<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Pulumi Blog: Sara Huddleston</title><link>https://www.pulumi.com/blog/author/sara-huddleston/</link><description>Pulumi blog posts: Sara Huddleston.</description><language>en-us</language><pubDate>Thu, 04 Dec 2025 07:56:40 +0000</pubDate><item><title>Future of the Cloud: 10 Trends Shaping 2026 and Beyond</title><link>https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/</link><pubDate>Thu, 04 Dec 2025 07:56:40 +0000</pubDate><guid>https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/index.png" /&gt;
&lt;p&gt;In 2026, several trends will dominate cloud computing, driving innovation, efficiency, and scalability. From Infrastructure as Code (IaC) to AI/ML, platform engineering to multi-cloud and hybrid strategies, and security practices, let&amp;rsquo;s explore the 10 biggest emerging trends.&lt;/p&gt;
&lt;h2 id="on-this-article"&gt;On This Article&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#1-cloud-will-become-a-business-necessity-by-2028"&gt;1. Cloud Will Become a Business Necessity by 2028&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#2-hyperscalers-accelerate-ai-driven-cloud-expansion"&gt;2. Hyperscalers Accelerate AI-Driven Cloud Expansion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#3-hybrid-and-multi-cloud-to-drive-innovation"&gt;3. Hybrid and Multi-Cloud to Drive Innovation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#4-enterprises-rebuild-their-cloud-foundations-to-operationalize-ai"&gt;4. Enterprises Rebuild Their Cloud Foundations to Operationalize AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#5-iac-drives-scalable-cloud-multi-cloud-and-ai-operations"&gt;5. IaC Drives Scalable Cloud, Multi-Cloud, and AI Operations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#6-devsecops-evolves-into-ai-integrated-security"&gt;6. DevSecOps Evolves Into AI-Integrated Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#7-platform-engineering--internal-developer-platforms-idps"&gt;7. Platform Engineering and Internal Developer Platforms&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#8-aiops-matures-into-a-cloud-operations-standard"&gt;8. AIOps Matures Into a Cloud Operations Standard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#9-kubernetes-dominance-and-increased-complexity"&gt;9. Kubernetes Dominance and Increased Complexity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#10-ai-code-assistants-in-the-enterprise"&gt;10. AI Code Assistants in the Enterprise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#the-future-of-cloud-reinvented-for-an-ai-first-decade"&gt;The Future of Cloud: Reinvented for an AI-First Decade&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="1-cloud-will-become-a-business-necessity-by-2028"&gt;1. Cloud Will Become a Business Necessity by 2028&lt;/h2&gt;
&lt;p&gt;According to &lt;a href="https://www.gartner.com/en/infrastructure-and-it-operations-leaders/topics/cloud-computing"&gt;Gartner&lt;/a&gt;, by 2028 the cloud will be the key driver for business innovation, and estimates that over 95% of new digital workloads will be deployed on cloud-native platforms.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/gartner-cloud-2028.png"
alt="The future of cloud computing. Credit: Gartner" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;The future of cloud computing. Credit: Gartner&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;According to McKinsey &amp;amp; Company&amp;rsquo;s &amp;ldquo;&lt;a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/in-search-of-cloud-value-can-generative-ai-transform-cloud-roi"&gt;In search of cloud value&lt;/a&gt;&amp;rdquo; report:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloud value is driven by innovation&lt;/strong&gt;, worth 5x more than cost savings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EBITDA uplift of 20–30% by 2030&lt;/strong&gt; for high-performing organizations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Asia leads in projected cloud value&lt;/strong&gt;, followed by the US and Europe.&lt;/li&gt;
&lt;li&gt;High-ROI organizations excel by aligning cloud strategy with business priorities, building strong cloud foundations, and using modern operating models.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Teams succeeding in this transition increasingly use Infrastructure as Code, automation, and unified governance frameworks like &lt;a href="https://www.pulumi.com/product/insights-governance/"&gt;Pulumi Insights + Policies&lt;/a&gt; to operationalize this value.&lt;/p&gt;
&lt;h2 id="2-hyperscalers-accelerate-ai-driven-cloud-expansion"&gt;2. Hyperscalers Accelerate AI-Driven Cloud Expansion&lt;/h2&gt;
&lt;p&gt;Hyperscalers are making the largest infrastructure investments in cloud history — nearly all centered on AI workloads, inference, and high-performance compute.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AWS&lt;/strong&gt; has integrated &lt;a href="https://www.aboutamazon.com/news/aws/anthropic-claude-4-opus-sonnet-amazon-bedrock"&gt;Anthropic’s Claude 3 and Claude 4 models into Amazon Bedrock&lt;/a&gt; for enterprise LLM workflows. “Claude Opus 4 and Claude Sonnet 4 are available today in Amazon Bedrock, enabling customers to build agents with stronger reasoning, memory, and tool use.” — AWS, May 2025&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Azure&lt;/strong&gt; revenue rose 33% year-over-year in Q3 (ended March 31), outperforming estimates of ~29.7%. &lt;a href="https://www.reuters.com/business/microsoft-beats-quarterly-revenue-estimates-ai-shift-bolsters-cloud-demand-2025-04-30/"&gt;AI contributed 16 percentage points to this growth&lt;/a&gt;, up from 13 points in the prior quarter. &amp;ldquo;Microsoft is on track to invest approximately $80 billion to build out AI-enabled datacenters to train AI models and deploy AI and cloud-based applications around the world,&amp;rdquo; said Brad Smith, the Microsoft Vice Chair and President.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Google Cloud&lt;/strong&gt; is committing &lt;a href="https://www.utilitydive.com/news/google-cloud-blackstone-aws-us-ai-data-center-buildouts/753202"&gt;$25 billion over two years for data center and AI infrastructure expansion&lt;/a&gt; across the PJM grid, with total capital expenditure for 2025 ranging from $75–85 billion. &amp;ldquo;As our CEO has said, in these early days of a very transformative technology, the risks of under-investing are dramatically higher than the risks of over-investing,&amp;rdquo; said Eunice Huang, Head of AI and Emerging Tech Policy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Oracle&lt;/strong&gt; anticipates 15–20% cloud revenue growth in FY 2026–2027 attributable to AI infrastructure demand, tied to its partnership in the &lt;a href="https://www.pcgamer.com/software/ai/openais-skyrocketing-spending-could-see-billions-of-dollars-in-silicon-headed-down-the-ai-mines-in-the-next-few-years-including-2-million-nvidia-chips-headed-to-texas-stargate-facility/"&gt;Stargate initiative&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As hyperscalers integrate AI deeper into their service layers, engineering teams must adapt with IaC-driven automation, reusable patterns, and policy controls to deploy cloud and AI infrastructure consistently.
See how organizations &lt;a href="https://www.pulumi.com/aws/#video"&gt;deploy AWS infrastructure at the speed of AI with Pulumi&lt;/a&gt; and &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Pulumi Policies&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="3-hybrid-and-multi-cloud-to-drive-innovation"&gt;3. Hybrid and Multi-Cloud to Drive Innovation&lt;/h2&gt;
&lt;p&gt;Hybrid and multi-cloud strategies are now mainstream:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hybrid cloud will grow from &lt;strong&gt;$130B to $310–330B&lt;/strong&gt; by 2030 (&lt;a href="https://www.businesswire.com/news/home/20250513124988/en/Hybrid-Cloud-Market-Analysis-Growth-Trends-and-Forecasts-Report-2024-2025-2030-Surging-Demand-for-Seamless-Interoperability-Between-Cloud-Services-and-Existing-Systems---ResearchAndMarkets.com"&gt;ResearchAndMarkets&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;87% of enterprises&lt;/strong&gt; run workloads across multiple clouds (&lt;a href="https://www.mordorintelligence.com/industry-reports/hybrid-cloud-market"&gt;Mordor Intelligence&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Gartner predicts that &lt;strong&gt;40% of enterprises&lt;/strong&gt; will adopt hybrid compute architectures in mission-critical workflows by 2028 (up from 8%).&lt;/li&gt;
&lt;/ul&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/most-popular-cloud-computing-infrastructure-by-industry.png"
alt="Most popular cloud computing infrastructure by industry. Credit: Cloud Worldwide Service, Forbes" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Credit: Cloud Worldwide Service, Forbes&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;As AI and regulatory requirements grow, organizations must deploy workloads across AWS, Azure, Google Cloud, on-prem, and edge — while maintaining consistent security, compliance, and configuration.&lt;/p&gt;
&lt;p&gt;Modern cloud teams use:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Infrastructure as Code&lt;/strong&gt; for consistent multi-cloud provisioning and environment standardization, forming the backbone of AI infrastructure orchestration&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reusable components and internal platforms&lt;/strong&gt; to define scalable architecture patterns and accelerate delivery across Kubernetes, AI/ML pipelines, and hybrid environments&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Policy-driven guardrails&lt;/strong&gt; to maintain cost, security, and compliance across environments, supporting cloud governance automation and modern cloud cost governance&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pulumi enables all three through its &lt;a href="https://www.pulumi.com/docs/iac/"&gt;multi-cloud IaC model&lt;/a&gt;, &lt;a href="https://www.pulumi.com/product/insights-governance#video"&gt;Pulumi Policies&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/product/internal-developer-platforms/#video"&gt;internal developer platform capabilities&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="4-enterprises-rebuild-their-cloud-foundations-to-operationalize-ai"&gt;4. Enterprises Rebuild Their Cloud Foundations to Operationalize AI&lt;/h2&gt;
&lt;p&gt;While hyperscalers are transforming the global cloud platform, enterprises face a different challenge: adapting their own cloud foundations to support AI at scale. Organizations are moving beyond prototypes and integrating AI into core products, internal workflows, and customer-facing systems, requiring new levels of automation, governance, and AI infrastructure orchestration.&lt;/p&gt;
&lt;p&gt;According to &lt;a href="https://www.networkworld.com/article/4058786/gartner-ai-spending-to-reach-1-5-trillion-dollars-this-year.html"&gt;Gartner&lt;/a&gt;, global AI infrastructure spending is expected to surpass &lt;strong&gt;$2 trillion in 2026&lt;/strong&gt;. &lt;a href="https://blogs.idc.com/2025/10/22/futurescape-2026-moving-into-the-agentic-future/"&gt;IDC predicts that by 2027&lt;/a&gt;, more than 50% of enterprises will use AI agents to drive core workflows, which requires scalable, secure, and automated cloud architectures to support model execution and orchestration.&lt;/p&gt;
&lt;p&gt;To enable this transition, enterprises are investing in:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;GPU provisioning and orchestration&lt;/strong&gt;, data pipelines, vector databases, feature stores, and LLM infrastructure needed for real-time AI workloads.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data pipelines, vector databases, and feature stores&lt;/strong&gt; needed for real-time AI workloads&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Model-serving infrastructure&lt;/strong&gt;, including gateways, inference routers, and autoscaling layers&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Strong identity, secrets, and access controls&lt;/strong&gt; as AI systems increase security exposure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automation through Infrastructure as Code&lt;/strong&gt; to ensure reproducibility and reduce drift&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Policy-driven governance&lt;/strong&gt; to secure cost, compliance, and architectural consistency&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As AI becomes deeply embedded across engineering organizations, teams are increasingly using software engineering approaches such as Infrastructure as Code, reusable components, platform engineering, and policy automation to standardize how AI infrastructure is deployed, scaled, and secured across clouds.&lt;/p&gt;
&lt;p&gt;To support this shift, Pulumi&amp;rsquo;s perspective on &lt;a href="https://www.pulumi.com/product/superintelligence-infrastructure/"&gt;Superintelligence Infrastructure&lt;/a&gt; explains why AI workloads, from pre-training to inference at massive scale, require dynamic infrastructure orchestration rather than static configuration.&lt;/p&gt;
&lt;h3 id="pulumi-users-increasingly-rely-on"&gt;Pulumi users increasingly rely on:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/iac/"&gt;Pulumi IaC&lt;/a&gt; for standardized AI infrastructure&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Pulumi ESC&lt;/a&gt; to manage all secrets and configuration at scale&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/insights-governance/"&gt;Pulumi Insights&lt;/a&gt; for visibility and misconfiguration analysis&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Pulumi Policies&lt;/a&gt; for AI-specific guardrails in code, cost detection, and to provide automated compliance protections&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="5-iac-drives-scalable-cloud-multi-cloud-and-ai-operations"&gt;5. IaC Drives Scalable Cloud, Multi-Cloud, and AI Operations&lt;/h2&gt;
&lt;p&gt;As cloud environments expand and AI workloads demand highly dynamic infrastructure, Infrastructure as Code (IaC) is becoming the foundation for scaling reliably across all environments. Organizations are increasingly adopting IaC in general-purpose languages to unify development and infrastructure workflows, reduce configuration drift, and deliver cloud resources at speed.&lt;/p&gt;
&lt;p&gt;Modern &lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;Infrastructure as Code&lt;/a&gt; is advancing far beyond simple provisioning:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Standardizing multi-cloud and hybrid patterns&lt;/strong&gt; so teams can deploy consistently across AWS, Azure, Google Cloud, on-prem, and edge environments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Integrating seamlessly with cloud providers and third-party services&lt;/strong&gt;, including data platforms and messaging systems like CockroachDB, Confluent Cloud, and Kafka.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Providing deeper validation and type-safety&lt;/strong&gt;, ensuring parameters, dependencies, and security controls are correct before deployment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Improving cloud resource efficiency and visibility&lt;/strong&gt; with tools like &lt;a href="https://www.pulumi.com/docs/insights/discovery/"&gt;Pulumi Insights Discovery&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Embedding security and compliance through &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policy as Code&lt;/a&gt;&lt;/strong&gt;, enforcing guardrails, cost controls, and regulatory requirements automatically, enabling truly policy-driven cloud management.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enabling intelligent automation&lt;/strong&gt;, from unit and integration tests to auto-remediation policies and policy-driven approvals.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Incorporating AI-driven optimization and insights&lt;/strong&gt;, helping teams detect misconfigurations, analyze usage patterns, and generate infrastructure updates with tools like &lt;a href="https://www.pulumi.com/product/neo/"&gt;Pulumi Neo&lt;/a&gt; and &lt;a href="https://www.pulumi.com/blog/policy-next-gen/"&gt;Pulumi Policies&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As organizations scale both traditional cloud workloads and AI-driven systems, IaC has become critical for achieving secure, repeatable, and high-velocity operations across every environment.&lt;/p&gt;
&lt;h2 id="6-devsecops-evolves-into-ai-integrated-security"&gt;6. DevSecOps Evolves Into AI-Integrated Security&lt;/h2&gt;
&lt;p&gt;As AI becomes embedded across cloud-native systems, DevSecOps is entering a new era. Gartner predicts that by &lt;strong&gt;2028, over 50% of enterprises will use AI security platforms&lt;/strong&gt; to protect their AI investments. Below are the 3 key predictions for the future of DevSecOps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;AI-driven security automation&lt;/strong&gt;: Teams will increasingly rely on AI to detect threats, enforce policies, and generate secure infrastructure patches. See Pulumi’s capabilities in &lt;a href="https://www.pulumi.com/product/insights-governance/#video"&gt;AI-powered remediation&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;More focus on secrets management&lt;/strong&gt;: With AI systems accessing more sensitive data, secure secret storage will be essential. &lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Pulumi ESC&lt;/a&gt; helps teams centralize and govern credentials, keys, and tokens safely.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Greater cross-team collaboration&lt;/strong&gt;: Dev, Sec, and Ops workflows will converge under shared frameworks: IaC, policy automation, runtime scanning, and GitOps.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;As organizations increase their use of AI across cloud-native systems, the need for tightly aligned security, governance, and cloud governance automation becomes even more urgent. At the Gartner Data &amp;amp; Analytics Summit in Sydney, Carlie Idoine, VP Analyst at Gartner, emphasized this growing dependency:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;[AI]&amp;hellip; it doesn’t deliver value on its own – AI needs to be tightly aligned with data, analytics, and governance to enable intelligent, adaptive decisions and actions across the organization.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This perspective mirrors what we’re seeing across modern DevSecOps practices: AI can amplify security, but only when paired with strong foundations in secrets management, governance, and cross-team collaboration.&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Build for an AI-first cloud&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Pulumi gives teams infrastructure as code, reusable components, and policy guardrails to deliver consistently across every cloud and AI workload.&lt;/div&gt;
&lt;a href="https://app.pulumi.com/signup" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Get started
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="7-platform-engineering--internal-developer-platforms-idps"&gt;7. Platform Engineering &amp;amp; Internal Developer Platforms (IDPs)&lt;/h2&gt;
&lt;p&gt;According to &lt;a href="https://www.gartner.com/en/articles/what-is-platform-engineering"&gt;Gartner&lt;/a&gt;, &lt;strong&gt;by 2026, 80% of large software engineering organizations will establish platform engineering teams&lt;/strong&gt; as internal providers of reusable services, components, and tools for application delivery. Platform engineering will ultimately solve the central problem of cooperation between software developers and operators.&lt;/p&gt;
&lt;p&gt;Mid-size to large companies will begin or continue to invest in implementing &lt;a href="https://www.pulumi.com/blog/platform-engineering-pillars-3/"&gt;platform engineering practices&lt;/a&gt;, with large tech companies as first adopters. They will provide &lt;a href="https://www.pulumi.com/blog/announcing-pulumi-idp/"&gt;Internal Developer Platforms (IDP)&lt;/a&gt; to elevate the &lt;a href="https://www.pulumi.com/blog/developer-experience-business-critical/"&gt;Developer Experience&lt;/a&gt; (DX, sometimes referred to as DE or DevEx), helping them work faster, like abstracting the complexities of configuring, testing, and validation, deploying infrastructure, and scanning their code for security.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-portal-platform-teams/platform-teams.png"
alt="Internal developer platform-in-a-box. Credit: Pulumi" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Internal developer platform-in-a-box. Credit: Pulumi&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;IDPs are reshaping how developers interact with cloud infrastructure, bringing together platform engineering, automation, and emerging AI platform engineering practices.&lt;/p&gt;
&lt;h2 id="8-aiops-matures-into-a-cloud-operations-standard"&gt;8. AIOps Matures into a Cloud Operations Standard&lt;/h2&gt;
&lt;p&gt;AIOps is becoming mainstream, helping teams predict failures, auto-scale infrastructure, and resolve incidents with minimal manual effort. As AI and automation continue to evolve, the fusion of these technologies will enable organizations to achieve unprecedented levels of efficiency and scalability.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Proactive Operations&lt;/strong&gt;: AI-powered tools will assist teams in foreseeing issues with greater accuracy, minimizing downtime, and reducing the firefighting nature of incident management. These tools will automatically detect anomalies, optimize performance, and trigger remediation actions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/automation-api/"&gt;Intelligent Automation&lt;/a&gt;&lt;/strong&gt;: Routine operational tasks like patching, monitoring, and resource scaling will be fully automated. AI-driven decision-making will allow for smarter resource allocation and optimization, dynamically adjusting infrastructure and workloads in response to real-time demands and predictions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/insights/"&gt;Data-Driven Insights&lt;/a&gt;&lt;/strong&gt;: AIOps will analyze vast amounts of operational data and provide actionable insights, enabling teams to focus on high-impact tasks such as improving system architecture and user experience. The AI-powered insights will also inform better strategic decisions, helping teams to continuously evolve their DevOps practices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Collaboration Across Teams&lt;/strong&gt;: AIOps will bridge the gap between DevOps, SecOps, and IT operations by bridging monitoring and automation. Cross-team collaboration will improve as AI systems consolidate and interpret data from various departments, allowing for a more cohesive approach to system management.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;AIOps features include observability, automation, and real-time analytics to bridge DevOps, SRE, and IT operations.&lt;/p&gt;
&lt;h2 id="9-kubernetes-dominance-and-increased-complexity"&gt;9. Kubernetes Dominance and Increased Complexity&lt;/h2&gt;
&lt;p&gt;Kubernetes will continue its ascent in 2026. According to &lt;a href="https://www.researchandmarkets.com/reports/6110428/kubernetes-global-strategic-business-report"&gt;Research &amp;amp; Markets&lt;/a&gt;, the global Kubernetes market was valued at USD 2.3 billion in 2024 and is projected to reach USD 8.2 billion by 2030, with a CAGR of 23.8% over the forecast period.&lt;/p&gt;
&lt;p&gt;The CNCF Annual Survey shows AI/ML workloads rapidly moving onto Kubernetes — including batch pipelines, model experimentation, real-time inference, and data preprocessing — even as only 41% of ML/AI developers are cloud-native today. This shift is accelerating as teams need flexible GPU scheduling, distributed pipelines, and portable execution environments.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#the-2026-convergence-of-ai-platforms-and-policy-in-kubernetes"&gt;Kubernetes is also evolving in response to AI demands&lt;/a&gt;. Inference workloads, powered by LLMs and GPUs, now require low-latency execution closer to the user. This shift is pushing organizations to build intelligent orchestration layers that schedule AI pipelines across edge and core clusters, often leveraging Kubernetes as the common control plane for AI cluster orchestration.&lt;/p&gt;
&lt;p&gt;As we move into 2026, three patterns are becoming clear:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Kubernetes is evolving to support AI&lt;/strong&gt; through GPU-aware scheduling, Kubernetes GPU scheduling optimizations, and more advanced workload orchestration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Governance and consistency matter more than ever&lt;/strong&gt;, as teams struggle to secure and manage multi-cluster, multi-cloud environments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Platform engineering is essential&lt;/strong&gt;, providing curated patterns and automation rather than raw YAML to reduce cognitive load.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Kubernetes will remain a strategic foundation — but operating it effectively now depends on robust automation, strong security controls, and standardized delivery models that scale across clouds, clusters, and AI pipelines.&lt;/p&gt;
&lt;h2 id="10-ai-code-assistants-in-the-enterprise"&gt;10. AI Code Assistants in the Enterprise&lt;/h2&gt;
&lt;p&gt;AI-powered coding assistants like GitHub Copilot, Claude Code, Cursor, and others are rapidly becoming part of modern software development.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;By 2027, the use of AI assistants will dramatically increase developer velocity&lt;/strong&gt; to meet functional business requirements for 70% of new digital solutions in production (source: &lt;a href="https://www.digitalnewsasia.com/business/idc-reveals-its-top-predictions-cloud-2023-and-beyond"&gt;IDC&lt;/a&gt;).&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/ai_code_assistants_value.png"
alt="The value of AI code assistants. Credit: Gartner" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;The value of AI code assistants. Credit: Gartner&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;According to &lt;a href="https://www.gartner.com/en/newsroom/press-releases/2024-04-11-gartner-says-75-percent-of-enterprise-software-engineers-will-use-ai-code-assistants-by-2028"&gt;Gartner&lt;/a&gt;, &lt;strong&gt;by 2028, 75% of enterprise software engineers will use dedicated AI code assistants&lt;/strong&gt;, and 63% of organizations are currently piloting, deploying or beginning to use AI code assistants.&lt;/p&gt;
&lt;p&gt;As enterprise adoption of AI assistants increases, expectations are rising: they must not only generate code but also understand the state of infrastructure, configurations, and security posture. That means being able to answer questions about environments, surface misconfigurations, or act directly on infrastructure.&lt;/p&gt;
&lt;p&gt;One of the newest developments is the release of &lt;a href="https://www.pulumi.com/blog/pulumi-agent-skills/"&gt;Pulumi Agent Skills&lt;/a&gt;, a collection of infrastructure expertise packaged for use in AI coding assistants. These skills teach tools such as Claude Code, Cursor, or Gemini CLI to reason about Pulumi projects, reducing hallucination and improving outputs based on real infrastructure conventions and practices.&lt;/p&gt;
&lt;p&gt;Combined with infrastructure access via tools like &lt;a href="https://www.pulumi.com/blog/remote-mcp-server/"&gt;Pulumi’s Remote MCP Server&lt;/a&gt;, teams can build secure, AI-driven workflows where assistants provide insights and Pulumi Neo safely executes actions with previews, policies, and orchestration.&lt;/p&gt;
&lt;p&gt;AI code assistants are no longer experimental; they&amp;rsquo;re fast becoming a competitive advantage in cloud software development.&lt;/p&gt;
&lt;h2 id="the-future-of-cloud-reinvented-for-an-ai-first-decade"&gt;The Future of Cloud: Reinvented for an AI-First Decade&lt;/h2&gt;
&lt;p&gt;Cloud infrastructure is entering its most transformative era since the rise of Kubernetes. The trends shaping 2026 reveal a clear pattern: AI is no longer a workload — it’s becoming the organizing principle of cloud strategy.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI-native cloud architectures&lt;/strong&gt; that require elastic compute, GPU orchestration, fast data access, and governance built into every layer&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Infrastructure as Code as the operational backbone&lt;/strong&gt;, standardizing deployments across AI, cloud, and hybrid environments&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Platform engineering and IDPs&lt;/strong&gt; to enable self-service, gold-standard patterns, and automated guardrails&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security integrated into every pipeline&lt;/strong&gt;, with AI-assisted threat detection, strong secrets management, and policy-driven compliance&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AIOps and intelligent automation&lt;/strong&gt; are becoming standard for scaling modern cloud systems&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Kubernetes evolving for AI&lt;/strong&gt;, driving new orchestration patterns across edge, core, and inference clusters&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Multi-cloud and hybrid ecosystems&lt;/strong&gt; accelerating to support interoperability, resilience, and global workload placement&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Taken together, these shifts point to a new model of cloud operations that is intelligent, automated, policy-aware, and built on software engineering principles rather than manual configuration.&lt;/p&gt;
&lt;p&gt;Organizations that invest now in &lt;strong&gt;modern IaC&lt;/strong&gt;, &lt;strong&gt;unified governance&lt;/strong&gt;, &lt;strong&gt;reusable components&lt;/strong&gt;, and &lt;strong&gt;policy frameworks&lt;/strong&gt; — all core capabilities of the Pulumi Cloud platform — will be positioned to lead in an AI-first world. The gap between teams that modernize and those that do not will widen rapidly in 2026 and beyond.&lt;/p&gt;
&lt;a
href="https://www.pulumi.com/docs/get-started/"
class="btn btn-primary"
&gt;
Try Pulumi for Free
&lt;/a&gt;</description><author>Sara Huddleston</author><category>ai</category><category>cloud-native</category><category>infrastructure-as-code</category><category>cloud-computing</category><category>multi-cloud</category><category>platform-engineering</category><category>devops</category><category>devsecops</category><category>security</category><category>kubernetes</category></item><item><title>Beyond YAML in Kubernetes: The 2026 Automation Era</title><link>https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/</link><pubDate>Wed, 12 Nov 2025 07:09:46 +0000</pubDate><guid>https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/beyond-yaml-kubernetes-2026-automation-era/index.png" /&gt;
&lt;p&gt;Kubernetes continues to evolve, powering not only applications but entire AI and ML systems across clouds, edges, and enterprises. By 2026, DevOps engineers, SREs, cloud engineers, and platform teams face growing pressure to deliver faster, smarter, and more secure infrastructure at scale.&lt;/p&gt;
&lt;p&gt;Kubernetes automation is entering a new era where infrastructure as code, policy enforcement, and AI-driven orchestration work together to manage cloud environments intelligently.&lt;/p&gt;
&lt;p&gt;Pulumi’s 2025 advancements, including &lt;a href="https://www.pulumi.com/blog/pko-2-0-ga/"&gt;Pulumi Kubernetes Operator 2.0 GA&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/iac/clouds/kubernetes/guides/playbooks/"&gt;new Kubernetes best practices playbooks&lt;/a&gt;, &lt;a href="https://www.pulumi.com/product/neo/"&gt;Pulumi Neo&lt;/a&gt; for AI assisted infrastructure management, and &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policy Automation&lt;/a&gt;, set the foundation for a new era of Kubernetes automation that extends across every role involved in managing modern infrastructure.&lt;/p&gt;
&lt;h2 id="in-this-kubernetes-article"&gt;In this Kubernetes article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#why-kubernetes-needs-to-go-beyond-yaml"&gt;Why Kubernetes Needs to Go Beyond YAML&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#the-2026-convergence-of-ai-platforms-and-policy-in-kubernetes"&gt;The 2026 Convergence of AI, Platforms, and Policy in Kubernetes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#the-2026-shift-ai-assisted-kubernetes-operations"&gt;The 2026 Shift: AI-Assisted Kubernetes Operations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#operator-first-kubernetes-deploys-your-cloud"&gt;Operator-First: Kubernetes Deploys Your Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#intelligent-infrastructure-across-every-cloud"&gt;Intelligent Kubernetes Infrastructure Across Every Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#bring-your-yaml-and-helm-then-evolve"&gt;Bring Your YAML and Helm, Then Evolve&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#begin-your-kubernetes-automation-journey"&gt;Begin Your Kubernetes Automation Journey&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#workshop-from-zero-to-production-in-kubernetes"&gt;Workshop: From Zero to Production in Kubernetes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#final-thoughts"&gt;Final Thoughts&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="why-kubernetes-needs-to-go-beyond-yaml"&gt;Why Kubernetes Needs to Go Beyond YAML&lt;/h2&gt;
&lt;p&gt;The article &lt;a href="https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/"&gt;&lt;em&gt;Kubernetes Best Practices I Wish I Had Known Before&lt;/em&gt;&lt;/a&gt; highlights a key challenge: relying solely on YAML as the source of truth for Kubernetes is no longer sustainable. Clusters are dynamic, environments multiply, and static YAML files cannot keep up with the complexity of modern infrastructure.&lt;/p&gt;
