Reposted by Pulumi𝙳𝚘𝚝𝚊𝚗 𝙷𝚘𝚛𝚘𝚟𝚒𝚝𝚜 @horovits.bsky.social · 10/09/2026Fun catching up with @ediri.de at AWS Summit Tel Aviv, and discussing open source, and how we can collaborate around #Pulumi, #OpenSearch and more. #selfie #AWSSummit @pulumi.com @opensearch.org 001
Pulumi @pulumi.com · 28/09/2026We paired TypeSafe's Jev with the Pulumi Automation API to build GeoDeploy: confidence-gated AI picks the best AWS, Azure, or Google Cloud region for your users, and Pulumi provisions the Kubernetes. Open source today.pulumi.comSelf-driving infrastructure with Pulumi and JevGeoDeploy pairs TypeSafe Jev's confidence-scored decisions with the Pulumi Automation API to place and scale Kubernetes across AWS, Azure, and Google Cloud. 000
Pulumi @pulumi.com · 28/09/2026Not every Claude Code message needs Opus. Engin Diri built jev-router to try Jev, TypeSafe's System One model. It asks Jev which Claude model each message needs, in a few hundred milliseconds and for a fraction of a cent. How it works, and how to try it:pulumi.comRoute every Claude Code message to the right model with Jevjev-router asks Jev, a System One model, which Claude model each Claude Code message needs, and routes it there for a fraction of a cent. 000
Pulumi @pulumi.com · 21/09/2026Ten coding agent tips, each checked against the research. The most expensive habit on the list: escalating to a bigger model mid-task. In an AWS study on SWE-bench, restarting Opus from scratch cost less and solved more than handing it Haiku's transcript.pulumi.com10 tips to improve your coding agent gameTen coding agent habits checked against the research behind them, from AGENTS.md drift and /compact to model switching, subagents, and review. 000
Pulumi @pulumi.com · 10/09/2026We've arrived at AWS Summit Tel Aviv 📍 Booth B10 The boxes made it. So did the hats. Engin and the crew are there all day. 000
Pulumi @pulumi.com · 02/09/2026Tomorrow: does your team need an exit plan from its cloud provider? Waldemar Kindler, Jim Dowling and Sarbjeet Johal, who thinks most companies shouldn't bother. Live, with Q&A.pulumi.comBeyond the Hyperscalers: Building Sovereign InfrastructureA live panel on cloud sovereignty as an architecture decision. Who is leaving the hyperscalers, why, and when staying is the right call. 000
Pulumi @pulumi.com · 28/08/2026Neo Security is our infrastructure security agent. It uses context about your full cloud estate—resources, semantics, code, reachability, runtime data, and more—to build a model of your estate and analyze it. Each finding is actionable thanks to IaC.pulumi.comNeo Security: Securing Infrastructure in the Agentic EraPulumi Neo Security threat models and traces attack paths across your entire cloud estate. Find and fix problems before the bad actors do. 010
Pulumi @pulumi.com · 27/08/2026A panel about leaving the hyperscalers — with Sarbjeet Johal on it arguing most companies shouldn't. Sep 3. www.pulumi.com/events/beyond-the-hy… 000
Pulumi @pulumi.com · 26/08/2026We just launched the Pulumi Context API: everything Pulumi knows about your infrastructure as one queryable graph, built agent-first. Any agent can learn it in one request, and Neo uses it out of the box. Here's a brief tour.pulumi.comPulumi Context API: One Graph for All Your InfrastructureThe Pulumi Context API is now in preview: query IaC state, stack dependencies, and discovered cloud resources as one graph built for AI agents. 010
Pulumi @pulumi.com · 25/08/2026Tomorrow: keep your Terraform estate, run it through Pulumi Cloud — no migration, no rewrite. Aug 26, 10 AM ET / 4 PM CEST 👇 www.pulumi.com/events/pulumi-for-al… 000
Pulumi @pulumi.com · 24/08/2026German enterprises' question has shifted: not "what does this cost?" but "could we move if we had to?" Waldemar Kindler, Sep 3. www.pulumi.com/events/beyond-the-hy… 000
Pulumi @pulumi.com · 20/08/2026Jim Dowling moved Hopsworks to OVHcloud and cut the bill 62%. Sep 3, he shows his work. www.pulumi.com/events/beyond-the-hy… 000
