Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI agent for devops engineers

Infrastructure as Code Plan Review Agent

Infrastructure changes reviewed for destructive and risky actions before they are applied

Infrastructure as Code Plan Review Agent: what goes in, what the agent does and what you get

What it does

Infrastructure defined as code is changed by applying a plan, and that plan can quietly replace a database or open a security group. Before anything is applied, this agent reads the plan output and classifies each action as create, change, replace or delete. It flags destructive actions on resources that hold data, public exposure and access that is too broad, and checks every change against your policy rules. For risky items it explains what would happen and a safer option, such as an in-place resize or a lifecycle protection. It confirms a recent backup exists for anything that would be replaced. After the engineer revises the code, it reviews the new plan again. You approve applying the plan. Edge case: replacing a production database is blocked until a fresh backup and explicit sign-off exist.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueApprovedNo 1 STARTS WHEN Infrastructure plan generated for a change 2 USES A TOOL Read the plan output and classify each action 3 DOES Flag deletes, replaces, public exposure and broadaccess 4 USES A TOOL Check changes against policy rules 5 USES A TOOL Check backup status for every resource that would bereplaced 6 CHECKS THE RESULT Are all risky actions justified, backed up andpolicy-compliant? If not: explain each risk and the safer option, and waitfor a revised plan. Back to step 2. 7 DOES Write a review note listing each action and its risklevel 8 YOU APPROVE Engineer approves applying the plan 9 RESULT Reviewed plan ready to apply
Read the steps as a list
  1. Infrastructure plan generated for a change
  2. Read the plan output and classify each action
  3. Flag deletes, replaces, public exposure and broad access
  4. Check changes against policy rules
  5. Check backup status for every resource that would be replaced
  6. Are all risky actions justified, backed up and policy-compliant?If not: explain each risk and the safer option, and wait for a revised plan. Back to step 2.
  7. Write a review note listing each action and its risk level
  8. Engineer approves applying the planThe agent waits here for your OK.
  9. Reviewed plan ready to apply

How it decides

It blocks destructive actions on stateful or production resources unless a backup and sign-off exist, and flags any policy violation.

  • Block replace or delete on production data without backup and sign-off
  • Flag any resource made public
  • Enforce policy rules on every change

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Resources treated as stateful or critical
  • Policy rules
  • Who can approve destructive changes
  • Backup check source

What keeps you in control

It always asks you first

  • Applying the infrastructure plan

Hard limits

  • Never applies the plan itself
  • Requires a backup before destructive actions

It stops when

  • Done: plan reviewed and safe to apply
  • Stop: the plan cannot be read or state is missing

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensOn August 19 a plan at Greystone Analytics showed one change and one replace. The replace was a production database, triggered by an instance-type edit, so the check failed. The agent blocked it and proposed an in-place resize. No recent backup existed, so it required one. The engineer revised the code and took a backup. The new plan passed, and the platform lead approved applying it.

More agents for devops engineers