<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Pulumi Blog: Aaron Kao</title><link>https://www.pulumi.com/blog/author/aaron-kao/</link><description>Pulumi blog posts: Aaron Kao.</description><language>en-us</language><pubDate>Wed, 19 Mar 2025 09:00:00 -0700</pubDate><item><title>Why Choose Pulumi Cloud Over DIY Backends?</title><link>https://www.pulumi.com/blog/why-choose-pulumi-cloud-over-diy-backends/</link><pubDate>Wed, 19 Mar 2025 09:00:00 -0700</pubDate><guid>https://www.pulumi.com/blog/why-choose-pulumi-cloud-over-diy-backends/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/why-choose-pulumi-cloud-over-diy-backends/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Note: This post discusses Pulumi Copilot, which Pulumi Neo has replaced. &lt;a href="https://www.pulumi.com/docs/ai/"&gt;Learn about Neo →&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Pulumi Cloud empowers engineers to automate, secure, and manage modern infrastructure platforms.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Many companies are building internal developer platforms or modern infrastructure platforms to provide developer self-service while maintaining security and compliance. Companies adopt Pulumi IaC so they can apply software engineering practices to their infrastructure scaling problems and because it is fully open source with a strong community and &lt;a href="https://github.com/orgs/pulumi/projects/44/"&gt;public roadmap&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;At Pulumi, we’re committed to open source—always have been; always will be. Pulumi IaC is &lt;a href="https://github.com/pulumi/pulumi"&gt;entirely open source&lt;/a&gt; (Apache 2.0 license), meaning you can adopt and extend it however you like. If you’re new to Pulumi, the open source edition is an excellent way to start modernizing your infrastructure. But as your organization grows and the complexity of your environment increases, you may find yourself devoting significant time to rolling your own enterprise IaC backend features.&lt;/p&gt;
&lt;p&gt;That’s why we built &lt;a href="https://www.pulumi.com/product/pulumi-cloud/"&gt;Pulumi Cloud&lt;/a&gt;—to help you avoid building and maintaining these capabilities from scratch while ensuring you can automate, secure, and manage your infrastructure at scale. Pulumi Cloud provides enterprise capabilities that make it easier to build modern infrastructure platforms. Companies receive increasing value from Pulumi Cloud as their organization and their infrastructure platforms grow in size and complexity.&lt;/p&gt;
&lt;p&gt;As companies expand or &lt;a href="https://www.pulumi.com/what-is/what-is-platform-engineering/"&gt;platform engineering&lt;/a&gt; mandates become more expansive, challenges arise around collaboration, security, governance, and scaling. Some questions that need answering include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How do teams collaborate?&lt;/li&gt;
&lt;li&gt;How do you securely manage infrastructure state?&lt;/li&gt;
&lt;li&gt;How do you enable self-service infrastructure?&lt;/li&gt;
&lt;li&gt;How do you adhere to IT security standards?&lt;/li&gt;
&lt;li&gt;How do you enforce governance policies?&lt;/li&gt;
&lt;li&gt;How do you protect sensitive data?&lt;/li&gt;
&lt;li&gt;How do you enforce least privileged access across the organization?&lt;/li&gt;
&lt;li&gt;How do you maintain uptime or get support for your architecture?&lt;/li&gt;
&lt;li&gt;How do you manage the cost and complexity of multi-cloud environments?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If some of these questions apply to you or your team, learn more about Pulumi Cloud below to understand when it makes sense to transition to a &lt;a href="https://www.pulumi.com/pricing/"&gt;paid Pulumi offering&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="what-drives-the-most-value-in-pulumi-cloud"&gt;What drives the most value in Pulumi Cloud?&lt;/h2&gt;
&lt;p&gt;The most frequent business values that our existing customers experience with Pulumi Cloud relate to speed, scale, security, and savings.&lt;/p&gt;
&lt;h3 id="speed"&gt;Speed&lt;/h3&gt;
&lt;p&gt;There are speed benefits that customers typically experience across three areas: the infrastructure platform, developer productivity, and operations. Pulumi Cloud simplifies building and running complex infrastructure automation workflows through the Automation API. It also makes it easy to componentize best practices that can be easily shared and distributed through a centralized repository.&lt;/p&gt;
&lt;p&gt;Pulumi Cloud streamlines the software delivery pipeline with &lt;a href="https://www.pulumi.com/product/pulumi-deployments/"&gt;Pulumi Deployments&lt;/a&gt; and a wide range of 3rd party &lt;a href="https://www.pulumi.com/docs/iac/using-pulumi/continuous-delivery/"&gt;CI/CD integrations&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Pulumi Cloud provides &lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt;, offering search, analytics, and AI-driven insights over your infrastructure. With Insights, you can instantly search for critical information - such as finding MySQL databases on end-of-life versions across all your cloud assets, reducing the operational time it takes to find needles in haystacks.&lt;/p&gt;
&lt;h3 id="scale"&gt;Scale&lt;/h3&gt;
&lt;p&gt;Part of building an infrastructure platform is so your organization can scale and make it easy to onboard new developers. Pulumi Cloud integrates seamlessly with various &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/oidc/"&gt;identity providers&lt;/a&gt; like Azure ActiveDirectory, Okta, G Suite, or any &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/saml/"&gt;SAML/SSO provider&lt;/a&gt;, offering deep support for role-based access control (RBAC) and SCIM for automatic synchronization and revocation of access based on identity provider groups. Audit logs keep track of developer activity within an organization, recording what actions were taken, when, and by whom.&lt;/p&gt;
&lt;p&gt;Pulumi Cloud also makes it easy to &lt;a href="https://www.pulumi.com/product/internal-developer-platforms/"&gt;build developer portals&lt;/a&gt; for developer self-service. Organization Templates can provide a centralized repository for cloud components, best practices and configurations. The New Project Wizard also provides a gallery interface to pick a template and easily walk through configuration and deployment of the infrastructure.&lt;/p&gt;
&lt;h3 id="security"&gt;Security&lt;/h3&gt;
&lt;p&gt;Another reason your organization is investing in an infrastructure platform is so that security and compliance can be automated as infrastructure is self-serviced. Your platform must prevent infrastructure deployments that violate security, reliability, cost, or compliance policies. Pulumi Cloud, through Pulumi CrossGuard, provides out-of-the-box support for common security and compliance policies, ensuring PCIDSS, ISO27001, SOC2, and CIS compliance for cloud applications and infrastructure.&lt;/p&gt;
&lt;p&gt;For applications being built across the organization, securing sensitive information like database passwords, cloud credentials, and API keys is paramount. Secrets can inadvertently end up in insecurely stored state files, leading to potential breaches. Pulumi Cloud, however, encrypts all data in transit and at rest, utilizing hardware security module (HSM) based encryption. Read the &lt;a href="https://www.pulumi.com/security/pulumi-cloud-security-whitepaper"&gt;Pulumi Cloud Security Whitepaper&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Pulumi Cloud further enhances security with Pulumi ESC, a centralized &lt;a href="https://www.pulumi.com/what-is/what-is-secrets-management/"&gt;secrets management&lt;/a&gt; and orchestration service. This service pulls and syncs secrets from various stores like HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, and 1Password, making it easy to adopt dynamic, short-lived secrets on demand. Secrets can be accessed via CLI, API, Kubernetes operator, the Pulumi Cloud UI, and in-code with TypeScript/JavaScript, Python, and Go SDKs. Pulumi ESC leverages the same identity, RBAC, Teams, SAML/SCIM, OIDC, and scoped access tokens used by Pulumi IaC, ensuring that secrets management complies with enterprise security policies.&lt;/p&gt;
&lt;h3 id="savings"&gt;Savings&lt;/h3&gt;
&lt;p&gt;Building a platform and managing cloud infrastructure demands considerable time and energy. As discussed above, &lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt; X-Rays your entire cloud footprint, so you can observe, plan, and drive changes across your infrastructure. With this total visibility, Pulumi Insights helps you reduce waste by showing you usage information and identifying potentially stale infrastructure, which can lead to substantial cost savings.&lt;/p&gt;
&lt;p&gt;You can also have a conversation with &lt;a href="https://www.pulumi.com/product/copilot/"&gt;Pulumi Copilot&lt;/a&gt; about your infrastructure in natural language and get answers to operational questions that would take hours to piece together from other sources.&lt;/p&gt;
&lt;h2 id="why-not-build-your-own-enterprise-features-on-top-of-pulumi-iac-open-source"&gt;Why not build your own enterprise features on top of Pulumi IaC open source?&lt;/h2&gt;
&lt;p&gt;Build vs buy is a question of opportunity cost. Should you and your team build and operate your own enterprise backend service that engineers at Pulumi have already built to handle the needs and scale of the world’s biggest companies? Or is their time better spent focused on building a modern infrastructure platform that will increase development velocity across the company and drive business growth?&lt;/p&gt;
&lt;h3 id="maintenance-costs"&gt;Maintenance costs&lt;/h3&gt;
&lt;p&gt;When you build and operate your own enterprise backend, you’ll need to dedicate one full-time engineer for every team of ten - that’s nearly 10% of your engineering expense. Running a backend requires maintenance, updates, and troubleshooting. Outages and incidents can lead to significant financial losses. Pulumi Cloud, as a fully managed service, frees up your team’s time from the operational and maintenance burdens of managing an IaC backend.&lt;/p&gt;
&lt;h3 id="operational-reliability-and-availability"&gt;Operational reliability and availability&lt;/h3&gt;
&lt;p&gt;One of the primary functions of the enterprise backend is managing state. State management involves managing concurrency controls, preventing state corruption, ensuring backup and recovery, maintaining high availability of the state service, and providing consistent visibility across all managed resources; this is easy to get wrong. Manual human intervention is frequently required to recover and repair state files, a process that is time-consuming, can create or prolong outages, and carries significant risk.&lt;/p&gt;
&lt;h3 id="security-and-compliance"&gt;Security and compliance&lt;/h3&gt;
&lt;p&gt;Building your own enterprise backend also requires you to design and manage the service to adhere to numerous IT security standards, including SOC 1/SSAE 16/ISAE 3402, SOC 2, SOC 3, FISMA, FedRAMP, DOD SRG Levels 2 and 4, PCI DSS Level 1, EU Model Clauses, ISO 9001 / ISO 27001 / ISO 27017 / ISO 27018, ITAR, IRAP, FIPS 140-2, MLPS Level 3, and MTCS. This involves a manual assessment and validation process for each standard, which can be time-consuming and complex.&lt;/p&gt;
&lt;h3 id="customer-support"&gt;Customer support&lt;/h3&gt;
&lt;p&gt;You will also be giving up 12x5 or 24x7 customer support, which helps ensure your organization receives immediate assistance with any architectural, cloud-related, or Pulumi best-practices issues. Pulumi also has an experienced group of Solutions Architects and Customer Success Architects that have experience scaling &lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;infrastructure as code&lt;/a&gt; and building modern infrastructure platforms.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Pulumi Cloud is an enterprise-ready solution that comes with less risk and less maintenance costs than the DIY approach. With Pulumi Cloud, you get a fully managed service that automates deployments, ensures compliance, and offers comprehensive security features out-of-the-box. You’ll get a clear understanding of the product roadmap as well as talented engineers supporting your architecture and use cases.&lt;/p&gt;
&lt;p&gt;Pulumi Cloud gives you the platform to automate, secure, and manage your modern infrastructure platform so your company can choose to focus on innovation and growth.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Try Pulumi Cloud for free&lt;/a&gt; and see how it can accelerate your infrastructure automation. Sign up today and start building with Pulumi Cloud.&lt;/p&gt;</description><author>Aaron Kao</author><category>infrastructure-as-code</category><category>platform-engineering</category><category>pulumi-cloud</category></item><item><title>Infrastructure as Code: The Hidden Cost of Doing It Yourself</title><link>https://www.pulumi.com/blog/hidden-costs-of-infrastructure-management/</link><pubDate>Tue, 10 Dec 2024 09:00:00 -0800</pubDate><guid>https://www.pulumi.com/blog/hidden-costs-of-infrastructure-management/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/hidden-costs-of-infrastructure-management/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Note: This post discusses Pulumi Copilot, which Pulumi Neo has replaced. &lt;a href="https://www.pulumi.com/docs/ai/"&gt;Learn about Neo →&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;Infrastructure as Code (IaC)&lt;/a&gt; has revolutionized how cloud resources are managed, allowing for more efficient, scalable, and repeatable deployments. We designed &lt;a href="https://www.pulumi.com/product/infrastructure-as-code/"&gt;Pulumi IaC&lt;/a&gt; to let you program cloud infrastructure using familiar programming languages like TypeScript, JavaScript, Python, Go, .NET, Java, and YAML. This approach not only simplifies the process but also integrates seamlessly with existing development tools and ecosystems (e.g., IDEs, standard unit test frameworks, integration test). You can define infrastructure with code, often in just one line, for serverless, Kubernetes, AI/ML, databases, and more. You can also preview changes before deploying unlike many other IaC solutions. Pulumi IaC is fully open source with a &lt;a href="https://github.com/orgs/pulumi/projects/44/"&gt;public roadmap&lt;/a&gt;. We value working with the community to shape the product through feedback and contributions.&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;
Since this post was published, Pulumi has added first-class support for HashiCorp
Configuration Language (HCL). You can now write Pulumi programs in HCL directly, alongside
general-purpose languages like TypeScript, Python, Go, and C#. To see how it works, see
&lt;a href="https://www.pulumi.com/docs/iac/languages-sdks/hcl/"&gt;Pulumi HCL&lt;/a&gt;.
