<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Pulumi Blog: Dan Biwer</title><link>https://www.pulumi.com/blog/author/dan-biwer/</link><description>Pulumi blog posts: Dan Biwer.</description><language>en-us</language><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><item><title>Enforce ISO 27001 Across Your AWS Infrastructure</title><link>https://www.pulumi.com/blog/iso-27001-policy-pack-for-aws/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/iso-27001-policy-pack-for-aws/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/iso-27001-policy-pack-for-aws/index.png" /&gt;
&lt;p&gt;ISO/IEC 27001 is the international standard for information security management. Proving you meet it usually means months of mapping abstract security controls to concrete cloud configuration, then authoring custom checks one resource at a time. We&amp;rsquo;re changing that.&lt;/p&gt;
&lt;p&gt;Today we&amp;rsquo;re shipping a pre-built ISO/IEC 27001:2022 policy pack for AWS, live now in Pulumi Cloud as &lt;code&gt;iso-27001-aws&lt;/code&gt;. It encodes the standard&amp;rsquo;s security expectations as 238 ready-to-run policies, so you can align your AWS estate to ISO 27001 in minutes, not months.&lt;/p&gt;
&lt;h2 id="why-iso-27001-matters"&gt;Why ISO 27001 matters&lt;/h2&gt;
&lt;p&gt;For many companies, ISO 27001 is what stands between them and a customer or a market. The sooner you can reach a certifiable state and prove you stay there, the less compliance slows the business down. The pack collapses months of policy work into something you run continuously, so security keeps pace with growth instead of blocking it.&lt;/p&gt;
&lt;h2 id="how-the-pack-maps-to-iso-27001"&gt;How the pack maps to ISO 27001&lt;/h2&gt;
&lt;p&gt;The hard part of ISO 27001 has always been translation: its controls are written in the language of governance and risk management, not in the language of AWS resources. Every team has had to interpret each control and decide what it means for an S3 bucket or an RDS instance.&lt;/p&gt;
&lt;p&gt;The pack does that interpretation for you. Its 238 policies are aligned to the relevant ISO 27001 controls, so each result connects back to the standard instead of leaving you to map it yourself. You can browse the full pack in the &lt;a href="https://www.pulumi.com/docs/reference/pre-built-policy-packs/iso-27001/aws/"&gt;pack reference&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="audit-and-prevent"&gt;Audit and prevent&lt;/h2&gt;
&lt;p&gt;The same pack works two ways, so you can both reach compliance and stay there:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Audit.&lt;/strong&gt; Scan your existing AWS estate against the pack, including resources that Pulumi doesn&amp;rsquo;t manage. You get an honest baseline of where you stand against ISO 27001 today, with every finding tied back to the control it affects.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prevent.&lt;/strong&gt; Run the same pack as a preventative policy during &lt;code&gt;pulumi up&lt;/code&gt; to block non-compliant resources before they&amp;rsquo;re ever created. New infrastructure is born aligned to the standard.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Audit gets you clean. Preventative policies keep you clean.&lt;/p&gt;
&lt;h2 id="a-growing-library-of-pre-built-packs"&gt;A growing library of pre-built packs&lt;/h2&gt;
&lt;p&gt;ISO 27001 joins a growing library of pre-built packs for AWS, each authored and maintained by Pulumi and kept current with its source standard:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;ISO/IEC 27001:2022&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CIS Controls v8.1&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;NIST SP 800-53 Rev. 5&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PCI DSS v4.0&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HITRUST CSF v11.5&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pulumi Best Practices&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Adopting any pack means you skip the authoring work entirely, inherit framework mappings maintained by Pulumi, and apply a consistent baseline across every stack and account.&lt;/p&gt;
&lt;h2 id="get-started-today"&gt;Get started today&lt;/h2&gt;
&lt;p&gt;The ISO 27001 pack is available now to every Pulumi Cloud user:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Browse the &lt;a href="https://www.pulumi.com/docs/reference/pre-built-policy-packs/iso-27001/aws/"&gt;pack reference&lt;/a&gt; to see all 238 policies and how they map to the standard&amp;rsquo;s controls.&lt;/li&gt;
