Skip to content

Rank #1 of 4 in Infrastructure as Code

Pulumi logo

Pulumi

Open Source Built-in AI assistant

Pulumi Corporation

25.7k2.6k/yrnpm 2.2M/wk +37npm/wk -1.2M

Access

Install

brewbrew install pulumi/tap/pulumi
installercurl -fsSL https://get.pulumi.com | sh

Vendor-official, but review any script before piping it to a shell.

Compare head-to-head

Alternatives to Pulumi

Showcase

Pulumi homepage screenshot
homepage · captured Sep 2026 · view live ↗
Pulumi docs screenshot
docs · captured Sep 2026 · view live ↗

Try itExperimental

See what an agent can do with Pulumi before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$pulumi versionrecorded session — replayed, not live
recorded 2026-09-04 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

41.3/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

13.5/100

Import migration — stories about import migration in this arenaImport migrationevidence →

Stories about import migration in this arena

68.4/100

Licensing governance — stories about licensing governance in this arenaLicensing governanceevidence →

Stories about licensing governance in this arena

0.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

43.8/100

Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan applyevidence →

The plan/apply loop — previewing infrastructure changes and applying them safely

73.4/100

Policy as code — stories about policy as code in this arenaPolicy as codeevidence →

Stories about policy as code in this arena

60.0/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

16.0/100

Providers modules — stories about providers modules in this arenaProviders modulesevidence →

Stories about providers modules in this arena

71.8/100

Secrets config — stories about secrets config in this arenaSecrets configevidence →

Stories about secrets config in this arena

46.0/100

State management — stories about state management in this arenaState managementevidence →

Stories about state management in this arena

54.8/100

Testing validation — stories about testing validation in this arenaTesting validationevidence →

Stories about testing validation in this arena

53.3/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full9/10T

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full6/10C

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3partial6/10T

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none0/10

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial7/10T

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10X

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1partial7/10T

Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change C

Agent plan parsing

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full9/10T

Import existing cloud resources under management and generate matching configuration code G

Import

platform-engineerImport migration — stories about import migration in this arenaImport migration3full9/10C

Manage resources across all major clouds and SaaS providers through a broad provider ecosystem C

Providers

developerProviders modules — stories about providers modules in this arenaProviders modules3full9/10T

Preview exactly what will change — creates, updates, and destroys — before applying C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full9/10T

Enforce policy-as-code checks that block non-compliant infrastructure changes before apply C

Policy

devops-leadPolicy as code — stories about policy as code in this arenaPolicy as code3full8/10C

Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval C

Ai infra ops

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full8/10T

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full8/10T

Store state in a remote backend with locking so concurrent runs cannot corrupt it C

State backends

platform-engineerState management — stories about state management in this arenaState management3full8/10X

Consume and publish reusable modules or components from a public registry C

Modules

developerProviders modules — stories about providers modules in this arenaProviders modules3partial6/10T

Detect drift between my declared configuration and the actual cloud resources C

Drift

platform-engineerState management — stories about state management in this arenaState management3partial6/10T

Run plan and apply non-interactively in CI using saved plan artifacts and approval flags C

Plan workflow

devops-leadPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3partial6/10T

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial5/10X

Pass secrets and sensitive configuration into deployments without exposing them in code or logs C

Secrets

developerSecrets config — stories about secrets config in this arenaSecrets config3partial5/10T

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3none0/10

Rely on an open license and open governance so the tool cannot be relicensed out from under my company G

Licensing

devops-leadLicensing governance — stories about licensing governance in this arenaLicensing governance3none0/10

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Define infrastructure in a general-purpose programming language with types, loops, and IDE support C

Languages

developerProviders modules — stories about providers modules in this arenaProviders modules2full9/10X

Drive deployments programmatically from my own application code rather than only through the CLI G

Automation api

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2full9/10X

Tear down an entire environment cleanly with a destroy operation C

Plan workflow

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2full9/10T

Generate infrastructure code from natural language using AI assistance built into the toolchain C

Ai authoring

ai-native userProviders modules — stories about providers modules in this arenaProviders modules2full8/10T

Write automated tests for my infrastructure code and run them without touching production C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation2full8/10T

Encrypt state at rest so credentials and sensitive values are not readable in plaintext state files C

State backends

devops-leadState management — stories about state management in this arenaState management2full7/10T

Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces C

Config stacks

developerSecrets config — stories about secrets config in this arenaSecrets config2full7/10T

Migrate an existing Terraform-format codebase and its state into this tool C

Migration

platform-engineerImport migration — stories about import migration in this arenaImport migration2partial6/10C

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial6/10T

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2partial5/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial5/10T

Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes C

Ai infra ops

ai-native userPolicy as code — stories about policy as code in this arenaPolicy as code2partial5/10T

Safely inspect and modify state — moving, removing, or renaming resources — when refactoring C