&lt;p&gt;Teams across disciplines face similar challenges:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Multi-cluster and hybrid-cloud sprawl&lt;/li&gt;
&lt;li&gt;Inefficient manual configuration and drift&lt;/li&gt;
&lt;li&gt;Lack of policy enforcement and governance at scale&lt;/li&gt;
&lt;li&gt;Secrets scattered across systems&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pulumi addresses these challenges by introducing &lt;strong&gt;general-purpose programming languages&lt;/strong&gt; such as TypeScript, JavaScript, Python, Go, .NET, and Java into Kubernetes management. This approach enables teams to define, test, and share reusable infrastructure code, bridging the gap between declarative manifests and modern software engineering practices.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/Q8WKLq-v_6k?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;Learn more: &lt;a href="https://www.pulumi.com/docs/iac/clouds/kubernetes/"&gt;Pulumi Kubernetes documentation&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="the-2026-convergence-of-ai-platforms-and-policy-in-kubernetes"&gt;The 2026 Convergence of AI, Platforms, and Policy in Kubernetes&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://www.cncf.io/wp-content/uploads/2025/11/cncf_report_stateofcloud_111025a.pdf"&gt;CNCF State of Cloud Native Development Q3 2025&lt;/a&gt; report shows that more than half of DevOps professionals and nearly a third of all developers now identify as cloud native. Adoption of hybrid and multi-cloud architectures continues to grow, while AI and ML workloads are becoming first-class citizens in Kubernetes environments. The report notes that 41% of professional ML and AI developers are cloud native, confirming that Kubernetes has become a foundational technology for building intelligent, scalable systems.&lt;/p&gt;
&lt;p&gt;This trend highlights how the next generation of Kubernetes operations is evolving. Teams need unified platforms that simplify AI-driven workloads, automatically enforce governance, and reduce operational complexity across environments. Pulumi already delivers this through an integrated platform that brings automation, security, and developer productivity together in one place.&lt;/p&gt;
&lt;p&gt;Pulumi’s platform provides a complete foundation for intelligent infrastructure management that extends from development to production.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/neo/"&gt;&lt;strong&gt;Pulumi Neo&lt;/strong&gt;&lt;/a&gt; adds AI-assisted infrastructure management that turns natural language into production-ready Kubernetes and cloud code.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/internal-developer-platforms/"&gt;&lt;strong&gt;Pulumi IDP&lt;/strong&gt;&lt;/a&gt; enables engineering and platform teams to build self-service environments that abstract complexity for developers while maintaining consistency and control.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/insights-governance/"&gt;&lt;strong&gt;Pulumi Policies&lt;/strong&gt;&lt;/a&gt; brings continuous compliance and policy enforcement directly into the delivery workflow.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;&lt;strong&gt;Pulumi ESC&lt;/strong&gt;&lt;/a&gt; secures credentials, API keys, and sensitive configurations across Kubernetes and cloud environments.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Together, these capabilities form a unified automation and governance layer for Kubernetes and cloud native systems.&lt;/p&gt;
&lt;p&gt;The result is a model where infrastructure, policy, and developer experience work together to power secure, scalable, and AI-ready platforms that meet the needs of engineering teams of every size and discipline, from application development to security and cloud operations.&lt;/p&gt;
&lt;h2 id="the-2026-shift-ai-assisted-kubernetes-operations"&gt;The 2026 Shift: AI-Assisted Kubernetes Operations&lt;/h2&gt;
&lt;p&gt;The next phase of Kubernetes management will be AI-driven, context-aware, and self-healing. Infrastructure will not only follow instructions but also understand intent. This is the vision behind &lt;a href="https://www.pulumi.com/product/neo/"&gt;&lt;strong&gt;Pulumi Neo&lt;/strong&gt;&lt;/a&gt;, an AI Infrastructure Agent designed to help teams automate complex systems.&lt;/p&gt;
&lt;p&gt;Pulumi Neo can interpret natural-language requests such as “deploy a GPU-backed EKS cluster with three node groups,” generate infrastructure code that adheres to organizational policies, and continuously refine that code as environments change.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI-powered observability and decision-making.&lt;/strong&gt; According to the &lt;a href="https://www.cncf.io/reports/cncf-annual-survey-2024/"&gt;CNCF Annual Survey&lt;/a&gt;, 93% of organizations already use or plan to adopt AI-driven monitoring and predictive analysis for Kubernetes environments. The goal is to identify performance and reliability issues before they affect users. Pulumi Policies assists to get clean and stay clean, while Neo extends this capability by acting on those insights, transforming detected issues into actionable infrastructure updates that teams can validate or deploy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ML and GPU workloads on Kubernetes.&lt;/strong&gt; As organizations expand AI and ML pipelines across clusters, automation and cost efficiency become critical (&lt;a href="https://www.finops.org/wg/scaling-kubernetes-for-ai-ml-workloads-with-finops/"&gt;FinOps Foundation&lt;/a&gt;). &lt;a href="https://www.pulumi.com/docs/insights/discovery/get-started/"&gt;Pulumi Insights&lt;/a&gt; is an intelligent infrastructure management service that helps you discover, understand, manage, and improve your infrastructure. Insights improves security, compliance, and efficiency through AI-powered asset and compliance management.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Unifying DevOps, SRE, and MLOps workflows.&lt;/strong&gt; The convergence of software and model delivery continues to accelerate (&lt;a href="https://www.techradar.com/pro/breaking-silos-unifying-devops-and-mlops-into-a-unified-software-supply-chain"&gt;TechRadar&lt;/a&gt;). Pulumi’s code-based approach, combined with Neo’s agentic reasoning, creates a unified workflow for infrastructure, applications, and AI systems.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional insights and demonstrations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/neo/#video"&gt;Founder/CEO Joe Duffy on Pulumi Neo’s AI Infrastructure Agent vision&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.linkedin.com/feed/update/urn:li:activity:7391188887337000960"&gt;Pulumi Neo 90sec demo and agentic workflows&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Kubernetes and Pulumi Neo together represent a future of &lt;strong&gt;autonomous infrastructure management&lt;/strong&gt;, where AI assists teams in deploying, maintaining, and improving their environments intelligently and securely.&lt;/p&gt;
&lt;h2 id="operator-first-kubernetes-deploys-your-cloud"&gt;Operator-First: Kubernetes Deploys Your Cloud&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://www.pulumi.com/blog/pulumi-kubernetes-operator-2-0-ga/"&gt;Pulumi Kubernetes Operator 2.0 GA&lt;/a&gt; introduced a Kubernetes-native approach to infrastructure management. Each Pulumi stack becomes a &lt;strong&gt;Kubernetes Custom Resource&lt;/strong&gt;, allowing Kubernetes itself to execute Pulumi programs written in any supported language. This enables:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Management of AWS, Azure, and GCP infrastructure from within the cluster&lt;/li&gt;
&lt;li&gt;Integration with GitOps systems such as Argo CD and Flux&lt;/li&gt;
&lt;li&gt;Continuous reconciliation and drift detection through Pulumi’s state and policy engine&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With the new &lt;a href="https://www.pulumi.com/blog/pulumi-kubernetes-operator-2-3/"&gt;Pulumi Kubernetes Operator 2.3&lt;/a&gt;, the operator gets even more production-ready features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Faster and more resilient stack updates through improved workspace lifecycle management&lt;/li&gt;
&lt;li&gt;Support for multi-namespace and multi-tenant deployments&lt;/li&gt;
&lt;li&gt;Better visibility with enhanced events, status reporting, and error surfacing&lt;/li&gt;
&lt;li&gt;Performance improvements for large-scale environments and parallel stack operations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Documentation: &lt;a href="https://www.pulumi.com/docs/iac/guides/continuous-delivery/pulumi-kubernetes-operator/"&gt;Using the Pulumi Kubernetes Operator&lt;/a&gt;&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Kubernetes beyond YAML&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Define clusters, workloads, and policies in TypeScript, Python, or Go, and manage EKS, AKS, and GKE from a single code-first workflow.&lt;/div&gt;
&lt;a href="https://app.pulumi.com/signup" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Get started
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="intelligent-infrastructure-across-every-cloud"&gt;Intelligent Infrastructure Across Every Cloud&lt;/h2&gt;
&lt;p&gt;Kubernetes has become the control plane for everything from application deployments to AI and ML workloads across clouds and environments. Engineering teams are running clusters on Amazon EKS, Microsoft AKS, and Google GKE while also managing edge, hybrid, and on-premises environments. Pulumi extends Kubernetes automation across all of them, unifying clusters, workloads, and cloud resources under a consistent model of infrastructure as code.&lt;/p&gt;
&lt;p&gt;With Pulumi, teams can use familiar programming languages to define Kubernetes resources, cloud infrastructure, and policies together. This approach provides a single workflow for managing compute, networking, storage, and identity across multiple clouds without relying on brittle YAML templates. It enables consistent provisioning, policy enforcement, and automation across every cluster and environment.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/2P8JLgAc5QI?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;By treating Kubernetes as the universal control plane for cloud infrastructure, Pulumi gives teams a scalable foundation that adapts to any workload and environment. The result is an intelligent, multi-cloud Kubernetes infrastructure that combines the flexibility of cloud providers with the reliability of modern automation.&lt;/p&gt;
&lt;h2 id="bring-your-yaml-and-helm-then-evolve"&gt;Bring Your YAML and Helm, Then Evolve&lt;/h2&gt;
&lt;p&gt;Teams do not need to start from scratch. Pulumi supports &lt;a href="https://www.pulumi.com/docs/iac/guides/migration/migrating-to-pulumi/from-kubernetes/"&gt;importing existing YAML manifests and Helm charts&lt;/a&gt; to help organizations adopt a code-first approach incrementally. Many teams begin by wrapping existing manifests in Pulumi code, then refactor them into reusable components that enforce best practices and compliance policies.&lt;/p&gt;
&lt;p&gt;This hybrid approach enables modernization without disrupting existing CI/CD pipelines or team workflows.&lt;/p&gt;
&lt;h2 id="begin-your-kubernetes-automation-journey"&gt;Begin Your Kubernetes Automation Journey&lt;/h2&gt;
&lt;p&gt;For teams preparing for the next phase of Kubernetes management in 2026:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/iac/get-started/kubernetes/"&gt;Get Started with Kubernetes&lt;/a&gt; to create your first Pulumi program.&lt;/li&gt;
&lt;li&gt;Add the &lt;a href="https://www.pulumi.com/docs/iac/guides/continuous-delivery/pulumi-kubernetes-operator/"&gt;Pulumi Kubernetes Operator&lt;/a&gt; to enable infrastructure deployments from within your clusters.&lt;/li&gt;
&lt;li&gt;Integrate GitOps workflows with Argo CD, Flux, or Jenkins X.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Apply policy guardrails&lt;/a&gt; to enforce security and compliance automatically.&lt;/li&gt;
&lt;li&gt;Refactor infrastructure into &lt;a href="https://www.pulumi.com/docs/iac/concepts/components/"&gt;reusable components&lt;/a&gt; for consistent, scalable operations.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="agentic-workflows-for-production-ready-kubernetes"&gt;Agentic Workflows for Production-ready Kubernetes&lt;/h2&gt;
&lt;p&gt;Experience Kubernetes automation in practice. See how agentic workflows power production-ready Kubernetes by automating GitOps operations, managing environments, and reducing manual effort in this on-demand workshop.&lt;/p&gt;
&lt;p&gt;Watch &lt;a href="https://www.pulumi.com/events/from-zero-to-production-in-kubernetes/"&gt;&lt;em&gt;Agentic Workflows for Production-ready Kubernetes&lt;/em&gt;&lt;/a&gt; to learn how to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provision and manage clusters across clouds using general-purpose programming languages&lt;/li&gt;
&lt;li&gt;Multi-cloud Kubernetes infrastructure management&lt;/li&gt;
&lt;li&gt;Fleet management with GitOps (Argo CD)&lt;/li&gt;
&lt;li&gt;Reduce YAML complexity while maintaining reliability and speed&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/events/from-zero-to-production-in-kubernetes/"&gt;Watch On Demand&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="final-thoughts"&gt;Final Thoughts&lt;/h2&gt;
&lt;p&gt;Kubernetes in 2026 and beyond is not just for platform engineers. It is for DevOps professionals, SREs, and cloud teams, big and small, responsible for maintaining infrastructure security, reliability, and performance.
Pulumi unifies infrastructure as code, secrets management, policy governance, and AI automation into a single platform, enabling every team to adopt an intelligent, code-driven approach to Kubernetes that scales across workloads, clouds, and the AI-driven future.&lt;/p&gt;
&lt;a
href="https://www.pulumi.com/docs/get-started/"
class="btn btn-primary"
&gt;
Try Pulumi for Free
&lt;/a&gt;</description><author>Sara Huddleston</author><category>kubernetes</category><category>gitops</category><category>pulumi-neo</category><category>infrastructure-as-code</category><category>platform-engineering</category><category>devops</category><category>mlops</category></item><item><title>Why Azure Teams Are Moving from ARM Templates to .NET</title><link>https://www.pulumi.com/blog/why-azure-resource-manager-templates-suck-for-deployments/</link><pubDate>Fri, 22 Aug 2025 01:41:10 +0000</pubDate><guid>https://www.pulumi.com/blog/why-azure-resource-manager-templates-suck-for-deployments/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/why-azure-resource-manager-templates-suck-for-deployments/index.png" /&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/iac/adopting-pulumi/migrating-to-pulumi/from-arm/"&gt;Azure Resource Manager (ARM)&lt;/a&gt; templates are powerful, but painful. If you’ve ever tried to provision cloud infrastructure using ARM, you know the challenges:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Templates that started simple… and now span thousands of lines&lt;/li&gt;
&lt;li&gt;Manual configuration stitched together with bespoke deployment logic&lt;/li&gt;
&lt;li&gt;Lack of support for key services like Databricks&lt;/li&gt;
&lt;li&gt;Slow, error-prone deployments that require multiple manual steps&lt;/li&gt;
&lt;li&gt;No reuse, no testing, and no relief&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;ARM wasn’t built for the complexity of modern Azure workloads. If you&amp;rsquo;re already familiar with general-purpose languages, there’s a better path: &lt;a href="https://www.pulumi.com/docs/iac/clouds/azure/"&gt;Pulumi&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="top-pain-points-of-arm-templates"&gt;Top Pain Points of ARM Templates&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Pain Point&lt;/th&gt;
&lt;th&gt;ARM Templates&lt;/th&gt;
&lt;th&gt;Pulumi (C#)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Language&lt;/td&gt;
&lt;td&gt;JSON&lt;/td&gt;
&lt;td&gt;C#, Python, TypeScript, or Go&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Code Reuse&lt;/td&gt;
&lt;td&gt;None—copy/paste only&lt;/td&gt;
&lt;td&gt;Classes, functions, modules&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Logic&lt;/td&gt;
&lt;td&gt;Complex condition syntax&lt;/td&gt;
&lt;td&gt;if / switch / for loops&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;IDE Support&lt;/td&gt;
&lt;td&gt;Very limited&lt;/td&gt;
&lt;td&gt;Full IntelliSense and refactoring&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Testing&lt;/td&gt;
&lt;td&gt;None&lt;/td&gt;
&lt;td&gt;Unit tests with xUnit/NUnit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Debugging&lt;/td&gt;
&lt;td&gt;Post-deploy troubleshooting&lt;/td&gt;
&lt;td&gt;Step-through debugging in IDE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Refactoring&lt;/td&gt;
&lt;td&gt;Manual edits&lt;/td&gt;
&lt;td&gt;Standard IDE workflows&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="pulumi-the-obvious-upgrade-for-net-and-azure"&gt;Pulumi: The Obvious Upgrade for .NET and Azure&lt;/h2&gt;
&lt;p&gt;Pulumi solves these problems at their root. It lets you define your &lt;a href="https://www.pulumi.com/docs/iac/clouds/azure/"&gt;Azure infrastructure&lt;/a&gt; using C#, the same language you&amp;rsquo;re already using to build your applications. With Pulumi, you get:&lt;/p&gt;
&lt;p&gt;✅ Familiar programming languages
✅ Type safety and compile-time validation
✅ Full IDE support (IntelliSense, refactoring, debugging)
✅ Built-in support for Databricks, Kubernetes, and more
✅ Automated config and secrets management
✅ Easy testing, reuse, and CI/CD integration&lt;/p&gt;
&lt;h2 id="from-static-templates-to-software-engineering"&gt;From Static Templates to Software Engineering&lt;/h2&gt;
&lt;p&gt;Here’s an example of how different it is to build a storage account:&lt;/p&gt;
&lt;h3 id="-arm-template-json"&gt;⛔ ARM Template (JSON)&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;$schema&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;contentVersion&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1.0.0.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;parameters&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;storageAccountName&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;string&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;metadata&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Globally unique, 3–24 lowercase letters and numbers.&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;resources&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Microsoft.Storage/storageAccounts&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;apiVersion&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2021-09-01&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;name&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;[parameters(&amp;#39;storageAccountName&amp;#39;)]&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;location&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;[resourceGroup().location]&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;sku&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;name&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Standard_LRS&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;kind&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;StorageV2&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;properties&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;outputs&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;storageAccountId&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;string&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;[resourceId(&amp;#39;Microsoft.Storage/storageAccounts&amp;#39;, parameters(&amp;#39;storageAccountName&amp;#39;))]&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="-azure-with-pulumi-in-c"&gt;✅ Azure with Pulumi in C#&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-csharp" data-lang="csharp"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;Pulumi&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;Pulumi.AzureNative.Storage&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;MyStack&lt;/span&gt; &lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Stack&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="n"&gt;MyStack&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="kt"&gt;var&lt;/span&gt; &lt;span class="n"&gt;storageAccount&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;StorageAccount&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;mystorage&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;StorageAccountArgs&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ResourceGroupName&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;&amp;#34;my-rg&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Sku&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;SkuArgs&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="n"&gt;Name&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;SkuName&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Standard_LRS&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Kind&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Kind&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;StorageV2&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;It’s clean. It’s familiar. And it works seamlessly with your .NET tooling.
Pulumi is open source, and your Pulumi Cloud account is free for individuals and small teams, with advanced editions for large enterprises.
&lt;a href="https://app.pulumi.com/signup"&gt;Try Pulumi Cloud for FREE-&amp;gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="why-it-just-works-for-net-teams"&gt;Why It Just Works for .NET Teams&lt;/h2&gt;
&lt;p&gt;If your organization is built on Azure and .NET:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use C# across both infrastructure and application layers&lt;/li&gt;
&lt;li&gt;Share libraries and logic between services&lt;/li&gt;
&lt;li&gt;Test infrastructure the same way you test code&lt;/li&gt;
&lt;li&gt;Integrate with Azure DevOps and GitHub Actions&lt;/li&gt;
&lt;li&gt;Manage secrets, environments, and policies as code&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pulumi supports all the Azure services ARM does (and more), while giving you flexibility and control ARM never could.&lt;/p&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/iac/adopting-pulumi/migrating-to-pulumi/from-arm/"&gt;ARM templates&lt;/a&gt;weren’t designed to scale with the complexity of today’s cloud environments. They’re static, verbose, hard to test, and increasingly brittle.&lt;/p&gt;
&lt;p&gt;Pulumi gives you the tools to manage Azure the way you manage software: modular, testable, scalable, and secure.&lt;/p&gt;
&lt;p&gt;If you’re already building with C# and .NET, you’re 90% of the way there. Why suffer through another slow, error-prone ARM deployment?&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Try Pulumi Open Source&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/iac/get-started/azure/"&gt;Get Started with Azure + Pulumi Docs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/registry/packages/azure-native/how-to-guides/"&gt;Azure Native: How-to-Guides&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><author>Sara Huddleston</author><category>azure</category><category>arm-templates</category><category>azure-resource-manager</category></item><item><title>AI/ML on Kubernetes: Deploying Models with Pulumi on Google Cloud</title><link>https://www.pulumi.com/blog/ai-ml-on-kubernetes-google-cloud-llm-rag/</link><pubDate>Mon, 24 Mar 2025 07:32:19 +0000</pubDate><guid>https://www.pulumi.com/blog/ai-ml-on-kubernetes-google-cloud-llm-rag/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/ai-ml-on-kubernetes-google-cloud-llm-rag/index.png" /&gt;
&lt;p&gt;Kubernetes has transformed cloud infrastructure by enabling scalable, containerized applications. While it initially gained traction for managing web applications and microservices, its capabilities now extend to AI/ML workloads, making it the go-to platform for data scientists and machine learning engineers.&lt;/p&gt;
&lt;p&gt;Running AI/ML workloads on Kubernetes presents unique challenges, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Specialized hardware&lt;/strong&gt; requirements (e.g., GPUs, TPUs)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scalability&lt;/strong&gt; for model training and inference&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Complex data pipelines&lt;/strong&gt; that integrate various cloud services&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Infrastructure automation&lt;/strong&gt; for seamless deployment&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Google Cloud Kubernetes (GKE) provides a robust foundation for AI/ML workloads, but managing infrastructure manually can be cumbersome. This is where Pulumi comes in—enabling Infrastructure as Code (IaC) to automate and simplify AI/ML infrastructure on Kubernetes.&lt;/p&gt;
&lt;h2 id="pulumi-automating-aiml-infrastructure-on-google-cloud"&gt;Pulumi: Automating AI/ML Infrastructure on Google Cloud&lt;/h2&gt;
&lt;p&gt;Pulumi is a modern Infrastructure as Code (IaC) tool that allows teams to define and manage cloud infrastructure using general-purpose programming languages like Python, TypeScript, and Go. This approach is particularly beneficial for AI/ML teams, as Python is already the dominant language in data science and machine learning.&lt;/p&gt;
&lt;p&gt;With Pulumi, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Provision and scale Kubernetes clusters&lt;/strong&gt; on &lt;a href="https://www.pulumi.com/docs/iac/clouds/gcp/"&gt;Google Cloud&lt;/a&gt; automatically.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Define AI/ML environments as code&lt;/strong&gt;, making deployments repeatable and version-controlled.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Integrate infrastructure with machine learning pipelines&lt;/strong&gt;, reducing operational overhead.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="deploying-aiml-workloads-on-kubernetes"&gt;Deploying AI/ML Workloads on Kubernetes&lt;/h2&gt;
&lt;p&gt;Below, we explore two use cases for running AI/ML workloads on &lt;a href="https://www.pulumi.com/templates/kubernetes/gcp/"&gt;Google Kubernetes Engine (GKE)&lt;/a&gt; using Pulumi.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/CoZM9BCJcJ4?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h3 id="use-case-1-deploying-a-large-language-model-llm-with-retrieval-augmented-generation-rag"&gt;Use Case 1: Deploying a Large Language Model (LLM) with Retrieval Augmented Generation (RAG)&lt;/h3&gt;
&lt;p&gt;Large Language Models (LLMs) like &lt;strong&gt;GPT-3, Whisper, and DALL-E&lt;/strong&gt; require significant infrastructure for training and inference. &lt;strong&gt;Retrieval Augmented Generation (RAG)&lt;/strong&gt; enhances LLMs by integrating external knowledge sources, improving accuracy and relevance.&lt;/p&gt;
&lt;p&gt;Using Pulumi, you can &lt;strong&gt;automate the deployment of an open-source &lt;a href="https://www.pulumi.com/blog/codegen-learnings/"&gt;LLM with RAG&lt;/a&gt;&lt;/strong&gt; on Kubernetes.&lt;/p&gt;
&lt;h4 id="step-1-set-up-a-kubernetes-cluster-on-google-cloud"&gt;Step 1: Set Up a Kubernetes Cluster on Google Cloud&lt;/h4&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi_gcp&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;gcp&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Create a GKE cluster for AI/ML workloads&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;cluster&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;gcp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;container&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Cluster&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;ml-cluster&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;location&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;us-central1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;initial_node_count&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;node_version&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;1.23&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;min_master_version&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;1.23&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Create a node pool optimized for ML workloads&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;node_pool&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;gcp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;container&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;NodePool&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;ml-node-pool&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;cluster&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;cluster&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;node_config&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;gcp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;container&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;NodePoolNodeConfigArgs&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;machine_type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;n1-standard-4&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;oauth_scopes&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;https://www.googleapis.com/auth/devstorage.read_only&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;https://www.googleapis.com/auth/logging.write&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;labels&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;team&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;ml&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;shielded_instance_config&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;gcp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;container&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;NodePoolNodeConfigShieldedInstanceConfigArgs&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;enable_secure_boot&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;enable_integrity_monitoring&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;),&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;),&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;initial_node_count&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;location&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;us-central1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;version&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;1.23&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;...&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This Pulumi script:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provisions a &lt;strong&gt;Kubernetes cluster&lt;/strong&gt; on Google Cloud.&lt;/li&gt;
&lt;li&gt;Creates a &lt;strong&gt;dedicated node pool&lt;/strong&gt; optimized for AI/ML workloads.&lt;/li&gt;
&lt;li&gt;Ensures &lt;strong&gt;security best practices&lt;/strong&gt; for machine learning environments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="step-2-deploy-the-llm-with-rag-model"&gt;Step 2: Deploy the LLM with RAG Model&lt;/h4&gt;
&lt;p&gt;Once the cluster is set up, we can deploy the &lt;strong&gt;LLM with RAG model&lt;/strong&gt; using Pulumi’s &lt;a href="https://www.pulumi.com/blog/pko-2-0-ga/"&gt;Kubernetes provider&lt;/a&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Define &lt;strong&gt;Kubernetes Deployments&lt;/strong&gt; for the LLM and RAG model.&lt;/li&gt;
&lt;li&gt;Package models as &lt;strong&gt;Docker containers&lt;/strong&gt; and deploy them to the cluster.&lt;/li&gt;
&lt;li&gt;Configure &lt;strong&gt;Kubernetes Services&lt;/strong&gt; to expose APIs for model inference.&lt;/li&gt;
&lt;li&gt;Use &lt;strong&gt;ConfigMaps and Secrets&lt;/strong&gt; to manage parameters and credentials.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;By defining these resources in Pulumi, deployments become &lt;strong&gt;fully automated, repeatable, and scalable&lt;/strong&gt;.&lt;/p&gt;
&lt;h3 id="use-case-2-training-and-serving-custom-machine-learning-models"&gt;Use Case 2: Training and Serving Custom Machine Learning Models&lt;/h3&gt;
&lt;p&gt;Beyond pre-trained LLMs, &lt;a href="https://www.pulumi.com/docs/iac/clouds/kubernetes/"&gt;Kubernetes&lt;/a&gt; is ideal for &lt;strong&gt;training and serving custom AI/ML models&lt;/strong&gt;. Pulumi can help automate every stage of the ML lifecycle.&lt;/p&gt;
&lt;h4 id="step-1-set-up-the-model-training-environment"&gt;Step 1: Set Up the Model Training Environment&lt;/h4&gt;
&lt;p&gt;Using Pulumi, we define a training environment with:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;Kubernetes Deployment&lt;/strong&gt; for training jobs (GPU-enabled).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Persistent Volume Claims (PVCs)&lt;/strong&gt; for storing training data and model artifacts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Monitoring tools&lt;/strong&gt; for tracking performance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="step-2-deploy-and-serve-the-trained-model"&gt;Step 2: Deploy and Serve the Trained Model&lt;/h4&gt;
&lt;p&gt;Once the model is trained, Pulumi can be used to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deploy the trained model as a &lt;strong&gt;Kubernetes Deployment&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Expose the model via a &lt;strong&gt;Kubernetes Service&lt;/strong&gt; (REST API or gRPC).&lt;/li&gt;
&lt;li&gt;Add &lt;strong&gt;autoscaling rules&lt;/strong&gt; for dynamic inference scaling.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pulumi allows teams to &lt;strong&gt;manage the entire AI/ML pipeline&lt;/strong&gt; in a structured and automated way.&lt;/p&gt;
&lt;p&gt;Try Jay’s demo code on &lt;a href="https://github.com/jasonsmithio/pulumi-experiments/tree/main/ai-ml-platform/gke-training"&gt;Creating an AI Training Platform on GKE with Pulumi&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="why-use-pulumi-for-aiml-on-kubernetes"&gt;Why Use Pulumi for AI/ML on Kubernetes?&lt;/h2&gt;
&lt;p&gt;Pulumi provides several advantages for AI/ML teams running workloads on Kubernetes:&lt;/p&gt;
