IaC Goals

Idempotency, Repeatability and Drift as IaC Goals

An IaC tool should be idempotent (applying a definition twice equals applying it once), repeatable (one template builds identical staging and production copies) and able to report drift, a change made outside it:

Deploying, changing the table behind CloudFormation's back, and deploying againShell
cd ~/v5-ch7/booknest/infra
aws cloudformation deploy --stack-name booknest-catalog --template-file catalog.yaml
aws dynamodb update-table --table-name booknest-books --billing-mode PROVISIONED \
  --provisioned-throughput ReadCapacityUnits=5,WriteCapacityUnits=5 \
  --query TableDescription.BillingModeSummary.BillingMode --output text
aws cloudformation deploy --stack-name booknest-catalog --template-file catalog.yaml
Output
Waiting for changeset to be created..
Waiting for stack create/update to complete
Successfully created/updated stack - booknest-catalog
PROVISIONED
Waiting for changeset to be created..
No changes to deploy. Stack booknest-catalog is up to date

The second deploy is a no-op that hides the hand edit: CloudFormation 24 compares your template with the template it last deployed, not with the live table. On AWS 24 , detect-stack-drift would flag the table as DRIFTED; LocalStack 63,725 answers that it is "not currently supported" (Drift and Import). So once a resource belongs to a stack, change it only through the template.