December 2025 Summaries
14 posts from Pulumi
Filter
Month:
Year:
Post Summaries
Back to Blog
The year 2025 marked a significant evolution in platform engineering with the introduction of Pulumi Neo, a purpose-built AI designed to address the challenges faced by platform engineers, who had been struggling to keep pace with the rapid advancements in AI-accelerated development. Neo brings dedicated AI tools to platform teams, understanding cloud environments and infrastructure as code, and operates within Pulumi’s existing platform capabilities, ensuring security and compliance. Innovations throughout the year included AI-assisted development tools integrated with Pulumi's CLI, next-generation policy management for AI-powered governance, and the foundation of Internal Developer Platforms (IDP) for self-service infrastructure. Pulumi also enhanced secrets management to address security risks, introduced comprehensive Identity and Access Management (IAM), and expanded Infrastructure as Code (IaC) capabilities with major cloud provider updates and language support. These developments aimed to transform platform engineering from a reactive process to a proactive, strategic enabler of sustainable velocity in AI-driven environments, setting the stage for further innovations in the future.
Dec 22, 2025
1,993 words in the original blog post.
Pulumi is positioning itself as a modern, open-source-friendly infrastructure as code (IaC) platform, offering new capabilities to attract HashiCorp customers dissatisfied with the company's recent changes under IBM ownership. Pulumi Cloud now supports both Terraform and OpenTofu, allowing users to benefit from features like AI-driven infrastructure management and governance, without having to abandon their existing tools. Pulumi is also introducing native support for HashiCorp Configuration Language (HCL) alongside its existing multi-language support, making it a versatile choice for diverse development teams. To encourage migration from HashiCorp, Pulumi offers financial incentives, including covering costs until existing contracts expire, and provides workshops to assist in the transition process. The company emphasizes its commitment to customer success and flexibility, aiming to provide a universal platform that accommodates various languages and tools while enhancing productivity, compliance, and infrastructure visibility.
Dec 18, 2025
2,556 words in the original blog post.
In December 2020, CDK for Terraform (CDKTF) was deprecated by HashiCorp/IBM, prompting users to seek alternatives for their infrastructure management needs. The blog post explores three primary options available for teams previously using CDKTF: reverting to HashiCorp Configuration Language (HCL) with Terraform, migrating to AWS Cloud Development Kit (CDK), or transitioning to Pulumi. While returning to HCL might be feasible, it contradicts the original motivation for choosing CDKTF, and AWS CDK, though similar in concept, requires significant rewrites due to differences in APIs and resource models. Pulumi emerges as a compelling alternative, offering compatibility with existing CDKTF workflows and leveraging general-purpose languages like TypeScript, Python, and more. It supports Terraform providers and modules, facilitating smoother transitions with its built-in conversion and import functions that translate CDKTF projects into Pulumi programs. The migration process entails exporting CDKTF projects to HCL, converting and importing them into Pulumi, and refactoring to align the new Pulumi code with deployed resources. Pulumi's advantages include a declarative deployment engine and the ability to manage infrastructure across multiple clouds, positioning it as a practical choice for CDKTF users.
Dec 18, 2025
1,392 words in the original blog post.
Pulumi Cloud, a platform that manages cloud infrastructure, has introduced a long-requested dark mode feature for its users. This update, resulting from the efforts of the User Experience team to implement a shared design system, allows users to choose between light mode, dark mode, and a system default setting that aligns with their operating system preferences. Users can easily switch themes through their account settings by selecting their profile image and navigating to the Preferences section. The dark mode provides a darker background with lighter text and graphics, which is preferred by many users for extended use or in low-light conditions. Pulumi encourages users to try the new feature and provide feedback through their Community Slack or GitHub repository.
Dec 17, 2025
329 words in the original blog post.
Pulumi has introduced native OIDC token exchange support in its CLI, addressing the security and management challenges associated with long-lived credentials in CI/CD pipelines. This feature allows CI/CD environments like GitHub Actions, GitLab CI, or Kubernetes to authenticate to Pulumi Cloud using short-lived tokens issued by identity providers, eliminating the need to store long-lived credentials as secrets. The OIDC token exchange mitigates risks such as credential exposure, rotation complexity, over-privileged access, and audit trail gaps by offering short-lived, customizable tokens. The process involves using the `pulumi login` command with OIDC tokens, which can be scoped to specific teams or users, and supports integration with various token delivery systems. This enhancement, compatible with Kubernetes clusters like EKS, GKE, and AKS, requires setting up an OIDC provider and configuring authorization policies within Pulumi Cloud. Pulumi encourages users to update to the latest CLI version and adapt their CI/CD workflows to leverage this new functionality for enhanced security in infrastructure automation.