&lt;h3 id="1-use-general-purpose-languages-for-infrastructure-as-code"&gt;1. Use General-Purpose Languages for Infrastructure as Code&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Most AI/ML engineers already work with &lt;strong&gt;Python&lt;/strong&gt; or &lt;strong&gt;Go&lt;/strong&gt;, and Pulumi lets them manage infrastructure using the same language.&lt;/li&gt;
&lt;li&gt;No need to learn YAML or Kubernetes manifests—define everything programmatically.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="2-automate-aiml-workflows"&gt;2. Automate AI/ML Workflows&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Define infrastructure, training jobs, and model serving in &lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/"&gt;one unified IaC framework&lt;/a&gt;&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Ensure &lt;strong&gt;consistency&lt;/strong&gt; across development, staging, and production environments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="3-improve-scalability-and-cost-efficiency"&gt;3. Improve Scalability and Cost Efficiency&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Pulumi integrates with &lt;strong&gt;Google Cloud AI services&lt;/strong&gt; for optimized compute resources.&lt;/li&gt;
&lt;li&gt;Automate &lt;strong&gt;autoscaling and resource allocation&lt;/strong&gt; for AI/ML workloads.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="4-increase-security-and-compliance"&gt;4. Increase Security and Compliance&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Manage credentials and secrets securely with &lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/esc/"&gt;Pulumi ESC (Secrets Management)&lt;/a&gt;&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Apply &lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/using-pulumi/crossguard/"&gt;policy-as-code&lt;/a&gt;&lt;/strong&gt; to enforce security best practices.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="get-started-with-aiml-on-kubernetes-with-pulumi"&gt;Get Started with AI/ML on Kubernetes with Pulumi&lt;/h2&gt;
&lt;p&gt;Pulumi makes it easy to deploy, scale, and manage AI/ML workloads on Kubernetes, leveraging Google Cloud&amp;rsquo;s AI infrastructure. Whether you&amp;rsquo;re serving LLMs, training custom models, or automating ML pipelines, Pulumi provides a developer-friendly, scalable, and secure solution.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/tag/ml/"&gt;Explore AI/ML Projects using Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/"&gt;Discover Essential Kubernetes Best Practices&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/iac/clouds/gcp/"&gt;Get Started with Pulumi on Google Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi ➡️&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By combining Kubernetes, Google Cloud, and Pulumi, you can accelerate AI/ML innovation while reducing infrastructure complexity.&lt;/p&gt;</description><author>Sara Huddleston</author><category>kubernetes</category><category>ai</category><category>llm</category><category>google-cloud</category><category>gke</category></item><item><title>Why Every Cloud Engineer Needs Pulumi ESC for Secrets Management</title><link>https://www.pulumi.com/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/</link><pubDate>Mon, 17 Mar 2025 07:28:56 +0000</pubDate><guid>https://www.pulumi.com/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/index.png" /&gt;
&lt;p&gt;Managing secrets is one of the most critical responsibilities in cloud engineering. Secrets like API keys, database credentials, and encryption tokens are the backbone of secure and seamless cloud operations. Yet they are so often an afterthought. They get replicated across cloud-specific secrets managers and stuffed in GitHub secrets, compromising security for the sake of simplicity. ¿Por que no los dos? Why can&amp;rsquo;t secrets management be secure and simple?&lt;/p&gt;
&lt;p&gt;Enter &lt;strong&gt;Pulumi ESC (Environments, Secrets, and Configuration)&lt;/strong&gt;—a breakthrough in taming secrets sprawl and streamlining configuration management across infrastructure. Let&amp;rsquo;s explore why Pulumi ESC is a necessity for cloud engineers, helping make secrets management secure while keeping it simple.&lt;/p&gt;
&lt;h2 id="in-this-article"&gt;In this article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/#the-challenge-of-secrets-management-in-modern-cloud-environments"&gt;The Challenge of Secrets Management in Modern Cloud Environments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/#what-is-pulumi-esc"&gt;What is Pulumi ESC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/#key-features-of-pulumi-esc"&gt;Key Features of Pulumi ESC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/#why-cloud-engineers-need-pulumi-esc"&gt;Why Cloud Engineers Need Pulumi ESC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/why-every-cloud-engineer-needs-pulumi-esc-secrets-management/#the-future-of-secrets-management-with-pulumi-esc"&gt;The Future of Secrets Management with Pulumi ESC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-challenge-of-secrets-management-in-modern-cloud-environments"&gt;The Challenge of Secrets Management in Modern Cloud Environments&lt;/h2&gt;
&lt;p&gt;Secrets management has changed significantly over the past decade. Gone are the days when secrets could be hardcoded, manually maintained in static configuration files, or left floating around in plaintext on dev machines. Nowadays, cloud environments demand a higher level of sophistication:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Distributed Systems&lt;/strong&gt;: Even in multi-cloud and hybrid setups, secrets must be accessible across varied platforms without exposing vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dynamic Infrastructure&lt;/strong&gt;: Kubernetes, serverless architectures, and ephemeral environments must have secrets that adapt dynamically.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security Risks&lt;/strong&gt;: Hardcoded or poorly managed secrets can lead to catastrophic breaches, costing companies millions in data recovery and compliance penalties.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Operational Burdens&lt;/strong&gt;: Manual secrets management is error-prone, inefficient, unscalable, and needs to align with DevOps and DevSecOps best practices.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Pulumi ESC addresses these issues head-on, redefining how cloud engineers manage secrets efficiently, securely, and at scale.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Jk Jensen, Team Lead at Mysten Labs, said:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;Pulumi ESC has been a lifesaver for us. It’s nice to throw everything behind an ESC environment and eliminate one-off granting/IAM permissions and other issues related to static credentials. It gives us peace of mind knowing that we can grant permissions quickly and revoke easily limiting blast radius for any access.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="what-is-pulumi-esc"&gt;What is Pulumi ESC?&lt;/h2&gt;
&lt;p&gt;Pulumi ESC simplifies how organizations manage secrets and configurations. It is designed to secure sensitive configurations across modern cloud environments and supports seamless integration, enabling engineers to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Access, share, and manage&lt;/strong&gt; secrets, passwords, API keys, and configuration settings like network and deployment options.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Synchronize secrets and configuration&lt;/strong&gt; from any secrets manager to any app, tool, or CI/CD platform.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Access secrets securely&lt;/strong&gt; through CLI, API, Kubernetes operator, the Pulumi Cloud UI, and in-code with Typescript/Javascript, Python, and Go SDKs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Connect to cloud providers and secrets stores&lt;/strong&gt; via OIDC to generate dynamic, short-lived, auto-expiring credentials.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Set role-based access controls (RBAC)&lt;/strong&gt;, making securing secrets and configurations easy by assigning permissions to users based on their roles.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Whether integrated with Pulumi&amp;rsquo;s Infrastructure as Code (IaC) platform or used as a standalone service, Pulumi ESC enables cloud engineers to streamline secrets management with centralized control.&lt;/p&gt;
&lt;h2 id="key-features-of-pulumi-esc"&gt;Key Features of Pulumi ESC&lt;/h2&gt;
&lt;h3 id="1-seamless-integration-with-external-platforms"&gt;1. Seamless Integration with External Platforms&lt;/h3&gt;
&lt;p&gt;Pulumi ESC integrates with popular secrets providers, including &lt;a href="https://www.pulumi.com/docs/esc/integrations/dynamic-secrets/aws-secrets/"&gt;AWS Secrets Manager&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/esc/integrations/dynamic-secrets/azure-secrets/"&gt;Azure Key Vault&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/esc/integrations/dynamic-secrets/gcp-secrets/"&gt;GCP Secret Manager&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/esc/integrations/dynamic-secrets/1password-secrets/"&gt;1Password&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/docs/esc/integrations/dynamic-secrets/vault-secrets/"&gt;HashiCorp Vault&lt;/a&gt;, making it adaptable for multi-cloud and hybrid cloud architectures.&lt;/p&gt;
&lt;h3 id="2-dynamic-secrets-synchronization-with-eso"&gt;2. Dynamic Secrets Synchronization with ESO&lt;/h3&gt;
&lt;p&gt;Partnering with the &lt;a href="https://www.pulumi.com/docs/esc/integrations/kubernetes/external-secrets-operator/"&gt;External Secrets Operator&lt;/a&gt;, Pulumi ESC synchronizes secrets securely into Kubernetes clusters. This eliminates hardcoding secrets into manifests or relying on unsecured manual processes.&lt;/p&gt;
&lt;h3 id="3-safely-roll-back-to-a-previous-version"&gt;3. Safely Roll Back to a Previous Version&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/esc-versioning-launch/"&gt;Pulumi ESC Versioning&lt;/a&gt; gives you unprecedented control over your secrets and configuration. Every change is captured in an immutable revision history, allowing you to audit modifications, compare versions, and safely roll back.&lt;/p&gt;
&lt;h3 id="4-secure-by-design"&gt;4. Secure by Design&lt;/h3&gt;
&lt;p&gt;Pulumi ESC follows a &amp;ldquo;secure by default&amp;rdquo; model, employing encryption, access control, and detailed audit trails. Engineers can meet compliance regulations effortlessly while gaining full visibility into secret access patterns.&lt;/p&gt;
&lt;h3 id="5-automated-rotation-and-expiry"&gt;5. Automated Rotation and Expiry&lt;/h3&gt;
&lt;p&gt;Pulumi ESC minimizes security risks by automating the &lt;a href="https://www.pulumi.com/blog/esc-rotated-secrets-launch/"&gt;rotation of secrets&lt;/a&gt;. This feature aligns secrets management with CI/CD processes for cloud engineers focused on DevOps, ensuring credentials remain valid only when needed.&lt;/p&gt;
&lt;h3 id="6-configuration-as-code-automation-and-integration-everywhere"&gt;6. Configuration-as-Code, Automation, and Integration Everywhere&lt;/h3&gt;
&lt;p&gt;Pulumi ESC embraces an &amp;ldquo;as-code&amp;rdquo; approach, enabling configuration and secrets management using TypeScript, JavaScript, Go, Python, or YAML. The &amp;rsquo;esc&amp;rsquo; CLI and API support automation in CI/CD environments, reducing credential duplication and ensuring a single source of truth.&lt;/p&gt;
&lt;h3 id="7-dev-tools-integrations"&gt;7. Dev Tools Integrations&lt;/h3&gt;
&lt;p&gt;Pulumi ESC’s metadata and support for popular configuration formats enable seamless integration with tools like &lt;a href="https://www.pulumi.com/docs/esc/integrations/dev-tools/direnv/"&gt;Direnv&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/esc/integrations/dev-tools/docker/"&gt;Docker&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/docs/esc/integrations/dev-tools/github/"&gt;GitHub&lt;/a&gt;, allowing easy management of environment variables, secrets, and configurations.&lt;/p&gt;
&lt;h3 id="8-infrastructure-tools-integrations"&gt;8. Infrastructure Tools Integrations&lt;/h3&gt;
&lt;p&gt;Pulumi ESC extends its capabilities beyond Pulumi IaC by integrating with other infrastructure tools such as &lt;a href="https://www.pulumi.com/docs/esc/integrations/infrastructure/cloudflare/"&gt;Cloudflare&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/esc/integrations/infrastructure/terraform/"&gt;Terraform&lt;/a&gt;, and OpenTofu. These integrations enable seamless provisioning of cloud credentials and input variables directly from ESC environments.&lt;/p&gt;
&lt;h2 id="why-cloud-engineers-need-pulumi-esc"&gt;Why Cloud Engineers Need Pulumi ESC&lt;/h2&gt;
&lt;h3 id="enhanced-security-and-compliance"&gt;Enhanced Security and Compliance&lt;/h3&gt;
&lt;p&gt;Cloud engineers often have to balance security and operations. Pulumi ESC centralizes secrets in a secure vault, ensuring encrypted storage, access control, and audit visibility. It also &lt;a href="https://www.pulumi.com/docs/administration/onboarding-guide/setting-up-for-success/#choose-your-compliance-approach"&gt;complies with industry standards like SOC 2, PCI-DSS, and MTCS&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="streamlined-multi-cloud-management"&gt;Streamlined Multi-Cloud Management&lt;/h3&gt;
&lt;p&gt;Managing secrets across AWS, Azure, and GCP can quickly become chaotic. Pulumi ESC&amp;rsquo;s cross-platform integration simplifies this process, ensuring engineers can manage and sync secrets from a single interface.&lt;/p&gt;
&lt;h3 id="simplified-kubernetes-secrets"&gt;Simplified Kubernetes Secrets&lt;/h3&gt;
&lt;p&gt;Kubernetes&amp;rsquo; default secrets offer limited security and scalability. Pulumi ESC with ESO and Secrets Store CSI Driver overcomes these limitations by securely synchronizing and managing secrets within Kubernetes clusters. This prevents unauthorized access and provides automated updates.&lt;/p&gt;
&lt;h3 id="zero-downtime-through-automation"&gt;Zero Downtime Through Automation&lt;/h3&gt;
&lt;p&gt;Manual secrets management often leads to errors such as expired credentials or outdated tokens. Pulumi ESC automates the entire lifecycle of secrets—creation, rotation, replication, and expiry—guaranteeing uninterrupted services.&lt;/p&gt;
&lt;h3 id="developer-friendly-workflows"&gt;Developer-Friendly Workflows&lt;/h3&gt;
&lt;p&gt;Tools should make engineers&amp;rsquo; lives easier, not harder. Pulumi ESC&amp;rsquo;s CLI, SDKs, and API provide intuitive ways to integrate into existing workflows. For cloud engineers leveraging Infrastructure as Code with Pulumi, managing secrets alongside the stack becomes effortless.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Thomas Meckel, Senior Cloud Architect at Ophios GmbH, explains:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;Pulumi&amp;rsquo;s built-in encryption of secrets sets it apart as a leader in secure infrastructure management. Unlike other tools that leave sensitive data exposed or require complex configurations, Pulumi ensures secrets are encrypted by default, leveraging flexible options like Azure Key Vault or AWS KMS. This eliminates the risk of plaintext exposure and simplifies secure deployments. For any organization serious about cloud security, Pulumi&amp;rsquo;s approach to secrets management is a critical differentiator, combining ease of use with robust protection against breaches.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="kubernetes-secrets-management"&gt;Kubernetes Secrets Management&lt;/h3&gt;
&lt;p&gt;For secrets management in Kubernetes environments, Pulumi ESC becomes even more powerful when paired with External Secrets Operator (ESO) or the Secrets Store CSI Driver. Here&amp;rsquo;s how it works:&lt;/p&gt;
&lt;h4 id="using-pulumi-esc-with-external-secrets-operator"&gt;Using Pulumi ESC with External Secrets Operator&lt;/h4&gt;
&lt;p&gt;External Secrets Operator is an open-source Kubernetes operator that syncs secrets from external providers (like Pulumi ESC) into Kubernetes as native secrets.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Centralized Storage&lt;/strong&gt;: Store secrets securely in Pulumi ESC and synchronize them with Kubernetes across multiple clusters.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dynamic Updates&lt;/strong&gt;: Whenever a secret is updated in ESC, ESO automatically replicates the changes into Kubernetes, eliminating manual intervention.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Granular Management&lt;/strong&gt;: Define which secrets are synchronized and to which namespaces, ensuring tight access controls and minimizing risk.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automated Secret Rotation&lt;/strong&gt;: By leveraging ESC&amp;rsquo;s rotation capabilities, ESO ensures Kubernetes receives refreshed credentials without requiring downtime.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Learn how to manage Kubernetes secrets with &lt;a href="https://www.pulumi.com/blog/cloud-native-secret-management-with-pulumi-esc-and-external-secrets-operator/"&gt;Pulumi ESC and External Secrets Operator: The Perfect Solution for Today&amp;rsquo;s Cloud-Native Secret Management&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id="using-pulumi-esc-with-secrets-store-csi-driver"&gt;Using Pulumi ESC with Secrets Store CSI Driver&lt;/h4&gt;
&lt;p&gt;The Secret Store CSI Driver mounts secrets, certificates, and keys from external stores into Kubernetes pods as volumes.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Automated Secrets Injection&lt;/strong&gt;: Secrets Store CSI Driver enables Pulumi ESC to automatically inject secrets into Kubernetes pods as mounted volumes or environment variables. This reduces the manual overhead of managing secrets directly in Kubernetes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secure and Dynamic Secret Access&lt;/strong&gt;: By leveraging Pulumi ESC, Kubernetes applications can securely fetch secrets from external providers, ensuring dynamic access without exposing credentials in pod specifications.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Streamlined Operations&lt;/strong&gt;: This integration simplifies the process of synchronizing secrets from Pulumi ESC with Kubernetes-native constructs. The automation reduces errors and boosts efficiency.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Learn how to &lt;a href="https://www.pulumi.com/blog/master-kubernetes-secrets-with-pulumi-esc-secrets-store-csi-driver/"&gt;Master Kubernetes Secrets with Pulumi ESC + Secrets Store CSI Driver&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="the-future-of-secrets-management-with-pulumi-esc"&gt;The Future of Secrets Management with Pulumi ESC&lt;/h2&gt;
&lt;p&gt;Pulumi ESC is more than just a secrets management tool — it&amp;rsquo;s the foundation of secure, scalable, and agile cloud operations. For cloud engineers grappling with multi-cloud complexity, Kubernetes deployments, and compliance concerns, it provides a streamlined, automated approach that enhances efficiency and security.&lt;/p&gt;
&lt;p&gt;With rising cyber threats and stricter data regulations, adopting tools like Pulumi ESC is no longer optional. It&amp;rsquo;s a competitive advantage for cloud engineers and organizations aiming to lead in today&amp;rsquo;s cloud-native world.&lt;/p&gt;
&lt;h2 id="next-steps-to-secure-your-secrets"&gt;Next Steps to Secure Your Secrets&lt;/h2&gt;
&lt;p&gt;Secrets management doesn&amp;rsquo;t have to be a headache! With &lt;strong&gt;Pulumi ESC&lt;/strong&gt;, you can safeguard your infrastructure, ensure compliance, and eliminate manual errors—all while enhancing security and agility.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/esc/get-started/begin/"&gt;Get started with Pulumi ESC today&lt;/a&gt; and experience the future of secrets management. Take control of your cloud environment—securely and effortlessly.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi ➡️&lt;/a&gt;&lt;/p&gt;</description><author>Sara Huddleston</author><category>security</category><category>esc</category><category>external-secrets-operator</category><category>kubernetes</category><category>secrets-management</category><category>csi</category><category>secrets</category></item><item><title>2024 Year in Review: Growth, Innovation and Appreciation</title><link>https://www.pulumi.com/blog/pulumi-year-in-review/</link><pubDate>Fri, 20 Dec 2024 06:11:09 +0000</pubDate><guid>https://www.pulumi.com/blog/pulumi-year-in-review/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumi-year-in-review/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Note: This post discusses Pulumi Copilot, which Pulumi Neo has replaced. &lt;a href="https://www.pulumi.com/docs/ai/"&gt;Learn about Neo →&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;It&amp;rsquo;s the end of 2024, and like everyone, we&amp;rsquo;re counting down until 2025 while looking back at our year. We&amp;rsquo;ve had a very exciting year, from unveiling a bold new vision for Pulumi to delivering cutting-edge updates across our Pulumi Cloud.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s a look at how Pulumi has grown, evolved, and continued empowering teams worldwide.&lt;/p&gt;
&lt;h2 id="a-unified-vision-the-pulumi-platform"&gt;A Unified Vision: The Pulumi Platform&lt;/h2&gt;
&lt;p&gt;&lt;img src="pulumi-platform-vision.png" alt="Placeholder Image"&gt;&lt;/p&gt;
&lt;p&gt;This year, Pulumi unveiled a bold new vision for Pulumi—&lt;a href="https://www.pulumi.com/blog/pulumi-up-2024/"&gt;a comprehensive product suite&lt;/a&gt; that extends far beyond infrastructure as code. The Pulumi platform now consists of three core products:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/"&gt;Pulumi IaC&lt;/a&gt;&lt;/strong&gt;: Open source infrastructure as code in any programming language. With over 100M downloads, 167% growth in contributions, and industry-leading innovations, Pulumi IaC continues to redefine cloud automation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/esc/"&gt;Pulumi ESC&lt;/a&gt;&lt;/strong&gt;: Centralized secrets management and orchestration that scales. General availability this year brought features like SDKs, versioning, tagging, and integrations with 1Password and Kubernetes secrets operators.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/insights/"&gt;Pulumi Insights&lt;/a&gt;&lt;/strong&gt;: Visibility, intelligence, and control over all infrastructure resources. Insights 2.0 expanded support for resources created outside Pulumi IaC, delivering advanced graph visualizations and policy enforcement powered by Pulumi CrossGuard.&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/AepHQaXeNX0?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;Three core capabilities unite these products:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/copilot/"&gt;Pulumi Copilot&lt;/a&gt;&lt;/strong&gt;: Generative AI is used to manage cloud resources.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/using-pulumi/crossguard/"&gt;Pulumi CrossGuard&lt;/a&gt;&lt;/strong&gt;: A policy-as-code engine for compliance and best practices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/"&gt;Pulumi Deployments&lt;/a&gt;&lt;/strong&gt;: Infrastructure task orchestration.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Over 3,000 customers, including Nvidia, BMW, Unity Games, and Tivity Health, leveraged these solutions to enhance velocity, save costs, and secure their infrastructure.&lt;/p&gt;
&lt;h2 id="highlights-of-releases-and-enhancements"&gt;Highlights of Releases and Enhancements&lt;/h2&gt;
&lt;p&gt;&lt;img src="any-language-any-cloud.png" alt="Placeholder Image"&gt;&lt;/p&gt;
&lt;p&gt;Pulumi&amp;rsquo;s product innovations this year have empowered teams to automate, secure, and manage cloud infrastructure with confidence:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-esc-ga/"&gt;Pulumi ESC General Availability&lt;/a&gt;&lt;/strong&gt;, redefining secrets management with features like dynamic credentials and hierarchical environments. New capabilities include secrets syncing with external stores like AWS Secrets Manager and Kubernetes operators for runtime integration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-insights-2/"&gt;Pulumi Insights 2.0&lt;/a&gt;&lt;/strong&gt; delivers AI-powered search, a comprehensive inventory of resources created by Pulumi IaC as well as other tools like Terraform and CloudFormation, and automated remediation capabilities powered by CrossGuard.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/product/copilot/"&gt;Pulumi Copilot&lt;/a&gt;&lt;/strong&gt; leverages Generative AI to transform how teams diagnose and resolve IaC issues, providing instant feedback and deployment recommendations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-kubernetes-operator-2-0/"&gt;Pulumi Kubernetes Operator 2.0&lt;/a&gt;&lt;/strong&gt; introduced scalable, secure deployments with dedicated workspace pods, enhanced customization options, and improved stability under dynamic conditions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/drift-detection/"&gt;Drift Detection and Remediation&lt;/a&gt;&lt;/strong&gt; in Pulumi Cloud now automates drift detection for all 180+ supported providers, ensuring infrastructure consistency, enhanced security, and reduced operational risks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/azure-v6-release/"&gt;Azure Classic Provider v6.0.0&lt;/a&gt;&lt;/strong&gt; updates included the latest upstream changes and ensured compatibility with Pulumi Azure Native Provider.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/gcp-v8-release/"&gt;Google Cloud Provider v8.0.0&lt;/a&gt;&lt;/strong&gt; provides full resource coverage for the latest Google Cloud updates.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/aws-cdk-on-pulumi-1.0/"&gt;AWS CDK 1.0&lt;/a&gt;&lt;/strong&gt; expands compatibility with AWS CDK features, bridging the CDK and Pulumi ecosystems and enabling integration with constructs from AWS&amp;rsquo;s construct hub.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-vscode-extension/"&gt;Pulumi Visual Studio Code Extension&lt;/a&gt;&lt;/strong&gt; empowers developers with tools for debugging Pulumi programs, YAML language support, and direct ESC management within the IDE.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/docker-containers/"&gt;Pulumi Docker Containers&lt;/a&gt;&lt;/strong&gt; enhances CI/CD workflows with versioned images, pre-installed tools like Poetry and ppm, and runtime flexibility for Python, Node.js, and .NET.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="by-the-numbers"&gt;By the Numbers&lt;/h2&gt;
&lt;p&gt;&lt;img src="3000-customers.png" alt="Placeholder Image"&gt;&lt;/p&gt;
&lt;p&gt;Pulumi&amp;rsquo;s growth and impact this year have been amazing:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;75,000+ Pull Requests&lt;/strong&gt;: Driven by 5,600+ contributors.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;3,000+ Customers&lt;/strong&gt;: Empowering industries like AI, gaming, finance, and healthcare.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;100M+ Downloads&lt;/strong&gt;: Pulumi IaC adoption soared globally.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;167% Contribution Growth&lt;/strong&gt;: Outpacing other IaC tools like Terraform and OpenTofu.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;71% Cloud Cost Savings&lt;/strong&gt;: Customers like &lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/"&gt;Tivity Health saved millions&lt;/a&gt; with Pulumi.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="community-achievements"&gt;Community Achievements&lt;/h2&gt;
&lt;p&gt;&lt;img src="community-highlights.png" alt="Placeholder Image"&gt;&lt;/p&gt;
&lt;p&gt;Pulumi&amp;rsquo;s vibrant community has been at the heart of everything we&amp;rsquo;ve accomplished:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Global &lt;a href="https://luma.com/pulumi"&gt;Pulumi User Groups&lt;/a&gt; (PUGs)&lt;/strong&gt;: With 20 groups across 9 countries, including new meetups in &lt;a href="https://luma.com/pulumi"&gt;Chicago&lt;/a&gt;, &lt;a href="https://luma.com/pulumi"&gt;Columbus&lt;/a&gt;, &lt;a href="https://luma.com/pulumi"&gt;São Paulo&lt;/a&gt;, and &lt;a href="https://luma.com/pulumi"&gt;Tel Aviv&lt;/a&gt;, our community continues to grow. These meetups collectively hosted over 6,396 members.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PulumiUP 2024&lt;/strong&gt;: Over 8,000 registrants globally, with nearly 1,000 for the first-ever PulumiUP Europe.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/resources/#upcoming"&gt;Workshops&lt;/a&gt;&lt;/strong&gt;: 72 workshops with 14,500+ registrations from engineers wanting to learn Pulumi.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;22,000 GitHub Stars&lt;/strong&gt;: A testament to our community&amp;rsquo;s passion and dedication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="looking-ahead-to-2025"&gt;Looking Ahead to 2025&lt;/h2&gt;
&lt;p&gt;To our users, customers, partners, Puluminaries, and employees, &amp;ldquo;thank you!&amp;rdquo; Your support has made 2024 an amazing year, and we&amp;rsquo;re excited for what&amp;rsquo;s ahead in 2025. Together, we&amp;rsquo;ll continue to build the future of cloud infrastructure and security.&lt;/p&gt;
&lt;p&gt;Stay tuned for more innovations, community events, and collaboration opportunities. Here&amp;rsquo;s to another year of growth, transformation, and success!&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/"&gt;Explore Pulumi ➡️&lt;/a&gt;&lt;/p&gt;</description><author>Sara Huddleston</author><category>community</category><category>features</category></item><item><title>Integrating DevOps and Security in Platform Engineering</title><link>https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/</link><pubDate>Wed, 11 Dec 2024 07:41:06 +0000</pubDate><guid>https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/integrating-devops-and-security-for-scalable-platform-engineering/index.png" /&gt;
&lt;p&gt;Platform engineering has become essential for mid-to-large organizations, moving beyond a DevOps trend. Gartner predicts that by 2026, 80% of software companies will have internal platform services to streamline development. The goal is to empower developers with self-service tools while maintaining security, compliance, and reliability through DevSecOps practices.&lt;/p&gt;
&lt;p&gt;At PulumiUP Europe 2024, experts shared insights on aligning DevOps with security to build scalable, secure platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Jess Mink, Sr. Director of Platform Engineering at Honeycomb&lt;/li&gt;
&lt;li&gt;Kief Morris, Global Head of Infrastructure Engineering at ThoughtWorks&lt;/li&gt;
&lt;li&gt;Lindsay Jack, VP of Engineering &amp;amp; Security at Snyk&lt;/li&gt;
&lt;li&gt;Nariman Aga-Tagiyev, Application Security Architect at WiseFrog Security&lt;/li&gt;
&lt;li&gt;Komal Ali, Engineering Manager at Pulumi&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The panel discussed key strategies, challenges, and pillars of successful platform engineering.&lt;/p&gt;
&lt;h2 id="in-this-article"&gt;In this article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#the-core-pillars-of-platform-engineering"&gt;The Core Pillars of Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#aligning-devops-and-security-for-secure-platform-engineering"&gt;Aligning DevOps and Security for Secure Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#shift-left-security"&gt;Shift Left Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#embrace-automation-and-standardization"&gt;Embrace Automation and Standardization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#prioritize-observability-and-monitoring"&gt;Prioritize Observability and Monitoring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#foster-a-culture-of-collaboration"&gt;Foster a Culture of Collaboration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#challenges-of-integrating-security-in-platform-engineering"&gt;Challenges of Integrating Security in Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#balancing-autonomy-and-control"&gt;Balancing Autonomy and Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#driving-adoption-and-changing-mindsets"&gt;Driving Adoption and Changing Mindsets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#adapting-to-evolving-needs-and-technologies"&gt;Adapting to Evolving Needs and Technologies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#measuring-success-in-secure-platform-engineering"&gt;Measuring Success in Secure Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#the-future-of-secure-platform-engineering"&gt;The Future of Secure Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-core-pillars-of-platform-engineering"&gt;The Core Pillars of Platform Engineering&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/WUpyqn1Jfwg?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices/"&gt;Platform engineering teams&lt;/a&gt; comprise multiple professionals with many responsibilities and focus areas. According to our panel of experts, the core pillars of platform engineering include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/"&gt;Developer Experience (DevEx)&lt;/a&gt;&lt;/strong&gt;: Provide developers with the tools, frameworks, and abstractions they need to be productive and proactive without getting stuck in infrastructure or operational concerns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#an-effective-internal-developer-platform"&gt;Reliability and Scalability&lt;/a&gt;&lt;/strong&gt;: Ensure that the platform and infrastructure can support the organization&amp;rsquo;s needs, with the ability to scale up or down as required.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/"&gt;Security and Compliance&lt;/a&gt;&lt;/strong&gt;: Embed robust, accessible security and compliance frameworks into the development lifecycle while making it easy for developers to adhere to these policies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/automation-api/"&gt;Automation and Tooling&lt;/a&gt;&lt;/strong&gt;: Leverage &lt;a href="https://www.pulumi.com/product/infrastructure-as-code/"&gt;Infrastructure as Code (IaC)&lt;/a&gt; and automation to enforce standardized processes and consistency and reduce cognitive load and manual effort.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Observability and Monitoring&lt;/a&gt;&lt;/strong&gt;: Provide visibility into the platform&amp;rsquo;s health and performance, delivering actionable insights that allow teams to identify and resolve issues quickly.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These pillars work together to create a platform that empowers developers to innovate and deliver value to the organization and customers while maintaining the necessary controls and safeguards.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Jess Mink, Director of Platform Engineering at &lt;a href="https://www.pulumi.com/blog/observability-with-infrastructure-as-code/"&gt;Honeycomb&lt;/a&gt;, explains:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;The goal of platform engineering is to help the company run smoother and faster and unlock things people didn&amp;rsquo;t know were possible [&amp;hellip;] We tend to focus on tools and software, but it&amp;rsquo;s really about people, processes, and tools. If you consider this, platforms are responsible for social and technical support across the organization. A common pitfall is building tools no one uses because you didn’t meet people where they are.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="aligning-devops-and-security-for-secure-platform-engineering"&gt;Aligning DevOps and Security for Secure Platform Engineering&lt;/h2&gt;
