Home / Companies / Pulumi / Blog / May 2025

May 2025 Summaries

11 posts from Pulumi

Filter
Month: Year:
Post Summaries Back to Blog
Nico Thomas, a platform engineer at SEITENBAU, discusses how his team developed a flexible and reusable platform using Pulumi to support over 20 diverse projects with varying technology stacks, infrastructure requirements, and operational models. Unlike traditional platform engineering, which often focuses on a single product, SEITENBAU faced the challenge of accommodating a wide range of independent government and private sector projects, each with unique needs. To address this, they adopted a "buffet" approach rather than a one-size-fits-all solution, allowing teams to select from a variety of pre-configured, production-ready components tailored to their specific requirements. Using Pulumi and Python, they constructed a modular architecture with multiple Pulumi stacks to manage complexity and empower team autonomy, creating a component library that simplifies infrastructure management by offering high-level components that encapsulate complex patterns. This strategy has enabled SEITENBAU to efficiently serve its diverse projects while maintaining flexibility and consistency, illustrating the benefits of a customizable platform over a standardized one.
May 27, 2025 905 words in the original blog post.
Pulumi has introduced new AI capabilities in its CLI, powered by Pulumi Copilot, to enhance infrastructure management by translating complex changes into clear explanations and providing actionable guidance for resolving deployment errors. These features, available in preview mode with the --copilot flag, aim to tackle the challenges of understanding preview changes and interpreting error messages by offering plain-language summaries and diagnostics. The "explain" option in the CLI provides a concise summary of pending infrastructure updates, helping users verify changes and identify potential issues. Additionally, the diagnostics feature simplifies error logs into actionable solutions, reducing resolution time. These features require Pulumi CLI version v3.171.0 or greater and the Pulumi Cloud backend, and feedback from users during the preview period will shape future enhancements before general availability.
May 22, 2025 739 words in the original blog post.
Pulumi has launched the v1.0.0 release of its Go Provider SDK, a framework designed to enhance cloud infrastructure management by integrating various services, tools, and APIs into infrastructure as code workflows. This release, stable and production-ready, comes after extensive development and testing since 2022, incorporating feedback from enterprise users. The SDK provides several enhancements, including support for Go 1.24, a user-friendly Provider Builder API, functional-style components, and a comprehensive testing framework. It simplifies the creation of custom resources and components while ensuring reliability through lifecycle, component, and integration testing. The SDK also supports seamless multi-language use, allowing providers written in Go to be utilized across various programming languages supported by Pulumi, with automatic schema generation facilitating cross-language consumption. Pulumi encourages users to explore the SDK, contribute to the ecosystem, and engage with the community for collaborative development and feedback.
May 20, 2025 1,882 words in the original blog post.
Pulumi Cloud offers an efficient solution for overcoming the challenges of managing multi-cloud environments by integrating Infrastructure as Code (IaC) with automation, compliance, and security. It streamlines operations by automating deployments and centralizing secrets, which accelerates time to market and reduces onboarding time by 75%. Supporting modern programming languages, Pulumi Cloud enhances developer productivity and simplifies workflows, as demonstrated by companies like BMW Group that utilize it for scalable hybrid cloud implementations. The platform ensures compliance with security standards such as SOC2 and HIPAA through features like Pulumi CrossGuard and Pulumi ESC, effectively managing policy enforcement and secrets. It also provides AI-driven insights to optimize resource use, reducing waste and cutting costs while eliminating the need for dedicated backend engineers. Companies like Unity Technologies have benefited from significantly reduced deployment times, enabling a focus on innovation and scalability. Pulumi Cloud is presented as a comprehensive solution for modern cloud management, offering resources and workshops to aid teams in transitioning from self-managed environments.
May 16, 2025 444 words in the original blog post.
Managing large-scale infrastructure is streamlined with Pulumi's new features, which introduce the --exclude and --exclude-dependents flags for stack operations. These additions allow users to omit specific resources and their dependents from deployment tasks, such as pulumi up and pulumi destroy, offering a more refined control over which resources are affected during operations. Previously, the --target flag enabled targeting specific resources, but it became cumbersome when needing to exclude a few items from operations affecting large stacks. The new flags resolve this by allowing users to exclude resources like databases needing maintenance or draft articles from a website deployment, without resorting to workarounds or custom scripts. This enhancement is particularly useful for scenarios where infrastructure managers want to operate on most resources but leave out certain ones, providing a scalable approach to manage resources across different environments effectively. These features are part of Pulumi CLI v3.158.0, with future integration into automation APIs and GitHub actions.
May 14, 2025 1,201 words in the original blog post.
