The shift nobody is talking about honestly!
For a decade, shipping to the cloud meant a stack of specialist work: Terraform modules, YAML pipelines, PowerShell glue scripts, and one engineer who "knows how the release works."
That is changing quickly. Azure now has AI in every layer of that stack: code, infrastructure, pipelines, and operations. Combined, these pieces make a deployment accelerator: describe what you need, and a platform produces, validates, deploys, and monitors it.
My post below will covers what can be automated today, how to build such a platform on Azure, and what still needs humans.
What can be automated with Azure AI
| Area | Traditionally done by | AI-assisted approach on Azure |
|---|---|---|
| Infrastructure code | Engineer writes Terraform/Bicep | Natural-language prompt -> Bicep/Terraform via GitHub Copilot or Azure Copilot, based on Azure Verified Modules |
| CI/CD pipelines | Hand-written YAML | Agent generates GitHub Actions / Azure Pipelines from repo analysis |
| Environment provisioning | Tickets + scripts | Azure Developer CLI (azd) templates + Azure Deployment Environments |
| Policy and compliance | Manual review | Azure Policy + AI review of IaC before merge |
| Security scanning | Separate tooling | Defender for Cloud + GitHub Advanced Security with AI fix suggestions |
| Cost control | Spreadsheet reviews | Cost Management data + AI anomaly summaries |
| Incident response | On-call runbooks | Azure SRE Agent / Azure Monitor + AI triage |
| Documentation | Rarely done | Auto-generated from the code and the deployed state |
Architecture: the AI deployment accelerator
Developer request (chat / issue / PR)
|
v
AI Orchestrator (Azure AI Foundry agent)
|
+--> Azure MCP Server (read/act on Azure resources)
+--> Template library (Azure Verified Modules, azd templates)
+--> Policy engine (Azure Policy, Checkov, what-if)
|
v
Generated IaC + Pipeline -> Pull Request
|
v
Automated gates: lint, security scan, what-if, cost estimate
|
v
Human approval (for prod)
|
v
GitHub Actions deploys -> Azure
|
v
Azure Monitor + SRE Agent feed learnings back
Step-by-step: how to build it
1. Standardize first. Create a curated library of approved modules (Azure Verified Modules in Bicep or Terraform). AI is only as safe as the building blocks you let it use.
2. Give the agent tools, not freedom. Use Azure AI Foundry to build an agent and connect it to the Azure MCP Server so it can query and operate on Azure through scoped permissions.
3. Make generation produce pull requests, not deployments. The agent writes IaC and pipeline changes into a repo. Everything flows through Git, so you keep history, review, and rollback.
4. Add automated gates.
-
az deployment what-iforterraform planon every PR - Policy-as-code (Azure Policy, Checkov, PSRule for Azure)
- Secret and vulnerability scanning
- Cost estimate in the PR comment
5. Use identity properly. Federated credentials (OIDC) from GitHub to Azure and managed identities everywhere. No stored secrets.
6. Close the loop. Send deployment and runtime telemetry back to the agent so it can suggest fixes, tune sizing, and open remediation PRs.
7. Keep humans on production approvals until you have real data showing the gates are trustworthy.
Example: a prompt-to-production flow
"Create a web app with a SQL database in a private network, dev and prod environments, Key Vault for secrets, and alerts to the ops channel."
The accelerator produces a Bicep deployment, a GitHub Actions workflow for both environments, policy checks, and a cost estimate. A reviewer approves, and it deploys. The first draft takes minutes instead of days.
Do we still need Terraform and PowerShell engineers?
Honest answer: the manual typing of Terraform, YAML, and PowerShell is going away. The engineering judgment is not.
AI is very good at producing the first 80% of IaC and pipelines. It is not accountable for:
- Architecture decisions: network topology, landing zones, multi-region and DR trade-offs
- Security and compliance ownership: someone must own the risk
- Reviewing AI output: generated code can be subtly wrong, insecure, or expensive
- Platform design: building and governing the accelerator itself
- Incidents with no precedent: novel failures that don't match any pattern
- Cost and capacity trade-offs that depend on business context
The role shifts from writing scripts to platform engineering, governance, and AI-assisted operations. Teams that don't need ten script-writers may well need two strong platform engineers. Fewer people doing repetitive work is a realistic outcome. "No engineers at all" is not.
Why this is Azure's moment
Microsoft owns an unusual combination: GitHub (code and CI/CD), Azure (infrastructure), Entra ID (identity), Defender (security), Azure Monitor (operations), and Azure AI Foundry (agents). Few other platforms put the full path from idea to running, monitored workload under one identity and policy model, and AI sits across all of it.
Takeaways
- Start with standards and templates, then add AI on top.
- Generate through pull requests, never directly to production.
- Gate everything with policy, scanning, and what-if.
- Reskill toward platform engineering, security, and AI orchestration.
The question isn't "will AI replace DevOps?" It's "will you be the one building the accelerator, or the one it replaces?"
What are you automating first? Tell me in the comments.
By - Shivanna Gundanavar (MLOps and Cloud)
Top comments (1)
tr.ee/dev-to