&lt;p&gt;Integrating security into platform engineering ensures it becomes a proactive part of the development lifecycle and ensures that &amp;ldquo;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/"&gt;DevSecOps&lt;/a&gt;&amp;rdquo; is not an afterthought but a core consideration.&lt;/p&gt;
&lt;p&gt;Key best practices shared by the panel include:&lt;/p&gt;
&lt;h3 id="shift-left-security"&gt;Shift Left Security&lt;/h3&gt;
&lt;p&gt;One of the fundamental principles of DevSecOps is to &amp;ldquo;shift left&amp;rdquo; - that is, to integrate security earlier in the development process rather than waiting until the end. This can involve activities such as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Incorporating security requirements and threat modeling into the initial design phase&lt;/li&gt;
&lt;li&gt;Automating security scans and tests as part of the continuous integration (CI) pipeline&lt;/li&gt;
&lt;li&gt;Providing developers with secure coding guidelines and tools to &lt;a href="https://www.pulumi.com/blog/drift-detection/#why-pulumi-cloud-drift-detection-and-remediation"&gt;identify and remediate vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By addressing security concerns upfront, organizations can reduce the time and cost of remediating issues later in the development lifecycle.&lt;/p&gt;
&lt;h3 id="embrace-automation-and-standardization"&gt;Embrace Automation and Standardization&lt;/h3&gt;
&lt;p&gt;Consistency is key. Platform engineering teams should leverage automation and built-in safeguards and security processes. This may include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automating the provisioning of secure infrastructure and application environments&lt;/li&gt;
&lt;li&gt;Implementing Infrastructure as Code (IaC) to define and &lt;a href="https://www.pulumi.com/blog/pulumi-is-imperative-declarative-imperative/"&gt;manage infrastructure in a declarative&lt;/a&gt;, version-controlled manner&lt;/li&gt;
&lt;li&gt;Standardizing security controls, policies, and configurations across the platform&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By automating these tasks, platform engineering teams can reduce the risk of human error, improve visibility and auditability, and free up developers to focus on building features rather than managing infrastructure.&lt;/p&gt;
&lt;h3 id="prioritize-observability-and-monitoring"&gt;Prioritize Observability and Monitoring&lt;/h3&gt;
&lt;p&gt;Effective security requires visibility into the health and performance of the platform. Platform engineering teams should invest in robust observability and monitoring solutions to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/drift-detection/"&gt;Detect and respond&lt;/a&gt; to security incidents and anomalies in real-time&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Gain insights&lt;/a&gt; into the behavior and usage patterns of the platform&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#policy-enforcement-ensuring-compliance-and-security"&gt;Identify and address&lt;/a&gt; vulnerabilities or misconfigurations proactively&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By integrating security-focused monitoring and alerting into the platform, organizations can quickly identify and mitigate threats while also providing developers with the necessary context to understand and address security-related issues.&lt;/p&gt;
&lt;h3 id="foster-a-culture-of-collaboration"&gt;Foster a Culture of Collaboration&lt;/h3&gt;
&lt;p&gt;Platform engineering is often referred to as being the practical application of DevOps practices. Integrating security practices often requires a cultural shift towards collaboration and shared responsibility between all teams in development, operations, and security, thus the name DevSecOps. Platform engineering teams can facilitate this by:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Treating &lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#platforms-as-products-driving-success"&gt;Platforms as Products&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Involving security stakeholders in the design and planning of platform initiatives&lt;/li&gt;
&lt;li&gt;Providing security training and education to developers to empower them to make informed decisions&lt;/li&gt;
&lt;li&gt;Establishing communication channels and feedback loops between teams&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Kief Morris, Global Head of Infrastructure Engineering at &lt;a href="https://www.thoughtworks.com/en-us"&gt;ThoughtWorks&lt;/a&gt;, explains:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;There is a new way of thinking that is trying to avoid that &amp;ldquo;build it, and they will come mentality,&amp;rdquo; which leads to building it and nobody using it. One of the trends we are seeing is product thinking [&amp;hellip;]—using techniques like creating user personas of different types of users in the organization, conducting research to understand their needs, and talking with them.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Breaking silos and fostering communication helps organizations build secure, scalable platforms that support the needs of developers, platform engineers, architects, and security teams.&lt;/p&gt;
&lt;h2 id="challenges-of-integrating-security-in-platform-engineering"&gt;Challenges of Integrating Security in Platform Engineering&lt;/h2&gt;
&lt;p&gt;While the benefits of integrating DevOps and security in platform engineering are clear, the journey has expected challenges. Our panel of experts highlighted several key obstacles that organizations may face:&lt;/p&gt;
&lt;h3 id="balancing-autonomy-and-control"&gt;Balancing Autonomy and Control&lt;/h3&gt;
&lt;p&gt;The primary goal is to empower developers to be more productive and proactive. However, this autonomy needs to be balanced with necessary security controls and governance measures.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Jess Mink points out the importance of achieving harmony between developer autonomy and operational control, stating:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;It&amp;rsquo;s a delicate balance - you want to make things easy for developers, but you also need to maintain the right level of control and security. It&amp;rsquo;s about finding the right abstractions and interfaces that give developers the freedom they need while still ensuring the platform remains secure and compliant.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="driving-adoption-and-changing-mindsets"&gt;Driving Adoption and Changing Mindsets&lt;/h3&gt;
&lt;p&gt;Integrating security into the platform engineering workflow can often be met with resistance from developers accustomed to moving quickly and may view security as an obstacle to their productivity.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Nariman, a Software Security Architect, notes:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;The challenge is not just about the tools or the technology - it&amp;rsquo;s about changing the mindset and getting people to understand the importance of security. You need to find ways to motivate developers and make them feel like they&amp;rsquo;re part of the solution rather than just imposing more rules and processes.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Effective communication, education, and a focus on the business value of security are key to driving adoption and fostering a culture of shared responsibility.&lt;/p&gt;
&lt;h3 id="adapting-to-evolving-needs-and-technologies"&gt;Adapting to Evolving Needs and Technologies&lt;/h3&gt;
&lt;p&gt;As organizations grow and their technology stacks evolve, the demands on the platform engineering team can shift rapidly. Keeping up with these changes, while maintaining a secure and reliable platform, can be a significant challenge.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Lindsay Jack, VP of Engineering for the Platform Division at &lt;a href="https://partners.snyk.io/English/solutions/solution/2908/pulumi"&gt;Snyk&lt;/a&gt;, explains:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;You might have a platform team that&amp;rsquo;s really good at a certain set of technologies, but then the organization starts moving in a new direction, and suddenly those skills don&amp;rsquo;t match up anymore. It&amp;rsquo;s about being agile and adaptable and making sure you have the right mix of skills and expertise to support the organization&amp;rsquo;s evolving needs&lt;/em&gt;.&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Fostering internal mobility, continuous learning, and a flexible, modular platform architecture can help platform engineering teams navigate these changes more effectively.&lt;/p&gt;
&lt;h2 id="measuring-success-in-secure-platform-engineering"&gt;Measuring Success in Secure Platform Engineering&lt;/h2&gt;
&lt;p&gt;Measuring the success of a platform engineering initiative can be complex as it involves balancing a range of technical, operational, and business-oriented metrics but also considers human factors. According to our panel, some key metrics to include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Developer Experience&lt;/strong&gt;: Metrics such as developer satisfaction surveys, time-to-onboard new developers, and the number of self-service platform capabilities can provide insights into the effectiveness of the platform in supporting developer productivity and autonomy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reliability and Scalability&lt;/strong&gt;: Monitoring service-level objectives (SLOs), incident response times, and the ability to handle increased traffic or user demands can help assess the platform&amp;rsquo;s reliability and scalability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security and Compliance&lt;/strong&gt;: Tracking the number of security incidents, the ratio of security issues found during threat modeling versus post-deployment, and the adoption of security best practices can indicate the platform&amp;rsquo;s security posture.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automation and Tooling&lt;/strong&gt;: Metrics like the percentage of infrastructure provisioned through code, the frequency of platform updates, and the time saved through automation can demonstrate the platform&amp;rsquo;s operational efficiency.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Observability and Monitoring&lt;/strong&gt;: Measuring the effectiveness of observability tools, the time to detect and resolve issues, and the quality of incident reports can &lt;a href="https://www.pulumi.com/blog/insights-cloud-account-discovery/"&gt;provide insights into the platform&amp;rsquo;s overall health&lt;/a&gt; and performance.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Jess Mink emphasizes, it&amp;rsquo;s important not just to collect these metrics but to use them to drive meaningful action and improvement:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;We look at all of those [metric categories] every quarter and write summaries that go up to the executive level. This creates visibility and a shared understanding of problems so that there&amp;rsquo;s room for movement and change in the right ways.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="the-future-of-secure-platform-engineering"&gt;The Future of Secure Platform Engineering&lt;/h2&gt;
&lt;p&gt;Software development and infrastructure management are evolving, and the role of platform engineering will only become more critical to support it. By integrating DevOps and security practices, platform engineering teams can create scalable, secure platforms that empower developers to be more productive and innovate, delivering business value.&lt;/p&gt;
&lt;p&gt;Learn how Pulumi customers build secure, scalable platforms and empower their development teams:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tivity Health&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/"&gt;DevSecOps Game-Changer: Security Automation That Delivers Business Results&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;BMW Group&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/"&gt;Unified and Programmatic Approach to Infrastructure Management at BMW Using Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Lemonade&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/case-studies/lemonade/"&gt;How the DevOps team supports a much larger group of developers&lt;/a&gt; using by Pulumi to standardize infrastructure components and enforce best practices.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Discover platform engineering best practices in &lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices/"&gt;The Guide to Platform Engineering: 7 Steps to Get It Right&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Build secure, scalable platforms with confidence—get started with the &lt;a href="https://info.pulumi.com/platform-engineering-workshop-series"&gt;Platform Engineering Workshop Series &amp;amp; Course&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;</description><author>Sara Huddleston</author><category>devsecops</category><category>platform-engineering</category><category>developer-experience</category><category>devops</category><category>security</category></item><item><title>DevSecOps Game-Changer: Security Automation That Delivers Business Results</title><link>https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/</link><pubDate>Thu, 21 Nov 2024 07:16:30 +0000</pubDate><guid>https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/devsecops-strategy-security-automation-tivity-health/index.png" /&gt;
&lt;p&gt;Organizations are under constant pressure to deliver new products and features faster than ever. But speed alone isn’t enough—businesses must also navigate the complex challenges of ensuring security and managing infrastructure costs effectively.&lt;/p&gt;
&lt;p&gt;Enter DevSecOps - the strategic integration of security practices into the DevOps workflow. By automating security processes, organizations can achieve improved speed, scalability, and business impact, all while ensuring security remains a priority.&lt;/p&gt;
&lt;p&gt;Tivity Health, a leading health and fitness solutions provider, has embraced this DevSecOps approach using Pulumi, a modern infrastructure as code (IaC) platform. During PulumiUP 2024, David Giambruno, Tivity Health&amp;rsquo;s VP of Engineering and DevOps, shared how, by leveraging Pulumi, he led the transformation that continuously drives remarkable results in speed, cost savings, and security.&lt;/p&gt;
&lt;h2 id="on-this-article"&gt;On this article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#the-beginning-from-data-center-to-the-cloud"&gt;The Beginning: From Data Center to the Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#embracing-pulumi-the-power-of-automation-productivity-and-security"&gt;Embracing Pulumi: The Power of Automation, Productivity, and Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#driving-business-impact-through-security-automation"&gt;Driving Business Impact Through Security Automation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#fostering-devops-culture-through-cross-functional-collaboration"&gt;Fostering DevOps Culture Through Cross-Functional Collaboration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#lessons-learned-navigating-the-cultural-shift"&gt;Lessons Learned: Navigating the Cultural Shift&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#the-future-of-devsecops-and-pulumi-at-tivity-health"&gt;The Future of DevSecOps and Pulumi at Tivity Health&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-beginning-from-data-center-to-the-cloud"&gt;The Beginning: From Data Center to the Cloud&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.tivityhealth.com/"&gt;Tivity Health&lt;/a&gt;&amp;rsquo;s journey began with a strategic decision to transition from a traditional data center environment to a cloud-native architecture. Rather than opting for a &amp;ldquo;lift and shift&amp;rdquo; approach, they made the bold choice to go directly to a cloud-native model, embracing the principles of DevSecOps along the way.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/35vAiKdDux4?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;The need to &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/"&gt;automate infrastructure deployment&lt;/a&gt; and management was fundamental. Giambruno explained, &amp;ldquo;&lt;em&gt;If you can&amp;rsquo;t automate it, we don&amp;rsquo;t need it.&lt;/em&gt;&amp;rdquo; This philosophy drove the team to seek out a solution that would not only streamline their operations but also empower their developers to focus on building innovative products for their customers.&lt;/p&gt;
&lt;h2 id="embracing-pulumi-the-power-of-automation-productivity-and-security"&gt;Embracing Pulumi: The Power of Automation, Productivity, and Security&lt;/h2&gt;
&lt;p&gt;Tivity Health&amp;rsquo;s search for the right tool led them to Pulumi, a unified platform for all the infrastructure needs that allows teams to use general programming languages, such as TypeScript, Python, Java, and Go, to define and manage their cloud infrastructure. Giambruno and his team immediately recognized Pulumi&amp;rsquo;s ability to deliver on their key requirements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Automation&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/docs/iac/"&gt;Pulumi&amp;rsquo;s infrastructure as code (IaC)&lt;/a&gt; approach enabled Tivity Health to automate the deployment and management of its cloud environments, reducing the time and effort required for these tasks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Productivity&lt;/strong&gt;: using Pulumi&amp;rsquo;s general-purpose programming languages allowed developers to define, deploy, and manage infrastructure within their existing tools.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security&lt;/strong&gt;: Pulumi&amp;rsquo;s security features allowed Tivity Health to integrate &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/"&gt;security practices&lt;/a&gt; into its infrastructure deployment processes, reducing the risk of security breaches and ensuring compliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cost Optimization&lt;/strong&gt;: Pulumi&amp;rsquo;s ability to automate the spin-up and teardown of cloud environments on demand has led to significant cost reductions for Tivity Health.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Giambruno describes Pulumi as a &amp;ldquo;three-dimensional&amp;rdquo; tool, offering a versatile set of capabilities that have been instrumental in transforming Tivity Health&amp;rsquo;s operations. &amp;ldquo;&lt;em&gt;The ability to use those dimensions in lots of different ways to do the automation is what really makes a difference to the teams&lt;/em&gt;,&amp;rdquo; he says.&lt;/p&gt;
&lt;h2 id="driving-business-impact-through-security-automation"&gt;Driving Business Impact Through Security Automation&lt;/h2&gt;
&lt;p&gt;By adopting Pulumi and DevSecOps automation, Tivity Health realized significant business benefits:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Speed and Agility&lt;/strong&gt;: By automating its infrastructure deployment and management processes, Tivity Health has dramatically &lt;a href="https://www.pulumi.com/case-studies/unity/"&gt;reduced the time&lt;/a&gt; required to spin up new environments or change existing ones. &amp;ldquo;&lt;em&gt;We run it through automation and boom, it&amp;rsquo;s out, it&amp;rsquo;s done&lt;/em&gt;,&amp;rdquo; Giambruno says. This newfound speed and agility have empowered Tivity Health&amp;rsquo;s developers to focus on building products and features rather than getting bogged down in infrastructure-related tasks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cost Optimization&lt;/strong&gt;: Tivity Health&amp;rsquo;s cloud-native approach and Pulumi&amp;rsquo;s automation capabilities have resulted in &lt;a href="https://www.pulumi.com/case-studies/lemonade/"&gt;significant cost savings&lt;/a&gt;. The company estimates that its annual cloud spend has decreased from $9.5 million in its data center days to just $2 million—a staggering 79% reduction. These cost savings have allowed Tivity Health to redirect resources towards more strategic initiatives that drive business growth.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Improved Security and Compliance&lt;/strong&gt;: Tivity Health&amp;rsquo;s DevSecOps strategy, anchored by Pulumi, has strengthened its security posture and &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies/"&gt;compliance efforts&lt;/a&gt;. By integrating security directly into its infrastructure workflows, Tivity Health has improved its security posture. Automation ensures that security measures are enforced consistently across their cloud environments, reducing risks and improving compliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="fostering-devops-culture-through-cross-functional-collaboration"&gt;Fostering DevOps Culture Through Cross-Functional Collaboration&lt;/h2&gt;
&lt;p&gt;Using Pulumi provided more than technical benefits. It also enabled better collaboration between the development, security, and operations teams. By providing a common language and framework for infrastructure management, Pulumi has helped break down silos and align these traditionally disparate groups towards a shared goal of delivering secure, high-quality products faster.&lt;/p&gt;
&lt;h2 id="lessons-learned-navigating-the-cultural-shift"&gt;Lessons Learned: Navigating the Cultural Shift&lt;/h2&gt;
&lt;p&gt;Transitioning to DevSecOps and cloud-native practices required a cultural shift at Tivity Health. Giambrono acknowledges that this cultural shift was not without its challenges. He emphasizes the importance of addressing the human element of change, offering the following advice for organizations embarking on a similar journey:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Start with a proof of concepts&lt;/strong&gt;: Giambruno recommends beginning with a small-scale proof of concepts to demonstrate the capabilities and benefits of the new technologies and processes to help alleviate fears and build confidence among team members.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Empower developers and make them feel safe&lt;/strong&gt;: By involving developers in the process and ensuring they feel comfortable with the new tools and workflows, Tivity Health gained user buy-in and overall support for the new DevSecOps approach.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secure buy-in from business and financial stakeholders&lt;/strong&gt;: Address the concerns of business and financial stakeholders early on, such as the impact on costs and the ability to deliver tangible results. This is crucial for securing the necessary support and resources.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Celebrate successes and build momentum&lt;/strong&gt;: Giambruno highlights the importance of celebrating the team&amp;rsquo;s achievements along the way, even when there are bumps on the road, as this helps build enthusiasm and keep the momentum going.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-future-of-devsecops-and-pulumi-at-tivity-health"&gt;The Future of DevSecOps and Pulumi at Tivity Health&lt;/h2&gt;
&lt;p&gt;As Tivity Health continues to refine its DevSecOps strategy, Giambruno is optimistic about the future. He envisions a world where the company&amp;rsquo;s ability to deploy new products and features rapidly will give Tivity Health a significant competitive edge, allowing it to better serve its customers and drive business growth.&lt;/p&gt;
&lt;p&gt;Looking ahead, Giambruno is particularly enthusiastic about the potential of Pulumi&amp;rsquo;s AI-powered capabilities, which he believes will further streamline and optimize the company&amp;rsquo;s infrastructure management processes. &amp;ldquo;&lt;em&gt;I&amp;rsquo;m super looking forward to the tests we&amp;rsquo;re going to do, like when we acquire someone and then taking them in, &amp;lsquo;Borg-ing&amp;rsquo; them into our automation and seeing how much we can take out of their operating cost as fast as possible&lt;/em&gt;,&amp;rdquo; he says.&lt;/p&gt;
&lt;p&gt;Tivity Health&amp;rsquo;s journey with Pulumi is a powerful example of how the right tool, DevSecOps strategy, and automation can drive tangible business results. By focusing on automation, security, and collaboration, organizations can achieve faster, cheaper, and better cloud deployments—putting them on the path to long-term success in an increasingly competitive, cloud-native world.&lt;/p&gt;
&lt;p&gt;To learn more about Pulumi and how it can transform your software development and infrastructure management:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Get started with &lt;a href="https://www.pulumi.com/tutorials/"&gt;Pulumi Tutorials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Attend an &lt;a href="https://www.pulumi.com/resources/#upcoming"&gt;upcoming workshop&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Try out the &lt;a href="https://www.pulumi.com/product/neo/"&gt;Pulumi Neo&lt;/a&gt; code assistant to accelerate your infrastructure as code journey&lt;/li&gt;
&lt;/ul&gt;</description><author>Sara Huddleston</author><category>security</category><category>devsecops</category><category>devops</category><category>infrastructure-as-code</category><category>platform-engineering</category><category>infrastructure-lifecycle-management</category><category>developer-experience</category></item><item><title>The Guide to Platform Engineering: 7 Steps to Get It Right</title><link>https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices/</link><pubDate>Tue, 22 Oct 2024 07:47:03 +0000</pubDate><guid>https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/the-guide-platform-engineering-idp-steps-best-practices/index.png" /&gt;
&lt;p&gt;In today’s fast-paced digital landscape, organizations are increasingly adopting platform engineering to optimize their software delivery and operations. Gartner predicts that by 2026, 80% of large software engineering organizations will have platform engineering teams to provide reusable services, components, and tools for application delivery. Additionally, by 2027, 80% of large enterprises will leverage platform engineering to scale DevOps initiatives in hybrid cloud environments effectively.&lt;/p&gt;
&lt;p&gt;This shift is driven by the rise of cloud adoption, where many enterprises face the challenge of uncoordinated application teams deploying workloads in different ways across various cloud platforms. This siloed approach often results in a lack of standardization, security risks, and operational inefficiencies.&lt;/p&gt;
&lt;p&gt;Platform engineering offers a strategic solution to these issues. This guide provides the essential steps to successfully implement platform engineering, from laying the foundation to scaling internal developer platforms (IDPs) for future growth.&lt;/p&gt;
&lt;h2 id="on-this-article"&gt;On this article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#step-1-securing-executive-buy-in"&gt;Step 1: Securing Executive Buy-in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#step-2-staffing-the-platform-engineering-team"&gt;Step 2: Staffing the Platform Engineering Team&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#step-3-defining-the-platform-mandate"&gt;Step 3: Defining the Platform Mandate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#step-4-implementing-the-pre-production-pipeline"&gt;Step 4: Implementing the Pre-Production Pipeline&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#step-5-embracing-infrastructure-as-code"&gt;Step 5: Embracing Infrastructure as Code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#step-6-implementing-policy-as-code"&gt;Step 6: Implementing Policy as Code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#step-7-evolving-towards-self-service"&gt;Step 7: Evolving Towards Self-Service&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices#frequently-asked-questions"&gt;Frequently Asked Questions (Platform Engineering Concepts &amp;amp; Definitions)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="step-1-securing-executive-buy-in"&gt;Step 1: Securing Executive Buy-in&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/t4c3NOiuhXQ?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;The first step in your platform engineering journey is securing executive buy-in. This high-level support is essential, as platform engineering teams must create an organization-wide strategy that integrates internal developer portals (IDPs) and self-service capabilities. Leadership needs to understand how platform engineering can address inefficiencies caused by siloed application teams and uncoordinated cloud deployments.&lt;/p&gt;
&lt;p&gt;To do this, present a clear roadmap with measurable outcomes, such as improved delivery speed and security. Use metrics like &lt;a href="https://en.wikipedia.org/wiki/DevOps_Research_and_Assessment"&gt;DORA&lt;/a&gt; (Deployment Frequency, Lead Time, Mean Time to Recovery) to demonstrate how platform engineering enhances security, standardization, and efficiency. Outline the required resources (headcount, budget, tooling) and align the project with business objectives.&lt;/p&gt;
&lt;h2 id="step-2-staffing-the-platform-engineering-team"&gt;Step 2: Staffing the Platform Engineering Team&lt;/h2&gt;
&lt;p&gt;Once you have executive backing, the next step is to assemble your platform engineering team. This team will &lt;a href="https://www.pulumi.com/blog/developer-portal-platform-teams/"&gt;develop and maintain your internal developer platform (IDP)&lt;/a&gt;, ensuring it offers the organization secure, scalable, and self-service solutions.&lt;/p&gt;
&lt;p&gt;Successful platform engineering teams are characterized by a strong customer focus, empathy for the needs of application teams, and the ability to act as the &amp;ldquo;glue&amp;rdquo; that binds the organization together. Key roles and responsibilities within the platform team include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Customer-facing roles&lt;/strong&gt;: Serve as the primary point of contact for application teams, understanding their needs and advocating for their requirements within the platform.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Infrastructure expertise&lt;/strong&gt;: Possess deep knowledge of the underlying infrastructure, whether on-premises or in the cloud, to ensure the platform is reliable and scalable.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DevOps and automation skills&lt;/strong&gt;: Leverage infrastructure as code (IaC) tools and techniques to automate the provisioning and management of the platform.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/finops-with-pulumi/"&gt;FinOps&lt;/a&gt; and cost optimization expertise&lt;/strong&gt;: Understand the organization&amp;rsquo;s financial systems and processes to ensure the platform is cost-effective and aligned with budgetary constraints.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Software development capabilities&lt;/strong&gt;: Develop the platform&amp;rsquo;s core components, including self-service interfaces and reusable infrastructure modules, using best practices in software engineering.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By assembling a team with this diverse set of skills and a customer-centric mindset, you&amp;rsquo;ll be well-positioned to build a platform that truly meets the needs of your application teams.&lt;/p&gt;
&lt;h2 id="step-3-defining-the-platform-mandate"&gt;Step 3: Defining the Platform Mandate&lt;/h2&gt;
&lt;p&gt;Next, clearly define the platform team’s mandate to set expectations. This document should outline the platform’s purpose, the services it provides, and how it supports &lt;a href="https://www.pulumi.com/blog/building-developer-portals/"&gt;internal developer portals (IDPs)&lt;/a&gt; and self-service capabilities.&lt;/p&gt;
&lt;p&gt;The platform mandate should serve as a central reference point for the platform team and its customers, ensuring everyone is aligned on the team&amp;rsquo;s mission and its value. Key elements to include in the platform mandate include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Introduction&lt;/strong&gt;: A high-level overview of the platform team&amp;rsquo;s purpose and the organizational outcomes it aims to achieve.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Supported systems&lt;/strong&gt;: A list of the infrastructure, services, and tools that the platform team is responsible for managing and supporting.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Support model&lt;/strong&gt;: Details on how application teams can access platform services, including any self-service capabilities and the team&amp;rsquo;s response times for different types of requests.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Team structure&lt;/strong&gt;: An overview of the platform team&amp;rsquo;s members and their areas of expertise, making it easy for application teams to identify the right point of contact.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A well-defined mandate aligns the team and its customers with the platform’s value and purpose.&lt;/p&gt;