&lt;li&gt;Explore the full &lt;a href="https://www.pulumi.com/docs/insights/policy/policy-packs/pre-built-packs/"&gt;pre-built packs index&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Follow the &lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;get-started guide&lt;/a&gt; to run your first audit.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="try-pulumi-policies"&gt;Try Pulumi policies&lt;/h2&gt;
&lt;p&gt;Ready to align your AWS infrastructure to ISO 27001? &lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; and run the pack against your estate, or read the &lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;policy get-started guide&lt;/a&gt; to dig in.&lt;/p&gt;
&lt;p&gt;Need a compliance pack for a framework that isn&amp;rsquo;t listed here? Open a request in &lt;a href="https://github.com/pulumi/pulumi-cloud-requests"&gt;pulumi/pulumi-cloud-requests&lt;/a&gt; or come tell us in the &lt;a href="https://slack.pulumi.com/"&gt;community Slack&lt;/a&gt;. We&amp;rsquo;re listening.&lt;/p&gt;</description><author>Dan Biwer</author><category>pulumi-cloud</category><category>policy-as-code</category><category>crossguard</category><category>features</category><category>compliance</category><category>governance</category><category>security</category></item><item><title>Policy Packs Can Now Access Pulumi ESC Environments</title><link>https://www.pulumi.com/blog/policy-packs-can-now-access-pulumi-esc-environments/</link><pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/policy-packs-can-now-access-pulumi-esc-environments/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/policy-packs-can-now-access-pulumi-esc-environments/index.png" /&gt;
&lt;p&gt;Policy authors who need external credentials or environment-specific configuration have had to hardcode values or manage them outside of Pulumi. Policy packs can now reference &lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Pulumi ESC&lt;/a&gt; environments, bringing centralized secrets and configuration management to your policies.&lt;/p&gt;
&lt;h2 id="the-problem"&gt;The problem&lt;/h2&gt;
&lt;p&gt;Pulumi &lt;a href="https://www.pulumi.com/docs/insights/policy/policy-packs/"&gt;policy packs&lt;/a&gt; let you enforce rules across your infrastructure, but some policies need more than just the resource inputs they evaluate. A policy that validates resources against an external compliance API needs an API token. A cost-enforcement policy might need different spending thresholds for development and production environments. An access-control policy might need to reference an internal service registry.&lt;/p&gt;
&lt;p&gt;Until now, these values had to be hardcoded in your policy group configuration or managed through a separate process entirely. This created several problems:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Security risk&lt;/strong&gt;: Credentials stored in plain text in policy group config&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Operational burden&lt;/strong&gt;: Updating a credential meant touching every policy group that used it&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No environment separation&lt;/strong&gt;: The same values applied everywhere, with no way to vary configuration across environments&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="whats-new"&gt;What&amp;rsquo;s new&lt;/h2&gt;
&lt;p&gt;Policy packs can now reference ESC environments, just like &lt;a href="https://www.pulumi.com/docs/esc/environments/syntax/reserved-properties/pulumi-config/"&gt;stacks already do&lt;/a&gt;. When you attach an ESC environment to a policy pack in a policy group, the values from that environment are available to your policies at runtime — whether you&amp;rsquo;re running preventative or audit policies.&lt;/p&gt;
&lt;p&gt;This means your policy packs can use ESC for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Secrets&lt;/strong&gt;: API tokens, service credentials, and other sensitive values managed through ESC&amp;rsquo;s secrets management, including dynamic credentials from providers like AWS, Azure, and GCP&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configuration&lt;/strong&gt;: Environment-specific thresholds, allowed regions, service allowlists, and other policy parameters that vary across environments&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="policy-esc-screenshot.png" alt="Configuring ESC environments on a policy pack in the Pulumi Cloud console"&gt;&lt;/p&gt;
&lt;h2 id="how-it-works"&gt;How it works&lt;/h2&gt;