Dec 16, 2025
733 words in the original blog post.
Transitioning AI agents from prototypes to production can be challenging, particularly in areas like fraud detection. The process involves managing factors such as authentication, memory persistence, observability, and isolation. This in-depth guide illustrates the deployment of AI agents using Amazon Bedrock AgentCore, the Strands SDK, and Pulumi, highlighting the journey from initial development to a production-ready state. The Strands SDK facilitates local agent development with minimal code, while the Bedrock AgentCore offers a managed runtime with Firecracker isolation, supporting complex, long-running tasks. The guide also emphasizes the importance of adopting a progressive approach, starting with simple solutions and incorporating additional complexity and infrastructure as code only when necessary. Additionally, it explores event-driven architectures and the integration of short-term and long-term memory to enhance agent functionality. The use of Amazon's managed services, such as the MCP Gateway for tool integration and X-Ray for observability, ensures security and efficient operation at scale. This comprehensive roadmap not only demonstrates the technical steps involved in deploying a fraud detection AI agent but also underscores the strategic considerations necessary for effective production deployment.
Dec 15, 2025
4,856 words in the original blog post.
The text discusses the transformative impact of AI on software development and DevOps, predicting that by 2026 traditional IDEs will be replaced by agent-based interfaces that autonomously handle coding tasks. This shift will see engineers acting more as system architects rather than coders, using AI agents to automate complex tasks with minimal manual code review through artifact-based validation. Multiple AI providers are expected to specialize in different areas, necessitating infrastructure that supports various AI backends. The text also anticipates the rise of local AI enabled by advanced hardware, allowing large models to run on small devices with zero latency and full data privacy. Additionally, agent-to-agent protocols are gaining traction, enabling autonomous peer interactions and potentially monetizing AI capabilities via machine-to-machine payments. The text concludes by highlighting that DevOps teams must adapt their CI/CD pipelines for AI-generated code, ensuring robust validation systems and secure execution environments.
Dec 11, 2025
2,653 words in the original blog post.
The pursuit of superintelligence, defined as AI systems operating with genuine autonomy, is driving unprecedented infrastructure scaling, demanding innovative approaches to manage and scale this infrastructure. As AI models grow more complex, infrastructure spending is projected to reach trillions, with major companies like Microsoft, Meta, and Google investing heavily in data centers. Traditional infrastructure tools are inadequate for the rapid pace and complexity of current demands, leading to the emergence of a "superintelligence flywheel," where AI is used to manage the very infrastructure necessary for its development. Pulumi and Neo are positioned as critical components of this new era, providing infrastructure as code, multi-cloud management, and AI-driven automation to handle complex infrastructure tasks. This approach democratizes access to infrastructure, allowing organizations to innovate and compete by using AI to streamline infrastructure management, exemplified by companies like Wiz and Supabase, which have dramatically increased operational efficiency and agility. The self-reinforcing cycle of superintelligence and infrastructure development is accelerating, heralding a new era of computing where intelligent agents play an essential role in managing and scaling infrastructure.
Dec 11, 2025
2,274 words in the original blog post.
AWS re:Invent 2025 showcased a strategic integration of AI, silicon, and cloud infrastructure through several key announcements, including the expanded Nova model family, Nova Forge for custom model training, Trainium3 UltraServers, and AgentCore's enhanced production features. The event emphasized AWS's vertically integrated agent-training pipeline designed for enterprise AI, highlighting Nova Forge as a managed service for pretraining and fine-tuning Nova models using proprietary data, making advanced AI capabilities accessible without the need for extensive infrastructure. Trainium, AWS's AI accelerator, was presented as a cost-effective alternative to high-end GPUs, supporting AWS's model-factory ambitions by making iterative specialization economically viable. AgentCore was introduced as a managed runtime for AI agents, providing tools, memory, and policy guardrails. The Nova Act served as a practical demonstration of this integrated stack, showcasing specialized AI models deployed in real-world scenarios. AWS's approach reflects a shift toward customized AI agents driven by proprietary data and domain feedback, offering enterprises a comprehensive pipeline that many likely won't develop themselves.
Dec 10, 2025
1,498 words in the original blog post.