Pulumi @pulumi.com · 14/08/2026Our tfcompat tests never say what Pulumi HCL should do. A test is just an HCL program and its providers; OpenTofu's behavior is the spec. That one choice lets LLMs hunt our bugs. We wrote up how.pulumi.comCompatibility Testing Pulumi HCLHow we test that Pulumi HCL is an OpenTofu compatible HCL runtime. 110
Pulumi @pulumi.com · 14/08/2026European regulations and rising cloud bills have CTOs asking a question that was unthinkable five years ago: do we need an exit plan from our cloud provider? Sep 3, a live panel on when that makes sense, and when it doesn't. www.pulumi.com/events/beyond-the-hy…... 100
Pulumi @pulumi.com · 11/08/2026Tomorrow: a free hour on configuring Claude Code and opencode for infrastructure as code. We set both up from scratch, then put them to work live on a real task, so Pulumi comes out correct, not plausible. Aug 12, 12 PM ET 👇 www.pulumi.com/events/getting-start…... 020
Pulumi @pulumi.com · 10/08/2026Debugging a Pulumi error usually meant reproducing it by hand just to capture a log, then finding a safe way to share a file full of secrets. Pulumi v3.254.0 makes logs automatic and encrypted, safe to share even on a public GitHub issue. Here's what changed.pulumi.comAutomatic Logging for Faster, Secure DebuggingPulumi now writes encrypted logs for every operation automatically 000
Pulumi @pulumi.com · 05/08/2026Coding agents will write your infrastructure as code. Whether it's correct and consistent comes down to how you configure them. Aug 12, free workshop: set up Claude Code + opencode from scratch so they get Pulumi right. 👇 www.pulumi.com/events/getting-start…... 020
Pulumi @pulumi.com · 04/08/2026Teams running Terraform don't have to rip it out to move into the agentic infrastructure era. Pulumi Cloud is now GA as a Terraform state backend, HCL is GA as a native Pulumi language, and Terraform modules import without changes. Here's what shipped today.pulumi.comBring Your Terraform Estate Into the Agentic EraPulumi Cloud as a Terraform backend and HCL in Pulumi IaC are now GA, plus native Terraform module support — bring the IaC you already have. 000
Pulumi @pulumi.com · 04/08/2026Every coding agent has a YOLO mode. You're probably running it daily, and prompt guardrails fail right when it matters. Engin Diri on sandboxing agents with Docker Sandboxes, plus an open-source kit preloaded with Pulumi, Terraform, and cloud CLIs for infra work.pulumi.comYOLO Mode Is the Right Default. Your Laptop Is the Wrong Place for It.Prompt guardrails fail right when coding agents get dangerous. How Docker Sandboxes make YOLO mode safe, plus a ready-made kit for infrastructure work. 020
Pulumi @pulumi.com · 04/08/2026Tomorrow: a free hour on Pulumi ESC, from the basics up. What an environment is, how it pulls from the secret stores you already run, and how your IaC, CI/CD, and local dev consume it without scattered copies. 12 PM ET. www.pulumi.com/events/intro-to-pulu…... 000
Pulumi @pulumi.com · 31/07/2026Your secrets are in environment variables, a CI system, two cloud secret stores, and a .env file on somebody's laptop. Aug 5, free intro workshop: pull them into one Pulumi ESC environment everything reads from. www.pulumi.com/events/intro-to-pulu…... 000
Pulumi @pulumi.com · 30/07/2026Six months into a migration, can you say which of 800 resources actually made it to IaC — and which were quietly forgotten? The spreadsheet tracking it went stale the day it was written. The spreadsheet is retired for good.pulumi.comDiscovered Stacks: One Place for All Your InfrastructureDiscovered Stacks: Pulumi Cloud now models your CloudFormation and ARM deployments as Pulumi IaC stacks, with a built-in migration path. 100
Pulumi @pulumi.com · 30/07/2026We migrated a 61-resource CloudFormation stack to Pulumi — payments API, database, the works — and never ran pulumi up once. A zero-diff preview proved every resource was in sync. The full step-by-step is up.pulumi.comMigrate CloudFormation to Pulumi with Discovered StacksMigrate a CloudFormation stack to Pulumi with Discovered Stacks: verify every resource, import with a zero-diff preview, and track it all in Pulumi Cloud. 000