&lt;p&gt;You configure ESC environment references on a policy pack within a policy group. At runtime, the values from those environments are resolved and made available to your policies through the policy pack&amp;rsquo;s configuration.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s an example ESC environment that provides configuration to a compliance policy pack:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;values&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;compliance&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;apiToken&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;fn::secret&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;xxxxxxxxxxxxxxxx&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;costThreshold&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;5000&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;policyConfig&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;cost-compliance&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;maxMonthlyCost&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${compliance.costThreshold}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;apiEndpoint&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;https://compliance.example.com&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;apiToken&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${compliance.apiToken}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The &lt;a href="https://www.pulumi.com/docs/esc/environments/syntax/reserved-properties/policy-config/"&gt;&lt;code&gt;policyConfig&lt;/code&gt;&lt;/a&gt; property works just like &lt;a href="https://www.pulumi.com/docs/esc/environments/syntax/reserved-properties/pulumi-config/"&gt;&lt;code&gt;pulumiConfig&lt;/code&gt;&lt;/a&gt; does for stacks. Values nested under each policy name are made available as configuration to that policy at runtime. Secrets remain encrypted and are only decrypted when the environment is resolved.&lt;/p&gt;
&lt;p&gt;You can also use the &lt;code&gt;environmentVariables&lt;/code&gt; property to inject values as environment variables into the policy runtime, following the same pattern as &lt;a href="https://www.pulumi.com/docs/esc/environments/syntax/reserved-properties/environment-variables/"&gt;stack environment variables&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="example-compliance-api-validation"&gt;Example: compliance API validation&lt;/h2&gt;
&lt;p&gt;Consider a policy that validates every new resource against an external compliance API before it can be provisioned. The API requires an authentication token and returns whether the resource configuration meets your organization&amp;rsquo;s compliance standards.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Before&lt;/strong&gt;, the API token lived in the policy group configuration in plain text. Rotating the token meant updating every policy group. There was no audit trail for who accessed the credential, and no way to use different API endpoints for staging and production compliance checks.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;After&lt;/strong&gt;, the API token lives in an ESC environment. You get:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Centralized rotation&lt;/strong&gt;: Update the token in one place and every policy group that references the environment picks up the change&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Access controls&lt;/strong&gt;: ESC&amp;rsquo;s role-based access controls govern who can view or modify the credential&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit trail&lt;/strong&gt;: Every access to the environment is logged&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Environment separation&lt;/strong&gt;: Use different ESC environments for different policy groups, so staging policies validate against a staging compliance endpoint while production policies use the production endpoint&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="get-started"&gt;Get started&lt;/h2&gt;
&lt;p&gt;To start using ESC environments with your policy packs:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/esc/environments/working-with-environments/"&gt;Create an ESC environment&lt;/a&gt; with your policy configuration and secrets&lt;/li&gt;
&lt;li&gt;Attach the environment to a policy pack in your policy group through the Pulumi Cloud console&lt;/li&gt;
&lt;li&gt;Update your policies to read from the configuration values provided by the environment&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;To learn more:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/esc/environments/syntax/reserved-properties/policy-config/"&gt;&lt;code&gt;policyConfig&lt;/code&gt; reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/esc/"&gt;Pulumi ESC documentation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/policy-packs/"&gt;Policy packs documentation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/esc/get-started/"&gt;Get started with Pulumi ESC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><author>Dan Biwer</author><category>esc</category><category>policy-as-code</category><category>features</category></item><item><title>Expanded Version Control Support in Pulumi Cloud</title><link>https://www.pulumi.com/blog/expanded-version-control-support/</link><pubDate>Mon, 09 Mar 2026 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/expanded-version-control-support/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/expanded-version-control-support/index.png" /&gt;
