Infrastructure governance, drift detection, and lessons from building an IDP — notes from the workshop behind AskArchie.
Your team already has Terraform. The last thing they want to hear is "rewrite everything in our format." So I didn't ask them to — I imported HashiCorp's own public Terraform repo into a governed blueprint.
Deploying an AI agent on AWS AgentCore requires 8+ infrastructure components. I encoded all the learnings into a governed blueprint — now anyone on the team can deploy one by filling 5 fields.
I design cloud infrastructure for a living. VPCs, subnets, security groups, IAM policies. I've done it hundreds of times. But here's my dirty secret: I hate deploying what I design.
Someone added an inbound rule to a security group at 2 AM. Your Terraform state doesn't know. Your compliance team doesn't know. Here's why drift detection matters more than you think.
The IDP market is crowded with portals, catalogs, and orchestrators. But when you look at what each tool actually does end-to-end, the differences are stark.