Rank #1 of 4 in Infrastructure as Code
Install
Showcase


Try itExperimental
See what an agent can do with Pulumi before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$pulumi versionrecorded session — replayed, not liveVerified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Import migration — stories about import migration in this arenaImport migrationevidence →
Stories about import migration in this arena
Licensing governance — stories about licensing governance in this arenaLicensing governanceevidence →
Stories about licensing governance in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan applyevidence →
The plan/apply loop — previewing infrastructure changes and applying them safely
Policy as code — stories about policy as code in this arenaPolicy as codeevidence →
Stories about policy as code in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Providers modules — stories about providers modules in this arenaProviders modulesevidence →
Stories about providers modules in this arena
Secrets config — stories about secrets config in this arenaSecrets configevidence →
Stories about secrets config in this arena
State management — stories about state management in this arenaState managementevidence →
Stories about state management in this arena
Testing validation — stories about testing validation in this arenaTesting validationevidence →
Stories about testing validation in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Pulumi stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
~6/10
unlocks → Webhooks · Scoped API keys · Machine-readable spec · Versioning policy
Subscribe to events via webhooks
—–
Build against official SDKs
✓9/10
Issue scoped/least-privilege API credentials for an agent
—–
Connect an agent via an official MCP server
✓9/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
~7/10
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓8/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
✓6/10
unlocks → MCP client
Operate the product with natural-language commands
~7/10
Plug MCP servers into this product so it can use their tools
—0/10
Get AI-generated insights and suggestions from my data inside the product
~6/10
Set up automations that run autonomously in the background
~6/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Import migration — stories about import migration in this arenaImport migration
Stories about import migration in this arena
Licensing governance — stories about licensing governance in this arenaLicensing governance
Stories about licensing governance in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply
The plan/apply loop — previewing infrastructure changes and applying them safely
Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change
✓9/10
Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval
✓8/10
Drive deployments programmatically from my own application code rather than only through the CLI
✓9/10
Plan workflow
Policy as code — stories about policy as code in this arenaPolicy as code
Stories about policy as code in this arena
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Providers modules — stories about providers modules in this arenaProviders modules
Stories about providers modules in this arena
Generate infrastructure code from natural language using AI assistance built into the toolchain
✓8/10
Define infrastructure in a general-purpose programming language with types, loops, and IDE support
✓9/10
Consume and publish reusable modules or components from a public registry
~6/10
Manage resources across all major clouds and SaaS providers through a broad provider ecosystem
✓9/10
Secrets config — stories about secrets config in this arenaSecrets config
Stories about secrets config in this arena
State management — stories about state management in this arenaState management
Stories about state management in this arena
Testing validation — stories about testing validation in this arenaTesting validation
Stories about testing validation in this arena
Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 6/10 | Cclaimed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 6/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 7/10 | Tprobed | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Xcommunity | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | partial | 7/10 | Tprobed | |
Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change C Agent plan parsing | ai-native user | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | full | 9/10 | Tprobed | |
Import existing cloud resources under management and generate matching configuration code G Import | platform-engineer | Import migration — stories about import migration in this arenaImport migration | 3 | full | 9/10 | Cclaimed | |
Manage resources across all major clouds and SaaS providers through a broad provider ecosystem C Providers | developer | Providers modules — stories about providers modules in this arenaProviders modules | 3 | full | 9/10 | Tprobed | |
Preview exactly what will change — creates, updates, and destroys — before applying C Plan workflow | platform-engineer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | full | 9/10 | Tprobed | |
Enforce policy-as-code checks that block non-compliant infrastructure changes before apply C Policy | devops-lead | Policy as code — stories about policy as code in this arenaPolicy as code | 3 | full | 8/10 | Cclaimed | |
Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval C Ai infra ops | ai-native user | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | full | 8/10 | Tprobed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 8/10 | Tprobed | |
Store state in a remote backend with locking so concurrent runs cannot corrupt it C State backends | platform-engineer | State management — stories about state management in this arenaState management | 3 | full | 8/10 | Xcommunity | |
Consume and publish reusable modules or components from a public registry C Modules | developer | Providers modules — stories about providers modules in this arenaProviders modules | 3 | partial | 6/10 | Tprobed | |
Detect drift between my declared configuration and the actual cloud resources C Drift | platform-engineer | State management — stories about state management in this arenaState management | 3 | partial | 6/10 | Tprobed | |
Run plan and apply non-interactively in CI using saved plan artifacts and approval flags C Plan workflow | devops-lead | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | partial | 6/10 | Tprobed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 5/10 | Xcommunity | |
