Skip to content

Pulumi

Summary

Pulumi is an infrastructure-as-code platform in which you define cloud resources in general-purpose languages: TypeScript/JavaScript, Python, Go, .NET, Java, plus Pulumi YAML and, since 2026, Terraform-style HCL. An Apache 2.0 engine diffs the program's desired state against recorded state and drives provider plugins, including any Terraform/OpenTofu provider. The commercial layer is Pulumi Cloud: state, ESC secrets, Deployments, the Neo AI agent, the IDP, and Discovery & Governance. It is billed on managed resources under new Free / Essentials / Pro / Enterprise editions.

Key Facts

Attribute Detail
Latest Version CLI/SDK v3.264.0 (2026-09-23), minor releases roughly weekly
Repository github.com/pulumi/pulumi, ~22k+ stars (recorded by 2026-08)
License Apache 2.0 (CLI, engine, SDKs, ESC evaluator). Pulumi Cloud is proprietary (SaaS or self-hosted on Enterprise)
Company Pulumi Corporation (founded 2017)
Engine language Go
Program languages TypeScript/JavaScript (Node.js 22+ or Bun), Python 3.10+, Go, .NET (C#, F#, VB), Java 11+, YAML, HCL
Providers Pulumi Registry (native + Terraform-bridged) plus Any Terraform Provider via pulumi package add terraform-provider
State Pulumi Cloud, or DIY: S3 (and compatible), Azure Blob, GCS, PostgreSQL, local file
Pricing Free (1 user). Essentials from $40/month. Pro from $400/month. Enterprise from $2,000/month. See Reference
K8s Operator Pulumi Kubernetes Operator v2.9.1 (2026-09-03)

What Changed Recently (2025-2026)

  • Pulumi Neo (preview 2025-09) is the AI infrastructure agent across the console, CLI (pulumi neo), editors (ACP), Slack, PRs and MCP. It replaced Pulumi Copilot and Pulumi AI. pulumi new --ai was retired in 3.256.0.
  • Pulumi HCL (runtime: hcl) runs .tf files on the Pulumi engine. It is bundled in the CLI since 3.235.0, and the docs require CLI 3.256.0+.
  • Any Terraform Provider makes any Terraform/OpenTofu provider usable, with generated typed SDKs.
  • Insights is now Discovery & Governance: account scanning, resource search, audit/preventative policy groups and compliance packs.
  • Pulumi IDP (2025): private registry, org templates, no-code stacks, Backstage plugin.
  • ESC moved into the main CLI (pulumi env, pulumi env setup aws|azure|gcp). The standalone esc CLI is retired.
  • Breaking-ish: Node.js SDK needs Node 22+ (3.249.0). DIY non-project mode is an error since 3.257.0, with removal targeted before the end of 2026. Journaling is on by default (3.225.0).
  • New pricing editions (V6): Free / Essentials / Pro / Enterprise replace Individual / Team / Enterprise / Business Critical.

Architecture at a Glance

This diagram shows the main moving parts: the program talks to the engine through a language host, and the engine drives providers and persists state.

flowchart LR
    subgraph Dev["Your project"]
        Code["Program<br/>(TS, Python, Go, .NET, Java, YAML, HCL)"]
    end

    subgraph CLI["pulumi CLI"]
        LH["Language host<br/>(nodejs, python, go, ...)"]
        ENG["Engine<br/>(DAG, diff, journal)"]
    end

    subgraph Prov["Provider plugins"]
        NAT["Native / bridged<br/>(aws, azure-native, kubernetes)"]
        ATP["terraform-provider<br/>(any TF/OpenTofu provider)"]
    end

    subgraph State["State backend"]
        PC["Pulumi Cloud<br/>(+ ESC, Neo, Deployments, IDP)"]
        DIY["DIY: S3, Azure Blob,<br/>GCS, PostgreSQL, file"]
    end

    Code --> LH -->|gRPC| ENG
    ENG -->|gRPC| NAT
    ENG -->|gRPC| ATP
    NAT --> Clouds["Cloud APIs"]
    ATP --> Clouds
    ENG --> PC
    ENG --> DIY

The full component diagram and internals are in Explanation.