&lt;h2 id="step-4-implementing-the-pre-production-pipeline"&gt;Step 4: Implementing the Pre-Production Pipeline&lt;/h2&gt;
&lt;p&gt;With a mandate in place, begin building the core capabilities, starting with a pre-production pipeline. This pipeline standardizes how application code moves from development to deployment, emphasizing security and consistency.&lt;/p&gt;
&lt;p&gt;Key components of the pre-production pipeline include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Version control&lt;/strong&gt;: Implement a centralized version control system to manage application code and infrastructure as code (IaC) configurations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Continuous integration (CI)&lt;/strong&gt;: Automate the build and testing of application artifacts, such as container images or deployment packages.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Artifact management&lt;/strong&gt;: Provide a secure and versioned repository for storing and distributing the application artifacts produced by the CI process.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Static analysis&lt;/strong&gt;: Integrate tools that can scan application code and dependencies for security vulnerabilities and other issues.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Application delivery&lt;/strong&gt;: Automate the deployment of application artifacts to pre-production environments, such as staging or testing.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By establishing a standardized pre-production pipeline, you&amp;rsquo;ll ensure that all application teams follow a consistent, secure, and efficient process for getting their code into a production-ready state.&lt;/p&gt;
&lt;h2 id="step-5-embracing-infrastructure-as-code"&gt;Step 5: Embracing Infrastructure as Code&lt;/h2&gt;
&lt;p&gt;Leveraging infrastructure as code (IaC) is crucial for managing the platform’s infrastructure. It enables consistent, scalable, and secure operations by automating the provisioning of resources, monitoring, and enforcing security policies.&lt;/p&gt;
&lt;p&gt;Key areas where IaC can be applied within the platform include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Foundational infrastructure&lt;/strong&gt;: Provision and manage the underlying cloud resources, such as virtual networks, storage, and compute, that form the platform&amp;rsquo;s foundation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Runtime platforms&lt;/strong&gt;: Deploy and configure the runtime environments where application workloads will be executed, such as Kubernetes clusters or serverless functions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Observability and monitoring&lt;/strong&gt;: Set up the logging, metrics, and alerting systems that provide visibility into the platform&amp;rsquo;s health and performance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security and compliance&lt;/strong&gt;: Implement security controls, such as &lt;a href="https://www.pulumi.com/docs/esc/"&gt;secrets management&lt;/a&gt; and &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/get-started/"&gt;access policies&lt;/a&gt;, to ensure the platform meets regulatory and organizational requirements.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pipelines and &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/automation-api/"&gt;automation&lt;/a&gt;&lt;/strong&gt;: Use IaC to define and version-control the platform&amp;rsquo;s own deployment and management pipelines, ensuring consistency and repeatability.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/"&gt;infrastructure as code&lt;/a&gt;, the platform engineering team can ensure reliable, scalable, and secure infrastructure across the organization.&lt;/p&gt;
&lt;h2 id="step-6-implementing-policy-as-code"&gt;Step 6: Implementing Policy as Code&lt;/h2&gt;
&lt;p&gt;Alongside your IaC efforts, it&amp;rsquo;s important to set up a robust policy-as-code framework within your platform. Policy-as-code allows you to enforce security, compliance, and operational policies programmatically. This provides governance at scale, ensuring all teams follow the same rules.&lt;/p&gt;
&lt;p&gt;Policy as code can be applied in two key ways:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Preventative controls&lt;/strong&gt;: Implement policies that proactively validate and reject non-compliant infrastructure changes before they are provisioned, providing fast feedback to application teams.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Detective controls&lt;/strong&gt;: Establish policies that continuously monitor the deployed infrastructure, triggering alerts or remediation actions when deviations from the desired state are detected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By combining &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/"&gt;IaC and policy as code&lt;/a&gt; with self-service provisioning, you maintain security and compliance while giving teams autonomy.&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Build your internal developer platform&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Give developers self-service infrastructure with reusable components, golden paths, and governance built in using Pulumi IDP.&lt;/div&gt;
&lt;a href="https://www.pulumi.com/product/internal-developer-platforms/" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Explore Pulumi IDP
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="step-7-evolving-towards-self-service"&gt;Step 7: Evolving Towards Self-Service&lt;/h2&gt;
&lt;p&gt;As your platform matures, the ultimate goal is to empower your application teams with self-service capabilities, allowing them to provision the infrastructure and resources they need quickly and autonomously. This self-service model can take various forms, from pre-defined infrastructure modules to fully automated deployment pipelines.&lt;/p&gt;
&lt;p&gt;When implementing self-service capabilities, keep the following platform engineering best practices in mind:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Start small and iterate&lt;/strong&gt;: Don&amp;rsquo;t try to boil the ocean. Begin with a few well-defined use cases, such as CI/CD pipelines or database provisioning, and gradually expand the self-service offerings as your platform team gains experience and confidence.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/"&gt;Focus on user experience&lt;/a&gt;&lt;/strong&gt;: Ensure that the self-service interfaces, whether web-based or command-line, are intuitive and easy to use. Gather feedback from application teams and continuously refine the user experience.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Maintain stability and reliability&lt;/strong&gt;: Even with self-service, the platform team is responsible for ensuring the underlying infrastructure and services remain stable and reliable. Implement robust monitoring, alerting, and incident response processes to maintain platform health.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Embrace a product mindset&lt;/strong&gt;: Treat the &lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#platforms-as-products-driving-success"&gt;platform as a product&lt;/a&gt;, with the application teams as your customers. Continuously gather feedback, measure key performance indicators, and iterate on the platform&amp;rsquo;s capabilities to meet evolving needs.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By gradually transitioning towards a self-service model, you&amp;rsquo;ll empower your application teams to move faster while maintaining the necessary guardrails and controls to ensure the platform&amp;rsquo;s long-term success.&lt;/p&gt;
&lt;h2 id="conclusion-embracing-the-platform-engineering-journey"&gt;Conclusion: Embracing the Platform Engineering Journey&lt;/h2&gt;
&lt;p&gt;Building a successful platform engineering strategy involves following a clear roadmap. But remember, implementing the platform engineering strategy is a journey, not a destination. By following the steps outlined in this guide, you&amp;rsquo;ll be well on your way to building a robust, secure, scalable, and customer-centric internal developer platform (IDP) that empowers your organization to deliver software more efficiently and effectively.&lt;/p&gt;
&lt;p&gt;With the right approach and mindset, your platform engineering efforts will become a strategic enabler for your organization&amp;rsquo;s digital transformation.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Build secure, scalable platforms with confidence—&lt;a href="https://info.pulumi.com/platform-engineering-workshop-series"&gt;register for the Platform Engineering Course&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="frequently-asked-questions"&gt;Frequently Asked Questions&lt;/h2&gt;
&lt;h3 id="what-is-platform-engineering"&gt;What is Platform Engineering?&lt;/h3&gt;
&lt;p&gt;There are many definitions for platform engineering, one of which is designing, building, and maintaining internal platforms that streamline software delivery by providing reusable tools, services, and workflows for developers. It focuses on scalability, efficiency, and self-service capabilities for internal teams.&lt;/p&gt;
&lt;p&gt;For a more in-depth explanation of real-world use cases, see &lt;a href="https://www.pulumi.com/what-is/what-is-platform-engineering/"&gt;What is platform engineering&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="who-are-the-platform-customers"&gt;Who are the Platform Customers?&lt;/h3&gt;
&lt;p&gt;The platform customers are the end users, typically internal teams (e.g., application developers and DevOps engineers), who use the platform&amp;rsquo;s tools and services to build, deploy, and manage software.&lt;/p&gt;
&lt;h3 id="what-is-an-internal-developer-platform-idp"&gt;What is an Internal Developer Platform (IDP)?&lt;/h3&gt;
&lt;p&gt;A centralized platform that offers developers the tools and environments they need to build, test, and deploy applications. It abstracts away the complexity of underlying infrastructure, allowing teams to focus on coding and delivery.&lt;/p&gt;
&lt;h3 id="what-is-a-platform-team"&gt;What is a Platform Team?&lt;/h3&gt;
&lt;p&gt;The platform engineering team is a dedicated group of engineers responsible for managing the internal platform. They ensure the platform meets the needs of the organization, providing reliability, security, and scalability.&lt;/p&gt;
&lt;h3 id="what-is-a-self-service-infrastructure"&gt;What is a Self-Service Infrastructure?&lt;/h3&gt;
&lt;p&gt;A platform feature that allows development teams to provision, configure, and manage infrastructure resources on demand without relying on other teams, fostering agility.&lt;/p&gt;
&lt;h3 id="what-is-infrastructure-as-code-iac"&gt;What is Infrastructure as Code (IaC)?&lt;/h3&gt;
&lt;p&gt;The process of managing and provisioning infrastructure through code, allowing infrastructure to be versioned, automated, and managed consistently across environments.&lt;/p&gt;
&lt;p&gt;For a more in-depth explanation, see the &lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;What is Infrastructure as Code? page&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="what-is-policy-as-code-pac"&gt;What is Policy as Code (PaC)?&lt;/h3&gt;
&lt;p&gt;Policy as Code (PaC) defines security, compliance, and &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts/"&gt;operational policies&lt;/a&gt; in code to automate their enforcement across infrastructure and application deployments.&lt;/p&gt;
&lt;h3 id="what-is-developer-experience-devex"&gt;What is Developer Experience (DevEx)?&lt;/h3&gt;
&lt;p&gt;The overall experience developers have with using the platform, tools, and workflows provided by platform engineering. Optimizing DevEx ensures that developers can work more efficiently and effectively.&lt;/p&gt;
&lt;p&gt;For a more in-depth explanation, read &lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/"&gt;Beyond Productivity: Developer Experience is Business Critical.&lt;/a&gt;&lt;/p&gt;</description><author>Sara Huddleston</author><author>Josh Kodroff</author><category>platform-engineering</category><category>developer-portals</category><category>policy-as-code</category><category>finops</category><category>cost-efficiency</category></item><item><title>Unified and Programmatic Approach to Infrastructure Management at BMW Using Pulumi</title><link>https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/</link><pubDate>Thu, 03 Oct 2024 09:52:10 +0000</pubDate><guid>https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/index.png" /&gt;
&lt;p&gt;In the ever-evolving world of automotive technology, BMW has been at the forefront of innovation, seamlessly integrating software into the heart of their vehicles. As cars become increasingly complex, with a growing emphasis on connectivity, over-the-air upgrades, and brand-specific user experiences, the need for a robust and scalable software development approach has become paramount.&lt;/p&gt;
&lt;p&gt;Enter the BMW Software Factory, a platform that aims to empower the company&amp;rsquo;s developers and provide them with a superior development experience. At the core of this initiative is the adoption of Pulumi, a modern infrastructure as code (IaC) solution that has transformed the way BMW manages its software ecosystem.&lt;/p&gt;
&lt;h2 id="on-this-article"&gt;On this article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#the-challenges-of-a-sprawling-software-landscape"&gt;The Challenges of a Sprawling Software Landscape&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#the-evolution-of-bmws-software-development-toolchain"&gt;The Evolution of BMW&amp;rsquo;s Software Development Toolchain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#embracing-pulumi-streamlining-infrastructure-management"&gt;Embracing Pulumi: Streamlining Infrastructure Management&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#the-benefits-of-pulumi-accelerating-development-and-improving-maintainability"&gt;The Benefits of Pulumi: Accelerating Development and Improving Maintainability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#the-future-of-bmws-software-factory-embracing-the-cloud"&gt;The Future of BMW&amp;rsquo;s Software Factory: Embracing the Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#conclusion-unlocking-the-future-of-automotive-software"&gt;Conclusion: Unlocking the Future of Automotive Software&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-challenges-of-a-sprawling-software-landscape"&gt;The Challenges of a Sprawling Software Landscape&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/HIliBBo4c-g?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a href="https://www.bmwgroup.com/en/news/general/2023/BMWGroupIT.html"&gt;BMW&amp;rsquo;s software journey&lt;/a&gt; has been a testament to the exponential growth of automotive technology. What started with simple engine controllers has evolved into a complex network of electronic control units (ECUs) scattered throughout the vehicle. As the software footprint continues to expand, BMW recognized the need for a unified and efficient approach to software development and deployment.&lt;/p&gt;
&lt;p&gt;The company&amp;rsquo;s initial efforts involved introducing a platform called &amp;ldquo;Code Craft,&amp;rdquo; which provided a comprehensive stack of services to support the software development lifecycle. This stack included a GitHub Enterprise application for source code management, a Gerrit system for Android-based developments, a continuous integration (CI) pipeline, artifact stores, build caching, and various other tools and services.&lt;/p&gt;
&lt;p&gt;However, as the demand for software-driven features grew, the complexity of managing this sprawling ecosystem became increasingly challenging. BMW found itself grappling with the need to scale its infrastructure, navigate network limitations across multiple data centers, and adapt to the ever-changing landscape of cloud computing.&lt;/p&gt;
&lt;h2 id="the-evolution-of-bmws-software-development-toolchain"&gt;The Evolution of BMW&amp;rsquo;s Software Development Toolchain&lt;/h2&gt;
&lt;p&gt;BMW&amp;rsquo;s journey to streamline its software development process has been gradual and iterative. The company&amp;rsquo;s initial approach involved using &lt;a href="https://www.pulumi.com/docs/iac/comparisons/chef-puppet-etc/"&gt;Ansible&lt;/a&gt; for deployment and a custom-built deployment scripting solution for its OpenShift cluster.&lt;/p&gt;
&lt;p&gt;As the complexity of the platform increased, BMW turned to Helm and Kubernetes to manage its containerized services. However, as the company ventured into the public cloud, the limitations of these tools became apparent. The team recognized the need for a more comprehensive and scalable solution to manage their infrastructure as code.&lt;/p&gt;
&lt;p&gt;At this critical juncture, BMW discovered Pulumi. This modern IaC solution offered a unique advantage – the ability to leverage a full-fledged programming language, Python, to define and manage their infrastructure. This shift proved to be a game-changer, allowing BMW to leverage its expertise in Python and benefit from the rich ecosystem of libraries and tools available in the Python community.&lt;/p&gt;
&lt;h2 id="embracing-pulumi-streamlining-infrastructure-management"&gt;Embracing Pulumi: Streamlining Infrastructure Management&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/case-studies/bmw/"&gt;BMW&amp;rsquo;s adoption of Pulumi&lt;/a&gt; was a strategic move that aimed to address the growing complexity of its software ecosystem. By transitioning from a patchwork of tools to a unified IaC solution, the company was able to streamline its infrastructure management and improve developer productivity.&lt;/p&gt;
&lt;h3 id="shared-modules-promoting-reusability-and-best-practices"&gt;Shared Modules: Promoting Reusability and Best Practices&lt;/h3&gt;
&lt;p&gt;One of BMW&amp;rsquo;s key initiatives was developing a shared modules library, which allowed the team to abstract the complexity of various infrastructure components, such as databases, and provide a consistent and user-friendly interface for their developers.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;By leveraging &lt;a href="https://www.pulumi.com/docs/iac/languages-sdks/python/"&gt;Pulumi&amp;rsquo;s Python&lt;/a&gt; bindings, BMW was able to create reusable modules that encapsulated best practices and sensible defaults, making it easier for developers to provision and manage infrastructure resources.
BMW used Pydantic, a data validation library, to define schema-based configurations for its infrastructure. These were then integrated into its IDEs, providing developers with auto-completion and validation support.&lt;/li&gt;
&lt;li&gt;This approach not only accelerated the development process but also ensured that the infrastructure deployed across the organization adhered to consistent security and compliance standards.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="transformation-features-protecting-legacy-services"&gt;Transformation Features: Protecting Legacy Services&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;As part of their software factory, BMW also faced the challenge of integrating legacy services that did not natively support modern authentication and authorization mechanisms, such as &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/oidc/provider/"&gt;OpenID Connect (OIDC)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;To address this, BMW leveraged Pulumi&amp;rsquo;s transformation features to seamlessly inject an &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/oidc/client/#exchanging-oidc-tokens"&gt;OAuth2&lt;/a&gt; proxy into their deployments, providing a secure and consistent way to protect these services without requiring extensive modifications to the underlying applications.&lt;/li&gt;
&lt;li&gt;By encapsulating this functionality within a shared module, BMW was able to apply the OAuth2 proxy to multiple services, ensuring a consistent and secure access control layer across their software ecosystem.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="policy-enforcement-ensuring-compliance-and-security"&gt;Policy Enforcement: Ensuring Compliance and Security&lt;/h3&gt;
&lt;p&gt;One key benefit of &lt;a href="https://www.pulumi.com/product/infrastructure-as-code/"&gt;Pulumi&amp;rsquo;s IaC approach&lt;/a&gt; is the ability to define and enforce policies across the organization, ensuring that infrastructure deployments adhere to security and compliance standards.
BMW has leveraged &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/"&gt;Pulumi&amp;rsquo;s policy-as-code&lt;/a&gt; capabilities to implement mandatory checks, such as ensuring that all S3 buckets are encrypted at rest, preventing the deployment of non-compliant resources.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;By integrating these policy checks into their deployment workflows, BMW has shifted security and compliance concerns to the left, addressing issues early in the development process and reducing the risk of costly post-deployment &lt;a href="https://www.pulumi.com/blog/remediation-policies/"&gt;remediations&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-benefits-of-pulumi-accelerating-development-and-improving-maintainability"&gt;The Benefits of Pulumi: Accelerating Development and Improving Maintainability&lt;/h2&gt;
&lt;p&gt;BMW&amp;rsquo;s adoption of Pulumi has yielded significant benefits, transforming the way the company approaches software development and infrastructure management.&lt;/p&gt;
&lt;h3 id="accelerated-development-with-shared-modules"&gt;Accelerated Development with Shared Modules&lt;/h3&gt;
&lt;p&gt;The implementation of shared modules has been a game-changer for BMW. It allows developers to leverage pre-built and tested infrastructure components without having to reinvent the wheel. This has resulted in a significant acceleration of the development process, as teams can focus on building their applications rather than grappling with the complexities of infrastructure provisioning.&lt;/p&gt;
&lt;h3 id="improved-maintainability-and-consistency"&gt;Improved Maintainability and Consistency&lt;/h3&gt;
&lt;p&gt;By centralizing infrastructure management within the shared modules, BMW has ensured that best practices and security standards are consistently applied across the organization. This has not only improved the overall maintainability of the software ecosystem but has also reduced the risk of security and compliance violations.&lt;/p&gt;
&lt;h3 id="leveraging-pythons-ecosystem"&gt;Leveraging Python&amp;rsquo;s Ecosystem&lt;/h3&gt;
&lt;p&gt;BMW&amp;rsquo;s decision to leverage Pulumi&amp;rsquo;s Python bindings has been a strategic advantage, as the company was able to tap into the rich ecosystem of Python libraries and tools. This has enabled the team to seamlessly integrate Pulumi with their existing Python-based toolchain, including dependency management, testing frameworks, and code quality tools, further enhancing the development experience.&lt;/p&gt;
&lt;h3 id="streamlined-cloud-migration"&gt;Streamlined Cloud Migration&lt;/h3&gt;
&lt;p&gt;As BMW continues to expand its use of public cloud services, Pulumi has played a crucial role in simplifying the &lt;a href="https://www.pulumi.com/migrate/"&gt;migration process&lt;/a&gt;. By providing a consistent IaC approach across on-premises and cloud environments, Pulumi has enabled BMW to manage its infrastructure in a unified manner, reducing the complexity and overhead associated with &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/"&gt;multi-cloud deployments&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="the-future-of-bmws-software-factory-embracing-the-cloud"&gt;The Future of BMW&amp;rsquo;s Software Factory: Embracing the Cloud&lt;/h2&gt;
&lt;p&gt;Looking ahead, BMW&amp;rsquo;s Software Factory is poised to take the next step in its evolution, with plans to transition away from the self-hosted backend and embrace cloud-native services. This strategic move aims to further improve &lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/"&gt;developer productivity&lt;/a&gt; and reduce the internal effort required to maintain the underlying infrastructure.&lt;/p&gt;
&lt;p&gt;By leveraging the expertise and reliability of cloud service providers, BMW can focus on delivering innovative software features to their customers while the cloud providers handle the operational aspects of running the necessary services.&lt;/p&gt;
&lt;p&gt;As BMW continues to push the boundaries of automotive software, Pulumi&amp;rsquo;s role in its Software Factory will only become more crucial. By providing a scalable and flexible IaC solution, Pulumi empowers BMW&amp;rsquo;s developers to innovate with confidence and be secure in the knowledge that their infrastructure is managed consistently and in alignment with the company&amp;rsquo;s &lt;a href="https://www.pulumi.com/resources/security-automation-faster-cheaper-better/"&gt;security and compliance standards&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="conclusion-unlocking-the-future-of-automotive-software"&gt;Conclusion: Unlocking the Future of Automotive Software&lt;/h2&gt;
&lt;p&gt;BMW&amp;rsquo;s journey with Pulumi in the Software Factory showcases the power of modern IaC solutions in navigating the complexities of the automotive software landscape. By embracing a unified and programmatic approach to infrastructure management, BMW has accelerated development, improved maintainability, and ensured compliance across its sprawling software ecosystem.&lt;/p&gt;
&lt;p&gt;As the automotive industry continues to evolve, with cars becoming increasingly software-driven, the lessons learned by BMW can serve as a blueprint for other organizations looking to streamline their software development and deployment processes. By leveraging the capabilities of Pulumi and other cutting-edge technologies, the future of automotive software is poised to be more efficient, secure, and responsive to the ever-changing needs of both manufacturers and consumers.&lt;/p&gt;
&lt;p&gt;To learn more about Pulumi and how it can transform your software development and infrastructure management:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Get started with &lt;a href="https://www.pulumi.com/tutorials/"&gt;Pulumi Tutorials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Attend an &lt;a href="https://www.pulumi.com/resources/#upcoming"&gt;upcoming workshop&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Try out the &lt;a href="https://www.pulumi.com/product/neo/"&gt;Pulumi Neo&lt;/a&gt; code assistant to accelerate your infrastructure as code journey&lt;/li&gt;
&lt;/ul&gt;</description><author>Sara Huddleston</author><category>infrastructure-as-code</category><category>cloud-management</category><category>infrastructure-lifecycle-management</category><category>platform-engineering</category><category>developer-experience</category><category>ansible</category><category>containers</category><category>pulumi-deployments</category></item><item><title>AWS CDK vs Pulumi: Why SST Chose Pulumi</title><link>https://www.pulumi.com/blog/aws-cdk-vs-pulumi-why-sst-switched/</link><pubDate>Wed, 25 Sep 2024 07:32:40 +0000</pubDate><guid>https://www.pulumi.com/blog/aws-cdk-vs-pulumi-why-sst-switched/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/aws-cdk-vs-pulumi-why-sst-switched/index.png" /&gt;
&lt;p&gt;Cloud computing tools evolve, and so must the frameworks developers rely on. For SST (Serverless Stack), AWS CDK was a great starting point—but it had limitations.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CDK tied infrastructure to AWS.&lt;/li&gt;
&lt;li&gt;Debugging was frustrating due to CloudFormation templates.&lt;/li&gt;
&lt;li&gt;Multi-cloud was nearly impossible.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The solution? Pulumi. In this post, we’ll explore why SST moved to Pulumi, what challenges they overcame, and what this means for developers building modern cloud applications.&lt;/p&gt;
&lt;p&gt;TL;DR: Pulumi lets SST offer a faster, more flexible, and provider-agnostic infrastructure experience.&lt;/p&gt;
&lt;h2 id="in-this-article"&gt;In This Article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/#the-beginnings-of-sst"&gt;The Beginnings of SST&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/#cdk-and-cloudformation-limitations"&gt;CDK and CloudFormation Limitations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/#a-provider-agnostic-solution-discovering-pulumi"&gt;A Provider-agnostic Solution: Discovering Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/#transitioning-to-pulumi"&gt;Transitioning to Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/#the-benefits-of-pulumi"&gt;The Benefits of Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/#the-future-of-sst-with-pulumi"&gt;The Future of SST with Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-beginnings-of-sst"&gt;The Beginnings of SST&lt;/h2&gt;
&lt;p&gt;Application developers have witnessed the rapid evolution of cloud computing and the growing need for developers to have direct access to powerful cloud resources. However, the traditional tools and approaches to Infrastructure as Code (IaC) have often been geared more toward DevOps teams, leaving application developers feeling disconnected from the infrastructure side of their projects.&lt;/p&gt;
&lt;p&gt;This was the driving force behind the creation of &lt;a href="https://sst.dev/"&gt;SST (Serverless Stack)&lt;/a&gt;, a framework that aims to bridge the gap between application developers and infrastructure management. In the early days, SST was built on top of AWS&amp;rsquo;s Cloud Development Kit (CDK), which allowed developers to define their infrastructure using TypeScript or Python. While this was a step in the right direction, they soon realized that the limitations of CDK and the underlying AWS CloudFormation were holding them back from truly empowering application developers.&lt;/p&gt;
&lt;h2 id="cdk-and-cloudformation-limitations"&gt;CDK and CloudFormation Limitations&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/LXxJ9XMXC6o?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;As the SST&amp;rsquo;s team continued to work with CDK and CloudFormation, they encountered several challenges that led them to reevaluate their approach. One key issue was the disconnect between application developers&amp;rsquo; thinking and working and traditional IaC tools&amp;rsquo; operating methods.&lt;/p&gt;
&lt;p&gt;With CDK and &lt;a href="https://www.pulumi.com/docs/iac/comparisons/cloudformation/#what-is-aws-cloudformation"&gt;CloudFormation&lt;/a&gt;, the infrastructure code is essentially a code generator, producing an intermediary format (such as YAML or JSON) that is then executed to deploy the resources. This means that the actual code you write as a developer is not the same as the code running during the deployment process. This can lead to several problems, such as difficulty debugging, lack of visibility into the deployment process, and challenges in extending or customizing the deployment workflow.&lt;/p&gt;
&lt;p&gt;Additionally, as the SST&amp;rsquo;s team expanded its focus beyond the AWS ecosystem and started exploring other cloud providers and even on-premises infrastructure, it found that the &lt;a href="https://www.pulumi.com/docs/iac/comparisons/aws-cdk/#what-is-aws-cdk"&gt;AWS-centric nature of CDK&lt;/a&gt; and CloudFormation was becoming a limitation. It needed a more flexible and provider-agnostic solution that would allow it to deploy and manage infrastructure across a wide range of platforms.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Feature&lt;/th&gt;
&lt;th&gt;AWS CDK&lt;/th&gt;
&lt;th&gt;Pulumi&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Multi-Cloud Support&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;❌ AWS-Only&lt;/td&gt;
&lt;td&gt;✅ AWS, Azure, GCP, On-Prem&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Debugging&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;❌ Hard due to CloudFormation&lt;/td&gt;
&lt;td&gt;✅ Real-time debugging&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Language Support&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;⚠️ TypeScript, Python&lt;/td&gt;
&lt;td&gt;✅ Any programming language&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Deployment Speed&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;❌ Slower due to CloudFormation&lt;/td&gt;
&lt;td&gt;✅ Faster direct execution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Visibility&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;❌ Hard to trace errors&lt;/td&gt;
&lt;td&gt;✅ Clear deployment state&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Extensibility&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;⚠️ Limited to AWS ecosystem&lt;/td&gt;
&lt;td&gt;✅ Custom providers &amp;amp; workflows&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;State Management&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;❌ CloudFormation state file&lt;/td&gt;
&lt;td&gt;✅ Pulumi-managed state&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Secrets Management&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;❌ AWS Secrets Manager only&lt;/td&gt;
&lt;td&gt;✅ Cross-cloud secret support&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="a-provider-agnostic-solution-discovering-pulumi"&gt;A Provider-agnostic Solution: Discovering Pulumi&lt;/h2&gt;
&lt;p&gt;It was during this time that the SST team discovered Pulumi, a modern IaC platform that takes a fundamentally different approach to infrastructure management. Instead of generating an intermediary format, Pulumi treats the infrastructure code as a first-class program executed directly during deployment.&lt;/p&gt;