&lt;p&gt;Your version control provider shouldn&amp;rsquo;t limit your infrastructure workflows. Pulumi Cloud now works with &lt;a href="https://www.pulumi.com/docs/version-control/github-app/"&gt;GitHub&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/version-control/github-app/#github-enterprise-server-support"&gt;GitHub Enterprise Server&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/version-control/azure-devops-integration/"&gt;Azure DevOps&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/docs/version-control/gitlab/"&gt;GitLab&lt;/a&gt;. Every team gets the same &lt;a href="https://www.pulumi.com/docs/deployments/deployments/"&gt;deployment pipelines&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/deployments/deployments/review-stacks/"&gt;PR previews&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/docs/ai/"&gt;AI-powered change summaries&lt;/a&gt; regardless of where their code lives.&lt;/p&gt;
&lt;p&gt;&lt;img src="VCS.png" alt="Add account screen showing GitHub, GitLab, and Azure DevOps as VCS options"&gt;&lt;/p&gt;
&lt;h2 id="connect-multiple-providers-and-accounts"&gt;Connect multiple providers and accounts&lt;/h2&gt;
&lt;p&gt;You can connect multiple VCS providers to a single Pulumi organization simultaneously, like GitHub, GitLab, and Azure DevOps all at once. You can also connect multiple accounts of the same provider, such as two separate GitHub organizations or two GitLab groups. This means teams that work across different repositories, providers, or organizational boundaries can manage everything from one place.&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.21047dcd83825f0caafb78a6fd28628a694219e6b6824f6b3e24ee3147bac331.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;GitHub Enterprise Server is currently limited to one connection per Pulumi organization.&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="what-your-team-can-do"&gt;What your team can do&lt;/h2&gt;
&lt;h3 id="deploy-on-every-push"&gt;Deploy on every push&lt;/h3&gt;
&lt;p&gt;Connect a repository to a stack, and infrastructure deploys automatically when you push. Configure path filters to trigger only when relevant files change, and manage environment variables and secrets directly in Pulumi Cloud. No external CI/CD pipeline required.&lt;/p&gt;
&lt;h3 id="preview-changes-on-pull-requests"&gt;Preview changes on pull requests&lt;/h3&gt;
&lt;p&gt;Every pull request gets an infrastructure preview so reviewers can see exactly what will change before merging. The preview runs the same Pulumi operations your deployment would, giving your team confidence that a merge won&amp;rsquo;t break anything.&lt;/p&gt;
&lt;h3 id="neo-explains-your-changes"&gt;Neo explains your changes&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/product/neo/"&gt;Neo&lt;/a&gt; posts AI-generated summaries on your pull requests explaining what infrastructure changes mean in plain language. Reviewers who aren&amp;rsquo;t Pulumi experts can still understand the impact of a change without reading resource diffs.&lt;/p&gt;
&lt;p&gt;&lt;img src="ado-prcomments.png" alt="Neo posting an infrastructure change summary on a pull request"&gt;&lt;/p&gt;
&lt;h3 id="let-neo-open-pull-requests-for-you"&gt;Let Neo open pull requests for you&lt;/h3&gt;
&lt;p&gt;Ask Neo to make infrastructure changes and it opens pull requests directly against your connected repositories. Describe what you want in natural language, and Neo writes the code, opens the PR, and kicks off a preview, all without leaving Pulumi Cloud.&lt;/p&gt;
&lt;h3 id="detect-and-fix-drift"&gt;Detect and fix drift&lt;/h3&gt;
&lt;p&gt;Schedule &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/drift/"&gt;drift detection&lt;/a&gt; to catch out-of-band changes automatically. When someone modifies infrastructure outside of your Pulumi programs, drift detection flags the difference so your team can remediate before it causes issues.&lt;/p&gt;
&lt;h3 id="secure-authentication"&gt;Secure authentication&lt;/h3&gt;
&lt;p&gt;Pulumi Cloud authenticates with your VCS provider using OIDC or OAuth so no long-lived credentials need to be stored. Short-lived tokens keep your deployment pipelines secure without manual secret rotation.&lt;/p&gt;
&lt;h3 id="set-up-new-projects-from-your-vcs"&gt;Set up new projects from your VCS&lt;/h3&gt;
