Observed Signal · Aug 4, 2026 · Technical Implementation · Source: DEV Community · Impact: 1/5 · Sentiment: Neutral

Terraform Auto-Removes Manual AWS EC2 Tag

Executive Signal Summary

A developer tested an automatic remediation control loop that detects Terraform drift in AWS, classifies the severity, and runs a separate remediation pipeline to restore declared infrastructure. The pipeline uses a drift detector CodeBuild job that runs terraform plan, publishes structured changes via SNS, a Lambda that classifies changes (LOW/MEDIUM/HIGH) and, for eligible LOW non-deletion updates, starts a remediation CodeBuild job that runs terraform apply. The author adjusted the classifier to treat in-place updates on MEDIUM resources as LOW, separated detector and remediation IAM roles, ensured the correct Git commit is cloned for remediation, and observed that a manually added EC2 tag was removed when Terraform applied the Git-declared state.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Technical blog post describing a practical IaC drift-detection and remediation pattern; useful as implementation guidance but not industry-shifting for AdTech/MarTech.

SIGNAL RADAR

Track GitHub Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • A manual AWS EC2 tag added in the console was detected as drift and removed when Terraform applied the Git-declared configuration.
  • The detection pipeline runs terraform plan in an AWS CodeBuild project and publishes structured changes via SNS.
  • A Lambda function classifies changes into HIGH, MEDIUM, and LOW; in-place updates on MEDIUM resources were reclassified as LOW to permit automatic remediation.
  • For LOW classified changes that are not deletions, Lambda starts a separate remediation CodeBuild project which runs terraform apply.
  • Detector and remediation use separate CodeBuild projects and IAM roles so the read-only detector does not inherit apply permissions.

Connected Companies & Entities

3 Entities mapped

“- git clone https://github.com/lalitbagga/Three-Tier-Infra.git /tmp/Three-Tier-Infra...”

“- curl -o terraform.zip https://releases.hashicorp.com/terraform/1.10.0/terraform_1.10.0_linux_amd64.zip...”

“The next part of the system will keep a remediation history in a database, expose it through an API, and visualize it in Grafana....”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Aug 4, 2026
Original Coverage Title: “I Added a Tag in AWS. Terraform Removed It Automatically.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Infrastructure & IaC (DevOps)Aug 11, 2026

Infrastructure Drift: How to Detect and Prevent It

This technical guide defines infrastructure drift as mismatches between infrastructure-as-code (IaC) declarations and actual cloud state caused by manual edits. It describes common causes (emergency edits, partial migrations, console-first teams), explains why drift harms reliability and audits, and recommends detection and prevention techniques: schedule terraform plan runs and alert on diffs, use cloud-native drift tools (AWS Config, GCP Asset Inventory), treat Git as the source of truth, remove manual edit permissions or enforce write-only service accounts, and build fast-path IaC pipelines to enable quick emergency changes with auditability. The article was published on 2026-08-11 and authored by Samson Tanimawo, Founder & CEO of Nova AI Ops.

Read assessment
Infrastructure as CodeMay 26, 2026

Terraform Drift Detection and Recovery on Google Cloud

A developer-published lab and GitHub repository demonstrating Terraform drift detection, importing existing Google Cloud resources, and state recovery. The project uses a small baseline (VPC, subnet, firewall rule, service account) to simulate manual drift, demonstrates detection with terraform plan (including -detailed-exitcode and -refresh-only), shows terraform state inspection and terraform import for recovery, and automates scheduled drift checks via GitHub Actions. The workflow writes a GCS backend dynamically from repository variables, authenticates with Google Cloud using Workload Identity Federation (OIDC) to keep the pipeline keyless, and creates GitHub issues when drift is detected rather than auto-applying fixes. The artifact is published with documentation, scripts, example imports and CI workflows in a public GitHub repo.

Read assessment
InfrastructureMay 5, 2026

Agentic DevOps: AWS DevOps Agent Automates Remediation

A technical walkthrough demonstrates AWS DevOps Agent (general availability March 31, 2026) as an agentic AI service for autonomous incident ownership, root-cause analysis and proactive remediation across hybrid AWS environments. The report describes architecture elements — Agent Spaces, an immutable Investigation Journal, integration with CloudWatch/CloudTrail, Amazon Bedrock inference, and private connectivity via Amazon VPC Lattice — and the use of the open Model Context Protocol (MCP) to bridge local/hybrid telemetry (stdio and Streamable HTTP transports). A step-by-step Terraform lab intentionally deploys insecure resources (public S3, overly permissive IAM) and simulates brute-force and drift incidents to show the agent detecting issues, generating CLI remediation runbooks and (author-claimed) reducing MTTR by up to 75%. The post includes practical tooling (linux-mcp-server, terraform-mcp-server) and cleanup guidance.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.