Evaluation

Pros Cons
Real programming languages: IDE support, types, unit tests, refactoring Different paradigm from HCL, so there is a learning curve for ops-focused teams
Reusable components via npm, PyPI, NuGet, Maven, Go modules, and multi-language components Smaller community and fewer examples than Terraform
Any Terraform/OpenTofu provider, plus Pulumi HCL for HCL-first teams Bridged providers inherit upstream Terraform provider gaps and bugs
Per-value secret encryption in state, with ESC for dynamic OIDC credentials ESC, Neo, Deployments, IDP and org policy enforcement require Pulumi Cloud
Automation API for platforms and self-service tooling Arbitrary code runs during preview, and unknown outputs complicate branching
Apache 2.0 engine, DIY backends fully supported DIY backends lack transactional recovery, and non-project layout is being removed
Neo AI agent works on real state with RBAC and approvals Fast release cadence (weekly) plus runtime minimum bumps require regular CI upkeep

When It Fits

  • Good fit: developer-centric platform teams, and infrastructure with real logic (loops, abstractions, multi-tenant provisioning). Also self-service portals built on the Automation API or IDP, and teams that want one vendor for IaC + secrets + policy + AI.
  • Weaker fit: teams standardized on HCL with large module estates and no appetite for Pulumi Cloud, or organizations requiring a foundation-governed tool. See OpenTofu in that case.

Licensing & Pricing

The CLI, engine and SDKs are Apache 2.0 and free with DIY backends. Pulumi Cloud uses credit-based editions (1 credit = $1):

  • Free: 1 user, no managed-resource cap, 500 workflow minutes.
  • Essentials: $40/month, 500 resources.
  • Pro: $400/month, 2,000 resources. Adds SSO, RBAC, IDP and drift detection.
  • Enterprise: $2,000/month, 4,750 resources. Adds self-hosting, SCIM and compliance packs.

Neo is metered at $3 per 1M tokens. The full table and legacy edition names are in Reference.

Compatibility & Requirements

  • CLI binaries for Linux, macOS and Windows.
  • Runtime minimums changed in 2026: Node.js 22+ for the Node SDK, and Python 3.10+.
  • The runtime matrix is in Reference.

Alternatives, Migration & Lock-in

Alternative Relationship
Terraform HCL, BUSL-licensed. pulumi convert --from terraform or Pulumi HCL for migration
OpenTofu MPL 2.0 community fork of Terraform. Pulumi resolves providers from its registry
Crossplane Kubernetes-native control-plane IaC (no topic in this vault yet)
AWS CDK / CDKTF Also GPL-language IaC. CDKTF synthesizes to Terraform

Lock-in is moderate. Programs and state are portable between backends (pulumi stack migrate, pulumi stack export). Leaving Pulumi entirely means rewriting code, although bridged providers keep resource semantics close to Terraform's. The Pulumi Cloud services (ESC, Neo, IDP, Discovery) are the stickiest parts.

Community Health

  • ~22k+ GitHub stars on pulumi/pulumi (recorded by 2026-08), with active weekly releases (49 minor releases in 2026 through 2026-09-23).
  • Pulumi reported 3,500+ customer organizations and 350,000+ users at the IDP launch (2025, vendor figure).
  • Community Slack (slack.pulumi.com), Pulumi Registry, and the pulumi/examples repository.

Topic Map

  • How-to Guides: install/upgrade, backends, stacks and state, secrets and ESC, any Terraform provider, migrate from Terraform, policies, Neo, CI with OIDC, troubleshooting
  • Reference: versions and changes, runtime matrix, backends, secrets providers, CLI and env vars, pricing editions, RBAC, policy levels, benchmarks (unsourced), hardening checklist, pitfalls
  • Explanation: engine, language hosts, resource model, providers and Terraform bridge, state and journaling, Automation API, ESC, Neo, IDP, Discovery & Governance, security model, trade-offs

Sources

Questions

Open

  • When exactly did the V6 editions (Free/Essentials/Pro/Enterprise) launch, and how are existing Team/Business Critical customers migrated? See Reference.
  • In which release will DIY non-project mode be removed entirely ("before the end of 2026")?
  • How closely does Pulumi HCL match Terraform/OpenTofu semantics (modules, moved/import blocks, provider-defined functions)? See Explanation.
  • Is there a published limit on resources per stack, or measured performance data after journaling? The current figures are unsourced (Reference).

Answered

  • Can Pulumi use Terraform providers? Yes. Pre-bridged Registry packages cover the major ones, and pulumi package add terraform-provider <ns>/<name> works for any Terraform/OpenTofu provider, including local binaries. By default it resolves from the OpenTofu registry, whose metadata repo lists 4,603 providers (counted 2026-09-27).
  • What happened to Pulumi Copilot / Pulumi AI? Both were superseded by Pulumi Neo. pulumi ai web was removed in 3.246.0, and pulumi new --ai in 3.256.0.