&lt;p&gt;The new project wizard discovers your organizations, repositories, and branches so you can scaffold and deploy a new stack without leaving Pulumi Cloud. Pick your repo, choose a branch, and you&amp;rsquo;re ready to deploy.&lt;/p&gt;
&lt;p&gt;&lt;img src="ado-npw.png" alt="New project wizard showing repository settings"&gt;&lt;/p&gt;
&lt;h2 id="getting-started"&gt;Getting started&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;An org admin configures the integration under &lt;strong&gt;Settings&lt;/strong&gt; &amp;gt; &lt;strong&gt;Version Control&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Authorize with your VCS provider.&lt;/li&gt;
&lt;li&gt;Deploy infrastructure with first-class workflows.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For setup details, see the docs for &lt;a href="https://www.pulumi.com/docs/version-control/github-app/"&gt;GitHub&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/version-control/github-app/#github-enterprise-server-support"&gt;GitHub Enterprise Server&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/version-control/azure-devops-integration/"&gt;Azure DevOps&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/docs/version-control/gitlab/"&gt;GitLab&lt;/a&gt;.&lt;/p&gt;
&lt;a
href="https://app.pulumi.com/signin"
class="btn btn-primary"
target="_blank"
rel="noopener noreferrer"
&gt;
Connect your VCS
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular text-sm ml-2" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.21047dcd83825f0caafb78a6fd28628a694219e6b6824f6b3e24ee3147bac331.svg#p-arrow-square-out-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;</description><author>Luke Ward</author><author>Michael Fallihee</author><author>Boris Schlosser</author><author>Dan Biwer</author><category>features</category><category>pulumi-cloud</category><category>azure</category><category>github</category><category>gitlab</category></item><item><title>New Compliance Packs for CIS, NIST, and PCI DSS</title><link>https://www.pulumi.com/blog/policy-packs-cis-nist-pci/</link><pubDate>Wed, 05 Nov 2025 00:02:00 +0000</pubDate><guid>https://www.pulumi.com/blog/policy-packs-cis-nist-pci/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/policy-packs-cis-nist-pci/index.png" /&gt;
&lt;p&gt;Achieving compliance with industry standards such as &lt;strong&gt;CIS, NIST&lt;/strong&gt;, or &lt;strong&gt;PCI DSS&lt;/strong&gt; is a foundational step for every organization. Yet for many teams, it&amp;rsquo;s often a manual, months-long process that involves interpreting controls, authoring custom policies, and validating configurations across multiple clouds. These challenges often slow progress toward a known and secure cloud state.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re changing that. To simplify this journey, Pulumi launched a new suite of &lt;strong&gt;pre-built compliance policy packs&lt;/strong&gt; for &lt;a href="https://www.pulumi.com/docs/insights/policy/policy-packs/pre-built-packs/#available-policy-packs"&gt;CIS Controls v8.1, NIST SP 800-53 Rev. 5, and PCI DSS v4.0&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;These packs are your accelerator for the &amp;ldquo;&lt;strong&gt;Get Clean&lt;/strong&gt;&amp;rdquo; journey, allowing you to enforce critical security and compliance baselines across your cloud infrastructure &lt;strong&gt;in minutes, not months&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id="more-than-just-detection-the-complete-governance-lifecycle"&gt;More Than Just Detection: The Complete Governance Lifecycle&lt;/h2&gt;
&lt;p&gt;Traditional security tools are reactive, scanning for problems &lt;em&gt;after&lt;/em&gt; resources have been deployed. With Pulumi, these new compliance packs are the engine for an end-to-end governance lifecycle that integrates directly into your cloud operations.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Audit for Full Coverage:&lt;/strong&gt; Run these packs in audit mode to scan your entire cloud estate, including resources managed by Pulumi and those created through other means. This gives you an instant, comprehensive view of your current compliance posture.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Triage and Remediate:&lt;/strong&gt; When a pack finds a violation, the finding appears in the new &lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/policy-issue-management/"&gt;Policy Findings hub&lt;/a&gt;&lt;/strong&gt;. From there, your team can triage, assign, and track the issue through its entire lifecycle. And with our new AI-powered capabilities, you can assign the issue to &lt;strong&gt;Pulumi Neo&lt;/strong&gt; to automatically generate a pull request with the fix.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prevent Non-Compliance:&lt;/strong&gt; Once your environment is clean, you use these same packs as preventative guardrails. By running them during &lt;code&gt;pulumi up&lt;/code&gt;, you block non-compliant resources &lt;em&gt;before they are ever created&lt;/em&gt;, ensuring you &amp;ldquo;Stay Clean.&amp;rdquo;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This tri-modal capability—Audit, Remediate, and Prevent—is uniquely powerful, allowing you to fix existing issues while stopping new ones from being introduced.&lt;/p&gt;