Platform engineering is emerging as a potential evolution of DevOps, which aimed to dismantle silos between development and operations, but has encountered practical limitations in larger organizations due to specialization and governance needs. While some view platform engineering as merely a rebranding of existing concepts or a passing trend, others see it as a necessary adaptation that recognizes and addresses these challenges. The approach focuses on creating productive abstractions and interfaces between application teams and operational services, much like a platform functions as an abstraction layer, and treats the platform itself as a product. This method retains the collaborative spirit of DevOps while accommodating organizational growth and specialization, aiming to empower teams and reduce friction with dedicated tools and reusable abstractions. Despite the skepticism surrounding its novelty, platform engineering may represent a viable strategy for scaling the core principles of DevOps, with companies like Pulumi investing in features that support this evolution, not just because it's fashionable, but because it proves effective when implemented well.
May 12, 2025 920 words in the original blog post.
Pulumi has introduced Visual Import, a feature designed to streamline the onboarding of existing cloud infrastructure into Pulumi by enabling users to discover unmanaged resources, organize them, and generate Pulumi code with AI enhancements. Available to Team, Enterprise, and Business Critical customers with Pulumi Insights, Visual Import addresses the challenge of migrating cloud deployments by automating the discovery and codification process, thereby reducing manual efforts and increasing developer productivity. The workflow involves selecting and grouping resources, reviewing dependencies, and generating code in the preferred language, which can be refined using Pulumi Copilot. This tool not only accelerates the transition to a managed, version-controlled infrastructure but also ensures consistency and reliability through Pulumi's integrated features, such as policy enforcement and CI/CD integrations. By leveraging Pulumi Cloud's capabilities, users can transform their infrastructure into an auditable and deployable system, enhancing cloud operations and facilitating seamless integration into existing workflows.
May 08, 2025 787 words in the original blog post.
Pulumi has introduced the Pulumi Private Registry as part of its Integrated Developer Platform (IDP), aiming to simplify the creation of flexible golden paths for infrastructure management. This registry enables organizations to standardize resource provisioning through codified components and templates, enhancing security and compliance with tools like Pulumi ESC for secret management and Pulumi CrossGuard for policy enforcement. The registry facilitates streamlined publishing and consuming packages with a user-friendly CLI workflow, supporting various repositories and organizations, and offers simplified discovery of standardized components for developers. It also provides insights into Day 2 operations, such as infrastructure maintenance, by allowing platform engineers to track component usage and manage upgrades or decommissions efficiently. The Pulumi IDP, along with the Private Registry, is available in Public Preview, inviting users to explore its capabilities and integrate it into their workflows.
May 07, 2025 377 words in the original blog post.
Pulumi has introduced the Pulumi IDP (Internal Developer Platform) as an evolution of its cloud platform to automate, secure, and manage cloud infrastructure effectively. This platform is designed to support platform engineering by providing scalable workflows through self-service infrastructure management, addressing tool sprawl and Day 2 operational challenges that arose with the DevOps movement. Pulumi IDP integrates with the entire Pulumi product suite, facilitating flexible workflows that accommodate different user personas, from no-code to full-code solutions. Central to its functionality is the Pulumi Private Registry, which serves as a source of truth for reusable infrastructure components, ensuring discoverability, lifecycle management, and compliance. The introduction of Pulumi Services adds organizational context to infrastructure management, allowing teams to group stacks, resources, and environments logically while integrating metadata for enhanced context and operability. Pulumi IDP aims to empower platform teams to create secure, compliant, and reliable infrastructure workflows, offering a bottom-up framework that promotes the use of standardized components across various programming languages.
May 06, 2025 1,195 words in the original blog post.
Infrastructure as Code (IaC) tools like Pulumi can provide significant advantages when used correctly, ensuring both leverage and safety in infrastructure management. Oso, which offers Authorization as a Service, faced a complex infrastructure migration due to rapid growth necessitating a shift from Amazon ECS Fargate to self-managed EC2 instances. The key to a successful migration involved understanding how to safely modify infrastructure, writing reusable and predictable Pulumi code, and performing zero-diff refactors to ensure no unintended changes. Pulumi’s programming model involves a global state where resources are registered, making it vital to write code that is aware of these side effects. By utilizing snapshot testing and zero-diff refactors, Oso managed to transition without downtime, despite numerous challenges. The experience underscores the importance of leveraging IaC tools effectively to benefit from their potential while maintaining system stability.
May 05, 2025 1,831 words in the original blog post.
Pulumi ESC introduces two integrations designed to enhance the security and management of Snowflake credentials, addressing common challenges associated with static credentials and manual key rotation. The "snowflake-login" integration provides dynamic, short-lived OIDC tokens for temporary authentication, suitable for tasks requiring immediate but temporary access to Snowflake, thereby reducing the risks associated with storing long-lived credentials. Meanwhile, the "snowflake-user" integration automates the rotation of RSA keypair secrets, essential for maintaining secure key-pair authentication for applications requiring persistent connections. These integrations enable secure credential management through ESC's SDK, CLI, and Kubernetes integrations, ultimately improving Snowflake's security posture, reducing operational overhead, and aiding compliance. The use of these integrations allows for seamless temporary access and continuous key rotation, offering a robust solution for modern credential management challenges in data cloud environments.
May 01, 2025 742 words in the original blog post.