected finding should automatically request approval for the next supported workflow. The monitor’s configuration state is explicit:
| State | Scheduling behavior |
|---|---|
draft |
Configuration is saved but never scheduled. |
active |
Checks are eligible at the configured cadence. |
paused |
Scheduling stops temporarily while configuration and history remain available. |
disabled |
The monitor is deactivated and schedules no new checks. |
Saving an edit does not silently activate a draft. Pause or disable a monitor when its credentials, provider access, instance, or expected configuration is under change.
Cadence and scheduling
Section titled “Cadence and scheduling”| Parameter | Value |
|---|---|
| Minimum interval | 60 seconds |
| Maximum interval | 7 days |
| Default interval | 4 hours |
After an active monitor completes, Forgeplane calculates its next due time from the configured cadence. Draft, paused, and disabled monitors are not scheduled. A due monitor creates a non-mutating drift run; the worker compares the instance context with live infrastructure and reports the result.
Runtime status
Section titled “Runtime status”Configuration state and the latest check result are separate. A monitor can be active while its most recent check failed, or paused while retaining a prior drift_detected result.
| Status | Meaning |
|---|---|
idle |
No check is running. |
running |
A drift run is active. |
no_drift |
The latest check found no drift. |
drift_detected |
The latest check produced drift evidence. |
failed |
The latest check failed. |
consecutive_failures resets after a successful check. Repeated failures can indicate credential, provider, worker-capability, or reachability problems; they are not evidence of drift by themselves.
Findings and deduplication
Section titled “Findings and deduplication”When a check finds drift, Forgeplane records evidence and reuses an active finding when its fingerprint and scope match. The dedupe window throttles repeated automatic approval requests; it does not group findings. See the drift observation workflow for the distinction.
Review the finding’s evidence, severity, observation history, and current instance context before requesting a response. See Drift detection for finding states and supported resolution types.
Approval and convergence
Section titled “Approval and convergence”A monitor may automatically request approval for a supported follow-up. That option prepares the review step; it never approves or applies a change by itself.
Today, only revert_live convergence is executable. accept_live and codify_live are represented in the data model but their requests fail with a conflict. Any executable convergence remains subject to the environment’s feature gates and the normal review and evidence checks.
For run status, logs, cancellation, and follow-up operations, see Run operations.