State backends

platform-engineerState management — stories about state management in this arenaState management2partial5/10C

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial4/10C

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2partial3/10C

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2none0/10

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Rely on documented compatibility promises and upgrade guides between releases C

Stability

developerLicensing governance — stories about licensing governance in this arenaLicensing governance2noneuntestednone yet

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1partial6/10T

Target or exclude specific resources in a plan or apply C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply1noneuntestednone yet

Validate and auto-format my configuration before planning C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation1noneuntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 32 stories with headroom

What would move Pulumi’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools

    nonemoves agent-readyimpact 45

    All Pulumi MCP evidence describes Pulumi acting as an MCP *server* (exposing its own tools to external AI assistants like Cursor, Claude Code, Windsurf) — the opposite direction from the story, which asks whether Pulumi itself can consume/plug in external MCP servers as a client.

  2. Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events

    nonemoves PA Scoreimpact 30

    The evidence covers Pulumi's languages, testing, state backends, policy-as-code guardrails, import, and MCP/Automation API integrations, but none of it describes a mechanism for defining rules that automatically trigger actions in response to events (e.g., webhooks, event-driven pipelines, or reactive automation).

  3. Licensing governance — stories about licensing governance in this arenaRely on an open license and open governance so the tool cannot be relicensed out from under my company

    nonemoves PA Scoreimpact 30

    The evidence pack contains no mention of Pulumi's license type (e.g., Apache 2.0), its governance model, or any foundation/neutral steward that would prevent unilateral relicensing — only GitHub repo links and generic self-hosting/backend docs.

  4. Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent

    nonemoves agent-readyimpact 30

    The evidence covers Pulumi's MCP server for AI agent integration and CLI/API access broadly, but nothing describes issuing scoped or least-privilege API credentials/tokens specifically for an agent's use (e.g., token scoping, RBAC-limited service accounts, or credential minting for AI agents).

  5. Agenticness — how well agents can access and operate the productSubscribe to events via webhooks

    nonemoves agent-readyimpact 30

    Missing: any documentation or mention of webhook support, event subscription APIs, or notification triggers.

  6. Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples

    nonemoves API qualityimpact 30

    No evidence of an interactive API reference with runnable examples; probes explicitly show no OpenAPI/Swagger spec (404s across candidate paths) and no mention of a live/sandboxed API explorer.

  7. Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)

    nonemoves API qualityimpact 30

    A direct probe for an OpenAPI/equivalent spec at all standard candidate paths returned 404 across the board, and no evidence pack item shows Pulumi publishing a downloadable machine-readable API spec; the llms.txt found is a marketing/context file, not an API spec.

  8. Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy

    nonemoves API qualityimpact 30

    No evidence pack item discusses API versioning or a documented deprecation policy for Pulumi's APIs (CLI, SDK, Automation API, or MCP server); the OpenAPI probe returned 404s and no changelog/versioning policy is cited.

Showing the top 8 of 32 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map7 surfaces · 40 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

docs40 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$pulumi versionreproduced
$ pulumi version
v3.261.0
proves: Use an official CLIrecorded 2026-09-04
$pulumi preview --helpreproduced
$ pulumi preview --help
Show a preview of updates to a stack's resources.

This command displays a preview of the updates to an existing stack whose state is
represented by an existing state file. The new desired state is computed by running
a Pulumi program, and extracting all resource allocations from its resulting object graph.
These allocations are then compared against the existing state to determine what
operations must take place to achieve the desired state. No changes to the stack will
actually take place.

The program to run is loaded from the project in the current directory. Use the `-C` or
`--cwd` flag to use a different directory.

Usage:
  pulumi preview [flags]