&lt;h2 id="new-and-expanded-compliance-packs"&gt;New and Expanded Compliance Packs&lt;/h2&gt;
&lt;p&gt;Our new policy packs provide extensive, out-of-the-box coverage for some of the most widely adopted security frameworks. They are authored and maintained by Pulumi experts and join our existing library to provide a comprehensive toolkit for cloud governance.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Framework&lt;/th&gt;
&lt;th style="text-align: center"&gt;AWS&lt;/th&gt;
&lt;th style="text-align: center"&gt;Azure&lt;/th&gt;
&lt;th style="text-align: center"&gt;Google Cloud&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CIS Controls v8.1&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;NIST SP 800-53 Rev. 5&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;PCI DSS v4.0&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;HITRUST CSF v11.5&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Pulumi Best Practices&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="benefits-of-pre-built-packs"&gt;Benefits of Pre-Built Packs&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Accelerate Compliance:&lt;/strong&gt; Implement comprehensive governance controls in minutes without authoring hundreds of policies from scratch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Leverage Expert Knowledge:&lt;/strong&gt; Packs are authored and maintained by Pulumi, incorporating deep expertise in cloud and the nuances of each framework.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Codify Controls for Audits:&lt;/strong&gt; Demonstrate to auditors that specific compliance controls are consistently enforced through code, providing a clear evidence trail.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduce Risk Proactively:&lt;/strong&gt; Catch common security risks and compliance violations before deployment, drastically reducing your organization&amp;rsquo;s exposure.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="get-started-today"&gt;Get Started Today&lt;/h2&gt;
&lt;p&gt;These policy packs are available now and are the perfect way to begin your governance journey with Pulumi.&lt;/p&gt;
&lt;p&gt;To get started, head to the &lt;strong&gt;Policies&lt;/strong&gt; page in your Pulumi Cloud organization and click on the &lt;strong&gt;All&lt;/strong&gt; tab to find these new packs. Add them to an &lt;strong&gt;Audit Policy Group&lt;/strong&gt; and run a scan. Within minutes, you&amp;rsquo;ll see a complete picture of your compliance posture in the &lt;strong&gt;Policy Findings hub&lt;/strong&gt;, ready for triage and remediation.&lt;/p&gt;
&lt;p&gt;Need a compliance pack for a standard that isn&amp;rsquo;t listed here? Please let us know by raising a request on our &lt;a href="https://github.com/pulumi/pulumi-cloud-requests"&gt;GitHub repository&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="try-pulumi-policies"&gt;Try Pulumi Policies&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;New to Pulumi? Start your governance journey today.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; and start a compliance task with Neo&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;Read the Get Started guide&lt;/a&gt; to apply and manage policies across your cloud infrastructure&lt;/li&gt;
&lt;li&gt;&lt;a href="https://slack.pulumi.com/"&gt;Join the Community Slack&lt;/a&gt; to share feedback on the new features&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For complete documentation, visit our &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policies documentation&lt;/a&gt;.&lt;/p&gt;</description><author>Luke Ward</author><author>Dan Biwer</author><category>pulumi-cloud</category><category>policy-as-code</category><category>crossguard</category><category>features</category><category>compliance</category><category>governance</category><category>security</category></item><item><title>Policy Comes to Team and Enterprise, with New Out-of-the-box Policies and Management Experience</title><link>https://www.pulumi.com/blog/pulumi-policy-mgmt-launch/</link><pubDate>Wed, 17 Sep 2025 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/pulumi-policy-mgmt-launch/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumi-policy-mgmt-launch/index.png" /&gt;