Pulumi @pulumi.com · 30/07/2026An AI agent on Kubernetes isn't just another Deployment: GPUs, long-lived sessions, and a much bigger credential blast radius. Here's how to provision and govern that infrastructure with Pulumi, in TypeScript and Python.pulumi.comHow to Run AI Agents on Kubernetes with PulumiHow to provision and govern Kubernetes infrastructure for AI agents with Pulumi, in TypeScript and Python, and where kagent, KServe, Kueue, and Neo fit in. 030
Pulumi @pulumi.com · 27/07/2026Token rotation policies are easy to write and hard to enforce. Pulumi Cloud now enforces them for you: org admins can cap the max expiry of personal, organization, and team access tokens used against their organization, checked on every request.pulumi.comEnforce Access Token Expiry Policies in Pulumi CloudOrganization admins can now cap the maximum expiry of personal, organization, and team access tokens, so no credential outlives your rotation policy. 000
Pulumi @pulumi.com · 22/07/2026esc v0.26.0 is the last standalone ESC CLI release. The repo is archived, and every command now lives under pulumi env in the Pulumi CLI. Swapping esc for pulumi env covers most of them. The ones it doesn't cover are the ones worth knowing. We documented all of them.pulumi.comThe Standalone ESC CLI Retired: Use pulumi envThe standalone esc CLI is archived as of v0.26.0. Every ESC command is available in the Pulumi CLI under pulumi env: one binary to install and upgrade. 000
Pulumi @pulumi.com · 21/07/2026A container isn't much of a security boundary: every one on a host shares the same kernel. Kubernetes Agent Sandbox gives AI agents a kernel-isolated, disposable box instead. Adam Gordon Bell deployed it on GKE with Pulumi, one sandbox per developer. Here's how it's wired together.pulumi.comKubernetes Agent Sandbox: What It Is and How to Deploy It with PulumiAgent Sandbox gives AI agents kernel-isolated, disposable environments as Kubernetes resources. Here's what it is and how to deploy it on GKE with Pulumi. 000
Pulumi @pulumi.com · 20/07/2026Terraform alternatives in 2026 split into three camps: general-purpose-language platforms, HCL-compatible forks, and cloud-specific tools. The one that fits your team increasingly depends on something most comparisons skip: how well it works with an AI coding agent in the loop.pulumi.comBest Terraform Alternatives in 2026The best Terraform alternatives for 2026: Pulumi, OpenTofu, AWS CDK, Crossplane, and Bicep, compared on multi-cloud reach, governance, and AI-agent readiness. 001
Reposted by PulumiDaniel Ward - daninacan @danielwarddev.bsky.social · 20/07/2026Next San Antonio/Austin DNUG is in 10 days! Learn to build your infrastructure in C# with Pulumi! #dotnet #azure 🎤What: Serverless Dad Jokes: What If Everything Was Just C#? 👨🏫Who: Adam Gordon Bell ⌚When: July 30 @ Noon CST 🌐Where: Zoom Signup: www.meetup.com/sadnug/event... 041
Pulumi @pulumi.com · 20/07/2026Your infra is code. Your on-call setup is forty clicks in a web UI, done once. Engin Diri wires PagerDuty + AWS in one Pulumi program: teams, schedules, escalation policies, and the alarm that pages you. Integration keys flow as dependencies, nothing gets forgotten.pulumi.comIncident Response as Code: Managing PagerDuty with PulumiManage PagerDuty teams, schedules, escalation policies, and services with Pulumi, and wire alerting to the AWS infrastructure in the same program. 100
Pulumi @pulumi.com · 15/07/2026Connect your AWS, Azure, and Google Cloud accounts to Pulumi Insights in about three minutes. The same setup used to take hours to days of per-account OIDC and ESC configuration. We built a wizard that handles all of it. Here's how it works.pulumi.comConnect Your Cloud Accounts to Pulumi in MinutesOnboard your AWS, Azure, and Google Cloud accounts to Pulumi Insights in bulk with the new Connect cloud accounts wizard. OIDC-based, no long-lived secrets. 000
Pulumi @pulumi.com · 15/07/2026Now Pulumi Neo supports monthly usage limits, putting your Neo spend under control so you can hand it more and more infrastructure work.pulumi.comIntroducing Usage Limits for Pulumi NeoSet monthly organization or per-member Pulumi Neo dollar limits and get alerts via email. 000
