Home / Companies / Pulumi / Blog / August 2026

August 2026 Summaries

12 posts from Pulumi

Filter
Month: Year:
Post Summaries Back to Blog
Pulumi Kubernetes provider v4.34.0 adds enhanced Custom Resource Definition support, including a new `--extension` option that lets users generate typed SDKs for any CRD from its manifest and extend an existing Kubernetes provider instance without separate configuration or kubeconfig files. The release also includes Kubernetes v1.37.0 resources, dependency updates, and bug fixes, while addressing growing use of CRD-based technologies such as the Gateway API, now recommended for cluster ingress following ingress-nginx’s retirement. Generated CRD SDKs can be regenerated as dependencies through `pulumi install`, optionally versioned or committed to source control, and used across all Pulumi-supported languages, including YAML, with validated types and autocomplete support. Users of crd2pulumi can migrate by updating their SDK package reference without changing stack state, with upgrades expected to produce no changes during `pulumi up`; the feature requires Pulumi v3.255.0 and Kubernetes provider v4.34.0.
Aug 28, 2026 392 words in the original blog post.
Pulumi has introduced Neo Security, a research-preview AI agent designed to identify exploitable cloud infrastructure vulnerabilities that static code analysis may miss. Using Pulumi’s context graph, Neo examines an organization’s resources, dependencies, identities, runtime data, infrastructure code, policy results, and cloud-provider validation tools to build a threat model, map potential attack paths, and verify risks across environments including AWS, Azure, Google Cloud, Kubernetes, and non-IaC-managed resources. Its read-only assessment ranks validated findings by severity and confidence, covering issues such as overly permissive identity roles, public network exposure, weak encryption, unrotated credentials, and improperly shared data. Where infrastructure source code is available, Pulumi can translate findings into proposed code changes and pull requests while leaving deployment within existing review workflows. The company says tests with production environments found previously unknown critical vulnerabilities, and it is offering initial scans free to a limited group of invited customers during the preview.
Aug 28, 2026 1,389 words in the original blog post.
Pulumi has introduced the Context API in preview for Enterprise and Business Critical organizations, providing a queryable infrastructure graph that unifies Pulumi-managed resources, externally discovered cloud resources, stacks, dependencies, and stack outputs. Designed primarily for AI agents such as Pulumi Neo as well as third-party tools and custom automation, the API enables users to investigate change impact, identify infrastructure outside infrastructure-as-code management, and find unused stacks or resources for possible cleanup. Queries use a JSON structure to define starting nodes, traverse relationships, and return results, while response metadata indicates pagination, incomplete results, and RBAC-based visibility limits. Agents can retrieve an evolving Markdown schema primer to learn the graph vocabulary and query language, allowing them to translate natural-language infrastructure questions into API queries and correct validation errors. Access requires Pulumi CLI version 3.243.0 or later and follows existing Resource Search permissions, and Pulumi plans to expand the graph to include ESC environments, teams, roles, cloud accounts, and service-catalog information.
Aug 26, 2026 969 words in the original blog post.
Kubernetes infrastructure as code encompasses three complementary layers: provisioning clusters and cloud dependencies, defining and packaging in-cluster workloads, and continuously reconciling deployed state with Git. Terraform, OpenTofu, and Pulumi are leading choices for cluster and cloud provisioning, with Terraform favored for its mature ecosystem and Pulumi offering general-purpose languages, integrated workload management, dependency handling, and Kubernetes-specific features such as readiness checks and typed CRDs. Helm remains the dominant package format for third-party Kubernetes software, while Kustomize provides simpler patch-based environment overlays for plain YAML; code-oriented alternatives include cdk8s and Pulumi. Argo CD and Flux provide GitOps delivery and drift correction but depend on other tools to provision infrastructure and author manifests. Crossplane and the early-stage kro target platform teams building Kubernetes-native self-service infrastructure APIs, though they introduce additional operational and conceptual complexity. The recommended approach is generally to combine tools according to organizational needs, skills, scale, and desired reconciliation model, such as Terraform or Pulumi for clusters, Helm or Kustomize for workloads, and Argo CD or Flux for ongoing GitOps management.
Aug 14, 2026 4,338 words in the original blog post.
Pulumi HCL aims to ensure that HCL programs compatible with OpenTofu produce equivalent results when run through Pulumi, enabling shared Terraform modules and a clear correctness standard based on matching provider operations and stack outputs. Its tfcompat testing framework runs the same HCL scenario against OpenTofu and Pulumi in parallel using in-memory Terraform providers, captures provider gRPC calls and outputs, and passes only when both systems perform identical observable actions. Because tests specify scenarios rather than manually defined expected behavior, they can reliably detect real compatibility divergences. This approach also makes LLM-assisted bug discovery practical: models can generate failing tfcompat cases that demonstrate genuine differences between Pulumi HCL and OpenTofu, reducing false positives and supporting large-scale testing. The method applies to the subset of Pulumi HCL accepted by OpenTofu, while Pulumi HCL itself supports a broader language superset.
Aug 14, 2026 1,113 words in the original blog post.
Pulumi has introduced the Notification Center, a real-time inbox in the Pulumi Cloud console accessed through the sidebar bell icon, designed to surface events requiring user action without relying on open tabs or email. Initial notifications cover Neo tasks awaiting approval or completion, ESC change requests needing sign-off, and billing issues such as locked organizations or expiring trials, with alerts limited to relevant organization members. Each notification directs users to the specific page needed to complete its associated action, while delivery can be configured separately for console and email notifications. Organization administrators establish default preferences, and individual users can override them in account settings; Pulumi plans to expand notification types based on community feedback.
Aug 11, 2026 328 words in the original blog post.