&lt;p&gt;Pulumi’s Infrastructure as Code has included a powerful policy engine from day one. Over the past year, we’ve been enhancing it significantly to provide stronger governance for modern cloud platforms. Until now, these capabilities were limited to our Business Critical tier. Today, we’re excited to announce that &lt;a href="https://www.pulumi.com/docs/insights/policy-as-code/"&gt;policy guardrails&lt;/a&gt; are now available to all Team and Enterprise customers. Alongside this, we’re launching a redesigned policy management experience and introducing out-of-the-box policy packs that make it easier than ever to secure, govern, and optimize your cloud environments—even when powered by AI agents like &lt;a href="https://www.pulumi.com/blog/pulumi-neo/"&gt;Pulumi Neo&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="policy-as-guardrails-for-ai-infrastructure"&gt;Policy as Guardrails for AI Infrastructure&lt;/h2&gt;
&lt;p&gt;As developer velocity accelerates, AI agents like Neo are helping teams create and manage infrastructure at unprecedented speed. That speed creates a governance challenge: how do you ensure security, compliance, and cost-effectiveness without slowing developers down?&lt;/p&gt;
&lt;p&gt;Policy guardrails provide the answer. Pulumi’s Policy as Code (PaC) framework applies DevOps best practices to governance, letting you codify rules, test them through pull requests, and version them alongside your infrastructure. With policies in place, you can ensure that every change stays within your organization’s standards, whether it is a human developer or Neo making a change.&lt;/p&gt;
&lt;h2 id="what-makes-pulumi-policy-different"&gt;What Makes Pulumi Policy Different&lt;/h2&gt;
&lt;p&gt;Unlike many other policy solutions, Pulumi Policy uses general-purpose programming languages such as TypeScript and Python rather than restrictive DSLs or YAML. This unlocks richer and more flexible capabilities, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Conditional logic&lt;/strong&gt; to codify your organization&amp;rsquo;s nuanced rules.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reusable functions and abstractions&lt;/strong&gt; to create a shared library of policies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Unit tests&lt;/strong&gt; to validate policy behavior before rollout.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With today’s updates, this foundation is easier to adopt and scale across your teams than ever before.&lt;/p&gt;
&lt;h2 id="new-simplified-experience"&gt;New Simplified Experience&lt;/h2&gt;
&lt;p&gt;While Pulumi Policy has always allowed you to enforce compliance using TypeScript and Python, the existing workflow could be cumbersome—discovering policies required switching between the console and CLI, and applying them involved multiple steps.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve removed that friction to provide the seamless guardrails needed for this high-velocity, AI-driven world. The new experience is built around a streamlined, in-console workflow for discovering, applying, and managing your policies.&lt;/p&gt;
&lt;h3 id="in-console-discoverability"&gt;In-Console Discoverability&lt;/h3&gt;
&lt;p&gt;We are making it easier to find and understand policy packs. You can now browse a rich set of pre-built policy packs directly within the Pulumi Cloud console—no CLI or context switching required.&lt;/p&gt;
&lt;p&gt;You’ll find:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;A rich browsing experience:&lt;/strong&gt; See all available policy packs in one place.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Detailed information:&lt;/strong&gt; Each pack comes with a clear description of the policies included.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Organization-approved packs:&lt;/strong&gt; Org admins can curate a list of approved policy packs, ensuring your teams—and AI agents like Neo—are using a vetted set of policies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="new-pre-built-policy-packs"&gt;New Pre-Built Policy Packs&lt;/h3&gt;
&lt;p&gt;To help you establish guardrails immediately, we have authored several &lt;a href="https://www.pulumi.com/docs/insights/pre-built-packs/"&gt;pre-built policy packs&lt;/a&gt;. We are excited to highlight two that are available today:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Pulumi Best Practices:&lt;/strong&gt; A foundational set of recommended governance and security controls that serves as a strong starting point for any organization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HITRUST CSF v11.5:&lt;/strong&gt; Provides predefined controls that help align cloud resources with HITRUST CSF requirements.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="streamlined-policy-management-and-application"&gt;Streamlined Policy Management and Application&lt;/h3&gt;
