Pulumi¶
Summary
Pulumi is an infrastructure-as-code platform in which you define cloud resources in general-purpose languages: TypeScript/JavaScript, Python, Go, .NET, Java, plus Pulumi YAML and, since 2026, Terraform-style HCL. An Apache 2.0 engine diffs the program's desired state against recorded state and drives provider plugins, including any Terraform/OpenTofu provider. The commercial layer is Pulumi Cloud: state, ESC secrets, Deployments, the Neo AI agent, the IDP, and Discovery & Governance. It is billed on managed resources under new Free / Essentials / Pro / Enterprise editions.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version | CLI/SDK v3.264.0 (2026-09-23), minor releases roughly weekly |
| Repository | github.com/pulumi/pulumi, ~22k+ stars (recorded by 2026-08) |
| License | Apache 2.0 (CLI, engine, SDKs, ESC evaluator). Pulumi Cloud is proprietary (SaaS or self-hosted on Enterprise) |
| Company | Pulumi Corporation (founded 2017) |
| Engine language | Go |
| Program languages | TypeScript/JavaScript (Node.js 22+ or Bun), Python 3.10+, Go, .NET (C#, F#, VB), Java 11+, YAML, HCL |
| Providers | Pulumi Registry (native + Terraform-bridged) plus Any Terraform Provider via pulumi package add terraform-provider |
| State | Pulumi Cloud, or DIY: S3 (and compatible), Azure Blob, GCS, PostgreSQL, local file |
| Pricing | Free (1 user). Essentials from $40/month. Pro from $400/month. Enterprise from $2,000/month. See Reference |
| K8s Operator | Pulumi Kubernetes Operator v2.9.1 (2026-09-03) |
What Changed Recently (2025-2026)¶
- Pulumi Neo (preview 2025-09) is the AI infrastructure agent across the console, CLI (
pulumi neo), editors (ACP), Slack, PRs and MCP. It replaced Pulumi Copilot and Pulumi AI.pulumi new --aiwas retired in 3.256.0. - Pulumi HCL (
runtime: hcl) runs.tffiles on the Pulumi engine. It is bundled in the CLI since 3.235.0, and the docs require CLI 3.256.0+. - Any Terraform Provider makes any Terraform/OpenTofu provider usable, with generated typed SDKs.
- Insights is now Discovery & Governance: account scanning, resource search, audit/preventative policy groups and compliance packs.
- Pulumi IDP (2025): private registry, org templates, no-code stacks, Backstage plugin.
- ESC moved into the main CLI (
pulumi env,pulumi env setup aws|azure|gcp). The standaloneescCLI is retired. - Breaking-ish: Node.js SDK needs Node 22+ (3.249.0). DIY non-project mode is an error since 3.257.0, with removal targeted before the end of 2026. Journaling is on by default (3.225.0).
- New pricing editions (V6): Free / Essentials / Pro / Enterprise replace Individual / Team / Enterprise / Business Critical.
Architecture at a Glance¶
This diagram shows the main moving parts: the program talks to the engine through a language host, and the engine drives providers and persists state.
flowchart LR
subgraph Dev["Your project"]
Code["Program<br/>(TS, Python, Go, .NET, Java, YAML, HCL)"]
end
subgraph CLI["pulumi CLI"]
LH["Language host<br/>(nodejs, python, go, ...)"]
ENG["Engine<br/>(DAG, diff, journal)"]
end
subgraph Prov["Provider plugins"]
NAT["Native / bridged<br/>(aws, azure-native, kubernetes)"]
ATP["terraform-provider<br/>(any TF/OpenTofu provider)"]
end
subgraph State["State backend"]
PC["Pulumi Cloud<br/>(+ ESC, Neo, Deployments, IDP)"]
DIY["DIY: S3, Azure Blob,<br/>GCS, PostgreSQL, file"]
end
Code --> LH -->|gRPC| ENG
ENG -->|gRPC| NAT
ENG -->|gRPC| ATP
NAT --> Clouds["Cloud APIs"]
ATP --> Clouds
ENG --> PC
ENG --> DIY
The full component diagram and internals are in Explanation.
Evaluation¶
| Pros | Cons |
|---|---|
| Real programming languages: IDE support, types, unit tests, refactoring | Different paradigm from HCL, so there is a learning curve for ops-focused teams |
| Reusable components via npm, PyPI, NuGet, Maven, Go modules, and multi-language components | Smaller community and fewer examples than Terraform |
| Any Terraform/OpenTofu provider, plus Pulumi HCL for HCL-first teams | Bridged providers inherit upstream Terraform provider gaps and bugs |
| Per-value secret encryption in state, with ESC for dynamic OIDC credentials | ESC, Neo, Deployments, IDP and org policy enforcement require Pulumi Cloud |
| Automation API for platforms and self-service tooling | Arbitrary code runs during preview, and unknown outputs complicate branching |
| Apache 2.0 engine, DIY backends fully supported | DIY backends lack transactional recovery, and non-project layout is being removed |
| Neo AI agent works on real state with RBAC and approvals | Fast release cadence (weekly) plus runtime minimum bumps require regular CI upkeep |
When It Fits¶
- Good fit: developer-centric platform teams, and infrastructure with real logic (loops, abstractions, multi-tenant provisioning). Also self-service portals built on the Automation API or IDP, and teams that want one vendor for IaC + secrets + policy + AI.
