At my employer, we have a small script that automatically checks such generated config files. It does a diff between the old and the new version, and if the diff size exceeds a threshold (either total or relative to the size of the old file), it refuses to do the update, and opens a ticket for a human to look over it.
It has somewhat regularly saved us from disaster in the past.
It has somewhat regularly saved us from disaster in the past.