Pass secrets and sensitive configuration into deployments without exposing them in code or logs C Secrets | developer | Secrets config — stories about secrets config in this arenaSecrets config | 3 | partial | 5/10 | Tprobed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | none | 0/10 | ||
Rely on an open license and open governance so the tool cannot be relicensed out from under my company G Licensing | devops-lead | Licensing governance — stories about licensing governance in this arenaLicensing governance | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Define infrastructure in a general-purpose programming language with types, loops, and IDE support C Languages | developer | Providers modules — stories about providers modules in this arenaProviders modules | 2 | full | 9/10 | Xcommunity | |
Drive deployments programmatically from my own application code rather than only through the CLI G Automation api | developer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 2 | full | 9/10 | Xcommunity | |
Tear down an entire environment cleanly with a destroy operation C Plan workflow | developer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 2 | full | 9/10 | Tprobed | |
Generate infrastructure code from natural language using AI assistance built into the toolchain C Ai authoring | ai-native user | Providers modules — stories about providers modules in this arenaProviders modules | 2 | full | 8/10 | Tprobed | |
Write automated tests for my infrastructure code and run them without touching production C Testing | developer | Testing validation — stories about testing validation in this arenaTesting validation | 2 | full | 8/10 | Tprobed | |
Encrypt state at rest so credentials and sensitive values are not readable in plaintext state files C State backends | devops-lead | State management — stories about state management in this arenaState management | 2 | full | 7/10 | Tprobed | |
Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces C Config stacks | developer | Secrets config — stories about secrets config in this arenaSecrets config | 2 | full | 7/10 | Tprobed | |
Migrate an existing Terraform-format codebase and its state into this tool C Migration | platform-engineer | Import migration — stories about import migration in this arenaImport migration | 2 | partial | 6/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 6/10 | Tprobed | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 5/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 5/10 | Tprobed | |
Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes C Ai infra ops | ai-native user | Policy as code — stories about policy as code in this arenaPolicy as code | 2 | partial | 5/10 | Tprobed | |
Safely inspect and modify state — moving, removing, or renaming resources — when refactoring C State backends | platform-engineer | State management — stories about state management in this arenaState management | 2 | partial | 5/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 4/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 3/10 | Cclaimed | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Rely on documented compatibility promises and upgrade guides between releases C Stability | developer | Licensing governance — stories about licensing governance in this arenaLicensing governance | 2 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | partial | 6/10 | Tprobed | |
Target or exclude specific resources in a plan or apply C Plan workflow | platform-engineer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 1 | none | untested | none yet | |
Validate and auto-format my configuration before planning C Testing | developer | Testing validation — stories about testing validation in this arenaTesting validation | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 32 stories with headroom
What would move Pulumi’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
nonemoves agent-readyimpact 45
All Pulumi MCP evidence describes Pulumi acting as an MCP *server* (exposing its own tools to external AI assistants like Cursor, Claude Code, Windsurf) — the opposite direction from the story, which asks whether Pulumi itself can consume/plug in external MCP servers as a client.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
nonemoves PA Scoreimpact 30
The evidence covers Pulumi's languages, testing, state backends, policy-as-code guardrails, import, and MCP/Automation API integrations, but none of it describes a mechanism for defining rules that automatically trigger actions in response to events (e.g., webhooks, event-driven pipelines, or reactive automation).
Licensing governance — stories about licensing governance in this arenaRely on an open license and open governance so the tool cannot be relicensed out from under my company
nonemoves PA Scoreimpact 30
The evidence pack contains no mention of Pulumi's license type (e.g., Apache 2.0), its governance model, or any foundation/neutral steward that would prevent unilateral relicensing — only GitHub repo links and generic self-hosting/backend docs.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
The evidence covers Pulumi's MCP server for AI agent integration and CLI/API access broadly, but nothing describes issuing scoped or least-privilege API credentials/tokens specifically for an agent's use (e.g., token scoping, RBAC-limited service accounts, or credential minting for AI agents).
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
Missing: any documentation or mention of webhook support, event subscription APIs, or notification triggers.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
No evidence of an interactive API reference with runnable examples; probes explicitly show no OpenAPI/Swagger spec (404s across candidate paths) and no mention of a live/sandboxed API explorer.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
A direct probe for an OpenAPI/equivalent spec at all standard candidate paths returned 404 across the board, and no evidence pack item shows Pulumi publishing a downloadable machine-readable API spec; the llms.txt found is a marketing/context file, not an API spec.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
No evidence pack item discusses API versioning or a documented deprecation policy for Pulumi's APIs (CLI, SDK, Automation API, or MCP server); the OpenAPI probe returned 404s and no changelog/versioning policy is cited.