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="what-is-pulumi-cloud"&gt;What is Pulumi Cloud?&lt;/h2&gt;
&lt;p&gt;Infrastructure as Code tools like Pulumi require systems for coordinating deployments, which include concurrency control, state management, and security. For the purposes of this post, let&amp;rsquo;s refer to these systems as IaC backends. There are several options for managing these backends: you can either handle them yourself, which we&amp;rsquo;ll call DIY, or you can leverage &lt;a href="https://www.pulumi.com/product/pulumi-cloud/"&gt;Pulumi Cloud&lt;/a&gt;, available as a SaaS or self-hosted solution. With Pulumi Cloud, you gain access to a comprehensive infrastructure management platform designed to handle everything running in the cloud. This platform automates your IaC deployments, centralizes &lt;a href="https://www.pulumi.com/what-is/what-is-secrets-management/"&gt;secrets management&lt;/a&gt; and orchestration to manage secrets sprawl effectively, and employs AI to oversee infrastructure assets and ensure compliance. On the other hand, with a DIY approach, you have the flexibility to build everything Pulumi Cloud offers or opt for a more minimalistic setup tailored to your organization&amp;rsquo;s specific needs. Both options are well-supported by Pulumi, but there are distinct advantages to choosing Pulumi Cloud over the DIY method, which we&amp;rsquo;ll explore further.&lt;/p&gt;
&lt;h2 id="costs-and-complexities-of-diy-backends"&gt;Costs and Complexities of DIY Backends&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/I5lKzCtIj18?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;Building and maintaining your own Infrastructure as Code backend involves a significant engineering and operational commitment. On the engineering front, you face security and compliance challenges, as well as the need to develop features that ensure enterprise readiness. Operationally, the backend must be highly available and reliable, and it should facilitate easy onboarding for the rest of the organization when the time comes. Beyond these immediate concerns, there are also hidden personnel costs associated with running your own backend. Let&amp;rsquo;s break down some of those hidden costs.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;&lt;strong&gt;Materialize&lt;/strong&gt; reduced costs and accelerated time to market by making developer onboarding 75% faster.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Pulumi lets us manage multi-cluster Kubernetes infrastructure efficiently, all in one stack. It has hugely benefited productivity and our service&amp;rsquo;s reliability. Without Pulumi, we know that scaling and maintaining Materialize would be much harder for the team.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;–— Paul Hemberger, Engineering Manager for Materialize’s cloud team&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/case-studies/materialize/"&gt;Learn more&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="operational-excellence"&gt;Operational Excellence&lt;/h3&gt;
&lt;p&gt;One of the primary functions of IaC backends is managing state. State management involves managing concurrency controls, preventing state corruption, ensuring backup and recovery, maintaining high availability of the state service, and providing consistent visibility across all managed resources; this is easy to get wrong. For instance, an incorrect Git merge of your state can result in outages, as evidenced by &lt;a href="https://www.youtube.com/watch?v=ix0Tw8uinWs"&gt;Spotify speaking publicly&lt;/a&gt; about accidentally deleting two-thirds of their production Kubernetes clusters due to a faulty state merge.&lt;/p&gt;
&lt;p&gt;Pulumi Cloud offers total visibility into changes within your organization, allowing you to track who is deploying what, when, and where, down to the individual cloud infrastructure properties being changed and the source commits triggering them. If issues arise and you need to revert to a prior known state, Pulumi Cloud&amp;rsquo;s transactional state checkpointing protocol ensures automatic recovery from failures, and failures are common with transient cloud and networking issues. In contrast, DIY backends require manual human intervention to recover and repair state files, a process that is time-consuming, extends outages, and carries significant risk. Pulumi Cloud also automatically backs up and replicates your state checkpoints, facilitating easy recovery for audits or rollbacks, potentially preventing outages or meeting audit standards.&lt;/p&gt;
&lt;p&gt;Managing your infrastructure with IaC demands considerable time and energy. Pulumi Cloud provides &lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt;, offering search, analytics, and AI-driven insights over your infrastructure. If you&amp;rsquo;re using a DIY backend, you&amp;rsquo;ll need to build your own search clusters and grep systems. With Insights, you can instantly search for critical information - such as finding MySQL databases on end-of-life versions across all your cloud assets. You can also have a conversation with &lt;a href="https://www.pulumi.com/product/copilot/"&gt;Pulumi Copilot&lt;/a&gt; about your infrastructure in plain English and get
answers to operational questions that would take hours to piece together from other sources.&lt;/p&gt;
&lt;p&gt;&lt;img src="copilot.png" alt="Pulumi Copilot example prompt"&gt;&lt;/p&gt;
&lt;p&gt;With this total visibility, Pulumi Insights helps you reduce waste by showing you usage information and identifying potentially stale infrastructure, which can lead to substantial cost savings.&lt;/p&gt;
&lt;p&gt;When you build and operate your own IaC backend, you&amp;rsquo;ll need to dedicate one full-time engineer for every team of ten - that&amp;rsquo;s nearly 10% of your engineering expense. Pulumi Cloud, as a fully managed service, frees up your team&amp;rsquo;s time from the operational and maintenance burdens of managing an IaC backend.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;&lt;strong&gt;Unity&lt;/strong&gt; reduced deployment times by 80%, from weeks to hours, significantly improving their time to market.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Terraform relies on HCL and lacks support for concepts like classes, objects and inheritance. An equivalent deployment would take more lines of code while yielding IaC that is less reusable.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/case-studies/unity/"&gt;Learn more&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="security-and-compliance"&gt;Security and Compliance&lt;/h3&gt;
&lt;p&gt;IaC backends are mission-critical components that require robust security measures to protect the backend service, cloud assets, and applications running on the infrastructure.&lt;/p&gt;
&lt;p&gt;&lt;img src="security-layers.png" alt="3 layers of security"&gt;&lt;/p&gt;
&lt;p&gt;At the backend service layer, you must design and manage the service to adhere to numerous IT security standards, including SOC 1/SSAE 16/ISAE 3402, SOC 2, SOC 3, FISMA, FedRAMP, DOD SRG Levels 2 and 4, PCI DSS Level 1, EU Model Clauses, ISO 9001 / ISO 27001 / ISO 27017 / ISO 27018, ITAR, IRAP, FIPS 140-2, MLPS Level 3, and MTCS. This involves a manual assessment and validation process for each standard, which can be time-consuming and complex.&lt;/p&gt;
&lt;p&gt;Pulumi, as an Amazon Web Services Advanced Partner, undergoes a thorough review and certification of its security and compliance practices by the AWS team. Pulumi Cloud operates on AWS infrastructure, which is designed and managed in alignment with security best practices and all the aforementioned IT security standards. This infrastructure does not require or have access to personally identifiable information (PII), making it suitable for managing applications that require HIPAA and ISO 27018 compliance. Pulumi also conducts annual penetration testing of Pulumi Cloud and maintains active SOC 2 Type II compliance.&lt;/p&gt;
&lt;p&gt;Access control at the backend service layer is crucial for enforcing least privilege access. Pulumi Cloud integrates seamlessly with various identity providers like Azure ActiveDirectory, Okta, G Suite, or any SAML/SSO provider, offering deep support for role-based access control (RBAC) and SCIM for automatic synchronization and revocation of access based on identity provider groups. This fine-grained control over state access is a significant advantage over DIY backends, where all access control mechanisms would need to be built from scratch.
Audit logs play a vital role in tracking user activity within an organization, recording what actions were taken, when, and by whom. Pulumi&amp;rsquo;s audit logs are immutable, capturing the UNIX timestamp of events, the user who invoked the action, the event itself, and the source IP of the call. This level of auditing ensures that the activities of organization members are attributable, enhancing security and compliance.&lt;/p&gt;
&lt;p&gt;At the cloud asset layer, you and your team need to prevent infrastructure deployments that violate policies related to security, reliability, cost, or compliance. Pulumi Cloud, through &lt;a href="https://www.pulumi.com/crossguard/"&gt;Pulumi CrossGuard&lt;/a&gt;, provides out-of-the-box support for common security and compliance policies, ensuring PCIDSS, ISO27001, SOC2, and CIS compliance for cloud applications and infrastructure. Such organization-wide enforcement and specific policy support are not readily available with DIY backends.&lt;/p&gt;
&lt;p&gt;At the application layer, securing sensitive information like database passwords, cloud credentials, and API keys is paramount. Secrets can inadvertently end up in insecurely stored state files, leading to potential breaches, as highlighted by a &lt;a href="https://sysdig.com/blog/cloud-breach-terraform-data-theft/"&gt;Sysdig article&lt;/a&gt; where an attacker exploited a manually managed state file to gain control over an entire AWS account. Pulumi Cloud, however, encrypts all data in transit and at rest, utilizing hardware security module (HSM) based encryption. It also avoids capturing cloud credentials, instead relying on client-side authentication, as detailed in the &lt;a href="https://www.pulumi.com/security/pulumi-cloud-security-whitepaper"&gt;Pulumi Cloud Security Whitepaper&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Pulumi Cloud further enhances security with &lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Pulumi ESC&lt;/a&gt;, a centralized secrets management and orchestration service. This service allows for pulling and syncing secrets from various stores like HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, and 1Password, making it easy to adopt dynamic, short-lived secrets on demand. Pulumi ESC leverages the same identity, RBAC, Teams, SAML/SCIM, OIDC, and scoped access tokens used for Pulumi IaC, ensuring that secrets management complies with enterprise security policies. Every access or change to secrets or configuration values is logged for auditing, providing a secure and auditable environment for you and your team to access secrets via CLI, API, Kubernetes operator, the Pulumi Cloud UI, and in-code with TypeScript/JavaScript, Python, and Go SDKs. With a DIY backend, you have to manage integration and access controls with individual secrets stores, with potential secrets sprawl and operational overhead.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;&lt;strong&gt;Tetrate&lt;/strong&gt; uses Pulumi ESC to stop secrets sprawl and attain compliance more efficiently.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“With Pulumi ESC, our developers get dynamic AWS and Azure credentials on-demand. Onboarding new developers is quick and secure, with no more manually filling in .env templates.”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;–— Liam White, Platform Lead&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Learn more&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="organizational-scaling"&gt;Organizational Scaling&lt;/h3&gt;
&lt;p&gt;As your organization grows, you need an IaC backend that scales with the organization and makes it easy to onboard new teams. Pulumi IaC brings your development, infrastructure and security teams together. Your infrastructure teams can define and manage common infrastructure across the organization, collaborate with security teams to establish security and compliance guardrails, and enable easy self-service of infrastructure through custom developer platforms or shared infrastructure libraries. Teams that prefer not to program can use YAML, while those who do can leverage Python, TypeScript, Golang, or C# to define organization-wide components.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;
&lt;p&gt;&lt;strong&gt;You might also like:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.pulumi.com/blog/pulumi-for-aws-automate-secure-manage/"&gt;
Pulumi for AWS: Automate, Secure, and Manage Your Cloud
&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.pulumi.com/blog/python-uv-toolchain/"&gt;
Pulumi &amp;#43; uv: Fast Python Package and Project Management
&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/"&gt;
DevSecOps Game-Changer: Security Automation That Delivers Business Results
&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;With Pulumi IaC, your teams can tackle the growing complexity of modern architectures using familiar software engineering principles. Programming languages offer loops, conditional logic, class inheritance, and object-oriented design, allowing your organization to craft more sophisticated infrastructure compared to legacy IaC tools.&lt;/p&gt;
&lt;p&gt;When you’re scaling your organization, you’ll need an IaC backend that makes team onboarding efficient. DIY backends often involve ad-hoc onboarding with bespoke identity solutions, requiring custom documentation and training to troubleshoot unique problems. This can slow down onboarding and reduce end-user productivity. Additionally, DIY backends place the internal support burden on your team, requiring them to assist users in navigating the system.&lt;/p&gt;
&lt;p&gt;In contrast, Pulumi Cloud offers standardized, well-documented capabilities and integrates seamlessly with identity systems, leading to efficient onboarding and increased productivity for new employees. Pulumi Cloud provides &lt;a href="https://support.pulumi.com/hc/en-us"&gt;12x5 or 24x7 support&lt;/a&gt;, ensuring your organization receives immediate assistance with any architectural, cloud-related, or Pulumi best-practices issues. Furthermore, Pulumi Cloud includes built-in RBAC, simplifying the onboarding and scaling of new users.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;&lt;strong&gt;BMW Group&lt;/strong&gt; used Pulumi to build a scalable and resilient hybrid cloud implementation that could handle more than eleven thousand developers.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“When we started to use Terraform to deploy our first cloud services with AWS, it didn’t scale quickly enough for our needs. With Pulumi we’re really speeding up development. We can use any language instead of some special language like HCL and by automating policies, we have compliant and secure systems from the beginning.”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;–— Jan-Peter Alten, DevOps Engineer&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/case-studies/bmw/"&gt;Learn more&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;When you choose between managing your own backend and using Pulumi Cloud, you need to carefully consider all the costs. You&amp;rsquo;ll face substantial operational costs with DIY backends, requiring dedicated engineering resources for maintenance, updates, and troubleshooting. Outages and incidents can lead to significant financial losses, as demonstrated by real-world examples where improper state management resulted in major service disruptions. The cost of setup and maintenance for a DIY backend is not just financial but also involves the time and effort of your team, which could otherwise be focused on core business activities.&lt;/p&gt;