Pulumi v3.254.0 adds automatic encrypted logging for every operation, reducing the need to reproduce failures solely to collect diagnostic information for support. Logs are stored in `$PULUMI_HOME/logs`, encrypted with the relevant stack’s secrets manager when available, and use gzip compression with AES-256-GCM encryption; logs without a secrets manager are compressed without including property-value secrets. To limit disk use, logs are removed after seven days or once the directory exceeds 500 MB, with configurable retention settings, and users can decrypt local logs through `pulumi logs decrypt` when the appropriate stack secrets manager is available. The new `pulumi logs share` command re-encrypts logs with a server-managed key and redacts secrets by default, enabling users to securely share diagnostic files with Pulumi employees through even potentially unsafe channels such as GitHub issues.
Aug 10, 2026 462 words in the original blog post.
Terraform can manage Kubernetes through HashiCorp’s Kubernetes provider, Helm provider, and community kubectl-based providers, using typed HCL resources for common objects and manifest-based approaches for custom or unsupported resources. Its principal operational constraints are that `kubernetes_manifest` requires a live cluster API during planning and provider credentials can be evaluated unpredictably when clusters and Kubernetes resources are created in the same module, leading HashiCorp to recommend separate provisioning and workload deployment stages. Pulumi is presented as an alternative that uses general-purpose languages, generated Kubernetes API bindings, dependency resolution, Server-Side Apply, readiness handling, typed custom-resource generation, and multiple Helm integration models to manage clusters and workloads within one program. The comparison also highlights differing testing and policy approaches: Terraform offers HCL-based tests and mock providers, while Pulumi uses language-native test frameworks, mocks, automation APIs, and policy packs. Terraform remains suitable for organizations invested in its provider ecosystem, modules, governance, and unified infrastructure workflows, while migration can be incremental through conversion tools, HCL support, Terraform module consumption, and clearly divided ownership when both tools operate against the same Kubernetes environment.
Aug 07, 2026 2,919 words in the original blog post.
The text discusses the use of a command called --dangerously-skip-permissions, colloquially known as YOLO mode, in coding agents, which allows them to execute commands without user approval, potentially leading to significant security risks. While YOLO mode enhances the autonomy of coding agents, it also poses threats such as unauthorized access to sensitive files, network vulnerabilities, and potential data breaches, especially when working with infrastructure code. To mitigate these risks, the author advocates for the use of a sandbox environment, which isolates the agent from critical system files and processes, thereby providing a controlled space where agents can operate with full autonomy without compromising the host machine. The text introduces Docker Sandboxes, a tool that simplifies the sandboxing process, providing hypervisor isolation, network control, Docker engine isolation, and workspace isolation to protect the host system from potential malicious actions by the coding agents. Additionally, the author highlights the importance of integrating infrastructure-specific tools and configurations within the sandbox to facilitate secure and efficient infrastructure management, while emphasizing the need for both sandboxing and robust cloud control measures to fully safeguard against unintended consequences of autonomous coding agents.
Aug 04, 2026 2,281 words in the original blog post.
The latest release introduces a suite of features aimed at enhancing interoperability between Pulumi Cloud and the Terraform and OpenTofu ecosystems, focusing on three main areas: using Pulumi Cloud as a Terraform state backend with remote execution and human approvals, a Terraform module registry within Pulumi Cloud for cross-language module sharing, and first-class support for HCL in the Pulumi engine. The release provides a comprehensive walkthrough starting with a simple AWS deployment using Terraform, migrating to Pulumi Cloud, and showcasing various integrations and functionalities, including remote execution, module publishing, consumption from Pulumi programs in multiple languages, and native HCL support. This integration allows users to maintain existing infrastructure while leveraging Pulumi's capabilities, providing a flexible and robust framework for managing infrastructure as code across different platforms and languages.
Aug 04, 2026 2,525 words in the original blog post.
Pulumi's HCL support aims to seamlessly integrate existing Terraform configurations, allowing users to run them in Pulumi while addressing the semantic differences between Pulumi and OpenTofu. The HCL interpreter processes Terraform's resource semantics, providers, and modules, with a focus on translating them to Pulumi's engine protocol. Pulumi and Terraform both utilize providers, but Pulumi's "terraform-provider" acts as a bridge to facilitate compatibility with Terraform providers. Pulumi's HCL interpreter handles resource property translations, converting snake_case to camelCase and adapting to the type requirements of the Pulumi engine. The system also supports Terraform's provisioners and conditions through resource hooks, and translates resource options like lifecycle and provider settings to Pulumi's equivalents. Additionally, Terraform modules are represented as Pulumi components, allowing cross-language compatibility and integration. Pulumi's approach ensures that users can leverage Terraform's capabilities while benefiting from Pulumi's features, with ongoing efforts to address any discrepancies that arise.
Aug 04, 2026 2,489 words in the original blog post.
Pulumi is advancing the era of agentic infrastructure by offering a platform that integrates seamlessly with existing Infrastructure as Code (IaC) solutions like Terraform, allowing organizations to transition smoothly without dismantling current systems. Pulumi Cloud provides a backend for Terraform state, enabling users to maintain familiar deployment patterns while benefiting from Pulumi's advanced capabilities, such as tag-based access control, Neo code reviews, and preventive policies. The platform supports the inclusion of Terraform modules and the HashiCorp Configuration Language (HCL) as first-class citizens, ensuring compatibility and ease of use for teams accustomed to these tools. Pulumi offers financial incentives, including credits for unused HashiCorp contracts, free modernization workshops, and ROI calculations, to facilitate the transition and underscore the value and savings potential of adopting its platform. This strategic approach is designed to accommodate various organizational sizes and industries, emphasizing a smooth transition to modern infrastructure management without financial or operational obstacles.
Aug 04, 2026 1,078 words in the original blog post.