"Installed" is not a version. Two nodes built months apart, or one patched by hand during an incident, end up with different package versions, kernel settings, or routes, and they behave differently under the same input.
Detect drift by comparing, not by remembering:
- Query versions explicitly:
rpm -q PKG,dpkg-query -W PKG, orPKG --versionon each node. - Diff effective configuration, not files you think are in use. For example, compare
sshd -Twithsshd_config, andip route get ADDRwith the routing table you expect. - Record the approved version somewhere a machine checks. That can be a lockfile, an image digest, or an Ansible variable.
Fix drift at its source. Pin or declare the approved version in automation, roll it out, and verify every node reports it. Correcting one node by hand leaves the automation still producing the drifted state.
Twelve-Factor states the same idea for applications: declare dependencies explicitly and keep environments as similar as possible. Declarative configuration tools make it enforceable, because a second run that reports "changed" on a node is a drift alarm.