Infrastructure state and plan files may contain credentials, identifiers, and other sensitive attributes. A prompt should receive only the fields needed for the current question, with secrets and unrelated resources removed. Redaction must preserve action type and the attribute path that explains a proposed change; otherwise the model may call a dangerous replacement harmless. Drift is a difference between recorded configuration or state and observed infrastructure, not automatic permission to overwrite the live value. The prompt should ask whether the manual change is intentional, who owns it, and whether the desired state should adopt or reverse it. State access and lock recovery belong to controlled operational tools, not model instructions.
Infrastructure prompts: quarantine state secrets and drift
Operational case
Aster's database replacement is traced to a manual setting change made during an earlier incident, while the queue-retention request is unrelated. The prompt receives a redacted attribute diff and incident change record, not the full state file. It marks the database question as a separate ownership decision: keep the manual value and update configuration, or revert it through an approved change. Until that is resolved, the queue plan must be regenerated without an accidental database action. A hidden token in the state is never needed to classify the replacement, so it remains outside the model context.
Input: resource address, action, changed attribute name, redacted values.
Drift: database manual setting changed during prior incident.
Unknown: whether to adopt or reverse; owner must decide.
Never paste raw state, token, or saved binary plan into the prompt.
Regenerate and review the queue-only plan after resolution.Performance and operating cost
Redacting N plan fields is O(N) work; manual review is still needed for fields whose names reveal sensitive information. A narrow diff lowers model token use and disclosure risk. Drift investigation may require a separate incident record and owner conversation, which costs more than simply applying the plan but preserves change authority. If a state lock is held, diagnose its active owner before recovery; deleting a lock based on a model guess can allow concurrent writes and corrupt the operational record.
Common Mistakes
- Do not paste raw state into a general-purpose prompt.
- Do not treat detected drift as approval to overwrite an incident change.
- Do not force-unlock state without establishing whether another run is active.
Connected lessons
- Prompt engineering applications
- Prompt Engineering
- Prompt privacy: send only the fields needed for the task
- Sensitive output gates: check the rendered answer before release
- Infrastructure drift: distinguish emergency repair from unauthorized change
- Terraform state secrets: redaction is not removal
- Infrastructure prompts: bind scope, owner, and environment
- Infrastructure plans: classify every action before apply
- Infrastructure apply: separate review from execution
- Infrastructure release: verify live state and rollback limits
- Project: review an Aster queue retention change
- Infrastructure-change prompt decisions