Pulumi has introduced a new feature called the replaceWith resource option, designed to provide users with explicit control over replacement dependencies between resources in their infrastructure management processes. While Pulumi typically handles resource creation, updates, and deletions automatically, the replaceWith option addresses scenarios where finer-grained control is necessary, such as when implicit dependencies aren't readily apparent or involve application-level considerations. By declaring these dependencies explicitly in the code, users can ensure that resource replacements trigger updates to related resources, thus maintaining the consistency and functionality of interconnected services. This feature is now available in Pulumi v3.207.0 across the Go, Python, NodeJS, and Java SDKs, with plans to support C# and YAML in the future, enhancing the capability to manage complex resource interactions effectively.
Dec 09, 2025
1,040 words in the original blog post.
Organizations can now streamline their processes with Neo through the introduction of Custom Instructions and Slash Commands, which automate the application of institutional knowledge and simplify task requests. Custom Instructions allow users to embed organizational standards and preferences, such as naming conventions and compliance requirements, directly into Neo's functionality, enabling automatic application across all tasks. This reduces the need for repetitive manual input and ensures consistency. Slash Commands, on the other hand, provide a way to capture and reuse effective prompts by transforming them into easily accessible shortcuts, enhancing efficiency by allowing team members to apply proven approaches with a simple keystroke. These features, available in the Neo settings, offer built-in commands for common tasks and the flexibility to create custom ones, thereby optimizing team workflows and improving productivity.
Dec 09, 2025
456 words in the original blog post.
Pulumi enables the management of infrastructure as software, incorporating sophisticated programming languages, testing, and CI/CD practices akin to application development, and this includes applying feature flagging to infrastructure. Feature flags, commonly used in software to manage changes and mitigate risks, can also be leveraged in infrastructure to control rollout and accelerate development. The text discusses using Pulumi in conjunction with various tools like LaunchDarkly, Terraform, and ESC to create and manage flags, allowing for dynamic infrastructure adjustments without redeployment. Pulumi supports defining flags alongside infrastructure code, integrating with external providers like LaunchDarkly for advanced flagging features, and automating infrastructure updates through webhooks for continuous delivery. The choice between using Pulumi's ESC for straightforward configuration or integrating with LaunchDarkly for more advanced features depends on the team's needs and existing toolsets. This approach aligns infrastructure management with modern software development practices, ensuring flexibility and control in deployment processes.
Dec 06, 2025
1,286 words in the original blog post.
In 2026, cloud computing will undergo significant transformation driven by emerging trends that emphasize AI integration, Infrastructure as Code (IaC), and platform engineering. AI will become a central component of cloud strategy, necessitating AI-native architectures with elastic compute and GPU orchestration. Hyperscalers are investing heavily in AI-driven cloud expansions, with companies like AWS, Microsoft, and Google leading the charge. Hybrid and multi-cloud strategies will become mainstream, requiring consistent security and compliance across environments. Enterprises are rebuilding their cloud foundations to operationalize AI at scale, incorporating automation and governance to support AI workloads. IaC is becoming essential for scalable cloud operations, enabling teams to deploy consistently across multi-cloud and hybrid environments. DevSecOps will evolve to include AI-integrated security, with AI platforms protecting investments. Platform engineering will facilitate cooperation between developers and operators, while AIOps will mature into a standard for cloud operations, offering predictive failure and automated incident resolution. Kubernetes will continue to dominate, adapting to AI demands with optimized scheduling and orchestration. AI code assistants are gaining traction, enhancing developer productivity and integrating with cloud environments. These trends highlight a shift towards intelligent, automated, and policy-driven cloud operations, positioning organizations that embrace these changes to excel in an AI-first world.
Dec 04, 2025
2,611 words in the original blog post.
ESC Connect is a newly introduced feature in Pulumi ESC that allows users to integrate any secret source by building simple HTTPS adapter services, thus enabling access to secrets from proprietary systems, legacy tools, or third-party services without native ESC support. This capability allows developers to create custom adapters that fetch secrets from non-standard sources by handling requests from ESC, authenticating with signed JWT tokens for secure access, and returning the required secrets. The feature also includes support for automated secret rotation, ensuring seamless credential updates without downtime, and offers a deployable reference adapter implementation on AWS Lambda to showcase secure request validation. ESC Connect expands the flexibility of Pulumi ESC by allowing users to easily incorporate niche or custom secret management systems, with comprehensive documentation available to guide users in building these adapters and sharing them with the community.
Dec 01, 2025
567 words in the original blog post.