&lt;p&gt;Moreover, the cost of an engineer dedicated to managing the backend can be nearly 10% of your engineering budget, a significant investment for any organization. Figuring it out on your own adds to the complexity and potential for errors, increasing the risk of costly mistakes. Invisible excess waste in terms of unused or underutilized infrastructure can also accumulate, leading to unnecessary expenses.&lt;/p&gt;
&lt;p&gt;When it comes to scaling, the cost of onboarding new teams or users onto a DIY system can be high due to the need for custom documentation, training, and support. Security is another critical area where the costs can escalate, with the need to comply with numerous IT security standards, manage access control, and ensure robust secrets management.&lt;/p&gt;
&lt;p&gt;&lt;img src="backend-comparison.png" alt="Pulumi Cloud vs DIY IaC backend"&gt;&lt;/p&gt;
&lt;p&gt;We built Pulumi Cloud as a fully managed service to address these concerns by providing a platform that automates deployments, ensures compliance, and offers comprehensive security features out-of-the-box. You’ll reduce your operational burden, minimize your risk of outages, and make scaling and onboarding easier, ultimately leading to cost savings and increased productivity. By choosing Pulumi Cloud, your organization can focus on innovation and growth rather than the intricacies of IaC backend management. You get to optimize your infrastructure without the overhead of running your own DIY solution.&lt;/p&gt;
&lt;h2 id="next-steps"&gt;Next Steps&lt;/h2&gt;
&lt;p&gt;Each unique variable in your environment –— cloud providers, languages, team structure, business objective, etc. –— makes realizing the full benefits of Pulumi Cloud different for each organization.&lt;/p&gt;
&lt;p&gt;Our newly launched program called Immersion Days, is a customizable, half-day event designed to expand Pulumi’s impact across your organization.&lt;/p&gt;
&lt;p&gt;The program has 3 key components:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Strategic Leadership Engagement:&lt;/strong&gt; Address key business challenges like security posture, cost optimization, and developer productivity.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Architectural Review:&lt;/strong&gt; Evaluate and refine platform engineering projects to enhance efficiency and scalability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hands-On Workshops:&lt;/strong&gt; Equip your engineering teams with practical Pulumi skills through interactive technical sessions.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This program will help strengthen executive buy-in for your infrastructure initiatives while showcasing Pulumi&amp;rsquo;s value to your peer engineering teams.&lt;/p&gt;
&lt;p&gt;If this sounds valuable, let’s discuss tailoring the agenda to fit your organization’s priorities.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://info.pulumi.com/pulumi-platform-engineering-immersion-days"&gt;Register now&lt;/a&gt; or &lt;a href="https://www.pulumi.com/contact"&gt;contact your Pulumi sales team&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Meta image credit: &lt;a href="https://www.eso.org/public/images/eso0942a/"&gt;ESO/L. Calçada&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</description><author>Aaron Kao</author><category>infrastructure-as-code</category></item><item><title>Pulumi for AWS: Automate, Secure, and Manage Your Cloud</title><link>https://www.pulumi.com/blog/pulumi-for-aws-automate-secure-manage/</link><pubDate>Mon, 02 Dec 2024 09:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/pulumi-for-aws-automate-secure-manage/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumi-for-aws-automate-secure-manage/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Note: This post discusses Pulumi Copilot, which Pulumi Neo has replaced. &lt;a href="https://www.pulumi.com/docs/ai/"&gt;Learn about Neo →&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Pulumi is excited to be at &lt;a href="https://www.pulumi.com/reinvent/"&gt;AWS re:Invent&lt;/a&gt; this week, where we’re showcasing our broad and deep support for AWS across all our products. From automating infrastructure with Pulumi IaC to securing secrets with Pulumi ESC to managing cloud assets with Pulumi Insights, Pulumi makes AWS a competitive advantage. Whether you’re a developer, DevOps pro, or platform engineer, Pulumi delivers the tools you need to build and manage modern cloud applications with ease.&lt;/p&gt;
&lt;p&gt;Stop by the Pulumi re:Invent booth #370 this week to chat with experts on the Pulumi team. If you can’t make it to re:Invent, join our workshop, &lt;a href="https://www.pulumi.com/events/aws-immersion-day-platform-engineering/"&gt;&lt;em&gt;Accelerating Platform Engineering with Pulumi on AWS&lt;/em&gt;&lt;/a&gt;, on December 11, 2024, to see how Pulumi can enhance your cloud operations on AWS.&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;
Since this post was published, Pulumi has added first-class support for HashiCorp
Configuration Language (HCL). You can now write Pulumi programs in HCL directly, alongside
general-purpose languages like TypeScript, Python, Go, and C#. To see how it works, see
&lt;a href="https://www.pulumi.com/docs/iac/languages-sdks/hcl/"&gt;Pulumi HCL&lt;/a&gt;.
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="why-pulumi-for-aws"&gt;Why Pulumi for AWS?&lt;/h2&gt;
&lt;p&gt;Pulumi empowers your organization to automate AWS cloud infrastructure through code, tame secrets sprawl through centralized secrets management, and manage cloud assets and compliance with the help of AI. Pulumi encourages infrastructure, platform, development, DevOps, and security teams to collaborate and accelerates time to market with greater control and minimized risk.&lt;/p&gt;
&lt;p&gt;Pulumi will speed up your deployments and time to value, providing you with an approach to open source and community that gives stability and choice. It will also increase your productivity and velocity through better tooling. Lastly, Pulumi uses software engineering to tackle the scale of an infinite combination of cloud architectures. Read more about why &lt;a href="https://www.pulumi.com/blog/why-switch-to-pulumi/"&gt;engineers and developers switch to Pulumi.&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="pulumi-for-aws-over-the-years"&gt;Pulumi for AWS Over the Years&lt;/h2&gt;
&lt;p&gt;Pulumi was founded back in 2017 to tackle the mounting challenges of modern cloud applications, which have grown increasingly intricate, spanning multiple environments and relying on numerous cloud resources and SaaS services. This complexity creates significant challenges for managing infrastructure. Legacy tools are designed for “two virtual machines with a database” and not thousands or millions of resources across many clouds and accounts. Teams waste time wrestling with excessive YAML configurations, resorting to copy-paste solutions, or using limited domain-specific languages (DSLs) that fail to scale effectively.&lt;/p&gt;
&lt;p&gt;The fragmentation between development, infrastructure, and security teams only compounds these challenges. Pulumi&amp;rsquo;s founding vision addresses these pain points by enabling teams to build and manage cloud infrastructure through &lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;infrastructure as code&lt;/a&gt; using familiar programming languages and tools. &lt;a href="https://www.pulumi.com/product/infrastructure-as-code/"&gt;Pulumi Infrastructure as Code&lt;/a&gt; (IaC) was launched with strong support of the AWS cloud. We wanted to be the best way for you to manage and scale your AWS infrastructure through code. Over the years, we launched many AWS-specific features to simplify how to manage AWS infrastructure at scale.&lt;/p&gt;
&lt;h3 id="well-architected-aws-best-practices-as-a-component"&gt;Well-Architected AWS Best Practices as a Component&lt;/h3&gt;
&lt;p&gt;One of the first innovations made for AWS was &lt;a href="https://www.pulumi.com/docs/iac/clouds/aws/guides/"&gt;Pulumi Crosswalk for AWS&lt;/a&gt;, a collection of libraries that automatically use well-architected best practices to make common infrastructure-as-code tasks in AWS easier and more secure. Released in 2019, Crosswalk for AWS supports “day one” tasks, such as creating your initial container-based workloads, using Amazon Elastic Container Service (ECS) – including Fargate or Kubernetes (EKS) – and creating serverless workloads using Amazon API Gateway and AWS Lambda. Secure and cost-conscious defaults are chosen so that simple programs automatically use best practices for the underlying infrastructure, enabling better productivity with confidence.&lt;/p&gt;
&lt;p&gt;Crosswalk for AWS also supports “day two and beyond” tasks, such as scaling your workload, securing and integrating it with your existing infrastructure, and going to production in multiple complex environments. This includes Amazon Virtual Private Cloud (VPC) for network isolation, AWS Auto Scaling for dynamic scaling, and AWS Identity and Access Management (IAM) for securing your infrastructure.&lt;/p&gt;
&lt;p&gt;Earlier this month at KubeCon 2024, we launched the Pulumi Elastic Kubernetes Service (EKS) Provider v3.0.0, which is one of the Crosswalk libraries that makes Kubernetes management on AWS even easier. This release simplifies multi-cluster deployments, improves resource handling, and offers enhanced compatibility with the latest AWS EKS features.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/eks-v3-release/"&gt;Read more about the Pulumi EKS Provider 3.0.0&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="aws-policies-as-code"&gt;AWS Policies as Code&lt;/h3&gt;
&lt;p&gt;We released &lt;a href="https://www.pulumi.com/crossguard/"&gt;Pulumi CrossGuard&lt;/a&gt; to enforce your organization&amp;rsquo;s cloud governance — security, compliance, cost controls, and more. This enables Policy as Code within your organization so that you can define guardrails for your infrastructure, ensuring engineers are following best practices and putting security first. CrossGuard helps your organization prevent mistakes before they occur and respond rapidly to any incidents.&lt;/p&gt;
&lt;h3 id="building-controls-planes"&gt;Building Controls Planes&lt;/h3&gt;
&lt;p&gt;Many AWS customers build &lt;a href="https://www.pulumi.com/product/internal-developer-platforms/"&gt;internal developer platforms&lt;/a&gt; (IDP) for developers to self-service infrastructure. In 2020, &lt;a href="https://www.pulumi.com/automation/"&gt;Pulumi Automation API&lt;/a&gt; was created to help automate infrastructure for these IDP control planes. Automation API exposes the full power of infrastructure as code through a programmatic interface, instead of through CLI commands, and it lets you use the Pulumi engine as an SDK, enabling you to create software that can create, update, configure, and destroy infrastructure dynamically. This enables you to use Pulumi to build IDPs that are custom-tailored to your team, organization, or customers.&lt;/p&gt;
&lt;h3 id="aws-cdk-for-pulumi"&gt;AWS CDK for Pulumi&lt;/h3&gt;
&lt;p&gt;In 2022, Pulumi brought the ability to use AWS Cloud Development Kit (CDK) constructs from within a Pulumi deployment. For users already using AWS CDK, this provides Pulumi as a new option for orchestrating deployments in place of CloudFormation, offering improved deployment speed and integration with the full set of features of the Pulumi Platform. Even better, you can also now combine AWS CDK and Pulumi resources in a single Pulumi infrastructure as code project - passing outputs from Pulumi resources into AWS CDK constructs, and outputs from AWS CDK constructs into Pulumi resources.&lt;/p&gt;
&lt;p&gt;AWS Cloud Development Kit (CDK) on Pulumi is now generally available. This powerful integration includes full support for CDK features like assets, custom resources, aspects, and context values/methods. It provides access to the full ecosystem of over 1,200 CDK Construct libraries, and it also supports all 180+ Pulumi providers, allowing for CDK applications to include resources outside of AWS.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/aws-cdk-on-pulumi-1.0/"&gt;Read more about AWS CDK on Pulumi&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="cloud-control-api"&gt;Cloud Control API&lt;/h3&gt;
&lt;p&gt;In 2021, AWS launched Cloud Control API as a standard set of APIs to Create, Read, Update, Delete, and List (CRUDL) resources across hundreds of AWS Services. Pulumi supported that launch with a native provider called the Pulumi Cloud Control Provider, formerly known as AWS Native. The provider is now generally available, enabling day 1 support for new AWS resources, seamless compatibility with Pulumi IaC projects that currently use the Pulumi AWS provider, and extended support for third-party resources.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-aws-cloudcontrol-provider/"&gt;Read more about the Pulumi AWS Cloud Control Provider&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="beyond-pulumi-iac"&gt;Beyond Pulumi IaC&lt;/h2&gt;
&lt;p&gt;Over the last few years, our customers have shared a clear message: IaC alone is insufficient. The complexities of modern cloud environments demand more than just IaC to manage cloud resources, improve security, and ensure compliance. In response, Pulumi&amp;rsquo;s offerings have expanded into a comprehensive suite of tools that go beyond IaC.&lt;/p&gt;
&lt;p&gt;&lt;img src="platform.png" alt="Pulumi platform diagram"&gt;&lt;/p&gt;
&lt;h3 id="pulumi-insights-intelligent-cloud-management"&gt;Pulumi Insights: Intelligent Cloud Management&lt;/h3&gt;