&lt;p&gt;This paradigm shift had several important implications for SST and its users:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Visibility and Extensibility&lt;/strong&gt;: With Pulumi, the infrastructure code is the same code that is running during deployment, which means there is much greater visibility into the deployment process and the ability to extend or customize it as needed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Multi-Cloud Capabilities&lt;/strong&gt;: Pulumi&amp;rsquo;s provider-agnostic approach allows SST&amp;rsquo;s team to easily work with a wide range of cloud and on-premises platforms, giving their users the flexibility to deploy their infrastructure wherever it makes the most sense for their application.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Simplified Mental Model&lt;/strong&gt;: For application developers, the Pulumi model of &amp;ldquo;your code is the deployment&amp;rdquo; aligns much more closely with their existing mental models and workflows, making it easier for them to adopt and work with IaC tools.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="transitioning-to-pulumi"&gt;Transitioning to Pulumi&lt;/h2&gt;
&lt;p&gt;Transitioning SST from CDK to Pulumi was not a trivial undertaking. Still, they knew it was a necessary step to truly fulfill their mission of empowering application developers with powerful infrastructure management capabilities.&lt;/p&gt;
&lt;p&gt;One key challenge they faced was re-implementing the higher-level components and abstractions they had built on top of CDK. These components were designed to simplify the infrastructure management experience for their users, and they wanted to ensure that they could provide a similar level of abstraction and ease of use with Pulumi.&lt;/p&gt;
&lt;p&gt;Additionally, they had to carefully consider how to handle the various edge cases and complex deployment scenarios their users encountered with the CDK-based version of SST. They wanted to ensure that the Pulumi-based version would not only match the functionality of the previous version but also improve upon it and address some of the limitations they had encountered.&lt;/p&gt;
&lt;h2 id="the-benefits-of-pulumi"&gt;The Benefits of Pulumi&lt;/h2&gt;
&lt;p&gt;As they worked through the transition to Pulumi, they realized the significant benefits that Pulumi offered to both the SST team as the framework developers and the users.&lt;/p&gt;
&lt;p&gt;&lt;img src="sst-with-pulumi-infrastructure-as-code-deployments.png" alt="A quote from the Founding Engineer at SST: &amp;ldquo;With Pulumi, the deployment process feels like a natural extension of writing code - it&amp;rsquo;s intuitive and powerful and capable of advanced things that traditional IaC tools can&amp;rsquo;t handle.&amp;rdquo;"&gt;&lt;/p&gt;
&lt;h3 id="improved-visibility-and-debugging"&gt;Improved Visibility and Debugging&lt;/h3&gt;
&lt;p&gt;One of Pulumi&amp;rsquo;s most immediate and tangible benefits was the &lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;improved visibility and debugging capabilities&lt;/a&gt; it provided. With the infrastructure code being the same as the deployment code, they could easily trace issues back to the source and understand exactly what was happening during the deployment process.&lt;/p&gt;
&lt;p&gt;This starkly contrasted the CDK/CloudFormation approach, where the intermediary format (CloudFormation templates) often obscured the underlying logic and made it much more difficult to diagnose and resolve problems.&lt;/p&gt;
&lt;h3 id="extensibility-and-customization"&gt;Extensibility and Customization&lt;/h3&gt;
&lt;p&gt;Pulumi&amp;rsquo;s design also allowed the SST team to easily extend and customize the deployment process to meet the specific needs of their users. They could leverage Pulumi&amp;rsquo;s built-in extensibility features, such as custom providers and dynamic components, to integrate with a wide range of cloud and on-premises services and implement complex deployment workflows tailored to our users&amp;rsquo; requirements.&lt;/p&gt;
&lt;p&gt;This level of customization was much more challenging with the CDK/CloudFormation approach, where they often had to resort to hacky workarounds or custom Lambda functions to achieve the desired functionality.&lt;/p&gt;
&lt;h3 id="multi-cloud-capabilities"&gt;Multi-Cloud Capabilities&lt;/h3&gt;
&lt;p&gt;As mentioned earlier, one key driver for their transition to Pulumi was the need to support a wider range of cloud and on-premises platforms. With Pulumi&amp;rsquo;s provider-agnostic approach, the SST team was able to easily add support for new providers, allowing their users to deploy and manage infrastructure across a diverse set of environments.&lt;/p&gt;
&lt;p&gt;This flexibility has been particularly valuable for their users, who may have workloads or requirements that span multiple cloud providers or even on-premises infrastructure. With SST built on Pulumi, they can now manage all of their infrastructure through a single, consistent interface without having to juggle multiple tools or approaches.&lt;/p&gt;
&lt;h3 id="simplified-mental-model"&gt;Simplified Mental Model&lt;/h3&gt;
&lt;p&gt;One of Pulumi&amp;rsquo;s most significant benefits for SST users is the simplified mental model it provides. By treating the infrastructure code as a first-class program, Pulumi aligns much more closely with how application developers think and work.&lt;/p&gt;
&lt;p&gt;Instead of having to navigate the complexities of intermediary formats, deployment pipelines, and the separation between infrastructure code and deployment code, SST users can now focus on writing their infrastructure logic in the same programming languages they use for their application code. This makes it much easier for them to understand, maintain, and extend their infrastructure as their needs evolve.&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Build across any cloud with Pulumi&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Define your infrastructure in TypeScript, Python, Go, or C#, and deploy it across AWS, Azure, Google Cloud, and on-premises environments from one consistent workflow.&lt;/div&gt;
&lt;a href="https://app.pulumi.com/signup" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Get started
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="the-future-of-sst-with-pulumi"&gt;The Future of SST with Pulumi&lt;/h2&gt;
&lt;p&gt;With Pulumi&amp;rsquo;s foundation in place, they can now focus on further enhancing the developer experience and expanding the capabilities of their framework. Some of the key areas they are exploring include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Deeper Integration with Application Frameworks&lt;/strong&gt;: By leveraging Pulumi&amp;rsquo;s flexibility, they can create even tighter integrations between SST and the application frameworks and libraries that their users rely on, making managing infrastructure seamless alongside their application code.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Expanded Provider Support&lt;/strong&gt;: the SST team will continue to add support for a wide range of cloud and on-premises providers, ensuring that their users can deploy and manage their infrastructure wherever it makes the most sense for their needs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Improved Deployment Workflows&lt;/strong&gt;: Building on Pulumi&amp;rsquo;s extensibility, they can create &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/"&gt;more advanced deployment workflows&lt;/a&gt; that address the specific needs of application developers, such as faster deployment times, better rollback capabilities, and more granular control over the deployment process.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced Observability and Monitoring&lt;/strong&gt;: By treating the infrastructure code as a first-class program, they can provide their users with &lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;better visibility&lt;/a&gt; into the deployment process and more robust monitoring and observability capabilities, helping them to identify and resolve issues quickly.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As the SST team continues to evolve with Pulumi at its core, they aim to deliver an even more powerful and user-friendly infrastructure management experience for developers. This will empower teams to focus on building great applications while effortlessly managing the underlying infrastructure.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;If you&amp;rsquo;re interested in exploring Pulumi further, here are several ways to get involved:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discover how Pulumi Crosswalk for AWS simplifies “day one” tasks in our &lt;a href="https://www.pulumi.com/docs/iac/clouds/aws/guides/"&gt;AWS guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Watch our on-demand workshop &lt;a href="https://www.pulumi.com/resources/getting-started-with-iac-pulumi-aws/"&gt;Getting Stated with Infrastructure as Code on AWS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Register for one of our upcoming &lt;a href="https://www.pulumi.com/resources/#upcoming"&gt;Platform Engineering or DevOps workshops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;But most importantly, &lt;a href="https://app.pulumi.com/signup"&gt;try Pulumi&lt;/a&gt; today!&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="frequently-asked-questions"&gt;Frequently Asked Questions&lt;/h2&gt;
&lt;h3 id="what-is-sst"&gt;What is SST?&lt;/h3&gt;
&lt;p&gt;SST is a framework that makes building modern full-stack applications on your infrastructure easy.&lt;/p&gt;
&lt;h3 id="what-is-ssts-ion"&gt;What is SST&amp;rsquo;s Ion?&lt;/h3&gt;
&lt;p&gt;Ion is the code name for a new engine for deploying SST applications. The constructs (or components) are deployed using Pulumi instead of CDK and CloudFormation (CFN). Once Ion is stable, it will be released as SST v3.&lt;/p&gt;
&lt;h3 id="does-sst-use-mostly-terraform-or-pulumi"&gt;Does SST use mostly Terraform or Pulumi?&lt;/h3&gt;
&lt;p&gt;SST leverages Pulumi behind the scenes for its providers and deployment engine while also bridging Terraform providers through Pulumi.&lt;/p&gt;
&lt;h3 id="how-does-sst-make-money"&gt;How does SST make money?&lt;/h3&gt;
&lt;p&gt;SST (Serverless Stack) makes money primarily through its managed service, called SST Console. The Console is optional and includes a free tier. In short, SST primarily relies on SaaS (Software as a Service) revenue through its managed platform and potentially supplemental income streams like enterprise services and consulting.&lt;/p&gt;</description><author>Sara Huddleston</author><category>cloudformation</category><category>aws-cdk</category><category>case-studies</category><category>developer-experience</category></item><item><title>PulumiUP 2024: Dive Into the Future of Cloud, Platform Engineering, and AI/ML</title><link>https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/</link><pubDate>Wed, 11 Sep 2024 07:04:40 +0000</pubDate><guid>https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/index.png" /&gt;
&lt;p&gt;PulumiUP 2024 is just around the corner! It will be held on September 18th, starting at 8 AM PT | 15:00 UTC +0, and with over 5,500 engineers from all over the world already registered, this is shaping up to be the must-attend event for cloud professionals, platform engineers, and AI/ML enthusiasts alike. From entry-level engineers to tech executives, this event brings together professionals from companies of all sizes to explore the latest innovations and best practices in &lt;strong&gt;Cloud and IaC&lt;/strong&gt;, &lt;strong&gt;Platform Engineering &amp;amp; DevOps&lt;/strong&gt;, and &lt;strong&gt;AI/ML&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;If you haven’t registered yet, now’s the time! &lt;a href="https://conference.pulumi.com/schedule/?utm_source=PulumiUP&amp;amp;utm_medium=web&amp;amp;utm_campaign=FY2025Q1_Event_PulumiUP"&gt;Start building your schedule today&lt;/a&gt;, select the talks you want to watch live and on-demand and add them to your schedule.&lt;/p&gt;
&lt;h2 id="pulumiup-at-glance"&gt;PulumiUP at Glance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#main-track-keynote-cloud-culture-talks-and-more"&gt;Main Track: Keynote, Cloud Culture Talks, and More&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#aiml-track-highlights"&gt;AI/ML Track Highlights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#platform-engineering-and-devops-track-highlights"&gt;Platform Engineering and DevOps Track Highlights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#cloud-and-iac-track-highlights"&gt;Cloud and IaC Track Highlights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#workshops-and-hands-on-learning"&gt;Workshops and Hands-On Learning&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#amazing-partners-and-sponsors"&gt;Amazing Partners and Sponsors&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#build-your-schedule-now"&gt;Build Your Schedule Now&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="main-track-keynote-cloud-culture-talks-and-more"&gt;Main Track: Keynote, Cloud Culture Talks, and More&lt;/h2&gt;
&lt;p&gt;In the Main Track, you’ll hear directly from the Pulumi leadership team about exciting product innovations. Don’t miss the Cloud Culture talks focused on the human side of technology and collaboration.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/pulumiup-2024-keynote/"&gt;Keynote and New Product Announcements&lt;/a&gt;&lt;/strong&gt; - Joe Duffy (Co-founder and CEO), Luke Hoban (CTO), and other key Pulumi leaders will unveil new products and innovations shaping the next wave of cloud development. Expect to see live demos showcasing how these tools can revolutionize your workflows, from cloud infrastructure to security automation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/9Xf6DJMvQ08"&gt;Why Care About Building a Cloud Center of Excellence?&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Alex Radu (VP Product &amp;amp; Marketing Manager, Public Cloud, J.P. Morgan) discusses why building a Cloud Center of Excellence is essential for long-term cloud strategy success.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/30wTCwfj3cc"&gt;What Is &amp;lsquo;HugOps&amp;rsquo; and Why Is It Important?&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Rees Pozzi (Senior Platform Engineer, Kainos) explores the meaning and importance of &amp;ldquo;HugOps,&amp;rdquo; a practice promoting empathy and collaboration in the tech world but also by all those impacted by it.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="aiml-track-highlights"&gt;AI/ML Track Highlights&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://conference.pulumi.com/talks/panel-ai-cloud-development/"&gt;&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/pulumiup_2024-ai-cloud-development.png"
alt="Panelists of AI for Cloud Development" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Panel: AI for Cloud Development&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;AI is transforming how we approach development and infrastructure, and PulumiUP offers an incredible lineup of talks and panels on the topic.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/4IWGNoNVbiM"&gt;Data Privacy Challenges with Large Language Models&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Aditi Godbole (Data Science, AI &amp;amp; ML Leader, SAP) will address the critical question of managing data privacy, addressing LLM basics, AI data privacy fundamentals, and specific privacy issues in LLMs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/CoZM9BCJcJ4"&gt;Pulumi Powered AI/ML on Kubernetes&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jason Smith (App Modernization Specialist, Google Cloud) will show you how to serve an open-source LLM with a RAG on Kubernetes and set up a Kubernetes environment for AI/ML workloads with Pulumi.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/WoM8Bj76_Fw"&gt;AI Tools for Developers&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jim Clark (Principal Software Engineer, Docker) will explore how Tools can enhance the capabilities of AI assistants and show how the combination of AI, Tools, and containerized runtimes, can enhance interactions between developers and their tools.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/2mlb2jEBkoo"&gt;The AI Governance Challenge&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Patty O&amp;rsquo;Callaghan (Technical Director, Charles River) will explore the complexities of AI governance and how to navigate them.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/panel-ai-in-cloud-development/"&gt;Panel Discussion: &amp;ldquo;AI for Cloud Development&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; - Luke Hoban (CTO, Pulumi), Phillip Carter (Principal Product Manager, Honeycomb), Giri Sreenivas (CPO, Docker), Clare Liguori (Senior Principal Software Engineer, AWS) and Meagan Cojocar (Principal Product Manager, Pulumi) will provide diverse perspectives on how AI is shaping cloud infrastructure.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="platform-engineering-and-devops-track-highlights"&gt;Platform Engineering and DevOps Track Highlights&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/pulumiup_2024-secrets-policies-automating-cybersecurity.png"
alt="Panelists of Secrets and Policies—Automating Cybersecurity" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Panel: Secrets and Policies—Automating Cybersecurity&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;The Platform Engineering &amp;amp; DevOps track at PulumiUP is perfect for anyone looking to automate infrastructure, secure their systems, and scale their environments with ease. This track features talks and panels on cutting-edge technologies and practices.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/WZD1z2ldweY"&gt;Moving Mountains: How IaC Unlocks Massive Refactoring Possibilities&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Shaun Verch (Infrastructure Engineer, Oso) will show you how infrastructure as code can transform large-scale refactoring projects.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/1Q3XPmenthg"&gt;Using Pulumi to Empower Kubernetes Fleet Management&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Blake Romano (Senior Software Engineer, Imagine Learning) will show you how Imagine Learning leverages Pulumi to manage a fleet of Kubernetes clusters and other platform resources quickly and reliably, and how it revolutionized their workflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/f2r9rS9U2CA"&gt;Streamline Your Infrastructure Deployment with GitOps and Pulumi Operator&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Sam Cogan (Solutions Architect &amp;amp; Azure MVP, WTW) will highlight how you can define your infrastructure in Git, and have Pulumi automatically reconcile it into deployed infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/EQwpC02CQ9k"&gt;Is This a Platform? Platform Engineering Before PMF&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jk Jensen (Team Lead, Staff Software Engineer, MystenLabs) will share how they built their service platform around Pulumi to help engineers and researchers move from prototypes to deployed environments, enabling their teams to iterate more quickly and develop an increasing number of systems without additional complexity.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/events/security-automation-faster-cheaper-better/"&gt;Security Automation—Faster. Cheaper. Better.&lt;/a&gt;&amp;quot;&lt;/strong&gt; - David Giambruno (VP of Engineering and DevOps, Tivity Health) and Joe Duffy (Founder/CEO, Pulumi) will discuss security automation and how these efforts impacted speed and agility, cost optimization and improved security and compliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/CGE8VXgkjug"&gt;Meet Devs Where They Are: Why IaC Must Be Real Code&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jeremy Adams (Head of Ecosystems, Dagger) will present why real code (that teams already use for applications) is essential for both IaC and CI/CD pipelines, and to meet modern DevOps best practices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/2a-wlUnBY1g"&gt;Security of IaC Pipelines and Infrastructure Governance With Policies-As-Code&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Marina Novikova (Senior Partner Solutions Architect, AWS) and Andy Taylor (Senior Networking Specialist/ Solutions Architect, AWS) will explore security best practices for IaC pipelines and infrastructure governance using policies-as-code, cover best practices for handling sensitive information like access keys, tokens and encryption keys, and scaling and automating your DevSecOps.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/secrets-policies-automating-cybersecurity/"&gt;Panel Discussion: &amp;ldquo;Secrets and Policies—Automating Cybersecurity&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; - Arun Loganathan (Senior Product Manager, Pulumi), Maya Kaczorowski (PM of Security), Jason Meller (VP, Product, 1Password), and Ofir Cohen (CTO, Container Security, Wiz) will explore the intersection of innovation and security, offering insights into how AI is reshaping the threat landscape and how organizations can stay ahead.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="cloud-and-iac-track-highlights"&gt;Cloud and IaC Track Highlights&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/pulumiup_2024-infrastructure-as-code.png"
alt="Panelists of Infrastructure as Code - Can we do better?" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Panel: Infrastructure as Code - Can we do better?&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;The Cloud and IaC track is ideal for those wanting to deepen their understanding of infrastructure as code and its impact on modern cloud computing. Learn from industry pioneers and see where the future of IaC is headed.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/"&gt;From CDK to Pulumi: Evolution of SST&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Dax Raad (Founding Engineer, SST) and Jay V (Founder, SST) will share insights into the early development of their product, initially built on AWS Cloud Development Kit (CDK), the challenges they encountered and the groundbreaking decision to transition to Pulumi.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/"&gt;Unified Software Development at BMW Software Factory with Pulumi&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jan-Peter Alten (Expert Software Engineer, DevOps, BMW Group) will showcase how BMW uses Pulumi to unify their software development processes, resulting in an increase in developer productivity, streamlined infrastructure management, and enhanced scalability, security, and compliance across their complex software ecosystem.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/E077QbXPOZE"&gt;Stacking Accounts: Multi-Account Deployments in a Single Stack for Monitoring, Management, and More&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Denis Willett (Software Engineer, North Carolina Institute for Climate Studies) will explain how they use Pulumi for managing 60+PB of environmental data across AWS, GCP, and Azure and leverage multi-account deployments in a single stack via the Pulumi Automation API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/C5ZuEVXesOk"&gt;Industrialize the Configuration of Your GitHub Repositories With IaC&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Alexandre Nédélec (Software Engineer, Avanade) will live code using the GitHub, Azure native, and Azure AD Pulumi providers to create a GitHub repository and configure its pipeline to deploy to Azure using OpenID Connect.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/panel-infrastructure-as-code-can-we-do-better/"&gt;Panel Discussion: &amp;ldquo;Infrastructure as Code — Can We Do Better?&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; - Joe Duffy (Co-Founder and CEO, Pulumi), Brian Grant (CTO, Stealth), Elad Ben-Israel (Co-Founder and CEO, Winglang), Adam Jacob (Co-Founder and CEO, System Initiative), and Luke Hoban (CTO, Pulumi) will discuss the past, the present, and the future of Infrastructure as Code and the overall infrastructure technologies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="workshops-and-hands-on-learning"&gt;Workshops and Hands-On Learning&lt;/h2&gt;
&lt;p&gt;Want to get hands-on experience? Our live workshops are designed to deepen your understanding of trending topics, Pulumi, and its applications.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/managing-team-secrets-with-1password-pulumi-esc/"&gt;Managing Team Secrets with 1Password &amp;amp; Pulumi ESC&lt;/a&gt;&amp;quot;&lt;/strong&gt; on September 25, led by Phil Johnston (1Password) and Diana Esteves (Pulumi).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/securing-iac-pipelines-in-regulated-industries/"&gt;Securing IaC Pipelines in Regulated Industries&lt;/a&gt;&amp;quot;&lt;/strong&gt; on September 26, led by Josh Kodroff (Pulumi) and Marina Novikova (AWS).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/deploy-tailscale-infrastructure-with-pulumi/"&gt;Deploy Tailscale infrastructure in AWS with Pulumi&lt;/a&gt;&amp;quot;&lt;/strong&gt; on October 15, led by Diana Esteves (Pulumi) and Lee Briggs (Tailscale).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/observability-as-code-for-ai-apps-new-relic/"&gt;Observability as Code for AI Apps with New Relic and Pulumi&lt;/a&gt;&amp;quot;&lt;/strong&gt; on October 30, led by Diana Esteves (Pulumi) and Harry Kimpel (New Relic).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="amazing-partners-and-sponsors"&gt;Amazing Partners and Sponsors&lt;/h2&gt;
&lt;p&gt;Thank you to our amazing customers, sponsors, and partners for supporting PulumiUP!&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://aws.amazon.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;AWS&lt;/a&gt;&lt;/strong&gt; The world&amp;rsquo;s most comprehensive and broadly adopted cloud, offering over 200 fully featured services from data centers globally.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://cloud.google.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Google Cloud&lt;/a&gt;&lt;/strong&gt; Help developers build quickly, securely, and cost effectively with the next generation of modern infrastructure designed to meet specific workload and industry needs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://newrelic.com/instant-observability/pulumi/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;New Relic&lt;/a&gt;&lt;/strong&gt; Data for engineers to monitor, debug, and improve their entire stack.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docker.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Docker&lt;/a&gt;&lt;/strong&gt; Accelerate how you build, share, and run applications.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://1password.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;1Password&lt;/a&gt;&lt;/strong&gt; Streamline how you manage SSH keys, API tokens, and other infrastructure secrets throughout the entire software development life cycle.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://tailscale.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Tailscale&lt;/a&gt;&lt;/strong&gt; Make creating software-defined networks easy: securely connecting users, services, and devices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://pinecone.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Pinecone&lt;/a&gt;&lt;/strong&gt; Build remarkable GenAI applications fast, with lower cost, better performance, and greater ease of use at any scale.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://wiz.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Wiz&lt;/a&gt;&lt;/strong&gt; Secure everything you build and run in the cloud.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://honeycomb.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Honeycomb&lt;/a&gt;&lt;/strong&gt; Observability that helps solve problems you couldn’t before.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://mystenlabs.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Mysten Labs&lt;/a&gt;&lt;/strong&gt; Building critical infrastructure to enable a more decentralized internet.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://imaginelearning.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Imagine Learning&lt;/a&gt;&lt;/strong&gt; Empowering educators to inspire breakthrough moments in every student’s unique learning journey with digital-first, K–12 education solutions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://dagger.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Dagger&lt;/a&gt;&lt;/strong&gt; Powerful, programmable open source CI/CD engine that runs your pipelines in containers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://osohq.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Oso&lt;/a&gt;&lt;/strong&gt; Authorization as a service.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="build-your-schedule-now"&gt;Build Your Schedule Now&lt;/h2&gt;
&lt;p&gt;With so many compelling topics across AI/ML, Platform Engineering, DevOps, and Cloud and IaC, now is the time to &lt;a href="https://conference.pulumi.com/schedule/?utm_source=PulumiUP&amp;amp;utm_medium=web&amp;amp;utm_campaign=FY2025Q1_Event_PulumiUP"&gt;build your PulumiUP schedule&lt;/a&gt;. Select the sessions that match your goals and interests to maximize your experience. Plus, you&amp;rsquo;ll receive a link to watch your chosen panel discussions and tech talks on-demand!&lt;/p&gt;
&lt;p&gt;Haven’t registered yet? It’s not too late! Join 5,500 engineers worldwide in this groundbreaking event and gain the insights you need to drive innovation at your company. &lt;a href="https://www.pulumi.com/pulumi-up/"&gt;Register now-&amp;gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We can’t wait to see you there!&lt;/p&gt;</description><author>Sara Huddleston</author><category>pulumi-events</category><category>announcements</category><category>platform-engineering</category><category>ai</category><category>cloud-computing</category><category>infrastructure-as-code</category><category>devsecops</category><category>community</category></item><item><title>Platform Engineering: Cloud-Native, Maturity Models, and Platforms as Products</title><link>https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/</link><pubDate>Fri, 26 Jul 2024 17:40:17 +0000</pubDate><guid>https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/platform-engineering-cncf-maturity-model/index.png" /&gt;
&lt;p&gt;The Platform Engineering &amp;amp; DevOps in-person series launched in Berlin with two great speakers. This blog article is an overview of Dominik Kress&amp;rsquo;s talk, “What the Heck is the CNCF Platform Working Group? Answers from a Member!” in which he discussed Cloud-Native Platforms, The Platform Maturity Model, and approaching Platforms as Products.&lt;/p&gt;
&lt;p&gt;In this article, you&amp;rsquo;ll learn more about &lt;a href="https://www.pulumi.com/what-is/what-is-platform-engineering/"&gt;platform engineering&lt;/a&gt; and how to get involved with the CNCF Platform Working Group. Make sure to check our &lt;a href="https://luma.com/pulumi"&gt;Pulumi User Groups (PUGs)&lt;/a&gt; to find a meetup near you.&lt;/p&gt;
&lt;h2 id="on-this-platform-engineering-article"&gt;On this platform engineering article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#what-is-a-platform"&gt;What is a Platform?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#defining-cloud-native-platforms"&gt;Defining Cloud Native Platforms&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#the-platform-maturity-model-charting-the-path-to-success"&gt;The Platform Maturity Model: Charting the Path to Success&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#platforms-as-products-driving-success"&gt;Platforms as Products: Driving Success&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#frequently-asked-questions"&gt;Frequently Asked Questions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-is-a-platform"&gt;What is a Platform?&lt;/h2&gt;
&lt;p&gt;According to CNCF, a platform in cloud-native computing is an integrated collection of capabilities designed to meet users&amp;rsquo; needs. It serves as a cross-cutting layer, ensuring a consistent experience integrating and managing services and capabilities for various applications and use cases. A good platform provides consistent user experiences through portals, project templates, and self-service APIs.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/case-studies/atlassian/"&gt;Atlassian&lt;/a&gt; describes platform teams as creators of capabilities used by multiple product teams, reducing their overhead and cognitive load. Martin Fowler and Evan Bottcher define a digital platform as a foundation of self-service APIs, tools, services, and support arranged as an internal product. These platforms enable autonomous teams to deliver features faster with less coordination.&lt;/p&gt;
&lt;p&gt;The specific capabilities of a platform are tailored to the needs of its stakeholders and users. While platform teams provide these capabilities, they do not always implement them directly. Managed service providers or dedicated internal teams can maintain the underlying implementations, ensuring consistency across the organization. Platforms are tailored to an enterprise’s internal users and are particularly relevant for cloud-native architectures, separating supporting capabilities from application-specific logic.&lt;/p&gt;
&lt;h2 id="defining-cloud-native-platforms"&gt;Defining Cloud Native Platforms&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/NUPK5CCm6XA?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;The core of the discussion at the CNCF Platform Working Group is: &amp;ldquo;What exactly is a cloud-native platform, and why do organizations need one?&amp;rdquo;
A cloud-native platform is a strategic business initiative that enables organizations to deliver value more efficiently and effectively. It is characterized by:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Vendor-neutrality&lt;/strong&gt;: A cloud-native platform should be open and agnostic, allowing organizations to leverage various technologies and services without being locked into a single vendor.