Showing the top 8 of 32 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map7 surfaces · 40 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs40 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Test against a sandbox environment without touching production data
- Perform bulk operations across many items at once
- Version, review, and roll back my automations
- Import existing cloud resources under management and generate matching configuration code
- Migrate an existing Terraform-format codebase and its state into this tool
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Self-host the core product
- Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change
- Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval
- Drive deployments programmatically from my own application code rather than only through the CLI
- Tear down an entire environment cleanly with a destroy operation
- Run plan and apply non-interactively in CI using saved plan artifacts and approval flags
- Preview exactly what will change — creates, updates, and destroys — before applying
- Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes
- Enforce policy-as-code checks that block non-compliant infrastructure changes before apply
- Choose where my data is stored (region/residency)
- Control data retention and deletion
- Generate infrastructure code from natural language using AI assistance built into the toolchain
- Define infrastructure in a general-purpose programming language with types, loops, and IDE support
- Consume and publish reusable modules or components from a public registry
- Manage resources across all major clouds and SaaS providers through a broad provider ecosystem
- Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces
- Pass secrets and sensitive configuration into deployments without exposing them in code or logs
- Detect drift between my declared configuration and the actual cloud resources
- Store state in a remote backend with locking so concurrent runs cannot corrupt it
- Encrypt state at rest so credentials and sensitive values are not readable in plaintext state files
- Safely inspect and modify state — moving, removing, or renaming resources — when refactoring
- Write automated tests for my infrastructure code and run them without touching production
Hacker News9 stories
- Get AI-generated insights and suggestions from my data inside the product
- Perform bulk operations across many items at once
- Version, review, and roll back my automations
- Export all of my data in open formats and leave
- Self-host the core product
- Drive deployments programmatically from my own application code rather than only through the CLI
- Define infrastructure in a general-purpose programming language with types, loops, and IDE support
- Manage resources across all major clouds and SaaS providers through a broad provider ecosystem
- Store state in a remote backend with locking so concurrent runs cannot corrupt it
Product docs7 stories
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Do everything through the API that I can do in the UI
- Read the product's source under an open license
- Generate infrastructure code from natural language using AI assistance built into the toolchain
GitHub README5 stories
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Define infrastructure in a general-purpose programming language with types, loops, and IDE support
- Consume and publish reusable modules or components from a public registry
- Manage resources across all major clouds and SaaS providers through a broad provider ecosystem
Pricing docs4 stories
OpenAPI spec2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$pulumi versionreproduced$ pulumi version v3.261.0
$pulumi preview --helpreproduced$ pulumi preview --help
Show a preview of updates to a stack's resources.
This command displays a preview of the updates to an existing stack whose state is
represented by an existing state file. The new desired state is computed by running
a Pulumi program, and extracting all resource allocations from its resulting object graph.
These allocations are then compared against the existing state to determine what
operations must take place to achieve the desired state. No changes to the stack will
actually take place.
The program to run is loaded from the project in the current directory. Use the `-C` or
`--cwd` flag to use a different directory.
Usage:
pulumi preview [flags]
Aliases:
preview, pre
Flags:
--attach-debugger stringArray[=program] Enable the ability to attach a debugger to the program and source based plugins being executed. Can limit debug type to 'program', 'plugins', 'plugin:<name>' or 'all'.
-c, --config stringArray Config to use during the preview and save to the stack config file
--config-file string Use the configuration values in the specified file rather than detecting the file name
--config-path Config [redacted]s contain a path to a property in a map or list to set
-d, --debug Print detailed debugging output during resource operations
--diff Display operation as a rich diff showing the overall change
-x, --exclude stringArray Specify a resource URN to ignore. These resources will not be updated. Multiple resources can be specified using --exclude urn1 --exclude urn2. Wildcards (*, **) are also supported
--exclude-dependents Allow ignoring of dependent targets discovered but not specified in --exclude list
--expect-no-changes Return an error if any changes are proposed by this preview
-h, --help help for preview
--ignore-protect Ignore the protect resource option for this operation, previewing the deletion or replacement of protected resources instead of failing
--import-file string Save any creates seen during the preview into an import file to use with 'pulumi import'
-j, --json Serialize the preview diffs, operations, and overall output as JSON. Set PULUMI_ENABLE_STREAMING_JSON_PREVIEW to stream JSON events instead.