Aliases:
  preview, pre

Flags:
      --attach-debugger stringArray[=program]   Enable the ability to attach a debugger to the program and source based plugins being executed. Can limit debug type to 'program', 'plugins', 'plugin:<name>' or 'all'.
  -c, --config stringArray                      Config to use during the preview and save to the stack config file
      --config-file string                      Use the configuration values in the specified file rather than detecting the file name
      --config-path                             Config [redacted]s contain a path to a property in a map or list to set
  -d, --debug                                   Print detailed debugging output during resource operations
      --diff                                    Display operation as a rich diff showing the overall change
  -x, --exclude stringArray                     Specify a resource URN to ignore. These resources will not be updated. Multiple resources can be specified using --exclude urn1 --exclude urn2. Wildcards (*, **) are also supported
      --exclude-dependents                      Allow ignoring of dependent targets discovered but not specified in --exclude list
      --expect-no-changes                       Return an error if any changes are proposed by this preview
  -h, --help                                    help for preview
      --ignore-protect                          Ignore the protect resource option for this operation, previewing the deletion or replacement of protected resources instead of failing
      --import-file string                      Save any creates seen during the preview into an import file to use with 'pulumi import'
  -j, --json                                    Serialize the preview diffs, operations, and overall output as JSON. Set PULUMI_ENABLE_STREAMING_JSON_PREVIEW to stream JSON events instead.
  -m, --message string                          Optional message to associate with the preview operation
      --neo                                     Enable Pulumi Neo's assistance for improved CLI experience and insights (can also be set with PULUMI_NEO environment variable)
      --override-env stringArray                [EXPERIMENTAL] Override an imported environment for this run only, as <env>=<replacement>; repeatable
  -p, --parallel int32                          Allow P resource operations to run in parallel at once (1 for no parallelism). (default 72)
      --policy-pack strings                     Run one or more policy packs as part of this update
      --policy-pack-config strings              Path to JSON file containing the config for the policy pack of the corresponding "--policy-pack" flag
  -r, --refresh string[="true"]                 Refresh the state of the stack's resources before this update
      --replace stringArray                     Specify resources to replace. Multiple resources can be specified using --replace urn1 --replace urn2
      --run-program                             Run the program to determine up-to-date state for providers to refresh resources, this only applies if --refresh is set
      --save-plan string                        [PREVIEW] Save the operations proposed by the preview to a plan file at the given path
      --show-config                             Show configuration [redacted]s and variables
      --show-full-output                        Display full length of inputs & outputs
      --show-policy-remediations                Show per-resource policy remediation details instead of a summary
      --show-reads                              Show resources that are being read in, alongside those being managed directly in the stack
      --show-replacement-steps                  Show detailed resource replacement creates and deletes instead of a single step
      --show-sames                              Show resources that needn't be updated because they haven't changed, alongside those that do
      --show-secrets false                      Show secrets in plaintext in the CLI output, if used with --save-plan the secrets will also be shown in the plan file. Defaults to false
      --skip-config-validation                  Skip validation of stack config values against the project config schema
      --skip-plugin-pre-install                 Skip the up-front provider plugin install step; missing plugins are installed lazily by the engine
  -s, --stack string                            The name of the stack to operate on. Defaults to the current stack
      --suppress-outputs                        Suppress display of stack outputs (in case they contain sensitive values)
      --suppress-permalink string[="false"]     Suppress display of the state permalink
      --suppress-progress                       Suppress display of periodic progress dots
  -t, --target stringArray                      Specify a single resource URN to update. Other resources will not be updated. Multiple resources can be specified using --target urn1 --target urn2
      --target-dependents                       Allow updating of dependent targets discovered but not specified in --target list
      --target-replace stringArray              Specify a single resource URN to replace. Other resources will not be updated. Shorthand for --target urn --replace urn.
      --urns                                    Display full URNs instead of short resource names

Global Flags:
      --color string                 Colorize output. Choices are: always, never, raw, auto (default "auto")
  -C, --cwd string                   Run pulumi as if it had been started in another directory
      --disable-integrity-checking   Disable integrity checking of checkpoint files
  -e, --emoji                        Enable emojis in the output (default true)
  -Q, --fully-qualify-stack-names    Show fully-qualified stack names
      --logflow                      Flow log settings to child processes (like plugins)
      --logtostderr                  Log to stderr instead of to files
      --memprofilerate int           Enable more precise (and expensive) memory allocation profiles by setting runtime.MemProfileRate
      --non-interactive              Disable interactive mode for all commands
      --otel-traces string           Export OpenTelemetry traces to the specified endpoint. Use file:// for local JSON files, grpc:// or https:// for remote collectors
      --profiling string             Emit CPU and memory profiles and an execution trace to '[filename].[pid].{cpu,mem,trace}', respectively
      --tracing file:                Emit tracing to the specified endpoint. Use the file: scheme to write tracing data to a local file
  -v, --verbose int                  Enable verbose logging (e.g., v=3); anything >3 is very verbose

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

11 of 15 testable claims verified · 0 contradictedintegrity 73/100

22 distinct capability claims found in Pulumi’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

11

Verified

4

Unverified

0

Contradicted

25

Undersold

Verified (16)
Unverified (6)
Undersold (25)
Claims outside our story set (2)

Real capability claims found in Pulumi’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Offers self-service infrastructure via templates, guardrails, and a developer portal

    source ↗
  • Provides Pulumi-maintained version control integrations for GitHub, GitLab, and Azure DevOps

    source ↗
Suggest a story for these →

Business model

open-sourcefree-tierusage-basedenterprise-custom

Pulumi engine and SDKs are Apache-2.0; Pulumi Cloud is free for individuals, then priced by usage (resources/credits) on team plans with custom Enterprise and self-hosted options.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score33 (Sep 4 '26)34 (Sep 4 '26)
Agent-ready58 (Sep 4 '26)51 (Sep 4 '26)

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data

Agent surface uptime llms.txt 100% (30d, checked every 6h since Sep 8 '26)