Home / Companies / Pulumi / Blog / Post Details
Content Deep Dive

Set Up Cloud OIDC From the Pulumi CLI

Blog post from Pulumi

Post Details
Company
Date Published
Author
Sean Yeh
Word Count
403
Company Posts That Month
1
Language
English
Hacker News Points
-
Post removed?
No
Summary

Pulumi ESC now supports OIDC onboarding for AWS, Azure, and Google Cloud directly through the Pulumi CLI via the new `pulumi env setup` command, allowing users, scripts, and agents to configure short-lived cloud credentials without relying on hard-coded secrets or completing setup in the Pulumi Cloud console. The command provides interactive, cloud-specific prompts to collect authentication details, target accounts, and access policies, then displays a proposed configuration before creating the required identity provider, roles, policy attachments, and an ESC environment for each account. For AWS, users can authenticate with existing credentials or AWS SSO and select policies such as AdministratorAccess, ReadOnlyAccess, or a custom policy ARN. Non-interactive flags are also available for automation, and the feature is included in the latest Pulumi CLI after authenticating with Pulumi Cloud.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.