&lt;p&gt;The new policy management experience dramatically simplifies policy application:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Intuitive Interface:&lt;/strong&gt; Browse, select, and apply policies through a streamlined workflow using &lt;strong&gt;Policy Groups&lt;/strong&gt; to bundle related policies and apply them to your stacks or cloud accounts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Expanded Scale:&lt;/strong&gt; We&amp;rsquo;ve eliminated the 4,000 stack UI limit on policy groups, allowing you to scale policies across your entire infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Granular Enforcement:&lt;/strong&gt; Configure the enforcement level (&lt;code&gt;advisory&lt;/code&gt; or &lt;code&gt;mandatory&lt;/code&gt;) for policies to either warn developers or block non-compliant deployments entirely.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="preventative-and-audit-approaches"&gt;Preventative and Audit Approaches&lt;/h3&gt;
&lt;p&gt;Pulumi Policy supports two complementary approaches to governance.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Preventative policies&lt;/strong&gt;: Block non-compliant deployments during &lt;code&gt;pulumi up&lt;/code&gt;, providing real-time guardrails for developers and AI agents.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit policies&lt;/strong&gt;: Continuously scan existing resources for ongoing compliance monitoring, giving you a complete picture of your cloud security posture.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This dual approach ensures new deployments meet standards while maintaining visibility across your entire infrastructure. Learn more in our &lt;a href="https://www.pulumi.com/docs/insights/preventative-vs-audit-policies/"&gt;Preventative vs. Audit Policies&lt;/a&gt; guide.&lt;/p&gt;
&lt;h2 id="how-to-get-started"&gt;How to Get Started&lt;/h2&gt;
&lt;p&gt;Getting started with the new policy management experience is straightforward:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Browse Policy Packs:&lt;/strong&gt; Navigate to the Policies tab in your Pulumi Cloud console to discover pre-built policy packs like Pulumi Best Practices and HITRUST CSF. Learn more about &lt;a href="https://www.pulumi.com/docs/insights/policy-as-code/"&gt;Policy as Code&lt;/a&gt; configuration and setup.
&lt;img src="policy-management-1.png" alt="Policy Packs Browser"&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Choose Your Approach:&lt;/strong&gt; Decide whether you need preventative policies (to block non-compliant deployments during &lt;code&gt;pulumi up&lt;/code&gt;) or audit policies (for continuous compliance monitoring across all cloud resources).
&lt;img src="policy-management-3.png" alt="Preventative Policy Overview"&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Create Policy Groups:&lt;/strong&gt; Set up policy groups to bundle related policies and apply them to your stacks or cloud accounts.
&lt;img src="policy-management-4.png" alt="Policy Group Configuration"&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure Enforcement:&lt;/strong&gt; Set enforcement levels (advisory, mandatory, or remediate) for each policy based on your requirements.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="now-available-to-team-and-enterprise-customers"&gt;Now Available To Team and Enterprise Customers&lt;/h2&gt;
&lt;p&gt;To ensure every organization can build with confidence, these policy management enhancements and the &lt;code&gt;pulumi-best-practices&lt;/code&gt; policy packs are &lt;strong&gt;now available to Team and Enterprise customers&lt;/strong&gt;. Checkout our &lt;a href="https://www.pulumi.com/pricing"&gt;pricing&lt;/a&gt; page for more information.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Governance doesn’t need to be a roadblock—it can be a foundation that accelerates innovation. With enhanced policy management and ready-to-use guardrails, Pulumi helps your teams and AI agents like Neo move fast while staying secure, compliant, and cost effective.&lt;/p&gt;
&lt;p&gt;Try the new experience in Pulumi Cloud today, and let us know what you think in the &lt;a href="https://slack.pulumi.com/"&gt;Pulumi Community Slack&lt;/a&gt;.&lt;/p&gt;</description><author>Luke Ward</author><author>Dan Biwer</author><author>Alejandro Cotroneo</author><category>pulumi-cloud</category><category>policy-as-code</category><category>crossguard</category><category>features</category><category>user-experience</category><category>pulumi-neo</category><category>ai</category></item></channel></rss>