-m, --message string Optional message to associate with the preview operation
--neo Enable Pulumi Neo's assistance for improved CLI experience and insights (can also be set with PULUMI_NEO environment variable)
--override-env stringArray [EXPERIMENTAL] Override an imported environment for this run only, as <env>=<replacement>; repeatable
-p, --parallel int32 Allow P resource operations to run in parallel at once (1 for no parallelism). (default 72)
--policy-pack strings Run one or more policy packs as part of this update
--policy-pack-config strings Path to JSON file containing the config for the policy pack of the corresponding "--policy-pack" flag
-r, --refresh string[="true"] Refresh the state of the stack's resources before this update
--replace stringArray Specify resources to replace. Multiple resources can be specified using --replace urn1 --replace urn2
--run-program Run the program to determine up-to-date state for providers to refresh resources, this only applies if --refresh is set
--save-plan string [PREVIEW] Save the operations proposed by the preview to a plan file at the given path
--show-config Show configuration [redacted]s and variables
--show-full-output Display full length of inputs & outputs
--show-policy-remediations Show per-resource policy remediation details instead of a summary
--show-reads Show resources that are being read in, alongside those being managed directly in the stack
--show-replacement-steps Show detailed resource replacement creates and deletes instead of a single step
--show-sames Show resources that needn't be updated because they haven't changed, alongside those that do
--show-secrets false Show secrets in plaintext in the CLI output, if used with --save-plan the secrets will also be shown in the plan file. Defaults to false
--skip-config-validation Skip validation of stack config values against the project config schema
--skip-plugin-pre-install Skip the up-front provider plugin install step; missing plugins are installed lazily by the engine
-s, --stack string The name of the stack to operate on. Defaults to the current stack
--suppress-outputs Suppress display of stack outputs (in case they contain sensitive values)
--suppress-permalink string[="false"] Suppress display of the state permalink
--suppress-progress Suppress display of periodic progress dots
-t, --target stringArray Specify a single resource URN to update. Other resources will not be updated. Multiple resources can be specified using --target urn1 --target urn2
--target-dependents Allow updating of dependent targets discovered but not specified in --target list
--target-replace stringArray Specify a single resource URN to replace. Other resources will not be updated. Shorthand for --target urn --replace urn.
--urns Display full URNs instead of short resource names
Global Flags:
--color string Colorize output. Choices are: always, never, raw, auto (default "auto")
-C, --cwd string Run pulumi as if it had been started in another directory
--disable-integrity-checking Disable integrity checking of checkpoint files
-e, --emoji Enable emojis in the output (default true)
-Q, --fully-qualify-stack-names Show fully-qualified stack names
--logflow Flow log settings to child processes (like plugins)
--logtostderr Log to stderr instead of to files
--memprofilerate int Enable more precise (and expensive) memory allocation profiles by setting runtime.MemProfileRate
--non-interactive Disable interactive mode for all commands
--otel-traces string Export OpenTelemetry traces to the specified endpoint. Use file:// for local JSON files, grpc:// or https:// for remote collectors
--profiling string Emit CPU and memory profiles and an execution trace to '[filename].[pid].{cpu,mem,trace}', respectively
--tracing file: Emit tracing to the specified endpoint. Use the file: scheme to write tracing data to a local file
-v, --verbose int Enable verbose logging (e.g., v=3); anything >3 is very verbose
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
11 of 15 testable claims verified · 0 contradicted → integrity 73/100
22 distinct capability claims found in Pulumi’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
11
Verified
4
Unverified
0
Contradicted
25
Undersold
Verified (16)
“Supports infrastructure definition in TypeScript, JavaScript, Python, Go, .NET, Java, YAML, and HCL with full provider coverage in each language”
Define infrastructure in a general-purpose programming language with types, loops, and IDE supportfullproof ↗
“Automation API lets you run Pulumi programs programmatically without invoking the CLI”
Drive deployments programmatically from my own application code rather than only through the CLIfullproof ↗
“Provides unit, property, and integration testing capabilities for infrastructure code, including in-memory mocked unit tests”
Write automated tests for my infrastructure code and run them without touching productionfullproof ↗
“Supports storing state either in Pulumi Cloud's managed backend or in a self-managed object store (S3, Azure Blob, GCS)”
Store state in a remote backend with locking so concurrent runs cannot corrupt itfullproof ↗
“Official MCP server lets AI assistants query Pulumi Cloud stacks and search across managed cloud resources”
“MCP server also lets AI coding assistants generate infrastructure code and delegate tasks to the Neo agent”
