Infracost
Infracost estimates the monthly cost of infrastructure code before it is applied: it prices each resource from the cloud's price list and reports what a pull request would add or remove. The Azure Enterprise Baseline's plan workflow runs it on every pull request when the optional API key is set.
What it does
Given OpenTofu code, Infracost produces a breakdown (this resource costs this much per month) and a diff (this change adds or removes this much). It needs an API key for its pricing service. Usage-based charges, such as data processed or log ingestion, cannot be seen in code and appear only as estimates. Teams use it to spot a change that quietly adds an expensive resource and to keep the cost decision on the pull request itself.
How BuiltForProd uses it
The Baseline's plan.yml ends with four steps, after the plan has been posted on the pull request:
- Check for the key. The repository secret
INFRACOST_API_KEYis@optional:. Without it the step prints that the estimate is skipped, and every later step is skipped too. - Set up Infracost with
infracost/actions/setupv4.2.0, pinned by commit SHA, currency USD. - Generate the breakdown with
infracost breakdown --path environmentsover the same generated tree the plan ran against, written as JSON. - Post the comment with
infracost/actions/commentand behaviorupdate: each pull request carries one cost comment, rewritten on every push.
Steps 2 to 4 are continue-on-error, so a missing key, a network failure or an Infracost outage never turns the plan red. Only the Baseline repository has these steps; the blueprint infrastructure workflows do not.
The platform's cost controls do not depend on Infracost. Every expensive Baseline service sits behind a switch in network.hcl or security.hcl whose comment states its list price, such as Azure Firewall Standard at ~$912/month. The blueprint stage files carry the same annotations beside each sizing value, such as Cosmos DB M30 at ~$270/month and Front Door Premium at ~$330/month base. See GitHub Actions for the plan workflow.
Terms you will see
| Term | Meaning |
|---|---|
| Breakdown | The full monthly cost of the resources in the configuration. |
| Diff | The change in monthly cost a pull request introduces. |
| API key | The credential for Infracost's pricing service, held as a repository secret. |
| Comment behavior | update: one cost comment per pull request, rewritten on each push. |
continue-on-error | The GitHub Actions setting that keeps the job green if the step fails. |
Where to read more
- Azure Enterprise Baseline overview for the repository.
- Billing FAQ for how cloud costs are paid.
- OpenTofu for the code being priced.