For a couple of days I am working on a way to generate a list of non-terraform created resources. Currently I am using the tagging method but this means that AWS resources that can't be tagged should also be excluded from the AWS Config query.
The tagging part is also quite cumbersome as this must be done manually.
- Is there a way to tell Terraform (or Terragrunt) to automatically use general tags on resources?
- Is there a way to ask Terraform or any other tool to create a list of resources that are not available in the state files?
for people still stumbling upon this. It seems that a community has created a tool named Driftctl that would check environments against your Terraform state.