Drift & Reconcile

Continuous desired-vs-actual comparison. Reconcile renders a plan; the exact plan you confirm is what executes, audited before any delete.
Managed
128
declared & live · in sync
Orphaned
3
live, tagged, not in state
Ghost
not computable on AWS — omitted, not “0”
Unknown
2
not correlatable · never deletable
Config drift
1
manual change detected
Provider fidelity — AWS: enumerate partial · correlate partial · delete best-effort. Some orphans are enumerable but not deletable — reported as skipped, never counted as cleaned. A bucket the engine could not compute is omitted from the report entirely.

Orphaned resources

tagged ManagedBy=cf · absent from declared state
ResourceTypeAgeDeletable
vf-prod-nat-b
left by an interrupted destroy · $32/mo
nat_gateway41d yes
vf-prod-snap-0612
orphaned EBS snapshot · $4/mo
ebs_snapshot54d yes
vf-prod-role-ingest-old
IAM role · no generic delete-by-ARN on AWS
iam_role78d skipped — reported
Review plan pl-88c1 in Approvals Plan-then-confirm. Nothing deletes without the typed confirmation.

Unknown — protected from deletion

could not be correlated · fail closed
arn:aws:sgr:…/sgr-09ab
security-group rule — identifier not projectable from state
unknown — never deletable
vf-prod-tfstate (S3)
state backend — protected: deleting it strands the state describing every deploy
protected
A resource is orphaned only if it was enumerated and its identifier was projected from state. Anything the engine cannot decide lands here — visible, and structurally excluded from every deletion set.

Configuration drift

Manual change on ingressproxy-body-size 8m → 64m, changed out-of-band 3d ago (kubectl, unaudited).
  ingress:
    annotations:
-     nginx.ingress.kubernetes.io/proxy-body-size: 8m   # declared
+     nginx.ingress.kubernetes.io/proxy-body-size: 64m  # live

Out-of-band changes are surfaced and asked about — never silently reverted.

Firewall — declared vs live

1 manual rule drifted meridian-health/prod · Azure NSG · subnet snet-apps
PriRuleSourceDest / portActionOwner
100allow-https-inboundInternetLB · 443/tcpallowcf-managed
110allow-health-probeAzureLBnodes · 10254/tcpallowcf-managed
200allow-vnet-internalVNetVNet · anyallowcf-managed
300allow-nat-egresssnet-appsallow-list · 443/tcpallowcf-managed
350temp-allow-vendor-vpn
added manually in the Azure portal · Aug 1 · not in declared state
203.0.113.40/32nodes · 22/tcpallowmanual · drift
4000deny-ssh-inboundInternetany · 22/tcpdenycf-managed
4096deny-all-inboundanyanydenycf-managed
NSGs and security groups are engine-owned resources — diffed and reconciled like everything else.

Fleet drift posture

read-only scan, every environment, every cycle
EnvironmentCloudLast scanManagedOrphanedUnknownConfig driftReconcile capability
verde-foods / prodaws13:47 today128321report + best-effort clean
meridian-health / prodazure13:02 today141000full clean available
helios-energy / prodazure12:40 today139000full clean available
osaka-robotics / prodaws11:15 today117010report + best-effort clean
cobalt-mining / prodair-gappedbundle · 3d ago96000report via bundle