&lt;p&gt;The complexities of modern cloud environments create significant challenges in making sense of the millions of resources and resource updates per month, across hundreds of clouds, regions, and accounts. Identifying cost saving opportunities is difficult amidst soaring cloud expenditures, and maintaining compliance and security is mission critical because errors can cause catastrophic damage.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt; empowers organizations to tackle cloud complexity by delivering visibility, actionable insights, and AI-assisted optimization for their infrastructure. With Pulumi Insights, companies can scan and sync their entire AWS resource inventory – including resources not managed with Pulumi IaC – ensuring a complete picture of their cloud assets. This Account Discovery capability is &lt;a href="https://www.pulumi.com/blog/insights-cloud-account-discovery/"&gt;now in public preview&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Compliance checks can also be run against standards such as PCI DSS, ISO 27001, and CIS benchmarks, helping maintain regulatory compliance and mitigate risks. The AI-powered &lt;a href="https://www.pulumi.com/product/copilot/"&gt;Pulumi Copilot&lt;/a&gt; provides an interactive assistant to gain visibility into a team&amp;rsquo;s activity, discover cost saving opportunities, get compliant, and debug cloud failures. Pulumi Insights enables companies to discover, understand, manage, and improve their cloud infrastructure on their journey towards intelligent infrastructure management.&lt;/p&gt;
&lt;h3 id="pulumi-esc-centralized-secrets-management"&gt;Pulumi ESC: Centralized Secrets Management&lt;/h3&gt;
&lt;p&gt;Cloud complexity creates significant challenges in managing sensitive credentials, API keys, and configurations across development, testing, and production environments. As organizations scale, they often face issues of secrets and configuration sprawl, duplication of secrets, and too many long-lived static secrets. None of the existing secrets management solutions adequately address these challenges, exposing enterprises to errors that can lead to security breaches, unintended exposure of sensitive data, and unauthorized access to critical resources.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Pulumi ESC&lt;/a&gt; addresses these challenges by offering seamless two-way integration – both pull and sync – with AWS Secrets Manager and other popular secrets stores, as well as the capability to consume secrets securely across any application, tool, and CI/CD platform. Developers gain easy, secure access to secrets via CLI, API, Kubernetes operators, and SDKs – eliminating the need for .env files and reducing the security risks associated with them. Additionally, Pulumi ESC can issue dynamic, short-lived AWS authentication tokens on demand via OpenID Connect (OIDC), reducing the risks that come with long-lived access tokens, while RBAC, versioning, and a detailed audit log let you trust (and prove) your secrets are secure.&lt;/p&gt;
&lt;h2 id="try-pulumi-cloud-today"&gt;Try Pulumi Cloud Today&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://github.com/orgs/pulumi/projects/44/views/1"&gt;Check out the Pulumi roadmap&lt;/a&gt; for upcoming features, let us know your feature requests by &lt;a href="https://github.com/pulumi/pulumi/issues"&gt;creating an issue on GitHub&lt;/a&gt;, connect with the &lt;a href="https://slack.pulumi.com/"&gt;Pulumi community on Slack&lt;/a&gt;, and if you haven’t yet, &lt;a href="https://app.pulumi.com/signup"&gt;sign-up for Pulumi Cloud&lt;/a&gt; to get access to our full suite of products – Pulumi IaC, Pulumi ESC, and Pulumi Insights – so you can automate, secure, and manage everything you run in the cloud.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Meta image credit: &lt;a href="https://www.eso.org/public/images/potw2229a/"&gt;ESO/M. Zamani&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</description><author>Aaron Kao</author><author>Gavin Johnson</author><category>aws</category><category>infrastructure-as-code</category></item><item><title>Why Switch to Pulumi for Infrastructure as Code?</title><link>https://www.pulumi.com/blog/why-switch-to-pulumi/</link><pubDate>Tue, 23 Jul 2024 19:47:50 -0700</pubDate><guid>https://www.pulumi.com/blog/why-switch-to-pulumi/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/why-switch-to-pulumi/index.png" /&gt;
&lt;p&gt;The cloud promised to revolutionize your business.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Faster innovation. Lower costs. Unlimited scalability.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;But for many companies, that promise remains frustratingly out of reach.
Instead of accelerating product development, infrastructure has
become a bottleneck. You and your team (DevOps, platform, or infrastructure engineering teams)
are bogged down by:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Clunky tools and manual processes&lt;/li&gt;
&lt;li&gt;Provisioning a simple test environment takes days&lt;/li&gt;
&lt;li&gt;Rolling out updates across regions takes weeks&lt;/li&gt;
&lt;li&gt;The combinations of modern cloud architectures seems infinite&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;
Since this post was published, Pulumi has added first-class support for HashiCorp
Configuration Language (HCL). You can now write Pulumi programs in HCL directly, alongside
general-purpose languages like TypeScript, Python, Go, and C#. To see how it works, see
&lt;a href="https://www.pulumi.com/docs/iac/languages-sdks/hcl/"&gt;Pulumi HCL&lt;/a&gt;.
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;You know there has to be a better way. A way to truly
harness the power of the cloud and turn it into your competitive
advantage.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;But how?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Enter Pulumi &amp;ndash; the open source infrastructure as code (IaC) platform
that gives 10x better scale, productivity, and time to value for thousands of companies worldwide.&lt;/p&gt;
&lt;p&gt;So why should you switch to Pulumi? How is it different from other
infrastructure as code tools? This post should answer all those
questions.&lt;/p&gt;
&lt;h2 id="what-is-pulumi"&gt;What is Pulumi?&lt;/h2&gt;
&lt;p&gt;Pulumi is an infrastructure as code platform that allows you to manage
and scale infrastructure, configurations, policies, and secrets with
programming languages. Pulumi facilitates clear collaboration across your
infrastructure, development, and security teams.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pulumi&amp;rsquo;s approach is better.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;10x Better.&lt;/strong&gt; Pulumi takes a unique and 10x better approach to
infrastructure as code by empowering you with the familiar
languages and tools you love for application development. While modern
programming languages have evolved to provide powerful features like AI
coding agents, Intellisense, linting tools, testing frameworks, and CICD
pipelines, infrastructure management has lagged behind, relying on rigid
scripting languages and error-prone manual processes. Pulumi bridges
this gap by allowing you to use industry-standard programming
languages to manage infrastructure with the same level of sophistication
and tooling you enjoy for application development. Pulumi embraces the
change and direction the industry is going, so you never fall
behind with your IaC tooling.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Powering the Next Wave.&lt;/strong&gt; Pulumi is at the forefront of the industry.
It helps you embrace the latest practices (e.g., Platform Engineering, GitOps) and
builds the latest technologies (e.g., AI agents like Pulumi Neo) into the core user
experience. It also helps you build and manage new technology
paradigms (e.g., AI workloads, LLMs, internal developer platforms).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Powerful Automations.&lt;/strong&gt; Another unique approach is that Pulumi makes it
easy to automate and scale modern cloud architectures. In the last
decade, the industry has moved from monolithic to microservices
architectures, which operate as distributed systems over shared
infrastructure platforms, to achieve greater resilience, team agility,
flexible scaling, and modular codebases. The cloud's programmability,
infinite elasticity, and on-demand nature made it easy to spin up
micro-sized services tailored to business demands, facilitated by
technologies like containers, Kubernetes, and serverless. Pulumi empowers you to apply
software engineering to manage infrastructure of this
modern and immense scale.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;AI-Powered.&lt;/strong&gt; Pulumi builds AI into the core infrastructure management
experience through Pulumi Neo, an agentic infrastructure engineer that
understands the real state of your cloud environments and works inside
your existing workflows. Neo runs multi-step tasks, generates previews
for approval, and opens pull requests for the changes it proposes, so
you stay in the loop while it does the legwork of finding and acting on
any resource in your infrastructure.&lt;/p&gt;
&lt;h3 id="ok-but-why-does-this-matter-enough-for-me-to-switch"&gt;Ok, but why does this matter enough for me to switch?&lt;/h3&gt;
&lt;p&gt;Only you can answer that question, but there are some compelling reasons
to adopt the platform trusted by hundreds of thousands of developers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Faster Time to Value.&lt;/strong&gt; Your company moved to the cloud to
increase innovation and reduce costs. However, getting infrastructure to
developers is a frequent bottleneck for you which can slow down
prototyping new products or shipping new features. Spinning up new
development or testing environments takes days and rolling out
production updates across many regions can take weeks. The existing
tools don&amp;rsquo;t allow you to set security and compliance guardrails and
enable easy self-service of infrastructure.&lt;br&gt;
&lt;br&gt;
&lt;em&gt;Pulumi will speed up your deployments and time to value.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Open Platform Commitment.&lt;/strong&gt; Some platforms, such as Terraform, have
altered their licensing and introduced uncertainty. They are no longer
true open source, and they tie their previously open source software to
their commercial services. The lack of an open source approach fragments
the community and introduces proprietary constraints to cloud
infrastructure.&lt;br&gt;
&lt;br&gt;
&lt;em&gt;Pulumi provides you with an approach to open source and community that
provides stability and choice.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Increased Productivity.&lt;/strong&gt; You expect your tools
and workflows to keep up with the industry: AI coding agents, Intellisense,
linting tools, testing frameworks, and CICD pipelines. But most of these
innovations are just for building applications and services and not for
infrastructure, configurations, policies, and secrets. Existing
infrastructure tools are fraught with bad UX, rigid scripting languages,
and error prone manual processes.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Pulumi will increase your productivity and velocity through better tooling.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Infinite Scale.&lt;/strong&gt; Modern cloud architectures are distributed systems
that are microservices that are dynamic and ephemeral in nature. The
number of infrastructure resource types and the configurable input
properties is staggering. You face the daunting task of how to
combine these resources to solve their unique problems. Without software
engineering, managing these modern distributed systems is fruitlessly
manual.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Pulumi uses software engineering to tackle the scale of infinite
combinations.&lt;/em&gt;&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Customers of Pulumi frequently experience 100% productivity increases, 99% time saved, and 10x acceleration when using Pulumi compared to what they were using before.&lt;/p&gt;
&lt;p&gt;&lt;img src="modern-benefits.png" alt="modern-benefits"&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="frequently-asked-questions---why-pulumi"&gt;Frequently Asked Questions - Why Pulumi?&lt;/h2&gt;
&lt;p&gt;Here are some frequently asked questions about why you should choose Pulumi based on the following use cases and alternatives:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#why-pulumi-by-use-case"&gt;Why Pulumi, by use case?&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#why-pulumi-for-internal-developer-platforms"&gt;Why Pulumi for Internal Developer Platforms?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#why-pulumi-for-ai-workloads"&gt;Why Pulumi for AI Workloads?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#why-is-pulumi-better-than-the-alternatives"&gt;Why is Pulumi better than the alternatives?&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#why-pulumi-vs-clickops"&gt;Why Pulumi vs. clickops?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#why-pulumi-vs-terraform"&gt;Why Pulumi vs. Terraform?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#why-pulumi-vs-aws-cloud-development-kit-cdk"&gt;Why Pulumi vs. AWS CDK?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#why-pulumi-vs-3rd-party-idp-providers-think-port-cortex-backstage"&gt;Why Pulumi vs. 3rd party IDP providers?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#how-can-i-switch-to-pulumi"&gt;How can I switch to Pulumi?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="why-pulumi-by-use-case"&gt;Why Pulumi, by use case?&lt;/h3&gt;
&lt;p&gt;There are many different use cases for why you might use Pulumi:
infrastructure CICD, modern applications, internal developer platforms,
AI/ML workloads, and infrastructure modernization. Below are more
details on two popular use cases.&lt;/p&gt;
&lt;h4 id="why-pulumi-for-internal-developer-platforms"&gt;Why Pulumi for Internal Developer Platforms?&lt;/h4&gt;
&lt;p&gt;You and your team may build internal developer platforms (IDPs) to
maximize the use of the cloud at scale across the company while
being secure and compliant, so your development teams can ship faster. There are a number of components/layers that are considered basic requirements when building an internal
developer platform. The layers are as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Developer Control Plane.&lt;/strong&gt; Curated experiences that empower
developers by meeting them at their level of expertise, whether
it's an abstracted developer portal, custom CLI, or shared IaC
templates.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Integration &amp;amp; Delivery.&lt;/strong&gt; Automations to version control, test,
trace, and deploy all infrastructure from resources, configurations,
environments, and secrets as well as orchestration automations to
manage provisioning workflows.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Monitoring &amp;amp; Logging.&lt;/strong&gt; Components to log, monitor, and observe
all infrastructure for greater operational control as well as
optimize against unnecessary costs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Security &amp;amp; Identity.&lt;/strong&gt; Security and compliance guardrails that
regulate every piece of infrastructure from policies to fine-grained
access controls to secrets.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Resources.&lt;/strong&gt; Providers that support modern cloud architectures
such as Kubernetes, containers, serverless, generative AI, machine
learning, data lakes, hybrid cloud/on-premises, and more.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This diagram illustrates the different layers of an internal developer
platform:&lt;/p&gt;
&lt;p&gt;&lt;img src="platform-req-diagram.png" alt="platform-requirements"&gt;&lt;/p&gt;
&lt;p&gt;Most solutions struggle to keep up with the requirements of each layer.
