Infra Planner

Azure architecture plans from a workload description — topology, network, WAF, IaC.

Back to SkillSafe
Or pick files: requirements docs are read in your browser and never uploaded as files. The description text itself is sent to the SkillSafe API as you type, because the price meter has to price the real input.
Extra constraints — budget, existing estate, team skills, deadlines
How it works

Nothing to hand? Load the — a regulated, multi-region production workload — or the , a small nonprod pilot on a tight budget.

1

Describe the workload

Prose, bullets or a pasted requirements doc. The instant prescan reads it for free while you type and lists what it mechanically found: Azure services by name, regions, compliance frameworks, and the DR, high-availability, private-networking, hybrid, autoscale and cost signals in your wording.

2

The AI architects it

A concrete resource topology with SKUs and regions, a network design with a CIDR plan, the identity and RBAC approach, and an honest read on all five Well-Architected pillars — aligned, risk or gap. Where your description was silent, the conservative default is taken and recorded as a risk instead of being invented into a requirement.

3

Take the starter and go

A Bicep or Terraform starter consistent with the resource table, right-sized for prod or nonprod, plus the ranked next steps, the resource table as CSV, plan history on this device, and Markdown or JSON export.

Derived from the @microsoft/azure-enterprise-infra-planner skill.

Questions

Is the plan production-ready or approved to deploy?

No. Infra Planner produces a design proposal from your description. It is not an architecture review, a security assessment, a compliance audit, or an approval to deploy, and no person reviews the output. A Well-Architected status of “aligned” is the model’s own self-assessment of its design intent, not a verified finding, and an empty risk list means no risks were recorded rather than that none exist. Have a qualified architect, your security function and your compliance function review any plan before it becomes infrastructure.

Does it tell me what the architecture will cost?

No. Costs are never computed. Any statement a plan makes about spend, budget fit or run rate is the model’s estimate from published behaviour at training time, not a quote and not a calculation, and the app cannot fetch live pricing. Azure list prices, discounts and regional rates change, so price every resource in the Azure pricing calculator against the current prices for your regions and agreement — those prices govern, not the plan.

What does the app verify by itself?

Three mechanical checks run in your browser with no model involved, and their results are shown with every plan: whether the generated starter file actually names each resource and region from the resource table, whether every region is a real Azure region name, and whether the CIDR plan parses, sits in RFC1918 private space, lands on network boundaries and contains no overlapping ranges. These prove consistency and arithmetic only. Passing them does not make the plan correct.

Can I compare a plan against the previous run?

Yes. Changing one input and running again is the normal way to use this app, so every plan is diffed against the run before it: resources added, removed or re-SKU’d, regions changed, network segments and CIDRs changed, Well-Architected statuses that moved, and risks that appeared or disappeared. Any past plan can be pinned as the baseline to compare against instead. Plan history is stored in your SkillSafe account as well as in this browser, so it follows you to another device; the pasted description itself is kept only in this browser.

What does it cost to use, and what is free?

Each plan is charged per run against your SkillSafe credit balance, and the price meter shows the amount reserved before you run. The instant prescan runs entirely in your browser and is always free, and the two bundled examples have saved runs that replay for free as long as you do not edit the input. Editing any field means the next run is billed normally.

Does my workload description leave my browser?

Yes, when it is priced and when it is planned. Dropped files are read in your browser and never uploaded as files, but the description text is sent to the SkillSafe API as you type so the price meter can price the real input, and again when you run a plan. Very long descriptions are clipped from the middle, keeping both ends, and the page tells you how much was cut.