&lt;strong&gt;Scalability and flexibility&lt;/strong&gt;: The platform should be designed to accommodate the organization&amp;rsquo;s growing and changing needs, with the ability to add or remove components as needed easily.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/"&gt;Developer-centricity&lt;/a&gt;&lt;/strong&gt;: The platform should empower developers to be more productive by providing self-service capabilities, streamlined workflows, and a consistent developer experience.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/developer-portal-platform-teams/"&gt;Operational efficiency&lt;/a&gt;&lt;/strong&gt;: The platform should simplify and automate the management and maintenance of the underlying infrastructure, allowing the organization to focus on delivering value to customers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Continuous improvement&lt;/strong&gt;: The platform should be designed with a mindset of continuous evolution, with regular updates and enhancements to address emerging needs and technologies.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By aligning with these principles, organizations can achieve faster time-to-market, improved developer productivity, and reduced operational overhead.&lt;/p&gt;
&lt;h2 id="the-platform-maturity-model-charting-the-path-to-success"&gt;The Platform Maturity Model: Charting the Path to Success&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/dominik-platform-engineering-berlin.png"
alt="Dominik Kress at the Berlin Pulumi Group meetup explaining the platform maturity model" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Dominik Kress at the Berlin Pulumi Group meetup explaining the platform maturity model&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;The Platform Working Group has developed a Platform Maturity Model. This framework can help assess the current state of a cloud native platform and identify steps to enhance its maturity. It defines five levels:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Ad-hoc&lt;/strong&gt;: At the lowest level, the platform is ad-hoc, with no dedicated team or budget and a reliance on individual efforts and workarounds.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Operational&lt;/strong&gt;: The platform has a dedicated team and budget, which focus primarily on operational tasks and maintenance rather than strategic initiatives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scalable&lt;/strong&gt;: The platform is now viewed as a product with a clear roadmap and a focus on delivering value to internal customers. The platform team has more autonomy and the ability to drive innovation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enabled&lt;/strong&gt;: The platform has become a strategic asset, with a thriving ecosystem of contributors and consumers. The platform team is empowered to make decisions and drive the platform&amp;rsquo;s evolution.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Optimized&lt;/strong&gt;: The platform is continuously optimized, focusing on measuring and improving key performance indicators. The platform is deeply integrated into the organization&amp;rsquo;s technology strategy and decision-making processes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By using the CNCF&amp;rsquo;s &lt;a href="https://tag-app-delivery.cncf.io/whitepapers/platform-eng-maturity-model/"&gt;Platform Maturity Model&lt;/a&gt; as a guide, organizations can assess their current level of platform maturity, identify areas for improvement, and develop a roadmap to reach a higher level of platform success. This model has proven to be a valuable tool for many organizations, helping them to align their platform initiatives with their broader business objectives.&lt;/p&gt;
&lt;h2 id="platforms-as-products-driving-success"&gt;Platforms as Products: Driving Success&lt;/h2&gt;
&lt;p&gt;One of the key initiatives currently underway within the Platform Working Group is the &amp;ldquo;&lt;a href="https://tag-app-delivery.cncf.io/blog/product-thinking-for-platforms/"&gt;Platforms as Products&lt;/a&gt;&amp;rdquo; research project. This effort aims to explore the parallels between traditional product management and the management of cloud-native platforms to identify best practices and patterns that can help organizations unlock their platforms&amp;rsquo; full potential.&lt;/p&gt;
&lt;p&gt;The core premise of the &amp;ldquo;Platforms as Products&amp;rdquo; initiative is that successful cloud-native platforms should be treated and managed like products rather than just technology projects. This means applying principles of product management, such as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Defining a clear vision and roadmap&lt;/strong&gt;: Establishing a long-term vision for the platform and a roadmap to get there, focusing on delivering value to internal customers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Measuring and optimizing for key metrics&lt;/strong&gt;: Identifying and tracking the right performance indicators to ensure the platform delivers the desired outcomes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fostering a thriving ecosystem&lt;/strong&gt;: Encouraging and enabling a community of contributors and consumers to drive the platform&amp;rsquo;s evolution and adoption.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Continuously iterating and improving&lt;/strong&gt;: Embracing a continuous improvement mindset, with regular updates and enhancements to the platform based on user feedback and emerging needs.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By adopting a product management approach to their cloud native platforms, organizations can better align their platform initiatives with their broader business goals and ensure that the platform delivers tangible value to the organization.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;This article and Dominik Kress&amp;rsquo;s talk highlighted the importance of platform engineering in cloud-native computing. Key points included defining cloud-native platforms, assessing platform maturity, and managing platforms with product management principles.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re interested in learning more about platform engineering and getting involved in CNCF&amp;rsquo;s initiatives, there are several ways to participate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Register for the &lt;a href="https://info.pulumi.com/platform-engineering-workshop-series"&gt;Platform Engineering workshop series course&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Join the bi-weekly &lt;a href="https://tag-app-delivery.cncf.io/wgs/platforms/#meetings"&gt;CNCF Platform Working Group meetings&lt;/a&gt; every other Tuesday at 5 PM Berlin time (11 AM ET).&lt;/li&gt;
&lt;li&gt;Learn how to &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/developer-portals/"&gt;build Developer Portals with Pulumi&lt;/a&gt;. You can get off the ground faster with organization templates, a new project wizard, or leveraging the backstage plugin.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="frequently-asked-questions"&gt;Frequently Asked Questions&lt;/h2&gt;
&lt;h3 id="what-is-the-cncf-platform-working-group"&gt;What is the CNCF Platform Working Group?&lt;/h3&gt;
&lt;p&gt;Within the &lt;a href="https://www.cncf.io/"&gt;CNCF&lt;/a&gt;, the Platform Working Group is a collaborative effort focused on the critical topic of cloud native platforms. As a working group member, you can share insights and experiences from our discussions.&lt;/p&gt;
&lt;p&gt;The Platform Working Group is part of the CNCF&amp;rsquo;s App Delivery Technical Advisory Group, which includes sustainability, runtime, observability, and security initiatives. The working group is open to anyone interested in contributing to the conversation around cloud native platforms, and its members come from diverse backgrounds, including product managers, engineers, and industry experts.&lt;/p&gt;
&lt;h3 id="who-is-dominik-kress"&gt;Who is Dominik Kress?&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://www.linkedin.com/in/dominik-kress-33a540174/"&gt;Dominik Kress&lt;/a&gt; is a product manager at Giant Swarm and a CNCF Platforms Working Group member.&lt;/p&gt;
&lt;p&gt;He is on a mission to simplify developers&amp;rsquo; lives by delivering intuitive developer platforms. He has been in the IT industry for over seven years, starting his journey as a Full Stack Software Engineer, falling in love with DevOps and Product Organisations to become a Product Manager for Cloud Technology later.&lt;/p&gt;
&lt;p&gt;Dominik is passionate about Cloud Transformation, Product Management, and helping people. He loves contributing to the community with talks, articles, or publications.&lt;/p&gt;
&lt;h3 id="how-can-i-participate-in-the-platform-as-a-product-research"&gt;How can I participate in the Platform As A Product research?&lt;/h3&gt;
&lt;p&gt;The &amp;ldquo;Platforms as Products&amp;rdquo; research project is currently underway, with the Platform Working Group conducting interviews and gathering insights from organizations that have successfully implemented cloud native platforms. The goal is to distill these learnings into a set of best practices and patterns that can be shared with the broader community.&lt;/p&gt;
&lt;p&gt;To participate in this research, &lt;a href="https://bit.ly/platform-research"&gt;sign up here&lt;/a&gt;.&lt;/p&gt;</description><author>Sara Huddleston</author><category>platform-engineering</category><category>community</category><category>pulumi-events</category></item><item><title>Platform Engineering &amp; DevOps Series Kickoff Announcement</title><link>https://www.pulumi.com/blog/platform-engineering-devops-event-meetup-community/</link><pubDate>Mon, 15 Jul 2024 14:38:46 +0000</pubDate><guid>https://www.pulumi.com/blog/platform-engineering-devops-event-meetup-community/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/platform-engineering-devops-event-meetup-community/index.png" /&gt;
&lt;p&gt;We are excited to announce the kickoff of the Platform Engineering &amp;amp; DevOps Series, which will run from July 16 to October 31. This series will feature in-person events across various cities, including Berlin, London, Paris, Sydney, Boston, San Francisco, Seattle, Austin, Denver, and NYC. For those unable to attend an in-person event, we encourage you to participate in a virtual DevOps &amp;amp; Platform Engineering workshop.&lt;/p&gt;
&lt;h2 id="upcoming-in-person-events"&gt;Upcoming In-Person Events&lt;/h2&gt;
&lt;p&gt;Pulumi is hosting in-person meetups and virtual workshops for engineers interested in Platform Engineering and DevOps, covering topics from best practices to setup and implementation to advanced topics. Join us for tech talks, hands-on workshops, and opportunities to network with fellow engineers.&lt;/p&gt;
&lt;h3 id="first-platform-engineering--devops-in-person-event-berlin---july-16"&gt;First Platform Engineering &amp;amp; DevOps in-person event: Berlin - July 16&lt;/h3&gt;
&lt;p&gt;Join &lt;a href="https://www.linkedin.com/in/dominik-kress-33a540174/"&gt;Dominik Kress&lt;/a&gt; (Product Manager at Giant Swarm and member of the CNCF Platforms Working Group) and &lt;a href="https://www.linkedin.com/in/guy-menahem/"&gt;Guy Menahem&lt;/a&gt; (Solutions Architect at Komodor and community leader at The Platformers) at LOBE Block for an engaging discussion on platform engineering.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Dominik Kress will present &amp;ldquo;What the Heck is the CNCF Platform Working Group? Answers from a Member!&amp;rdquo;&lt;/li&gt;
&lt;li&gt;Guy Menahem will present &amp;ldquo;For This Backstage, You Don’t Need a Special Pass: Platform Engineering in Practice.&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more details and to RSVP, visit the &lt;a href="https://luma.com/pulumi"&gt;Berlin Meetup page&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="second-in-person-event-boston-july-24"&gt;Second In-Person Event: Boston, July 24&lt;/h3&gt;
&lt;p&gt;Join Pulumi&amp;rsquo;s founder &amp;amp; CEO, &lt;a href="https://www.linkedin.com/in/joejduffy/"&gt;Joe Duffy&lt;/a&gt;, and &lt;a href="https://www.linkedin.com/in/jbaldanza/"&gt;Jamie Baldanza&lt;/a&gt;, Director of DevOps at Relay Therapeutics, for the launch of our Boston meetup at The Foundry. This is a great opportunity for DevOps engineers, platform engineers, software engineers, and Cloud enthusiasts to connect and share insights.&lt;/p&gt;
&lt;p&gt;RSVP is required due to limited capacity. Secure your spot, and RSVP at the &lt;a href="https://luma.com/pulumi"&gt;Boston Meetup page&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="more-coming-soon"&gt;More coming soon!&lt;/h3&gt;
&lt;p&gt;We expected Seattle, Paris, and London&amp;rsquo;s meetups to happen in early September.
Details for the other in-person events will be coming soon, so stay tuned for more updates at &lt;a href="https://info.pulumi.com/platform-engineering-devops-series"&gt;Platform Engineering &amp;amp; DevOps Series&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;No upcoming in-person events in your area? Attend one of our virtual workshops and keep up with the latest in DevOps &amp;amp; Platform Engineering!&lt;/p&gt;
&lt;h3 id="virtual-workshops"&gt;Virtual Workshops&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Getting Started with CI/CD for AWS using GitHub Actions&lt;/strong&gt;: July 17. Learn more and &lt;a href="https://www.pulumi.com/resources/getting-started-with-ci-cd-aws-pulumi-github-actions/"&gt;register here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;From Zero to Production in Kubernetes&lt;/strong&gt;: July 25. Learn more and &lt;a href="https://www.pulumi.com/resources/from-zero-to-production-in-kubernetes/"&gt;register here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Advanced CI/CD for AWS using Pulumi and GitHub Actions&lt;/strong&gt;: August 14. Learn more and &lt;a href="https://www.pulumi.com/resources/advanced-cicd-aws-pulumi-github-actions/"&gt;register here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mastering Platform Engineering: From Setup to Scaling Success&lt;/strong&gt;: TBD.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Join us for tech talks, hands-on workshops, and opportunities to network with industry peers. We are excited to meet you in person or virtually.
See you there!&lt;/p&gt;</description><author>Sara Huddleston</author><category>developer-experience</category><category>devops</category><category>platform-engineering</category><category>community</category><category>pulumi-events</category></item><item><title>Announcing PulumiUP Conference 2024</title><link>https://www.pulumi.com/blog/announcing-pulumiup-conference-2024/</link><pubDate>Wed, 01 May 2024 17:27:25 +0000</pubDate><guid>https://www.pulumi.com/blog/announcing-pulumiup-conference-2024/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/announcing-pulumiup-conference-2024/index.png" /&gt;
&lt;p&gt;Today we announce our annual PulumiUP virtual conference taking place on September 18, 2024. PulumiUP is our global cloud and IaC conference for anyone interested in infrastructure as code, cloud, AI, platform engineering, DevOps, and cloud culture. Every year, we strive to build a program packed with technical talks, demos, and best practices to empower you with new learnings and inspiration that you can apply in your professional life. Attend to hear from industry leaders, experts, and community peers.&lt;/p&gt;
&lt;h2 id="what-is-pulumiup"&gt;What is PulumiUP?&lt;/h2&gt;
&lt;p&gt;PulumiUP isn&amp;rsquo;t just another conference, it&amp;rsquo;s a global gathering of minds passionate about cloud technologies, AI, DevOps, and everything in between. Whether you&amp;rsquo;re an industry veteran or just dipping your toes into the vast ocean of cloud computing, PulumiUP has something for everyone.&lt;/p&gt;
&lt;p&gt;You&amp;rsquo;ll hear keynotes from Pulumi Founder/CEO Joe Duffy and CTO Luke Hoban, stories from industry leaders on their experiences with cloud adoption and transformation (and how they used Pulumi to make it happen), and talks from other members of the Pulumi community (like you!) aimed at helping you navigate the ever-changing world of the cloud.&lt;/p&gt;
&lt;h2 id="call-for-speakers-your-story-matters"&gt;Call for Speakers: Your Story Matters&lt;/h2&gt;
&lt;p&gt;One exciting addition to this year&amp;rsquo;s event is the call for speakers. We invite you, the community, to share your stories, experiences, and expertise with fellow attendees. Whether it&amp;rsquo;s a deep dive into a groundbreaking project, lessons learned from failures, or innovative best practices, your voice matters at PulumiUP.&lt;/p&gt;
&lt;h3 id="key-dates-to-remember"&gt;Key Dates to Remember&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;CFP opens: Thursday, April 25, 2024.&lt;/li&gt;
&lt;li&gt;CFP closes: Monday, June 17, 2024.&lt;/li&gt;
&lt;li&gt;CFP Notifications: Monday, July 22, 2024.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="selection-criteria"&gt;Selection Criteria&lt;/h3&gt;
&lt;p&gt;At PulumiUP, diversity and originality are celebrated. We welcome proposals from all corners of the tech community and prioritize fresh perspectives and solutions. Regardless of where you are in the world, we want to hear from you. Whether you&amp;rsquo;re a seasoned speaker or a first-timer, we encourage you to submit your ideas. Just remember, no vendor pitches allowed!&lt;/p&gt;
&lt;h3 id="talk-formats-and-themes"&gt;Talk Formats and Themes&lt;/h3&gt;
&lt;p&gt;You can submit up to two proposals in either the Lightning Talk (15-minute) or traditional session (30-minute) formats. The conference will cover a wide array of themes, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Infrastructure as Code&lt;/strong&gt;: From cloud providers to Kubernetes, explore the latest trends and best practices in cloud computing and IaC.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Platform Engineering &amp;amp; DevOps&lt;/strong&gt;: Learn how to streamline CI/CD practices, automate infrastructure operations, build internal developer portals (IDP), and improve developer experiences.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI / ML&lt;/strong&gt;: Dive into the world of AI and ML with topics like deploying AI application, LLM models, MLOps, and AIOps.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud Culture&lt;/strong&gt;: Discover the human side of tech, focusing on diversity, inclusivity, and collaboration within the industry.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Do you have a story to tell? &lt;a href="https://sessionize.com/pulumiup-conference-2024"&gt;Submit your proposal&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="join-us-on-september-18"&gt;Join Us on September 18!&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/pulumi-up/"&gt;Register for PulumiUP&lt;/a&gt;. Stay tuned for more updates and announcements as we gear up for PulumiUP 2024. We can&amp;rsquo;t wait to see you there!&lt;/p&gt;</description><author>Sara Huddleston</author><category>pulumi-events</category></item><item><title>Why Developer Experience (DevEx) is Business Critical</title><link>https://www.pulumi.com/blog/developer-experience-business-critical/</link><pubDate>Tue, 20 Feb 2024 20:47:44 +0000</pubDate><guid>https://www.pulumi.com/blog/developer-experience-business-critical/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/developer-experience-business-critical/index.png" /&gt;
&lt;p&gt;&amp;ldquo;Developer experience is hard to sell,&amp;rdquo; said Cleve Littlefield, Engineering Manager at Pulumi, during a casual meeting. With experience as both an end-user developer and a lead in self-service platform implementation, Cleve&amp;rsquo;s observation stuck with me.&lt;/p&gt;
&lt;p&gt;Though I have expertise in leading implementations and upgrades for internal platforms, none were specifically for developers. However, experience remains vital across departments, addressing tools, processes, systems, and best practices, aiming to reduce cognitive load, increase productivity, enhance collaboration, boost communication and much more.&lt;/p&gt;
&lt;p&gt;Intriguingly, engineering teams may perceive its value differently. Therefore, we will dive into the concept of developer experience, aka DevEx, which, in truth, should translate into a competitive advantage.&lt;/p&gt;
&lt;h2 id="in-this-devex-article"&gt;In this DevEx article&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#what-is-developer=experience"&gt;What is developer experience?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#is-developer-experience-important"&gt;Is developer experience important?&lt;/a&gt; (Spoiler alert: it&amp;rsquo;s business-critical)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#the-github-developer-experience-devex-formula"&gt;The GitHub developer experience (DevEx) formula&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#what-does-a-great-developer-experience-look-like"&gt;What does a great developer experience look like?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#how-does-devex-intersect-with-devops"&gt;How does DevEx intersect with DevOps?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#organizational-culture-is-a-predictor-of-outcome-success"&gt;Organizational culture is a predictor of outcome success&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#how-do-you-implement-a-great-developer-experience"&gt;How do you implement a great developer experience?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#what-devex-is-not"&gt;What DevEx is not&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#frequently-asked-questions"&gt;Frequently asked questions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-is-developer-experience"&gt;What is developer experience?&lt;/h2&gt;
&lt;p&gt;Developer experience (DevEx), also referred to as DevX or DX, encompasses systems, technology, processes, and culture that collectively impact the effectiveness of software development. It looks at all components of a developer&amp;rsquo;s ecosystem—from environment to workflows to tools—and evaluates how they contribute to developer productivity, satisfaction, and operational impact.&lt;/p&gt;
&lt;p&gt;Developer experience revolves around the ease or difficulty of executing essential tasks. &lt;strong&gt;A positive developer experience means those tasks are relatively easy to perform, translating into higher performance.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The quality of the experience is equally vital for developers building and managing internal software as it is for those involved in developing customer-facing software products.&lt;/p&gt;
&lt;h2 id="is-developer-experience-important"&gt;Is developer experience important?&lt;/h2&gt;
&lt;p&gt;It is not just important. &lt;strong&gt;It&amp;rsquo;s business critical.&lt;/strong&gt; If your company is in the business of creating and selling software or relies on critical internal software, developers are vital internal stakeholders to your business foundation.&lt;/p&gt;
&lt;p&gt;Greg Mondello, director of product at GitHub, said, &amp;ldquo;In most contexts, software development capacity is the limiting factor for innovation. Therefore, improvements to the effectiveness of software development are inherently valuable [&amp;hellip;] companies with better DevEx outperform their competitors, regardless of vertical.&amp;rdquo;&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-experience-business-critical/what-impact-are-you-experiencing-resulting-of-improving-developer-experience.jpg"
alt="Platform Engineering Forrester Opportunity Snapshot - DevEx impacts overall business performance. Credit: Humanitec" width="70%"&gt;&lt;figcaption&gt;
&lt;p&gt;Platform Engineering Forrester Opportunity Snapshot - DevEx impacts overall business performance. Credit: Humanitec&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;As per &lt;a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/tech-forward/why-your-it-organization-should-prioritize-developer-experience"&gt;McKinsey&amp;rsquo;s report&lt;/a&gt;, an enhanced developer experience (DevEx) can yield significant advantages for organizations, including enhanced talent hiring and retention, improved security, and increased developer productivity- this makes DevEx important for all companies, not just tech.&lt;/p&gt;
&lt;p&gt;A positive developer experience can yield numerous business advantages, which can include:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Improvement in collaboration across departments&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Higher attraction and retention top talent&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Increase developer productivity and developer velocity&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduction in operational costs&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Accelerate time-to-market&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Support innovation&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Elevate customer attraction and retention&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Increase bottom line through revenue growth&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;To this end, let&amp;rsquo;s look into what goes into developer experience and how to achieve it.&lt;/p&gt;
&lt;h2 id="the-github-developer-experience-devex-formula"&gt;The GitHub developer experience (DevEx) formula&lt;/h2&gt;
&lt;p&gt;GitHub&amp;rsquo;s DevEx formula takes into consideration the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Productivity: The speed and simplicity of implementing changes to a codebase&lt;/li&gt;
&lt;li&gt;Impact: The seamless transition from idea to production without obstacles&lt;/li&gt;
&lt;li&gt;Satisfaction: The environment, workflows, and tools influence developer happiness&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Optimizing DevEx involves fostering a collaborative environment where developers can be most productive, impactful, and satisfied.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-experience-business-critical/github-developer-experience-formula.png"
alt="DevEx formula. Credit: GitHub" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;DevEx formula. Credit: GitHub&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Noah Gift, the founder of Pragmatic AI Labs and a professor at Duke University specializing in machine learning, MLOps, AI, data science, and cloud architecture, noted that with the right platform, there could be:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A 75% increase in productivity&lt;/li&gt;
&lt;li&gt;A sustained 22% productivity increase three years later&lt;/li&gt;
&lt;li&gt;An 80% reduction in onboarding time&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Merely having skilled developers is insufficient. Developers also require the appropriate tools and processes to excel in their work. Top-tier developers anticipate the availability of such resources, influencing the hiring and retention of talent.&lt;/p&gt;
&lt;h2 id="what-does-a-great-developer-experience-look-like"&gt;What does a great developer experience look like?&lt;/h2&gt;
&lt;p&gt;Engineering teams that have good developer experiences are more productive and efficient. Great DevEx is often enabled by a platform where the end-users are the developers.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Developer-first readily available &lt;a href="https://www.pulumi.com/blog/platform-engineering-pillars-3/"&gt;internal developer platform&lt;/a&gt;, infrastructure, and development tooling, with well-organized and explicit documentation, including tutorials, demo environments, and curated learning paths.&lt;/li&gt;
&lt;li&gt;A unified hub for all developer requirements eliminates the need for developers to navigate through numerous tools, saving valuable time.&lt;/li&gt;
&lt;li&gt;Simplified workflows emerge when developers can swiftly select app patterns, such as API microservices or front-end journeys, and deploy them within minutes. This includes all-encompassing elements like environments, pre-integrated DevSecOps pipelines, monitoring, and fully automated change and release procedures.&lt;/li&gt;
&lt;li&gt;Centralized tracking of software, API, and infrastructure status and versions promotes asset transparency. A real-time view supports adherence to architectural standards, security controls, and patching status, with bots offering automatic suggestions for code enhancements related to issues.&lt;/li&gt;
&lt;li&gt;Integrated analytics and KPIs such as developer velocity, tech debt, error rate, mean time to recovery, and infrastructure cost can be automatically pulled by standard organizational tools, including backlog, pipeline, and monitoring tools.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-experience-business-critical/github-study-what-developers-spend-themost-time-on-daily.png"
alt="Survey by GitHub on a typical experience for developers. Credit: GitHub" width="60%"&gt;&lt;figcaption&gt;
&lt;p&gt;Survey by GitHub on a typical experience for developers. Credit: GitHub&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Without the proper tools, progress may slow down the development process and hinder developer productivity. It becomes crucial to implement appropriate measures to avoid disruptions that could impact everyone involved, including the developers themselves. Although not often mentioned, &lt;a href="https://www.pulumi.com/what-is/what-is-devops/"&gt;DevOps&lt;/a&gt; and &lt;a href="https://www.pulumi.com/what-is/what-is-platform-engineering/"&gt;Platform Engineering&lt;/a&gt; also aim to enhance the developer experience and achieve the associated benefits.&lt;/p&gt;
&lt;h2 id="how-does-devex-intersect-with-devops"&gt;How does DevEx intersect with DevOps?&lt;/h2&gt;
&lt;p&gt;DevOps is about developers and operations working together and sharing values, assumptions, and responsibility for the software they build and maintain.&lt;/p&gt;
&lt;p&gt;According to Vilas Veeraraghavan, VP of Engineering at Truckstop, &amp;ldquo;Developer Experience (DevEx) is the investment you make to enable solid DevOps practices, reduce developer burnout, and improve retention. The need for this investment is more pronounced as companies grow and the tech stack gets more diverse.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Watch Jowanza Joseph, Head of Engineering at StreamFT, below as he discusses how the right tool empowered developers, improved DevEx, reduced bottlenecks, increased productivity, and helped DevOps be a culture, a practice, not a person.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/I-GQ1xpyV0E?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;Let&amp;rsquo;s address a strong indicator of success or failure - culture.&lt;/p&gt;
&lt;p&gt;Culture is not something you are—it&amp;rsquo;s something you do. Software companies often focus on DevOps practices and culture, but all would benefit from adopting a DevOpsAll since the entire company should strive for the same thing. The diversity of perspectives, ideas, and insights can spark creativity and innovation and even ensure product-market alignment.&lt;/p&gt;
&lt;h2 id="organizational-culture-is-a-predictor-of-outcome-success"&gt;Organizational culture is a predictor of outcome success&lt;/h2&gt;
&lt;p&gt;Why it matters? Organizational culture encompasses everyone, from the development team and operations to product management teams, sales, marketing, and more.&lt;/p&gt;
&lt;p&gt;According to George Spafford, Senior Director Analyst at Gartner, &amp;ldquo;Infrastructure &amp;amp; Operations leaders embarking on DevOps initiatives and struggling to address organizational change and the value they will provide to the larger enterprise [&amp;hellip;] people-related factors tend to be the greatest challenges — not technology.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;According to a Harvard study encompassing 200 companies over 11 years, companies that focused on shaping their culture outperformed their competitors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Revenue growth was 4.1 times higher&lt;/li&gt;
&lt;li&gt;The stock price was 12.2 times higher&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.investopedia.com/terms/n/netincome.asp"&gt;Net income&lt;/a&gt; was 756% vs. 1%&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.investopedia.com/terms/r/returnoninvestment.asp"&gt;Return on investment (ROI)&lt;/a&gt; was 15 times higher&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The driving force behind this exceptional financial performance is that engaged employees are prone to increased productivity, fostering superior innovation and more effective problem-solving.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-experience-business-critical/employee-developer-experience-focus-areas.jpeg"
alt="Slide from a New York Atlassian Community Group presentation. Credit: Mark Cruth, principal modern work coach / advocate at Atlassian" width="80%"&gt;&lt;figcaption&gt;
&lt;p&gt;Slide from Mark&amp;rsquo;s New York Atlassian Community Group presentation. Credit: Mark Cruth, principal modern work coach/advocate at Atlassian&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Based on decades of research on employee engagement, &lt;a href="https://www.gallup.com/workplace/285674/improve-employee-engagement-workplace.aspx#ite-357638"&gt;Gallup has established that engaged employees consistently yield superior business outcomes compared to their counterparts&lt;/a&gt;. This holds true across various industries, company sizes, and nationalities and remains consistent in prosperous and challenging economic conditions.&lt;/p&gt;
&lt;p&gt;If it is not yet clear, then I will spell it out. Developer experience impacts employee engagement. A better developer experience can boost the engagement of the engineers and developers in the organization, and more engaged people are more likely to go the extra mile.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-experience-business-critical/developer-experience-more-engaged-developers.png"
alt="How developer experience supports better business outcomes. Credit: Swarmia" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;How developer experience supports better business outcomes. Credit: Swarmia&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;If organizations invest in cultural values centered on human-first factors, then even the choices made in tools, processes, and systems will also be with the end-user in mind.&lt;/p&gt;
&lt;h2 id="how-do-you-implement-a-great-developer-experience"&gt;How do you implement a great developer experience?&lt;/h2&gt;
&lt;p&gt;There isn&amp;rsquo;t a bulletproof checklist, but there are several aspects to consider, and you can see the outline below. First, you need to view the developers as customers.&lt;/p&gt;