Many of the alternative solutions can&amp;rsquo;t handle the scale of resources you need to
manage, find it difficult to tie infrastructure automation directly
into your core business, have leaky secrets, and enforce compliance and
security incompletely.&lt;/p&gt;
&lt;p&gt;Pulumi is a platform engineering solution that enables you to
build a bridge to your developers and empower them to leverage the
cloud with security, scalability, repeatability, and consistency. It provides
the building blocks for each of the five layers.&lt;/p&gt;
&lt;p&gt;&lt;img src="platform-pulumi-diagram.png" alt="pulumi platform"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Developer Control Plane.&lt;/strong&gt; Pulumi is the simplest and most
intuitive way to manage cloud infrastructure because of its ability
to use standard programming languages, including YAML. This removes
the friction to the basic requirements of managing cloud
infrastructure well. Pulumi Automation API makes it simple to code
any user interface for a developer portal / CLI. Pulumi also
provides private templates that integrate with developer
portals like AWS Proton and Backstage.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Integration &amp;amp; Delivery.&lt;/strong&gt; Pulumi Automation API can embed IaC
programs directly in applications, resulting in 10x greater
management of resources per engineer. Pulumi can take advantage of
all existing testing frameworks supported by the selected
programming language.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Monitoring &amp;amp; Logging.&lt;/strong&gt; Pulumi Insights adds advanced search,
analytics, and AI to any cloud infrastructure, giving unique
insights into cloud usage and cost optimizations. Pulumi partners
with leading observability solutions making it easy to manage
monitoring and logging resources through IaC.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Security &amp;amp; Identity.&lt;/strong&gt; Pulumi CrossGuard provides policy as code with
auto-remediation. Pulumi ESC makes it easy to manage secrets and configurations
for every environment. Access to each cloud resource and secret can be granularly
controlled and audited.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Resources.&lt;/strong&gt; Pulumi supports modern cloud architectures such as
Kubernetes, containers, serverless, generative AI, machine learning,
data lakes, hybrid cloud/on-premises, and more. Pulumi makes it
simple to create components that abstract away the complexity of
managing thousands of resources across hundreds of distinct clouds.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Pulumi is purpose built to make all aspects of platform engineering
vastly simpler.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/product/internal-developer-platforms/"&gt;Read more &amp;raquo;&lt;/a&gt;&lt;/p&gt;
&lt;h4 id="why-pulumi-for-ai-workloads"&gt;Why Pulumi for AI Workloads?&lt;/h4&gt;
&lt;p&gt;Your company may be using AI to increase innovation and reduce costs.
AI gives them the ability to design richer and more intuitive interfaces
for their products and/or services to connect better with their
customers. The hardest part of AI is at times not the AI pieces but
the cloud infrastructure parts: how to provision and manage the
infrastructure that AI workloads run on (e.g., compute and networking)
and depend on (e.g., databases and storage).&lt;/p&gt;
&lt;p&gt;There are many layers to building and managing AI applications: model
training, data pipelines, backend services, frontend applications.&lt;/p&gt;
&lt;p&gt;&lt;img src="ai-stack.png" alt="ai stack"&gt;&lt;/p&gt;
&lt;p&gt;Pulumi provides an abstraction across all the different layers of the AI
stack (web framework, LLM, containers, databases, secrets, policies,
configurations, etc) as a simple Python library. Through this
abstraction you can manage stacks of AI infrastructure as code.&lt;/p&gt;
&lt;p&gt;&lt;img src="ai-dev.png" alt="ai abstraction"&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Pulumi makes it trivial to take local AI development to production in
the cloud.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/solutions/ai/"&gt;Read more &amp;raquo;&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="why-is-pulumi-better-than-the-alternatives"&gt;Why is Pulumi better than the alternatives?&lt;/h3&gt;
&lt;p&gt;There are many different tools you can use to manage infrastructure. However, Pulumi provides
you with a more productive authoring experience and more powerful automations that will allow you to
ship faster and manage the infinite scale of cloud infrastructure. Read on for how Pulumi compares to specific options: clickops, Terraform, CDK, and IDP services.&lt;/p&gt;
&lt;h4 id="why-pulumi-vs-clickops"&gt;Why Pulumi vs. clickops?&lt;/h4&gt;
&lt;p&gt;Manually provisioning and managing infrastructure for production via the
cloud console (i.e., clickops) is a bad idea. There isn&amp;rsquo;t repeatability
or consistency which leads to errors, and that can lead to downtime or
worse, security breaches. That is why infrastructure as code was
invented as a way to have a single source of truth for all
infrastructure with changes 100% automated.&lt;/p&gt;
&lt;p&gt;If you don&amp;rsquo;t believe this, just ask any cloud or devops
subreddit, Slack group, or Discord server.&lt;/p&gt;
&lt;h4 id="why-pulumi-vs-terraform"&gt;Why Pulumi vs. Terraform?&lt;/h4&gt;
&lt;p&gt;Pulumi and Terraform are both infrastructure as code (IaC) platforms,
however they have fundamental differences in how they approach your needs
of infrastructure management. First, here are the similarities.&lt;/p&gt;
&lt;p&gt;Both Pulumi and Terraform include the ability to create, deploy, and
manage infrastructure as code on any cloud. Both Terraform and Pulumi
follow a desired state infrastructure as code model, where the IaC code
represents the desired state of the infrastructure. The deployment
engine compares this desired state with the current state of the stack
and determines the necessary actions, such as creating, updating, or
deleting resources. Both Terraform and Pulumi support many cloud
providers, including AWS, Azure, and Google Cloud, plus other services
like CloudFlare, Digital Ocean, and more.&lt;/p&gt;
&lt;p&gt;However, beyond the basics of infrastructure as code there are
significant differences that affect productivity,
scalability, and collaboration.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Increased Productivity.&lt;/strong&gt; As discussed at the beginning,
Pulumi&amp;rsquo;s promise is to build in all the
latest advancements in both the developer and operations experience.
When you write Pulumi code, you now have AI coding agents that can pair program with you,
IDEs that have autocompletion and Intellisense squiggles, powerful libraries of low
level and abstract functions, testing frameworks, code review tools, automated release controls via CICD pipelines, and great software packaging tools. When it
comes to managing infrastructure with Pulumi, you also have Pulumi Neo, an agentic
infrastructure engineer that works inside your existing workflow: it proposes
changes, runs previews, responds to failures, and opens pull requests in tight
feedback loops, grounded in the real state of your infrastructure in Pulumi
Cloud. Because that infrastructure is defined in Python, TypeScript, Go, C#, or
Java rather than a bespoke configuration language, Neo can read, reason about,
test, and ship it the same way an AI coding agent already handles the rest of
your codebase. Terraform, by contrast, is defined in HCL, a domain-specific
configuration language that AI agents can generate and reason about less
reliably than a general-purpose programming language — one more reason
teams switch.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Greater Scalability.&lt;/strong&gt; Pulumi embraces software engineering as a
way to solve and manage the exponentially increasing complexity of
modern architectures. Programming languages with their loops,
conditional logic, class inheritance, object orientedness allows
engineers to design more complex and sophisticated infrastructure
compared to using HCL. Pulumi also allows you to build custom
workflows atop infrastructure programs, giving rise to
event-driven automations or internal developer portals that provide
self-service.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Better Collaboration.&lt;/strong&gt; Pulumi makes it easy to prototype new
products and quickly ship them into production because it is easier
for the platform, development, and security teams to collaborate.
You (platform engineering and devops teams) can define and manage common
infrastructure across the company, work with the security teams
to set security and compliance guardrails, and enable easy
self-service of infrastructure whether through custom developer
platforms or shared infrastructure libraries. To define common
company-wide components, if you don&amp;rsquo;t want to program can use use YAML; if you
do, you can use Python, TypeScript, Golang, C#, etc. These components can be consumed by
the development team in their own IaC program in any programming
language with the development tools they already know. It's easy to
start with YAML and move to other languages when more power is
desired. With Terraform, you must understand and use HCL. It
is difficult to build self-service infrastructure platforms because it
lacks the programmability and ability to apply software engineering.
It's just harder to bring together platform, development, and
security teams and empower them with tools that work. Whereas Pulumi
unblocks infrastructure as the bottleneck for software delivery.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/iac/comparisons/terraform/"&gt;Read more &amp;raquo;&lt;/a&gt;&lt;/p&gt;
&lt;h4 id="why-pulumi-vs-aws-cloud-development-kit-cdk"&gt;Why Pulumi vs. AWS Cloud Development Kit (CDK)?&lt;/h4&gt;
&lt;p&gt;Pulumi and CDK are similar in that both allow you to use programming
languages to write infrastructure as code. However, there are some key
differences:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;No Vendor Lock-In.&lt;/strong&gt; CDK supports only AWS, whereas Pulumi
supports over 150 cloud and SaaS providers, with more being added
all the time. CDK depends on CloudFormation as the deployment
engine; it shares many of the same benefits and limitations as
CloudFormation (see &lt;a href="https://www.pulumi.com/docs/iac/comparisons/cloudformation/#what-is-aws-cloudformation"&gt;Pulumi vs.
CloudFormation&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Execution &amp;gt; Translation.&lt;/strong&gt; Pulumi and CDK support similar
programming languages but differ fundamentally in their deployment
approaches. Pulumi's engine directly understands these languages
and communicates with cloud providers. In contrast, CDK transpiles
code into AWS Cloud Assembly, an intermediate format consisting of
CloudFormation templates and other assets, before deployment via
CloudFormation. This difference impacts your development speed and
correctness. CDK's approach can lead to slower deployments and
delayed error discovery, potentially hours into the process since
the errors aren&amp;rsquo;t caught during compile time. Additionally, you need expertise in both CloudFormation and CDK for effective
debugging and successful deployments, whereas Pulumi's direct
approach simplifies this process.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Versatility.&lt;/strong&gt; CDK and Pulumi both support automated testing, but
Pulumi offers more versatile options. While both allow unit testing,
Pulumi's deep integration between language and runtime enables
fast, offline tests (in-memory) with mocked cloud provider calls. In
contrast, CDK only permits assertions against synthesized
CloudFormation templates and lacks offline testing capabilities.
This makes Pulumi's testing approach more comprehensive and
flexible than CDK's.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/iac/comparisons/aws-cdk/"&gt;Read more &amp;raquo;&lt;/a&gt;&lt;/p&gt;
&lt;h4 id="why-pulumi-vs-3rd-party-internal-developer-portal-providers"&gt;Why Pulumi vs. 3rd party internal developer portal providers?&lt;/h4&gt;
&lt;p&gt;There are many third party providers of internal developer portals (think Port, Cortex, Backstage).
