Pulumi
by Pulumi • • Infrastructure as Code (IaC) Tools
Pulumi is open-source infrastructure as code software for engineers and platform teams defining cloud resources in Python, Go, TypeScript, .NET or Java.
Pulumi is infrastructure as code software for engineers and platform teams who define cloud resources in general-purpose programming languages. Pulumi Corporation, based in Seattle, makes it. An open-source engine and command line tool run in the terminal and in CI, and Pulumi Cloud adds hosted state, deployments, secrets and governance around them. Programs are written in TypeScript, JavaScript, Python, Go, .NET, Java, YAML or HCL. The pulumi preview command shows the proposed changes to a stack before an update runs, and pulumi import brings existing cloud resources under management. Pulumi Deployments runs updates remotely with push-to-deploy, drift detection and remediation, and TTL stacks that tear themselves down. Pulumi ESC manages environments, secrets and configuration. Policy as Code stops a deployment when a mandatory policy is violated. Pulumi Discovery finds cloud resources, including ones Pulumi does not manage. Private Registry holds an organization's modules and templates. Pulumi Neo is an AI assistant for infrastructure tasks, pull-request annotations and natural-language search. Pulumi suits software engineers who prefer to write infrastructure in a language they already use. It also suits platform teams building an internal developer platform on shared modules and templates. Individuals and open-source projects can start on the Free edition. Larger organizations use the Pro and Enterprise editions for SAML/SSO, role-based access control and organization-managed policy, and Enterprise adds self-hosting and SCIM. Pulumi Cloud is bought as one platform in four editions, Free, Essentials, Pro and Enterprise, with Credits covering usage. Pulumi provisions resources on AWS, Azure, Google Cloud and Kubernetes through its providers. Previews appear on pull requests and merge requests in GitHub, GitLab, Bitbucket and Azure DevOps, and push-to-deploy starts updates from those repositories. Teams use it for multi-cloud provisioning, for secrets and configuration with ESC, and for policy and compliance work, including conformance packs on Enterprise. Slack integration and OIDC connect it to the chat and identity tools a team already runs, and stack references let one stack read the outputs of another.
Features
- Included: Providers for AWS, Azure and Google Cloud
- Included: Execution plan preview before apply
- Not included: Remote state with locking
- Included: Drift detection against deployed cloud state
- Included: Private module registry
- Included: Infrastructure in general-purpose languages
- Included: Policy-as-code checks at plan time
- Included: Pull-request plans from version control
- Not included: Cost estimate on each plan
- Included: Import of existing cloud resources
- Included: Encrypted workspace variables
- Included: Per-workspace access control
- Not included: Approval required before apply
- Included: Auto-destroy of temporary environments
- Included: Cross-stack output references
- Included: Self-hosted agents for private networks
- Included: Open source IaC engine
Additional Features
- Open-source Pulumi engine and CLI
- TypeScript, JavaScript, Python, Go, .NET, Java, YAML and HCL programs
- Providers for AWS, Azure, Google Cloud and Kubernetes
- pulumi preview of stack updates
- pulumi import for existing cloud resources
- Stack references between stacks
- Hosted stack state in Pulumi Cloud
- Masked secrets in program output
Best for
- Software engineers who want infrastructure written in a language they already use
- Platform teams building an internal developer platform on shared modules and templates
- Individuals and open-source projects starting on the Free edition
- Teams provisioning across AWS, Azure, Google Cloud and Kubernetes
- Organizations that need SAML/SSO, SCIM and conformance packs
- Companies that must run the platform in their own environment
Use cases
- Provisioning multi-cloud infrastructure from TypeScript, Python or Go programs
- Previewing infrastructure changes before an update runs
- Bringing existing cloud resources under management
- Sharing secrets and configuration across environments with ESC
- Stopping non-compliant deployments with mandatory policies
- Tearing down temporary environments on a schedule
- Publishing approved modules for other teams to reuse
- Running deployments from a pull request or a push
- Discovering cloud resources that Pulumi does not manage
Screenshots & Videos
Explore Pulumi in action