AtlasMigration accepts a policy.drift block that checks the target database for drift before the operator applies pending migrations.
The Atlas Kubernetes Operator now supports the pre-apply drift check on AtlasMigration resources. Before applying pending migrations, Atlas compares the target database with the latest applied version stored in the Atlas Registry. If the database was changed outside of the migration directory, the deployment is blocked or the drift is logged, depending on onError.
apiVersion: db.atlasgo.io/v1alpha1kind: AtlasMigrationmetadata:name: appspec:urlFrom:secretKeyRef:key: urlname: app-dbdir:remote:name: "atlas"tag: "commit-id"cloud:tokenFrom:secretKeyRef:key: tokenname: atlas-credentialspolicy:drift:onError: FAIL # FAIL (default) or CONTINUEexclude:- "public.audit_*"- "*[type=extension]"
The check requires a migration directory served from the registry (dir.remote) and an Atlas Pro token in cloud.tokenFrom. To get started with Atlas Pro, run atlas login.
Options
- onError: FAIL (default) aborts the deployment before any migration file runs. CONTINUE applies the migrations anyway.
- exclude: glob patterns of objects to ignore, using the atlas schema inspect --exclude syntax. When set, it replaces the env-level exclude list. The revisions table is always excluded.
Blocked Deployments
When drift blocks a deployment, the Ready condition turns False with the reason DriftDetected, a Warning event is emitted, and the operator retries until backoffLimit is reached.
$ kubectl get atlasmigrationsNAME READY REASONapp False DriftDetected
The check runs only when the directory has pending migrations, so it gates deployments rather than monitoring the database. To see which objects drifted, or to check for drift between deployments, run atlas migrate drift.
See the policy.drift reference for skip conditions, recovery steps, and how the policy merges with a custom configuration.