Some are services and others are open source software. These providers
are similar in that they offer simple developer portals that
are a single part of a greater infrastructure management platform.&lt;/p&gt;
&lt;p&gt;As discussed earlier, internal developer platforms have five layers:
developer control plane, integration &amp;amp; delivery, monitoring &amp;amp; logging,
resources management, and security &amp;amp; identity. Most of these providers
offer easy to use GUI consoles, simple CICD integrations, comprehensive
suite of monitoring &amp;amp; logging, and some form of role-based access
controls. However, they lack the infrastructure as code fundamentals and
automation capabilities that Pulumi has, which enable you to build powerful
customizations through software engineering. Many of these solutions
also lack strong secrets management and policy enforcement capabilities
that are critical for production and enterprise deployments.&lt;/p&gt;
&lt;p&gt;That said, if you need an off the shelf solution, then one of these
services or software might be a good choice for you. Some of these solutions can
integrate with Pulumi, and if your needs become more complex, you can always switch to
Pulumi later.&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Have a particular &lt;em&gt;&lt;strong&gt;Pulumi vs X&lt;/strong&gt;&lt;/em&gt;
comparison that you need thoughts on? Feel free to join the &lt;a href="http://pulumi"&gt;Pulumi Community
Slack&lt;/a&gt; if you have quick technical
questions, or talk to a &lt;a href="https://www.pulumi.com/contact/?form=tf-migration"&gt;Solutions Architect&lt;/a&gt; if you need more detailed
consultation about your specific architecture.&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="how-can-i-switch-to-pulumi"&gt;How can I switch to Pulumi?&lt;/h3&gt;
&lt;p&gt;Switching to Pulumi doesn&amp;rsquo;t have to be intimidating. We&amp;rsquo;ve done this
with thousands of customers before, and we can guide you through it.&lt;/p&gt;
&lt;p&gt;We provide self-service conversion tools that allow you to Import
infrastructure no matter how it was provisioned, click-ops included. You
can also use tools to convert your HashiCorp Terraform, AWS
CloudFormation, Azure Resource Manager (ARM) templates, or Kubernetes
YAML.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/iac/adopting-pulumi/"&gt;Self-service Tool
Guide&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If you need help, we have a team of cloud experts who can answer your
questions, give you a demo, or roll up their sleeves to get your
migration done.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/contact/?form=tf-migration"&gt;Contact Expert
Services&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We have done lots of migrations from all types of infrastructure as code
tools, and we are happy to help you think through how to make switching
to Pulumi as easy as possible.&lt;/p&gt;
&lt;a
href="https://www.pulumi.com/contact/?form=tf-migration"
class="btn btn-primary"
target="_blank"
rel="noopener noreferrer"
&gt;
Switch to Pulumi
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular text-sm ml-2" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-arrow-square-out-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;&lt;em&gt;Meta image credit: &lt;a href="https://www.eso.org/public/images/eso2402a/"&gt;ESO/M. Kornmesser&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</description><author>Aaron Kao</author><category>infrastructure-as-code</category><category>platform-engineering</category><category>ai</category></item><item><title>Celebrating 20,000 Stars: A Milestone for the Pulumi Community</title><link>https://www.pulumi.com/blog/celebrating-20k-stars/</link><pubDate>Thu, 23 May 2024 18:48:50 +0000</pubDate><guid>https://www.pulumi.com/blog/celebrating-20k-stars/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/celebrating-20k-stars/index.png" /&gt;
&lt;p&gt;Today, we&amp;rsquo;re excited to announce that the &lt;a href="https://github.com/pulumi/pulumi"&gt;Pulumi open source project&lt;/a&gt; has crossed the incredible milestone of 20,000 stars on GitHub. 🎉 This is a huge achievement, and it wouldn&amp;rsquo;t have been possible without y&amp;rsquo;all - our incredible global community of developers.&lt;/p&gt;
&lt;p&gt;Since its inception, Pulumi&amp;rsquo;s vision has been rooted in enabling teams to build and manage modern cloud infrastructure using familiar languages and tools. Over the years, your feedback, contributions, and passion have been invaluable in shaping Pulumi into what it is today. Seeing so many developers embrace our modern approach to cloud infrastructure management is really exciting. We are deeply grateful for the trust y&amp;rsquo;all have placed in us, and we will continue to push the boundaries in how teams manage cloud infrastructure.&lt;/p&gt;
&lt;h2 id="fueled-by-community-contributions"&gt;Fueled by Community Contributions&lt;/h2&gt;
&lt;p&gt;Over the past 7 years, the Pulumi project has had 4,400+ contributors that made 75,000+ pull requests. Pulumi is depended upon by 6,600+ GitHub projects and supports over 160+ packages in the registry. It has been downloaded more than 100 million times by 170,000+ developers. In just the last month, Pulumi has been the most active Infrastructure as Code (IaC) open-source project compared to Terraform or OpenTofu. Pulumi has had 117 merged pull requests (67 TF, 83 OpenTofu), 82 closed issues (49 TF, 54 OpenTofu), and 53 new issues (27 TF, 29, OpenTofu).&lt;/p&gt;
&lt;h2 id="notable-features-and-milestones"&gt;Notable Features and Milestones&lt;/h2&gt;
&lt;p&gt;We also want to take this time to reflect on some of the notable features we shipped that got us here. The &lt;a href="https://github.com/orgs/pulumi/projects/44/views/1"&gt;Pulumi roadmap&lt;/a&gt; is public so we can be transparent about the features being worked on and to encourage deeper collaboration with the community. Here are some of the most popular features that were added to Pulumi over the last 7 years.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Mar 2017 - Pulumi founded&lt;/li&gt;
&lt;li&gt;Jun 2018 - &lt;a href="https://www.pulumi.com/blog/introducing-pulumi-a-cloud-development-platform/"&gt;Pulumi open source project&lt;/a&gt; launched&lt;/li&gt;
&lt;li&gt;Aug 2018 - Kubernetes native provider&lt;/li&gt;
&lt;li&gt;Oct 2018 - Series A fundraise&lt;/li&gt;
&lt;li&gt;Oct 2018 - Pulumi Cloud launched&lt;/li&gt;
&lt;li&gt;Nov 2018 - &lt;a href="https://github.com/pulumi/pulumi/issues/109"&gt;Stack Reference&lt;/a&gt; to allow access of outputs of one stack from another&lt;/li&gt;
&lt;li&gt;Jun 2019 - &lt;a href="https://www.pulumi.com/blog/introducing-pulumi-crosswalk-for-aws-the-easiest-way-to-aws/"&gt;AWSX&lt;/a&gt; as higher-level components for the AWS platform&lt;/li&gt;
&lt;li&gt;Sep 2019 - &lt;a href="https://www.pulumi.com/blog/pulumi-1-0/"&gt;Pulumi 1.0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sep 2019 - &lt;a href="https://github.com/pulumi/pulumi/commit/9374c374c3d3a96fc2ae1e715da511b4125b6628"&gt;Transformations&lt;/a&gt; to modify the properties and resource options for child resource of a component or stack&lt;/li&gt;
&lt;li&gt;Nov 2019 - .&lt;a href="https://github.com/pulumi/pulumi/pull/3399"&gt;NET support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dec 2019 - &lt;a href="https://www.pulumi.com/blog/announcing-crossguard-preview/"&gt;CrossGuard&lt;/a&gt; for policy as code&lt;/li&gt;
&lt;li&gt;Apr 2020 - &lt;a href="https://www.pulumi.com/blog/pulumi-2-0/"&gt;Pulumi 2.0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;May 2020 - &lt;a href="https://www.pulumi.com/blog/go-support-pulumi-2-0/"&gt;Golang support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sep 2020 - &lt;a href="https://www.pulumi.com/blog/announcing-nextgen-azure-provider/"&gt;Azure Native Provider&lt;/a&gt; for same day access to new Azure features&lt;/li&gt;
&lt;li&gt;Oct 2020 - Series B fundraise&lt;/li&gt;
&lt;li&gt;Oct 2020 - &lt;a href="https://github.com/pulumi/pulumi/issues/3901#issuecomment-685803282"&gt;Automation API&lt;/a&gt; exposes IaC through a programmatic interface&lt;/li&gt;
&lt;li&gt;Oct 2020 - &lt;a href="https://github.com/pulumi/pulumi/pull/4765"&gt;Import command&lt;/a&gt; to import resources not managed by Pulumi into a stack&lt;/li&gt;
&lt;li&gt;Apr 2021 - First PulumiUP&lt;/li&gt;
&lt;li&gt;Apr 2021 - &lt;a href="https://www.pulumi.com/blog/pulumi-3-0/"&gt;Pulumi 3.0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Apr 2021 - &lt;a href="https://www.pulumi.com/blog/pulumiup-pulumi-packages-multi-language-components/"&gt;Pulumi Packages&lt;/a&gt; to provide multi-language support for components and providers&lt;/li&gt;
&lt;li&gt;Oct 2021 - &lt;a href="https://github.com/pulumi/pulumi-kubernetes-operator/issues/215"&gt;Pulumi Kubernetes Operator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;May 2022 - &lt;a href="https://github.com/pulumi/pulumi/issues/1539"&gt;Java support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nov 2022 - &lt;a href="https://www.pulumi.com/blog/nov-2022-launches/"&gt;Pulumi Deployments&lt;/a&gt; to automate infrastructure deployments&lt;/li&gt;
&lt;li&gt;Nov 2022 - &lt;a href="https://www.pulumi.com/blog/pulumi-yaml-ga/"&gt;YAML support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dec 2022 - &lt;a href="https://github.com/pulumi/pulumi/issues/2307"&gt;Hierarchical config&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Apr 2023 - &lt;a href="https://www.pulumi.com/blog/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt; for intelligence, search, and analytics over any infrastructure&lt;/li&gt;
&lt;li&gt;Apr 2023 - First Pulumi User Group (PUG)&lt;/li&gt;
&lt;li&gt;Jul 2023 - &lt;a href="https://github.com/pulumi/pulumi-terraform-bridge/issues/1273"&gt;Terraform conversion&lt;/a&gt; improvement as an easy way to migrate TF to Pulumi&lt;/li&gt;
&lt;li&gt;Sep 2023 - &lt;a href="https://www.pulumi.com/blog/pulumi-insights-ai-cli/"&gt;Pulumi AI&lt;/a&gt; added to &lt;code&gt;pulumi&lt;/code&gt; CLI&lt;/li&gt;
&lt;li&gt;Sep 2023 - &lt;a href="https://www.pulumi.com/blog/go-generics-preview/"&gt;Go generics&lt;/a&gt; support added&lt;/li&gt;
&lt;li&gt;Oct 2023 - Series C fundraise&lt;/li&gt;
&lt;li&gt;Oct 2023 - &lt;a href="https://www.pulumi.com/blog/environments-secrets-configurations-management/"&gt;Pulumi ESC&lt;/a&gt; to manage secrets and configuration complexity&lt;/li&gt;
&lt;li&gt;Oct 2023 - &lt;a href="https://www.pulumi.com/blog/developer-portal-platform-teams/"&gt;Pulumi for Platform Teams&lt;/a&gt; through developer portals and more&lt;/li&gt;
&lt;li&gt;Apr 2024 - &lt;a href="https://www.pulumi.com/blog/infrastructure-lifecycle-management/"&gt;Drift detection, TTL stacks, and scheduled deployments&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We also shipped many other features that didn’t make this post, so please see our &lt;a href="https://www.pulumi.com/blog/"&gt;blog&lt;/a&gt; for all those details.&lt;/p&gt;
&lt;h2 id="a-heartfelt-thank-you"&gt;A Heartfelt Thank You&lt;/h2&gt;
&lt;p&gt;We are immensely grateful to our community for helping us reach this incredible milestone and making Pulumi a thriving ecosystem. Your contributions, feedback, and support have been invaluable in shaping Pulumi&amp;rsquo;s journey. We also want to thank the &lt;a href="https://www.pulumi.com/community/puluminaries/"&gt;Puluminaries&lt;/a&gt; - our community leaders and advocates whose contributions have been pivotal to our success.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re passionate about cloud infrastructure, consider &lt;a href="mailto:da@pulumi.com"&gt;joining the Puluminaries&lt;/a&gt;. As a Puluminary, you’ll gain direct access to our engineering team, preview roadmaps, and help contribute to code, content, and community support.&lt;/p&gt;
&lt;p&gt;We look forward to continuing our innovations to democratize the cloud and empower developers worldwide. We encourage you to join our &lt;a href="https://slack.pulumi.com/"&gt;Slack community&lt;/a&gt; to engage with fellow developers and be part of the ongoing conversation about the future of how teams manage cloud infrastructure.&lt;/p&gt;
&lt;p&gt;Thank y&amp;rsquo;all for being part of this journey. Here’s to the next 20,000 stars and beyond!&lt;/p&gt;</description><author>Aaron Kao</author><category>announcements</category><category>open-source</category></item><item><title>Local Testing With Pulumi</title><link>https://www.pulumi.com/blog/local-testing-with-pulumi/</link><pubDate>Fri, 28 Apr 2023 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/local-testing-with-pulumi/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/local-testing-with-pulumi/index.png" /&gt;
&lt;p&gt;If you&amp;rsquo;ve been following along with our &lt;a href="https://www.pulumi.com/blog/iac-recommended-practices-code-organization-and-stacks/"&gt;IaC Recommended Practices series&lt;/a&gt;, then you&amp;rsquo;re already familiar with Zephyr Archaeotech Emporium, the fictional company at the center of the series. Today, you&amp;rsquo;ll get an inside look at how Zephyr starts using Pulumi for locally testing the application code for their online store and accelerating the inner dev loop for their development team.&lt;/p&gt;
&lt;p&gt;In the event you&amp;rsquo;re not familiar with the term &amp;ldquo;inner dev loop,&amp;rdquo; it&amp;rsquo;s used to describe the iterative code/build/test loop that every developer goes through to write code and verify that it works &lt;em&gt;before&lt;/em&gt; they push their code to version control to be reviewed and merged. Speeding up the inner dev loop makes it possible for developers to iterate on their code more quickly, reducing the time spent waiting on tools or environments.&lt;/p&gt;
&lt;p&gt;Structured as a conversation between two employees at Zephyr&amp;mdash;Alice, a developer on the team for Zephyr&amp;rsquo;s online store application, and Bob, a member of Zephyr&amp;rsquo;s platform engineering team&amp;mdash;this post shows one way to use Pulumi to help accelerate the inner dev loop. Let&amp;rsquo;s listen in&amp;hellip;&lt;/p&gt;
&lt;h2 id="listening-in-at-zephyr-hq"&gt;Listening in at Zephyr HQ&lt;/h2&gt;
&lt;p&gt;In a conversation at Zephyr HQ between Bob and Alice one day, Bob commented, &amp;ldquo;I&amp;rsquo;m really enjoying Pulumi. It&amp;rsquo;s nice for the platform team to be able to use TypeScript to define all the infrastructure we need.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Or to deploy our application onto that infrastructure,&amp;rdquo; Alice responded. &amp;ldquo;I just wish there was a way to speed up testing changes to our code.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Do you mean testing the Pulumi code?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;No, no, I was talking about our application code&amp;mdash;the code for the online store.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Oh, what&amp;rsquo;s wrong with the current way it&amp;rsquo;s handled? Is there something we can do better?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Alice paused. &amp;ldquo;Well, don&amp;rsquo;t get me wrong, the way we use &lt;a href="https://www.pulumi.com/blog/iac-recommended-practices-developer-stacks-git-branches/"&gt;per-developer stacks&lt;/a&gt; makes it super easy for me to deploy an entire copy of our environment. The problem is that&amp;hellip;well, it takes a fair amount of time to create all the AWS stuff. Sometimes I just need something faster, just to test some quick changes to the code before deploying the app to my dev stack.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Bob nodded thoughtfully. &amp;ldquo;I see. You know, Pulumi has a Docker provider; in fact, they recently released &lt;a href="https://www.pulumi.com/blog/build-images-50x-faster-docker-v4/"&gt;a new version of their Docker provider&lt;/a&gt;.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Alice&amp;rsquo;s eyes lit up. &amp;ldquo;So, you mean I can automate my local Docker instance using Pulumi?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Yeah, why?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Alice smiled. &amp;ldquo;I have an idea.&amp;rdquo;&lt;/p&gt;
