How the thing works, where it stops working, and what running it against real infrastructure taught us.
A Deployment can drift from its Helm release without anyone running kubectl, because controllers, admission webhooks and autoscalers all write to live objects by design. Here is what that means for detection, and why ownership is the harder half.
Most tools that claim drift detection across AWS, Azure and GCP are describing three different depths at once. Here are the three bars worth separating, why coverage is path-dependent rather than cloud-dependent, and what to ask a vendor.
Drift checking usually assumes one workspace system holds everything. Real estates keep state in S3, a storage account, a GCS bucket, a workspace and someone's laptop. Here is what that does to detection, and how to get one answer.
A terraform plan compares state to reality. A resource in no state file has nothing to compare against, so it stays invisible, however clean your plan output looks. Here is what actually finds it, and what each method costs.