FinOps, DevOps & Reliability Fintech ✓ Production

10Automated IaC Drift Detection — Compliance Radar for a Regulated Fintech

Daily drift checks in CI/CD — manual portal changes caught within a day

Role: Advisory Solution Engineer

Executive summary

Designed and implemented automated IaC drift detection that compares deployed Azure resources to Terraform/Bicep state and alerts on drift via Teams and email—improving the client's compliance posture.

  • Terraform
  • Bicep
  • Azure Resource Graph
  • Python
  • Azure DevOps
  • Azure Policy
SSituation

A fintech running Azure wanted to ensure their Infrastructure-as-Code (Terraform, Bicep) stayed aligned with deployed resources. Configuration drift was a compliance risk and potential security exposure, so they needed automated detection and alerting.

TTasks
  • Identify tools/features to compare deployed resources vs IaC (Terraform plan in check mode, Azure Resource Graph vs desired state).
  • Where no tool fits, design a custom script to parse IaC and cross-check Azure settings.
  • Integrate drift detection into CI/CD to run regularly and alert via email/Teams.
  • Document best practices to minimize drift (resource locks, policy).
AActions

I recommended Terraform's drift detection where possible and, for out-of-band resources, used Azure Resource Graph queries with Python scripts comparing against a baseline, integrated into a daily Azure DevOps pipeline that emits diffs and Teams/email alerts. Before rollout I ran a deliberate out-of-band change as a smoke test—it was caught on the next run, validating the pipeline end to end rather than serving as evidence of value. I refined scope with their DevOps engineers (some drift is acceptable—by agreement, tagged shared-sandbox resources are exempt from alerting), which kept alert volume credible, and packaged it into a maintainable internal tool.

RResults

The fintech adopted automated drift detection as part of its normal DevOps workflow—the alerts land in the same Teams channel the team already lives in, which is why they get acted on. Since rollout, portal-created manual resources have been caught and remediated within a day of appearing, preventing configuration sprawl undetected, and the compliance team gained a routine source of truth instead of finding drift at audit time. Documentation covers extending coverage and integrating Azure Policy for prevention.

LLessons Learned

Prevention via policy is ideal, but detection is an essential safety net—and the smoke-test catch I planted taught me the difference between validating a pipeline and proving its value. Tailoring to the client's stack—leveraging existing Terraform, and negotiating alert exemptions with them—beat introducing new tooling and low-noise alerts is what kept the channel trustworthy. Lightweight scripting and automation can solve critical business needs effectively.

Solution overview: Automated IaC Drift Detection — Compliance Radar for a Regulated Fintech Automated IaC Drift Detection — Compliance Radar for a Regulated Fintech — flow: Desired state then Detect (daily) then Pipeline then Alert & remediate. DESIRED STATE Terraform / Bicep DETECT (DAILY) Terraform plan (check) Azure Resource Graph Python diff vs baseline PIPELINE Azure DevOps CI/CD ALERT & REMEDIATE Teams + email alerts Remediated within a day Prevention via resource locks & Azure Policy · detection as a safety net
Solution overview — Automated IaC Drift Detection — Compliance Radar for a Regulated Fintech (illustrative; replace with your own diagram anytime)