&lt;h2 id="using-pulumi-for-the-inner-dev-loop"&gt;Using Pulumi for the inner dev loop&lt;/h2&gt;
&lt;p&gt;A couple days later, Alice contacted Bob and said, &amp;ldquo;I want to show you what I&amp;rsquo;ve come up with.&amp;rdquo;&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;To see the code that Alice created for local testing of the Zephyr online store with Pulumi, visit &lt;a href="https://github.com/pulumi/zephyr-app/"&gt;the zephyr-app repository&lt;/a&gt; and look at the &lt;a href="https://github.com/pulumi/zephyr-app/tree/blog/inner-dev-loop/"&gt;&lt;code&gt;blog/inner-dev-loop&lt;/code&gt;&lt;/a&gt; branch.&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;When Bob met up with Alice, Alice showed him a TypeScript program she&amp;rsquo;d written with Pulumi&amp;rsquo;s Docker provider that automates building and deploying the Zephyr online store to a local Docker daemon.&lt;/p&gt;
&lt;p&gt;&amp;ldquo;With this code,&amp;rdquo; Alice explains, &amp;ldquo;I can just run &lt;code&gt;pulumi up&lt;/code&gt; and it will deploy the entire Zephyr online store locally, all in just a few minutes. Here, let me just run &lt;code&gt;pulumi up&lt;/code&gt; real quick.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;But why use this instead of Docker Compose?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Oh, there&amp;rsquo;s absolutely nothing wrong with Docker Compose; it&amp;rsquo;s a great tool!&amp;rdquo; Alice replied. &amp;ldquo;But this allows me to work with TypeScript, and to build logic into my Pulumi program. Like this feature here&amp;mdash;I can specify whether I want to build a container, or use the released version of a container.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;See, at the top I have the Pulumi program check for a configuration value that I set using &lt;code&gt;pulumi config set&lt;/code&gt;. If the value isn&amp;rsquo;t set, it defaults to &lt;code&gt;build&lt;/code&gt;.&amp;rdquo;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-typescript" data-lang="typescript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;// Get configuration values
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;config&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;pulumi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Config&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;srcRepoPath&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;config&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="kr"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;srcRepoPath&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;../..&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;assetsFlag&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;config&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="kr"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;assetsFlag&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;build&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;cartsFlag&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;config&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="kr"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;cartsFlag&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;build&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;catalogFlag&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;config&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="kr"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;catalogFlag&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;build&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;checkoutFlag&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;config&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="kr"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;checkoutFlag&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;build&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;ordersFlag&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;config&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="kr"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;ordersFlag&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;build&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&amp;ldquo;There&amp;rsquo;s one for each service in the online store?&amp;rdquo; Bob asked.&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Right, except for the UI service, which is always built. This is so I can independently test changes to only a specific service. Farther down, the Pulumi code checks for this value and then either builds the container&amp;mdash;pulling in whatever changes I&amp;rsquo;ve made&amp;mdash;or uses an already released version of the container.&amp;rdquo;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-typescript" data-lang="typescript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;// Build the assets image or pull remote image, depending on value of assetsFlag
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;assetsImageRef&lt;/span&gt;: &lt;span class="kt"&gt;pulumi.Input&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;string&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;assetsFlag&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;build&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;assetsImage&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Image&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;assets-image&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;build&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="sb"&gt;`&lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;srcRepoPath&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="sb"&gt;/src/assets`&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;dockerfile&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="sb"&gt;`&lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;srcRepoPath&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="sb"&gt;/src/assets/Dockerfile`&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;platform&lt;/span&gt;: &lt;span class="kt"&gt;imagePlatform&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;imageName&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;zephyr-assets:latest&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;skipPush&lt;/span&gt;: &lt;span class="kt"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;retainOnDelete&lt;/span&gt;: &lt;span class="kt"&gt;true&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;assetsImageRef&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;assetsImage&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;assetsRegistryImage&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getRegistryImage&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;public.ecr.aws/aws-containers/retail-store-sample-assets:0.2.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;assetsRemoteImage&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;RemoteImage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;assets-image&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;name&lt;/span&gt;: &lt;span class="kt"&gt;assetsRegistryImage.then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;assetsRegistryImage&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;assetsRegistryImage&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;pullTriggers&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;assetsRegistryImage&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;assetsRegistryImage&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;assetsRegistryImage&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;sha256Digest&lt;/span&gt;&lt;span class="p"&gt;)],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;retainOnDelete&lt;/span&gt;: &lt;span class="kt"&gt;true&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;assetsImageRef&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;assetsRemoteImage&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;repoDigest&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;You can see that the released container image is hard-coded in this example. You could also pass this in as a configuration value to allow the Pulumi program to more easily account for new releases.&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&amp;ldquo;By setting the flag for the assets service to &lt;code&gt;build&lt;/code&gt; and all the other services to something else&amp;mdash;the code only builds if the value is set to &lt;code&gt;build&lt;/code&gt;&amp;mdash;then I can isolate changes made to that service for testing, to be sure I haven&amp;rsquo;t broken something elsewhere.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;That seems useful.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Indeed! And you can see here that we are building a Docker network for these containers; this is what enables connectivity between the various parts of the online store when it&amp;rsquo;s running locally via Docker.&amp;rdquo;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-typescript" data-lang="typescript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;// Create a network
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;network&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Network&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;network&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;zephyr-net&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;// Create an assets container
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;assetsContainer&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Container&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;assets-container&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;capabilities&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;drops&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;ALL&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;envs&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;PORT=8080&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;hostname&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;assets&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;image&lt;/span&gt;: &lt;span class="kt"&gt;assetsImageRef&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;memory&lt;/span&gt;: &lt;span class="kt"&gt;64&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;assets&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;networksAdvanced&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;name&lt;/span&gt;: &lt;span class="kt"&gt;network.name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;restart&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;always&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Bob nodded. &amp;ldquo;Yep, this all makes sense. Interesting, I hadn&amp;rsquo;t really considered Pulumi for this particular use case. Usually when folks mention Pulumi the first thought in my head is provisioning cloud infrastructure.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Oh, certainly, and it works really well for that&amp;mdash;but it also works really well for this case, too.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;And since we are already using Pulumi for deploying to Kubernetes in test and production, then this brings some consistency across environments. It&amp;rsquo;s just a &lt;code&gt;pulumi up&lt;/code&gt; regardless of whether you&amp;rsquo;re running the app locally or publishing to a Kubernetes cluster in your per-developer stack, the test stack, or even the prod stack.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Exactly. Oh, look here. It&amp;rsquo;s done. Looks like it took just over two minutes, and now our online store app is available at this URL on &lt;code&gt;localhost&lt;/code&gt;.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;img src="pulumi-op-finished.png" alt="A terminal window showing output from a completed Pulumi up operation"&gt;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;That&amp;rsquo;s pretty fast.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Alice nodded. &amp;ldquo;Yeah, a lot faster than waiting on a Kubernetes cluster to provision. We still need to run this in our dev stacks to be sure that it runs in an environment that closely mirrors production, but for quick feedback on changes I make this is very useful for me as a developer.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;So if you make a change to the code and want to see the results, what&amp;rsquo;s that look like?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Here, let&amp;rsquo;s do it real quick.&amp;rdquo; Alice switches to her code editor, makes a few changes, and then flips back to the terminal. &amp;ldquo;I&amp;rsquo;ll run a &lt;code&gt;pulumi preview&lt;/code&gt; so you can see what it&amp;rsquo;s going to do.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;img src="pulumi-preview-results.png" alt="A terminal window showing the output of the Pulumi preview command"&gt;&lt;/p&gt;
&lt;p&gt;Alice pointed to the terminal output. &amp;ldquo;Here, Pulumi has recognized that the source code for this container has changed, and so it is replacing the container image, and restarting all the containers. Let me run &lt;code&gt;pulumi up&lt;/code&gt;.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Bob watches as the operation completes in about 17 seconds.&lt;/p&gt;
&lt;p&gt;&lt;img src="pulumi-op-replace-resources.png" alt="A terminal window showing a completed Pulumi operation that lasted 17 seconds"&gt;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Wow, that&amp;rsquo;s really fast!&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Exactly, Bob. That&amp;rsquo;s what makes using Pulumi for this use case so helpful. While it doesn&amp;rsquo;t eliminate the need for our per-developer stacks, it gives developers a way to quickly see changes we&amp;rsquo;re making to the source code in very little time. When we are satisfied that the changes are working as we expect, then we can deploy to our dev stack to be sure that the changes are ready to work their way to production.&amp;rdquo;&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Speed up your inner dev loop&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Use Pulumi and the Docker provider to build and deploy your application locally, then promote the same program to your cloud stacks. Get started in Pulumi Cloud.&lt;/div&gt;
&lt;a href="https://app.pulumi.com/signup" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Get started
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="try-this-out-yourself"&gt;Try this out yourself&lt;/h2&gt;
&lt;p&gt;Now that you&amp;rsquo;ve seen how Alice uses Pulumi to streamline testing the Zephyr online store&amp;rsquo;s application code locally, feel free to try this out yourself! The code that you saw in this blog post is available &lt;a href="https://github.com/pulumi/zephyr-app/"&gt;in the &lt;code&gt;zephyr-app&lt;/code&gt; repository on GitHub&lt;/a&gt;. Just select the &lt;a href="https://github.com/pulumi/zephyr-app/tree/blog/inner-dev-loop/"&gt;&lt;code&gt;blog/inner-dev-loop&lt;/code&gt;&lt;/a&gt; branch and go to the &lt;code&gt;develop/pulumi&lt;/code&gt; folder.&lt;/p&gt;</description><author>Aaron Kao</author><author>Scott Lowe</author><author>Christian Nunciato</author><category>zephyr</category><category>docker</category></item><item><title>IaC Best Practices: Understanding Code Organization &amp; Stacks</title><link>https://www.pulumi.com/blog/iac-best-practices-understanding-code-organization-stacks/</link><pubDate>Mon, 20 Feb 2023 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/iac-best-practices-understanding-code-organization-stacks/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/iac-best-practices-understanding-code-organization-stacks/index.png" /&gt;