Pulumi @pulumi.com · 14/07/2026The LLM wiki everyone built after Karpathy's gist is a dialect only your own agent can read. Google's Open Knowledge Format pins it down: markdown, frontmatter, one required field. Knowledge as code.pulumi.comKnowledge as Code: The Memory File Just Got a SpecGoogle's Open Knowledge Format: a one-page spec for the LLM wiki. Markdown, one required field, git. Why knowledge as code is your agent loop's missing layer. 000
Pulumi @pulumi.com · 13/07/2026Phishing kits replicate the page. They cannot replicate the origin a passkey is bound to. Passkey sign-in is now live in Pulumi Cloud for users who sign in with email and password. Phishing-resistant, synced across devices. Here's how to enroll.pulumi.comSign in to Pulumi Cloud with PasskeysPulumi Cloud now supports passkeys: a phishing-resistant alternative to typing your password, for users who sign in with email and password. 000
Pulumi @pulumi.com · 08/07/2026Roey Zalta gave an AI agent its own Mac mini and full system access. His pitch: "give it an environment, tools, autonomy — and see what it builds." His warning: "it's 100% not secure." So how do you run an AI employee safely? Live panel, Jul 14pulumi.comSecuring Personal AI Agents: Guardrails and Infrastructure for OpenClawA live panel on securing OpenClaw and autonomous agents before they touch production cloud — the guardrails, identity, and verifiable state they need. 000
Pulumi @pulumi.com · 08/07/2026For a while, running an older Pulumi release meant the docs on the site described a newer one. We closed that gap. You no longer have to guess which parts of the reference still apply to your version. Here's what we shipped.pulumi.comNew: Versioned CLI and SDK DocsThe Pulumi CLI command reference and SDK API docs now include a version selector, so you can browse the docs that match the release you're running. 000
Pulumi @pulumi.com · 01/07/2026ISO 27001 compliance on AWS has meant months of mapping governance controls to actual cloud resources, interpreting each one for S3, RDS, CloudTrail. We built 238 policies to handle that mapping. Live today in Pulumi Cloud.pulumi.comEnforce ISO 27001 Across Your AWS InfrastructureAlign your AWS infrastructure to ISO/IEC 27001:2022 with a pre-built Pulumi policy pack of 238 ready-to-run security policies. 000
Pulumi @pulumi.com · 30/06/2026A GPU box that pulls a model and serves Ollama the second pulumi up finishes, same program on AWS, Azure, and Google Cloud. No static keys (OIDC from one Pulumi ESC environment), no wait loops. Engin Diri shows how.pulumi.comFully Automated AI Inference on AWS, Azure, and Google Cloud with PulumiA zero-touch Ollama GPU inference server on AWS, Azure, or Google Cloud as one Pulumi program, with OIDC credentials from Pulumi ESC and no static keys. 000
Reposted by PulumiCascadiaJS @cascadiajs.com · 22/06/2026Joe Duffy, Founder and CEO of @pulumi.com, closed out Day 1 of CascadiaJS 2026 with a look at what happens when AI agents move beyond writing code and start handling the messy world of infrastructure, deployment, and operations. youtu.be/SOMEfFNPsew 141
Pulumi @pulumi.com · 25/06/2026Thinking of giving an AI agent shell access and your cloud creds? OpenClaw, Hermes, Claude CoWork — they turn useful fast, and risky just as fast. Live panel with Microsoft on running them safely, Jul 14 👇pulumi.comSecuring Personal AI Agents: Guardrails and Infrastructure for OpenClawA live panel on securing OpenClaw and autonomous agents before they touch production cloud — the guardrails, identity, and verifiable state they need. 100
Pulumi @pulumi.com · 24/06/2026Hermes is a self-improving agent that writes and runs its own code — which is why you don't want it on the public internet. Here's how to deploy one as a single Pulumi program with no front door: Render, Modal, and Tailscale.pulumi.comDeploy a Private Hermes Agent on Render Securely with Pulumi, Modal, and TailscaleDeploy a self-hosted Hermes agent as one Pulumi program across Render, Modal, and Tailscale — a code-executing AI agent with nothing on the public internet. 010
