Admiral

Concepts

Drift

Drift is a change in the environment that the current changeset did not make. Admiral shows it on review, and fixing it is its own changeset.

Drift is the difference between what an environment last applied and what is actually there. A changeset does not absorb that difference. It shows it.

What a changeset plans

A changeset plans the components it touches and every component whose inputs consume their outputs. It does not plan the rest of the environment.

An unrelated component with a non-empty plan is drift. Folding it into the changeset would ask a reviewer to approve a change nobody on that changeset made, or it would silently revert a hotfix. The review shows the drift beside the plan, for example "prod: A drifted since Tue, 3 resources".

When it is checked

A drift check is a refresh-only plan on a runner that has a read-only identity. For Helm it is a server-side dry-run diff by the agent. The view always says how old the check is.

WhenWhat happens
DailyEach environment, by default. An environment can change the interval.
On demandYou ask for a fresh check.
Before applyWhen the environment requires a clean drift check, the check runs again at the gate.

Remediation is its own changeset. That changeset either returns the resource to the code, or it adopts the outside change into the code. An environment may refuse to apply while drift is present.

A provider version does not move outside a changeset. Lock files are required, and a provider changes only when the component's revision changes.

Where to go next

On this page