“MCP server also lets AI coding assistants generate infrastructure code and delegate tasks to the Neo agent”
Generate infrastructure code from natural language using AI assistance built into the toolchainfullproof ↗
“Can preview exactly what changes (creates/updates/deletes) a deployment will make without applying them”
Preview exactly what will change — creates, updates, and destroys — before applyingfullproof ↗
“Lets infrastructure be authored using standard general-purpose language features like loops, functions, classes, and package managers instead of YAML”
Define infrastructure in a general-purpose programming language with types, loops, and IDE supportfullproof ↗
“Unit tests are written in the same language as the Pulumi program and can use familiar test/mock frameworks like Mocha or NUnit”
Write automated tests for my infrastructure code and run them without touching productionfullproof ↗
“MCP server integrates with multiple AI coding tools including Cursor, Claude Code, Windsurf, and Claude Desktop”
“Neo can be instructed in plain English to handle dependencies, execute changes, and monitor outcomes automatically”
Operate the product with natural-language commandspartialproof ↗
“Neo can be instructed in plain English to handle dependencies, execute changes, and monitor outcomes automatically”
Set up automations that run autonomously in the backgroundpartialproof ↗
“Backend options include a managed Pulumi Cloud service or simple object storage in AWS S3, Azure Blob Storage, or Google Cloud Storage”
Store state in a remote backend with locking so concurrent runs cannot corrupt itfullproof ↗
“Pulumi can be self-hosted”
“Automatically provisions and manages resources across AWS, Azure, GCP, Kubernetes, and 300+ providers”
Manage resources across all major clouds and SaaS providers through a broad provider ecosystemfullproof ↗
Unverified (6)
“Policy-as-code framework to define and enforce guardrails across resources managed by Pulumi, Terraform, CloudFormation, or created manually”
Enforce policy-as-code checks that block non-compliant infrastructure changes before applyfullproof ↗
“Can import an existing cloud resource into Pulumi state and auto-generate the matching program code to manage it”
Import existing cloud resources under management and generate matching configuration codefullproof ↗
“Can generate an import file listing all resources a program would create, for review before bulk-importing”
Import existing cloud resources under management and generate matching configuration codefullproof ↗
“Neo is a built-in AI agent that provisions, governs, and optimizes cloud infrastructure with enterprise controls”
Delegate tasks to a built-in AI assistant inside the productfullproof ↗
“Provides guided migration path from Terraform, CloudFormation, and other IaC tools”
Migrate an existing Terraform-format codebase and its state into this toolpartialproof ↗
“Most IaC projects require bringing existing resources (from other tools or manual creation) under management, which Pulumi supports”
Import existing cloud resources under management and generate matching configuration codefullproof ↗
Undersold (25)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Drive the product through a documented public APIpartialproof ↗
Get AI-generated insights and suggestions from my data inside the productpartialproof ↗
Test against a sandbox environment without touching production datapartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Export all of my data in open formats and leavepartialproof ↗
Read the product's source under an open licensepartialproof ↗
Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed changefullproof ↗
Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approvalfullproof ↗
Tear down an entire environment cleanly with a destroy operationfullproof ↗
Run plan and apply non-interactively in CI using saved plan artifacts and approval flagspartialproof ↗
Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changespartialproof ↗
Choose where my data is stored (region/residency)partialproof ↗
Consume and publish reusable modules or components from a public registrypartialproof ↗
Manage per-environment configuration (dev, staging, prod) as separate stacks or workspacesfullproof ↗
Pass secrets and sensitive configuration into deployments without exposing them in code or logspartialproof ↗
Detect drift between my declared configuration and the actual cloud resourcespartialproof ↗
Encrypt state at rest so credentials and sensitive values are not readable in plaintext state filesfullproof ↗
Safely inspect and modify state — moving, removing, or renaming resources — when refactoringpartialproof ↗
Claims outside our story set (2)
Real capability claims found in Pulumi’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Offers self-service infrastructure via templates, guardrails, and a developer portal”
source ↗“Provides Pulumi-maintained version control integrations for GitHub, GitLab, and Azure DevOps”
source ↗
Business model
Pulumi engine and SDKs are Apache-2.0; Pulumi Cloud is free for individuals, then priced by usage (resources/credits) on team plans with custom Enterprise and self-hosted options.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime llms.txt 100% (30d, checked every 6h since Sep 8 '26)