- Weaker fit: teams standardized on HCL with large module estates and no appetite for Pulumi Cloud, or organizations requiring a foundation-governed tool. See OpenTofu in that case.
Licensing & Pricing¶
The CLI, engine and SDKs are Apache 2.0 and free with DIY backends. Pulumi Cloud uses credit-based editions (1 credit = $1):
- Free: 1 user, no managed-resource cap, 500 workflow minutes.
- Essentials: $40/month, 500 resources.
- Pro: $400/month, 2,000 resources. Adds SSO, RBAC, IDP and drift detection.
- Enterprise: $2,000/month, 4,750 resources. Adds self-hosting, SCIM and compliance packs.
Neo is metered at $3 per 1M tokens. The full table and legacy edition names are in Reference.
Compatibility & Requirements¶
- CLI binaries for Linux, macOS and Windows.
- Runtime minimums changed in 2026: Node.js 22+ for the Node SDK, and Python 3.10+.
- The runtime matrix is in Reference.
Alternatives, Migration & Lock-in¶
| Alternative | Relationship |
|---|---|
| Terraform | HCL, BUSL-licensed. pulumi convert --from terraform or Pulumi HCL for migration |
| OpenTofu | MPL 2.0 community fork of Terraform. Pulumi resolves providers from its registry |
| Crossplane | Kubernetes-native control-plane IaC (no topic in this vault yet) |
| AWS CDK / CDKTF | Also GPL-language IaC. CDKTF synthesizes to Terraform |
Lock-in is moderate. Programs and state are portable between backends (pulumi stack migrate,
pulumi stack export). Leaving Pulumi entirely means rewriting code, although bridged providers keep resource semantics
close to Terraform's. The Pulumi Cloud services (ESC, Neo, IDP, Discovery) are the stickiest parts.
Community Health¶
- ~22k+ GitHub stars on
pulumi/pulumi(recorded by 2026-08), with active weekly releases (49 minor releases in 2026 through 2026-09-23). - Pulumi reported 3,500+ customer organizations and 350,000+ users at the IDP launch (2025, vendor figure).
- Community Slack (
slack.pulumi.com), Pulumi Registry, and thepulumi/examplesrepository.
Topic Map¶
- How-to Guides: install/upgrade, backends, stacks and state, secrets and ESC, any Terraform provider, migrate from Terraform, policies, Neo, CI with OIDC, troubleshooting
- Reference: versions and changes, runtime matrix, backends, secrets providers, CLI and env vars, pricing editions, RBAC, policy levels, benchmarks (unsourced), hardening checklist, pitfalls
- Explanation: engine, language hosts, resource model, providers and Terraform bridge, state and journaling, Automation API, ESC, Neo, IDP, Discovery & Governance, security model, trade-offs
Related Topics¶
- IaC Comparison: Terraform vs OpenTofu vs Pulumi
- IaC comparisons index and the IaC domain
- Terraform and OpenTofu
- Multi-cloud governance: Pulumi in multi-cloud setups
- External Secrets Operator: syncs Pulumi ESC secrets into Kubernetes
- HashiCorp Vault: ESC secrets provider and a
hashivault://secrets provider - Kubernetes: target of the Pulumi Kubernetes provider and Operator
Sources¶
- Pulumi docs
- pulumi/pulumi repository and CHANGELOG
- @pulumi/pulumi on npm and pulumi on PyPI (version cross-check)
- Languages & SDKs and Pulumi HCL
- Using any Terraform provider and announcement
- pulumi/pulumi-terraform-bridge
- Pricing
- Pulumi ESC
- Pulumi Neo docs and Pulumi 2025 product launches
- Pulumi IDP docs and IDP announcement
- Insights 2.0 announcement
- Automation API
- State and backends
- Pulumi Examples
Questions¶
Open¶
- When exactly did the V6 editions (Free/Essentials/Pro/Enterprise) launch, and how are existing Team/Business Critical customers migrated? See Reference.
- In which release will DIY non-project mode be removed entirely ("before the end of 2026")?
- How closely does Pulumi HCL match Terraform/OpenTofu semantics (modules,
moved/importblocks, provider-defined functions)? See Explanation. - Is there a published limit on resources per stack, or measured performance data after journaling? The current figures are unsourced (Reference).
Answered¶
- Can Pulumi use Terraform providers? Yes. Pre-bridged Registry packages cover the major ones, and
pulumi package add terraform-provider <ns>/<name>works for any Terraform/OpenTofu provider, including local binaries. By default it resolves from the OpenTofu registry, whose metadata repo lists 4,603 providers (counted 2026-09-27). - What happened to Pulumi Copilot / Pulumi AI? Both were superseded by Pulumi Neo.
pulumi ai webwas removed in 3.246.0, andpulumi new --aiin 3.256.0.