&lt;p&gt;This is the first in a series of blog posts that explores how a fictional company&amp;mdash;Zephyr Archaeotech Emporium&amp;mdash;uses Pulumi to manage their online retail store. This post explores a couple of common questions that users ask when working with Pulumi; specifically, where should I store my Pulumi code? And how do I support multiple environments with Pulumi? This post will provide some guidance and &lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;Infrastructure as Code&lt;/a&gt; best practices around these topics, using Zephyr and their online store as the use case.&lt;/p&gt;
&lt;p&gt;The ultimate goal of this series is to discuss recommended practices for using Pulumi to manage a fairly complex containerized application. However, it&amp;rsquo;s important to note that these practices will emerge over the course of the series&amp;mdash;not all immediately, and not all in the beginning. This is a deliberate decision to allow you to see how Zephyr&amp;rsquo;s use of Pulumi evolves as the company grows and their online retail store application changes to accommodate their growth.&lt;/p&gt;
&lt;h2 id="setting-up-the-scenario"&gt;Setting Up the Scenario&lt;/h2&gt;
&lt;p&gt;Zephyr is short for Zephyr Archaeotech Emporium, the fictional company in our scenario. Zephyr is an online retailer that specializes in the sale of &amp;ldquo;rare arcane artifacts and replicas.&amp;rdquo; Over the past few years, the company has experienced a significant increase in its online presence, making it easier for customers to purchase unique and mysterious items. Zephyr&amp;rsquo;s collection includes a variety of rare and unusual objects that are difficult to find elsewhere, making it a popular destination for collectors, enthusiasts, and adventurers.&lt;/p&gt;
&lt;h2 id="moving-to-a-containerized-architecture"&gt;Moving to a Containerized Architecture&lt;/h2&gt;
&lt;p&gt;Zephyr&amp;rsquo;s application is the second generation of their online store. Their first generation was a monolith that they manually deployed. It was sufficient in Zephyr&amp;rsquo;s early days, but as word about Zephyr spread and the volume of traffic to their online store increased, Zephyr found it increasingly difficult to deploy small, incremental changes to the store&amp;rsquo;s code. As a result, the velocity of their development efforts slowed. In preparation for the next phase of their growth&amp;mdash;driven by robust sales of arcane artifacts&amp;mdash;Zephyr&amp;rsquo;s team evaluated a number of different architectures that would enable them to increase development velocity and give them greater flexibility in scaling different aspects of their online store. In the end, they settled on a containerized architecture deployed to &lt;a href="https://www.pulumi.com/kubernetes/"&gt;Kubernetes&lt;/a&gt; because some of the existing team was already familiar with these technologies.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s a diagram of their second-generation application architecture:&lt;/p&gt;
&lt;p&gt;&lt;img src="app-architecture-vpc-eks-cluster.jpg" alt="A diagram depicting an application consisting of containerized microservices"&gt;&lt;/p&gt;
&lt;p&gt;As you can see in the diagram, the application has been broken down into microservices. The UI service communicates with other backend services via HTTP APIs; the various backend services communicate with various databases like MySQL and Redis for data persistence and/or caching. The backend services are responsible for implementing the functionality of a typical e-commerce site like orders, checking out, and managing the inventory catalog. While the choice of Kubernetes does afford Zephyr some much-needed functionality&amp;mdash;like the ability to easily scale different services within the application&amp;mdash;it also brings with it an added level of complexity that did not exist with their previous monolithic architecture. The Kubernetes manifest to deploy their application tops out at just over 1,000 lines of YAML!&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Astute readers may note that Zephyr&amp;rsquo;s application looks very similar to &lt;a href="https://github.com/aws-containers/retail-store-sample-app/"&gt;this application&lt;/a&gt;; in truth, this series uses a fork of the AWS Containers retail store example as the application in this fictional scenario. (Many thanks to the AWS Containers DA team for their hard work here!) This is an admittedly over-engineered application, but it does afford the opportunity to address a range of customer scenarios in this blog series.&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="managing-infrastructure-and-application-deployments"&gt;Managing Infrastructure and Application Deployments&lt;/h2&gt;
&lt;p&gt;As part of the switch to their new architecture, Zephyr decided they wanted to use Pulumi to manage both the infrastructure and the application deployment. Why Pulumi? Zephyr’s team recognized that moving to microservices on Kubernetes was going to make it more difficult to create reproducible, consistent implementations of their application. Zephyr&amp;rsquo;s team also knew that adopting infrastructure as code would help them with fast and repeatable deployments with little additional complexity. Another bonus was being able to use programming languages they already knew.&lt;/p&gt;
&lt;p&gt;As they prepared to embark on using Pulumi, a couple of questions came up for the Zephyr team:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Where should they store their Pulumi code?&lt;/strong&gt; The ability for Zephyr&amp;rsquo;s developers to use a full programming language to manage the infrastructure and deployment of their online store is a huge plus, but should this code go in the same repository as their application code? Or a different repository?&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;How do they address the need for multiple environments?&lt;/strong&gt; It&amp;rsquo;s clear to the Zephyr development team that they&amp;rsquo;ll need multiple instances of the online store (for things like testing, QA, or development). What&amp;rsquo;s the best way to handle this when using Pulumi?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let&amp;rsquo;s examine each of these issues in a bit more detail, and see how Zephyr chose to proceed.&lt;/p&gt;
&lt;h3 id="storing-pulumi-code"&gt;Storing Pulumi Code&lt;/h3&gt;
&lt;p&gt;When it comes to answering the question of where to store Pulumi code relative to the application(s) it supports, there are two basic options:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;In the same repository as your application code:&lt;/strong&gt; This approach has the advantage of being simpler, but may not offer the necessary flexibility when dealing with multiple teams or varying levels of access control.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;In a separate repository from your application code:&lt;/strong&gt; Using a separate repository adds some complexity, but does provide greater flexibility to more easily address a variety of organizational requirements and varying levels of access control.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So which approach is best? That will depend on a number of different factors, many of which are outlined in the &lt;a href="https://www.pulumi.com/docs/using-pulumi/organizing-projects-stacks/"&gt;organizing projects &amp;amp; stacks documentation&lt;/a&gt;. Some other factors that users need to take into consideration include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Who is responsible for maintaining the code? If the application code and the Pulumi code are managed by different teams, then using separate repositories may be the best approach.&lt;/li&gt;
&lt;li&gt;What sort of access controls are needed? If the organization needs different access controls for the application code and the Pulumi code, then separate repositories are generally needed.&lt;/li&gt;
&lt;li&gt;What is the relationship between the infrastructure resources managed by Pulumi and the applications? If the infrastructure is &amp;ldquo;shared,&amp;rdquo; meaning it is used by multiple applications, then keeping the Pulumi code in a separate repository may be preferred. If the infrastructure is dedicated to a specific application, then keeping the application code and the Pulumi code together may be preferred.&lt;/li&gt;
&lt;li&gt;What about CI/CD? If an organization will use a &lt;a href="https://www.pulumi.com/what-is/what-is-ci-cd/"&gt;CI/CD pipeline&lt;/a&gt;, that may affect how you organize your code. (This is something we&amp;rsquo;ll delve into more deeply later in this series.)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It&amp;rsquo;s worth stressing that the answers to these questions may change over time as organizations grow and their applications evolve. Addressing that change and its effects on an organization&amp;rsquo;s Pulumi projects and stacks is something we&amp;rsquo;ll be discussing later in this series.&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;The discussion above is working from the assumption that Pulumi users will store their Pulumi code in a version control system, like Git. Strictly speaking, using a version control system isn&amp;rsquo;t required for Pulumi to function (there is one exception we&amp;rsquo;ll touch on later in this series when we discuss &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/"&gt;Pulumi Deployments&lt;/a&gt;), but we &lt;strong&gt;very strongly&lt;/strong&gt; recommend that all users use Pulumi in conjunction with version control.&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;In the case of Zephyr, their team felt like a monorepo approach (storing Pulumi code and application code together) was most appropriate for their specific requirements. Zephyr is a relatively small organization with a single team of developers who are responsible for managing both the cloud infrastructure as well as the development and deployment of the online store application. Zephyr&amp;rsquo;s team also decided to use a single Pulumi project&amp;mdash;for now. (Be sure to follow this blog series to see how that evolves, and why!)&lt;/p&gt;
&lt;h3 id="addressing-the-need-for-multiple-environments"&gt;Addressing the Need for Multiple Environments&lt;/h3&gt;
&lt;p&gt;The second question Zephyr encountered is how to handle the need for multiple instances of their application. In addition to a production instance&amp;mdash;which is the instance behind Zephyr&amp;rsquo;s public-facing online store&amp;mdash;Zephyr also felt they needed an environment for the developers to use in testing changes to the online store.&lt;/p&gt;
&lt;p&gt;This use case&amp;mdash;needing to have multiple, separate instances of the infrastructure and applications created by a single Pulumi program&amp;mdash;is exactly what &lt;a href="https://www.pulumi.com/docs/concepts/stack/"&gt;Pulumi stacks&lt;/a&gt; were designed to address. Each stack is a separate instance of the resources created by a Pulumi program within a project. Further, each stack has its own independent state, and each stack has its own configuration values. Stacks can be short-lived (meaning the associated resources are also short-lived), or stacks can be long-lived. Aside from the cloud resources created by the Pulumi program, stacks are lightweight and simple to create or delete.&lt;/p&gt;
&lt;p&gt;Zephyr decided to initially start with two stacks: a production stack (named &amp;ldquo;prod&amp;rdquo;) and a development stack (named &amp;ldquo;dev&amp;rdquo;). As you&amp;rsquo;ll observe throughout this series, this is a decision that is easily adjusted over time as your organization&amp;rsquo;s requirements change.&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Organize your infrastructure with stacks&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Model separate development, staging, and production environments as Pulumi stacks in a single project, each with its own state and configuration.&lt;/div&gt;
&lt;a href="https://app.pulumi.com/signup" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Get started
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="viewing-the-first-iteration-of-code"&gt;Viewing the First Iteration of Code&lt;/h2&gt;
&lt;p&gt;You can view the first iteration of Zephyr&amp;rsquo;s Pulumi and application code&amp;mdash;the iteration that corresponds to the decisions described in this blog post&amp;mdash;by navigating to &lt;a href="https://github.com/pulumi/zephyr-app/"&gt;the Zephyr App GitHub repository&lt;/a&gt;. From the branch/tag dropdown, switch from the &lt;code&gt;main&lt;/code&gt; branch to viewing the &lt;a href="https://github.com/pulumi/zephyr-app/tree/blog/original/"&gt;&lt;code&gt;blog/original&lt;/code&gt;&lt;/a&gt; branch.&lt;/p&gt;
&lt;p&gt;From that GitHub repository, you can also choose to deploy the Pulumi code yourself. Full instructions for deploying the code are found in the repository.&lt;/p&gt;
&lt;h2 id="summarizing-best-practices-organizing-code-and-stacks"&gt;Summarizing Best Practices: Organizing Code and Stacks&lt;/h2&gt;
&lt;p&gt;This article introduced you to Zephyr, the fictional company for this blog series, and reviewed the application architecture for Zephyr&amp;rsquo;s online store (a containerized application running on Kubernetes). Throughout the blog series, this application serves as the use case around which various recommended practices are discussed.&lt;/p&gt;
&lt;p&gt;In this post the following guidelines were covered:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Use version control for your Pulumi code.&lt;/strong&gt; Although it isn&amp;rsquo;t strictly required in many cases, a number of the benefits of adopting infrastructure as code are lost without the use of version control.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Place your Pulumi code into version control repositories in a way that aligns with organizational requirements.&lt;/strong&gt; There is no &amp;ldquo;right&amp;rdquo; or &amp;ldquo;wrong&amp;rdquo; approach; choose the approach that enables you to satisfy your organization&amp;rsquo;s requirements around access control, code/repo ownership, and other organizational requirements.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Leverage Pulumi stacks to create multiple instances of cloud resources with a single Pulumi program.&lt;/strong&gt; Pulumi stacks were created to address the need for organizations to create multiple instances of cloud resources, each with its own state and its own set of configuration data, from a single Pulumi program.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For now, Zephyr has decided to go with a monorepo approach&amp;mdash;a single repository that contains both their application code and the Pulumi code to manage the infrastructure resources. All of the resources are defined in a single Pulumi project, with multiple stacks that correspond to development and production environments. Over the course of this series, we&amp;rsquo;ll see how Zephyr&amp;rsquo;s use of Pulumi changes as Zephyr grows and their application evolves.&lt;/p&gt;
&lt;p&gt;The next Zephyr blog post will examine how the Zephyr team adjusts their use of stacks and Git branches to support developer productivity. Stay tuned!&lt;/p&gt;</description><author>Aaron Kao</author><author>Christian Nunciato</author><author>Scott Lowe</author><category>best-practices</category><category>cloud-engineering</category><category>aws</category><category>eks</category></item></channel></rss>