Pulumi @pulumi.com · 16/06/2026This week in New York, three ways to get into deploying AI agents with Pulumi. Wed June 17: AWS Summit, then our hands-on AI Camp workshop at GA Flatiron, 5:30 PM. Thu June 18, 6 PM: NY Pulumi User Group kicks off with Pinecone. Workshop: www.aicamp.ai/event/eventdetails/W2…aicamp.aiDeveloper Workshop (NYC) - Deploying AI Agents with Pulumi and AWSJoin over half million developers learning how to use and build AI through expert-led tech talks, workshops, bootcamps and crash courses. Level up your skills, and stay ahead of the industry | AICamp 000
Pulumi @pulumi.com · 15/06/2026Have you ever been rate limited by Docker Hub? Haven't we all. It happened to Adam Gordon Bell mid-demo at a live AKS workshop. Azure had refused the first region before that. Here are the six Kubernetes recommendations that came out of what happened next.pulumi.comSix Live Kubernetes Recommendations: AKS, Cilium, Rate Limiting, and MoreDeploy an AKS cluster with Pulumi C#. Six Kubernetes recommendations from a live workshop, including the Docker Hub rate limit that hit mid-demo. 000
Pulumi @pulumi.com · 09/06/2026The unit of work moved from the prompt to the loop. You stop prompting the agent and start designing the thing that prompts it. The pieces already ship in your tools. The part that makes a loop worth running doesn't.pulumi.comStop Prompting. Design the Loop.The unit of work moved from the prompt to the loop. The five pieces of loop engineering, the memory that makes it compound, and what it won't do for you. 000
Pulumi @pulumi.com · 09/06/2026Cloudflare edge config does not need to live in clickops. Build DNS, WAF, Workers, and Access policies as a Pulumi baseline.pulumi.comhttps://www.pulumi.com/blog/cloudflare-first-networking-with-pulumi/?utm_source=bluesky&utm_medium=social&utm_content=cloudflare-first-networking-with-pulumi 000
Pulumi @pulumi.com · 08/06/2026Pulumi is in New York June 17 and 18, with three ways to get into deploying AI agents: a hallway chat at AWS Summit, a hands-on workshop, and the New York Pulumi User Group kickoff. Workshop seats are limited: www.aicamp.ai/event/eventdetails/W2…aicamp.aiDeveloper Workshop (NYC) - Deploying AI Agents with Pulumi and AWSJoin over half million developers learning how to use and build AI through expert-led tech talks, workshops, bootcamps and crash courses. Level up your skills, and stay ahead of the industry | AICamp 000
Pulumi @pulumi.com · 08/06/2026Heading to DevOpsCon Berlin June 16-17. Visit our Silver sponsor booth or catch Wladi Mitzel's talk "Designed for agents, useful for humans: Five IaC practices that pay off twice." Grounded in Pulumi telemetry across ~10M production deployments. Practices apply to Pulumi, Terraform, and OpenTofu.devopscon.ioDevOpsCon Berlin | June 15 - 19, 2026 |DevOpsCon Berlin - The Conference for CI/CD, Container, Docker, Kubernetes, DevSecOps & Lean Business | June 15 - 19, 2026 | Berlin or Online 010
Pulumi @pulumi.com · 05/06/2026Pulumi Deployments can now trigger on git tag pushes. Push a version tag like v1.2.0 and Pulumi runs pulumi up automatically — with glob-based tag filters so you only deploy the releases you choose.pulumi.comTrigger Deployments on Git TagsTie infrastructure deployments to your release tags. Push a version tag like v1.2.0 and let Pulumi Deployments run pulumi up automatically. 000
Pulumi @pulumi.com · 04/06/2026Cloud AI APIs keep agents easy until tradeoffs show up: data leaves your network, offline work breaks, and every token has a meter. Pablo Seibelt rebuilt the stack locally with Gemma 4, llama.cpp, k3d, Pulumi, and Tailscale. The interesting part is what runs where, and why.pulumi.comUse Your Mac for AI Agents: Self-Host Gemma 4 12 B with Pulumi and TailscaleSelf-host multimodal Gemma 4 on a Mac with Pulumi, llama.cpp, and Tailscale, using Unsloth's Gemma 4 12 B Q8 GGUF with a 128K context window. 000