&lt;p&gt;You will need to understand how developers work, the developer workflow, what the onboarding process looks like for a new developer, the developer teams&amp;rsquo; pain points, what developers love and hate about their day-to-day work, where they are spending most of their time, where they wish they spent most of their time, and so much more, that boils down to communication, and asking the right questions, and deep diving into analytics.&lt;/p&gt;
&lt;h3 id="cultivate-a-devops-culture"&gt;Cultivate a DevOps culture&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Shared responsibility&lt;/strong&gt;: Encourage a culture of shared responsibility where developers, operations, and other stakeholders work collaboratively&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Continuous learning&lt;/strong&gt;: Promote a culture of continuous learning and improvement to adapt to evolving technologies and methodologies&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Open communication&lt;/strong&gt;: Foster open communication channels to enhance collaboration and transparency among team members&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Company-wide collaboration tools&lt;/strong&gt;: It&amp;rsquo;s essential to encourage communication among developers and cross-functional teams to stimulate creativity, spark innovation, and enhance productivity and the speed of decision-making. Cross-functional collaboration contributes to successful business outcomes&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="define-clear-objectives"&gt;Define clear objectives&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Alignment with business goals&lt;/strong&gt;: Ensure DevEx objectives align with business goals to drive meaningful outcomes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User-centric approach&lt;/strong&gt;: Prioritize user needs and feedback, shaping the DevEx strategy around the actual experiences of developers&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="leverage-developer-first-tools"&gt;Leverage developer-first tools&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/building-developer-portals/"&gt;&lt;strong&gt;Internal developer portals (IDPs)&lt;/strong&gt;&lt;/a&gt;: IDPs enable developers to quickly provision approved infrastructure, boosting productivity with pre-configured architectures, automated testing, and deployment adhering to organizational standards&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CI pipelines&lt;/strong&gt;: usually, pipelines can be made faster and more unified. If they have a microservice architecture, they are likely duplicating pipeline code for every service&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/languages-sdks/"&gt;&lt;strong&gt;Software development kits (SDKs)&lt;/strong&gt;&lt;/a&gt;: SDKs are integral components of a positive DevEx and provide developers with tools that facilitate crafting applications tailored to specific platforms or frameworks. Offering easy-to-access, well-designed, functional SDKs can make a meaningful difference in helping engineers quickly prototype ideas and refine their creations&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/"&gt;&lt;strong&gt;Infrastructure as code (IaC)&lt;/strong&gt;&lt;/a&gt;: Developers like to write code, particularly in their preferred programming language, provision infrastructure, ensuring consistency and reproducibility&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Monitoring and observability&lt;/strong&gt;: Implement effective monitoring and observability tools (e.g., Prometheus, &lt;a href="https://www.pulumi.com/resources/observability-as-code-with-new-relic/"&gt;New Relic&lt;/a&gt;, Grafana) to gain insights into application performance and proactively address issues&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Collaborative documentation platforms&lt;/strong&gt;: Use collaborative documentation platforms to document code, processes, and best practices, ensuring knowledge sharing and reducing onboarding friction&lt;/li&gt;
&lt;/ul&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-experience-business-critical/steps-to-improve-developer-experience.jpg"
alt="Platform Engineering Forrester Opportunity Snapshot - which of the following steps has your org take to improve the developer experience? Top 43% internal developer platform or platform engineering Credit: Humanitec" width="70%"&gt;&lt;figcaption&gt;
&lt;p&gt;Platform Engineering Forrester Opportunity Snapshot - Which of the following steps organizations are taking to improve DevEx? Credit: Humanitec&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3 id="prioritize-developer-friendly-workflows"&gt;Prioritize developer-friendly workflows&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Fast feedback loops&lt;/strong&gt;: Minimize feedback loops by integrating quick feedback mechanisms, allowing developers to identify and resolve issues early in the development cycle&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Self-service environments&lt;/strong&gt;: Provide developers with self-service environments to facilitate experimentation, testing, and debugging without unnecessary dependencies on other teams&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Version control best practices&lt;/strong&gt;: Enforce version control best practices to maintain a clean and organized codebase, allowing for easier collaboration and tracking of changes&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="continuous-integration-of-feedback"&gt;Continuous integration of feedback&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Developer surveys&lt;/strong&gt;: Conduct regular surveys to gather feedback on the DevEx, ensuring continuous improvement based on real user experiences&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Rapid iteration&lt;/strong&gt;: Encourage a culture of rapid iteration, where feedback is quickly incorporated into the development process to enhance the overall developer experience&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="measure-and-optimize"&gt;Measure and optimize&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Key performance indicators (KPIs)&lt;/strong&gt;: Define and track key metrics such as deployment frequency, lead time, and mean time to recovery to measure the effectiveness of the DevEx strategy&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Iterative optimization&lt;/strong&gt;: Continuously iterate and optimize DevEx based on performance metrics and user feedback&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/platform-engineering-pillars-4/"&gt;Implementing a Developer Experience&lt;/a&gt; requires a holistic approach that blends cultural aspects with powerful DevOps and platform engineering tools. Watch Daniel Tao, Head of Engineering at &lt;a href="https://www.pulumi.com/case-studies/atlassian/"&gt;Atlassian&lt;/a&gt;, and Sven Peters, developer evangelist, discuss how to build a great developer experience through culture and an integrated approach to developer tools.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/xriRD7ugX20?si=LurTGLx1KfgRGIQZ&amp;amp;t=192?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="what-devex-is-not"&gt;What DevEx is not&lt;/h2&gt;
&lt;p&gt;Now that DevEx has been defined, let&amp;rsquo;s address some common misconceptions about developer experience.&lt;/p&gt;
&lt;h3 id="devex-is-not-the-same-as-user-experience-ux"&gt;DevEx is not the same as User Experience (UX)&lt;/h3&gt;
&lt;p&gt;Developer experience may sound similar to user experience (for developers), but it&amp;rsquo;s different, although user experience is a component. For example, a platform engineer &lt;a href="https://www.pulumi.com/blog/developer-portal-platform-teams/"&gt;building an internal developer platform&lt;/a&gt; must view the developers as their customers and create a good user experience by making it intuitive and easy to use.&lt;/p&gt;
&lt;h3 id="devex-is-not-about-enabling-lazy-developers"&gt;DevEx is not about enabling lazy developers&lt;/h3&gt;
&lt;p&gt;Part of the DevEx strategy is to retain talent. Companies that invest in DevEx don&amp;rsquo;t do it to pamper developers. The true reason behind it is that they want their developers to stay &amp;ldquo;in the zone,&amp;rdquo; also known as &amp;ldquo;deep work.&amp;rdquo; When in this state, they are immersed in writing code and solving problems they enjoy working on, and their creativity is higher, it sparks innovative ideas, and the quality and speed of their output are also higher.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/NbhpII8DIKA?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h3 id="devex-is-not-about-implementing-ai-and-cool-tools"&gt;DevEx is not about implementing AI and cool tools&lt;/h3&gt;
&lt;p&gt;Technology impacts developer experience, &lt;a href="https://www.pulumi.com/product/neo/"&gt;a robust generative AI tool can help create code faster&lt;/a&gt;, and internal developer platforms can help reduce cognitive load on developers. But again, tooling is only one aspect of it. Tools can&amp;rsquo;t fix culture or replace processes. Many DevEx considerations should be considered to ensure that when the development teams adopt a tool, it addresses their pain points and enables developers.&lt;/p&gt;
&lt;h3 id="devex-is-not-a-one-person-decision"&gt;DevEx is not a one-person decision&lt;/h3&gt;
&lt;p&gt;DevEx should be a joint effort from the entire team. One needs to be aware of the issues to plan to fix them, so open communication and team collaboration are vital to developing and implementing a DevEx strategy, intersecting DevOps and platform engineering initiatives. Many large organizations already have DevEx teams or professionals with a bird&amp;rsquo;s-eye view of what happens within the engineering team. They are internal advocates for software engineers. They consider the developer&amp;rsquo;s journey from being new developers and their &amp;lsquo;Time to First Contribution&amp;rsquo; to day-to-day activities. They work with engineers to learn which problems are a priority and identify misconceptions and bottlenecks that may slow the development process.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Developer experience (DevEx) is essential for creating maximum output while increasing developer satisfaction. The appropriate technology tools, workflows, and a supportive development community can help foster progress and innovation while promoting high-quality software engineering results that can become a competitive advantage and ultimately benefit the business&amp;rsquo;s bottom line.&lt;/p&gt;
&lt;p&gt;By dedicating attention to improving the DevEx, companies will also be able to bring more talent aboard, reduce their &amp;ldquo;Time to First Contribution,&amp;rdquo; enable developers to provide higher output contributions and improve talent retention. It&amp;rsquo;s time to start focusing on superior developer experiences.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discover &lt;a href="https://www.pulumi.com/blog/developer-portal-platform-teams/"&gt;Pulumi for Platform Teams: New Features for Developer Portals, Policy and Deployments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Read &lt;a href="https://www.pulumi.com/blog/pulumi-developer-workflow/"&gt;The Pulumi &amp;lsquo;Push to start&amp;rsquo; GitOps Experience&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="frequently-asked-questions"&gt;Frequently asked questions&lt;/h2&gt;
&lt;h3 id="what-does-business-critical-mean"&gt;What does business critical mean?&lt;/h3&gt;
&lt;p&gt;Business critical means essential for a business to operate and be successful. It refers to business processes, systems, or activities that are considered essential for proper functioning, success, or survival. If these elements are disrupted or compromised, the impact can significantly affect its operations, financial health, or overall business objectives. Business-critical components are often prioritized for attention, protection, and resource allocation to ensure the organization&amp;rsquo;s continued effectiveness and stability, and to remain competitive.&lt;/p&gt;
&lt;h3 id="what-is-the-role-of-a-developer-experience-engineer-dxe"&gt;What is the role of a Developer Experience Engineer (DXE)?&lt;/h3&gt;
&lt;p&gt;Developer Experience Engineers are internal advocates indispensable to making life easier for developers by making workflows more efficient, implementing the same processes across the development team, and assisting in choosing tools to lighten their load. Some companies do not necessarily have engineers with that job title, and it&amp;rsquo;s instead seen as part of DevOps or Platform Engineering initiatives. Other times, the internal developer advocate natural rises from the developer community to help form an integral part of the developer team&amp;rsquo;s unity. They also champion communication and work with cross-function coworkers and feel safe means of providing constructive feedback.&lt;/p&gt;
&lt;h3 id="how-do-we-cultivate-a-positive-developer-community"&gt;How do we cultivate a positive developer community?&lt;/h3&gt;
&lt;p&gt;The importance of DevEx&amp;rsquo;s human element is now in focus. A productive and effective developer community could be seen as a flourishing habitat, strengthening cooperation and maximizing productivity through collaboration. Such an atmosphere also sustains morale among the developers, resulting in job satisfaction and contentment.&lt;/p&gt;
&lt;p&gt;Here are some steps to build a developer community: open communication needs to become standard, successes should consistently be recognized, and avenues for growth need to exist. Diversity and acceptance are significant. Task expectations should be attainable goals and set high enough not to compromise quality but not realistic so they can be achieved without burnout and unbalanced life routines.&lt;/p&gt;
&lt;h3 id="how-does-technology-impact-developer-experience"&gt;How does technology impact developer experience?&lt;/h3&gt;
&lt;p&gt;Technological advancements continue to change software development and impact the Developer experience. AI, ML, TDD, and internal developer platforms are some of these technologies that help reduce developers&amp;rsquo; cognitive load. They automate complex tasks for more accuracy and enable intelligent decision-making. Besides this, generative AI has come into play in creating higher-quality code faster. At the same time, GitOps is a management approach based on one source of truth - Git, which makes collaboration smoother &amp;amp; boosts productivity by allowing automation. All these things undoubtedly improve the DX substantially for any developer out there!&lt;/p&gt;</description><author>Sara Huddleston</author><category>developer-experience</category><category>devops</category><category>platform-engineering</category><category>developer-portals</category><category>software-development</category></item><item><title>How AI is Transforming DevOps: AI Talks for DevOps Insights</title><link>https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/</link><pubDate>Mon, 13 Nov 2023 22:05:34 +0000</pubDate><guid>https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/index.png" /&gt;
&lt;p&gt;The integration of artificial intelligence (AI) with DevOps signals a new era in software development. DevOps possesses unique characteristics and needs that make it exceptionally compatible with AI augmentation. Given that code fundamentally relies on language, and large language models (LLMs) serve as the core of GPT functionality, these models are particularly well-suited for tasks such as code generation. This article unwraps the topics addressed during our “AI: Friends or Foe | AI Talks for DevOps” event in San Francisco.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#how-will-ai-impact-the-future-of-devops"&gt;How will AI Impact the Future of DevOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#what-is-devops-in-ai"&gt;What is DevOps in AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#what-is-ai-in-devops"&gt;What is AI in DevOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#how-ai-is-currently-used-in-devops"&gt;How AI is Currently Used in DevOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#how-can-a-devops-team-take-advantage-of-artificial-intelligence"&gt;How Can a DevOps Team Take Advantage of Artificial Intelligence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#top-5-skills-for-devops-engineers-in-the-ai-era"&gt;Top 5 Skills for DevOps Engineers in the AI era&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#how-to-overcome-ai-for-devops-challenges"&gt;How to Overcome AI for DevOps Challenges&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/#frequently-asked-questions"&gt;Frequently Asked Questions&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-will-ai-impact-the-future-of-devops"&gt;How will AI Impact the Future of DevOps&lt;/h2&gt;
&lt;p&gt;In the Fireside chat, Luke Hoban expressed his enthusiasm for incorporating AI into DevOps, emphasizing its potential utilization by both DevOps professionals and the development team. In contrast, Nana Janashia, &lt;a href="https://www.youtube.com/@TechWorldwithNana"&gt;TechWorld with Nana&lt;/a&gt;, adopted a more cautious stance, drawing attention to potential risks, particularly regarding reliability.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/i09F14yc0l4?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="what-is-devops-in-ai"&gt;What is DevOps in AI&lt;/h2&gt;
&lt;p&gt;When considering the adoption of AI and AI engineering, such as prompt engineering and other specific disciplines, AI engineers rely heavily on the cloud. Many AI-based systems are built around cloud-native tools, practices, and managed services.&lt;/p&gt;
&lt;p&gt;The extensive use of cloud-native primitives means that AI is fundamentally a cloud adoption story. Consequently, established DevOps and &lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;infrastructure as code&lt;/a&gt; tooling and best practices play an important role in AI engineering, in what is being done, and in leveraging its use.&lt;/p&gt;
&lt;h2 id="what-is-ai-in-devops"&gt;What is AI in DevOps&lt;/h2&gt;
&lt;p&gt;Integrating AI in DevOps entails employing machine learning (ML) and other artificial intelligence technologies to automate and optimize various software development and delivery aspects, including tasks such as automating testing and deployment processes and refining resource management.&lt;/p&gt;
&lt;p&gt;The incorporation of AI in DevOps can result in:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enhanced speed&lt;/li&gt;
&lt;li&gt;Improved resource management&lt;/li&gt;
&lt;li&gt;Increased reliability throughout the software development lifecycle&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Consequently, organizations may experience swifter deployments, reduced errors, and heightened overall productivity. By substituting manual processes with automation and AI-powered solutions, DevOps teams can elevate product quality and more efficiently oversee their systems.&lt;/p&gt;
&lt;h2 id="how-ai-is-currently-used-in-devops"&gt;How AI is Currently Used in DevOps&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/luke-nana-adora-discussing-devop-ai.png"
alt="Luke Hoban at the San Francisco Pulumi Group meetup discussing the usage of AI, during the AI Talks for DevOps" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Luke Hoban at the San Francisco Pulumi Group meetup discussing the usage of AI, during the AI Talks for DevOps&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;DevOps significantly impacts all stages of the development and operations lifecycle. It has helped break silos and optimize to increase developer velocity and productivity, creating a positive impact on the ops side.&lt;/p&gt;
&lt;p&gt;AI assists DevOps teams to refine their operations by detecting inefficiencies and triggering warnings as soon as issues appear. This technology also enables real-time observation of systems and applications, permitting prompt actions from operations personnel and minimizing downtime.&lt;/p&gt;
&lt;p&gt;AI-driven automation can also help the software development process with code generation. The operations teams from both departments quickly pinpoint any issues in their workflows while speeding up decision-making processes.&lt;/p&gt;
&lt;p&gt;In the long term, the AI may use cloud credentials to create and autonomously automate deployment and management and perform DevOps tasks on behalf of the DevOps or &lt;a href="https://www.pulumi.com/what-is/what-is-platform-engineering/"&gt;platform engineering&lt;/a&gt; team. In the near term, it is used to assist humans, from DevOps professionals to developers.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;“In the near term, AI usage in DevOps is about how do you keep the human in the loop, how do you use it as a learning tool, as a code generation tool, and for auditing to provide actionable notifications, all of which are still very human-dependent. There is so much more it can be used for. Currently, it&amp;rsquo;s a tool serving humans. But it is fascinating to imagine it in the future when it can be trusted to be an autonomous agent.”&lt;/strong&gt;&lt;/em&gt; - &lt;em&gt;Luke Hoban, CTO of Pulumi and co-creator of TypeScript&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, how does this technology bring about these advancements? Two main ways are by streamlining development tasks and improving monitoring and security protocols.&lt;/p&gt;
&lt;h3 id="streamlining-development-workflows"&gt;Streamlining Development Workflows&lt;/h3&gt;
&lt;p&gt;AI has the potential to significantly change the software development life cycle by automating routine processes, using resources efficiently, and offering solutions for improved code. DevOps teams can leverage AI-driven tools to increase effectiveness when managing their assets while also improving code quality, leading to faster project deliveries.&lt;/p&gt;
&lt;p&gt;For instance, AI can identify any slowdowns during progress and recommend improvements, analyze root causes, and help make judicious decisions regarding resource allocation, ultimately resulting in efficient delivery of software products.&lt;/p&gt;
&lt;h3 id="enhancing-monitoring-and-security"&gt;Enhancing Monitoring and Security&lt;/h3&gt;
&lt;p&gt;The usage of AI significantly boosts DevOps monitoring and security. With the assistance of AI tools, operations teams can use machine learning algorithms to examine a massive amount of data to protect their applications from potential risks and enhance reliability. These algorithmic solutions provide valuable advice for development personnel, which helps strengthen protection measures while optimizing performance simultaneously.&lt;/p&gt;
&lt;h2 id="how-can-a-devops-team-take-advantage-of-artificial-intelligence"&gt;How Can a DevOps Team Take Advantage of Artificial Intelligence&lt;/h2&gt;
&lt;p&gt;A DevOps team can leverage AI in several ways to enhance efficiency, automation, and overall productivity. Here are some key strategies for a DevOps team to leverage AI:&lt;/p&gt;
&lt;h3 id="code-generation-and-learning"&gt;Code Generation and Learning&lt;/h3&gt;
&lt;p&gt;AI can be a powerful tool to make the development process much smoother. It can help engineers focus on what matters instead of searching for documentation on websites, developer forums, or search engines for answers to help solve specific problems. The perfect code snippet is often hard to find or may not even exist.&lt;/p&gt;
&lt;p&gt;Generative AI, powered by LLMs, can help developers and DevOps engineers quickly discover, learn, and, for example, use new cloud infrastructure APIs.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumi-ai/run-metabase-in-azure.png"
alt="Pulumi AI response to Run metabase in Azure, using TypeScript" width="90%"&gt;&lt;figcaption&gt;
&lt;p&gt;Pulumi AI response to Run metabase in Azure, using TypeScript&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;You can see it in practice &lt;a href="https://www.pulumi.com/blog/pulumi-ai/"&gt;using Pulumi AI&lt;/a&gt;. You can use natural language to ask for a specific cloud infrastructure goal and obtain a corresponding Pulumi program in your preferred programming language. Moreover, Pulumi AI facilitates the iterative refinement of your cloud infrastructure, incorporating new features, enhancements to security and performance, resolution of correctness issues, and clarification of requirements. &lt;a href="https://www.pulumi.com/product/neo/"&gt;Try Pulumi Neo&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="intelligent-resource-management"&gt;Intelligent Resource Management&lt;/h3&gt;
&lt;p&gt;Platform and developer teams are spinning up resources across many cloud accounts within multiple cloud providers. It can be almost impossible to aggregate and search your infrastructure across these accounts since every cloud and every account is (by design!) a walled garden.&lt;/p&gt;
&lt;p&gt;Often, to answer key questions about their business, such as “Which team has the largest cloud footprint?”, teams need to combine data across various clouds, cloud accounts, and SaaS tools. This prevents organizations from getting quick answers to operational questions and barriers to building aggregations to derive insights. AI can provide actionable insights over infrastructure with natural language processing (NLP) queries.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;“I can get developers using IaC immediately with Pulumi Deployments and its GitHub integration, while Pulumi Insights [Resource Search] makes it really easy to find idle developer environments that need to be shut down, which reduces our cloud costs”&lt;/strong&gt;&lt;/em&gt; - &lt;em&gt;Santosh Dornal, Head of Software Test &amp;amp; DevOps, Alkira.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When using Pulumi Cloud, you can leverage &lt;a href="https://www.pulumi.com/blog/ai-assist-improvements/"&gt;AI Assist&lt;/a&gt;. You can provide a plain English (Spanish, French, or Japanese) request to express queries where you might not know the exact syntax, type tokens, or package names. AI Assist makes it easier by providing answers to queries like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;show me all s3 buckets not tagged in production&lt;/li&gt;
&lt;li&gt;show azure and azure native security groups&lt;/li&gt;
&lt;li&gt;show all AWS VPCs&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="remediation-tool-continuous-and-automatic-compliance"&gt;Remediation Tool: Continuous and Automatic Compliance&lt;/h3&gt;
&lt;p&gt;Defining and managing security rules, criteria, and conditions are key to enabling security at scale. Policy as Code, or Compliance as Code, has the ability to verify and spot problems before deploying the infrastructure. When policies are written with code, you can apply software development practices such as testing, automated deployment, and version control.&lt;/p&gt;
&lt;p&gt;AI can be valuable not just in anomaly detection but also in remediation, which doesn&amp;rsquo;t just warn or error but can change the infrastructure directly to remediate compliance gaps. With Pulumi, &lt;a href="https://www.pulumi.com/blog/remediation-policies/"&gt;Remediation policies&lt;/a&gt; can be configured and applied across any subset of stacks within an organization.&lt;/p&gt;
&lt;p&gt;Consider the &lt;a href="https://techcrunch.com/2017/02/01/gitlab-suffers-major-backup-failure-after-data-deletion-incident/"&gt;unfortunate incident at GitLab&lt;/a&gt;, marked by a disastrous sequence of events resulting in the loss of segments of production databases and substantial user data.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/tLdRBsuvVKc?si=brUXETRY4Rew7954?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;In this scenario, AI could have swiftly pinpointed the root cause and proposed a rapid solution, potentially mitigating the extent of damage before it escalated.&lt;/p&gt;
&lt;p&gt;While the benefits of writing policies as code are evident for DevOps engineers, &lt;a href="https://www.pulumi.com/blog/benefits-of-policy-as-code/"&gt;the organizational benefits are even more significant&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="enhance-collaboration-and-communication"&gt;Enhance Collaboration and Communication&lt;/h3&gt;
&lt;p&gt;Nowadays, many professionals with DevOps in their titles are held accountable for the multiple aspects of Dev + Ops. At its core, DevOps is a cultural movement that removes barriers among teams and promotes collaboration and shared responsibility between dev and ops.&lt;/p&gt;
&lt;p&gt;DevOps teams have seen great benefits from AI-driven tools, particularly in improving transparency, encouraging feedback, providing quick answers to common queries, and automating routine tasks. Many major companies, like Microsoft, use AI to build efficient workflows that make better decisions, leading to increased business outcomes. This includes smoother application delivery, a prime function of DevOps initiatives.&lt;/p&gt;
&lt;h3 id="improved-product-delivery"&gt;Improved Product Delivery&lt;/h3&gt;
&lt;p&gt;Companies incorporating AI into their DevOps strategy reap the rewards of accelerated product delivery. This has been made possible through improved workflows, automated testing, and strengthened security measures, leading to greater efficiency in software development by allowing development and operations teams more scope for dealing with complex tasks using machine learning models. They can make better decisions, resulting in faster product delivery and enhanced business outcomes.&lt;/p&gt;
&lt;p&gt;By streamlining existing systems within this context, customers can benefit from superior products delivered faster than before while companies provide and reinforce their business value.&lt;/p&gt;
&lt;h3 id="planning-and-cost-optimization"&gt;Planning and Cost Optimization&lt;/h3&gt;
&lt;p&gt;Implementing AI algorithms or AI tools that analyze usage patterns can assist in predicting future resource needs and optimize cloud infrastructure costs. This also ties in with intelligent resource management mentioned before, which can enhance cost efficiency, optimize resource allocation, and prevent unnecessary expenses.&lt;/p&gt;
&lt;h2 id="top-5-skills-for-devops-engineers-in-the-ai-era"&gt;Top 5 Skills for DevOps Engineers in the AI Era&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/devops-ai-developer-future--pulumi-user-group-tech-talks/adora-nana-talking-angle.png"
alt="Adora Nwodo with Nana discussing skills that DevOps engineers will need to learn to make AI work" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Adora Nwodo with Nana discussing skills that DevOps engineers will need to learn to make AI work&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;DevOps engineers must open new skills, mainly in cloud services, data, and AI/ML.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Programming Languages&lt;/strong&gt;: Although DevOps don&amp;rsquo;t usually need to know general programming languages in-depth, they should know what is most used by application teams. It&amp;rsquo;s a nice-to-have to find errors in CI/CD pipelines and fix them themselves as needed, but it is a must-have if the goal is to work MLOps.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Infrastructure as Code&lt;/strong&gt;: Automation is important for DevOps and critical for MLOps. IaC, using familiar languages, has been used since the early days of MLOps and is a key component to solving the cloud orchestration challenge present in AI/ML. Dive into more detail in &lt;a href="https://www.pulumi.com/blog/mlops-the-ai-challenge-is-cloud-not-code/"&gt;The Real AI Challenge is Cloud, not Code!&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Continuous Integration and Delivery&lt;/strong&gt;: CI/CD is mandatory knowledge, and it must be understood in detail to predict data preparation code, AI/ML code, CI/CD code, and infrastructure-related code.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Custom containers&lt;/strong&gt;: As a DevOps professional, you are expected to understand Docker and/or Kubernetes concepts and best practices.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Orchestration&lt;/strong&gt;: This is the holy grail of Ops and your key to unlocking AI.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/UfQeX-8HRmI?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="how-to-overcome-ai-for-devops-challenges"&gt;How to Overcome AI for DevOps Challenges&lt;/h2&gt;
&lt;p&gt;The integration of AI in DevOps brings forth several challenges that organizations must navigate to leverage the full potential of these technologies. Here are some key challenges and potential strategies to overcome them:&lt;/p&gt;
&lt;h3 id="1-skills-and-expertise"&gt;1. Skills and Expertise&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Challenge&lt;/strong&gt;: AI &amp;amp; ML expertise is often scarce within DevOps teams, leading to a skill gap in implementing and managing AI-driven tools.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Overcoming Strategy&lt;/strong&gt;: Organizations will need to hire professionals with AI and ML expertise, or existing team members will need training in machine learning, becoming proficient in MLOps combined to DevOps principles. Collaboration between DevOps and data science teams can also bridge the knowledge gap.&lt;/p&gt;
&lt;h3 id="2-integration-complexity"&gt;2. Integration Complexity&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Challenge&lt;/strong&gt;: Integrating AI seamlessly into existing DevOps workflows can be complex, given the diverse technologies and processes involved.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Overcoming Strategy&lt;/strong&gt;: Prioritize a phased integration approach, gradually introducing AI capabilities into specific stages of the DevOps pipeline. This allows teams to adapt without disrupting established processes.&lt;/p&gt;
&lt;h3 id="3-scalability"&gt;3. Scalability&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Challenge&lt;/strong&gt;: As AI applications within DevOps expand, ensuring scalability becomes crucial to accommodate growing workloads.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Overcoming Strategy&lt;/strong&gt;: Design AI solutions with scalability in mind, utilizing cloud resources and containerization. Regularly assess performance and adjust infrastructure to meet evolving demands.&lt;/p&gt;
&lt;h3 id="4-data-quality-and-availability"&gt;4. Data Quality and Availability&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Challenge&lt;/strong&gt;: AI models rely heavily on high-quality and readily available data. Inconsistent or inadequate data can lead to inaccurate predictions or suboptimal performance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Overcoming Strategy&lt;/strong&gt;: Prioritize data quality and establish robust data pipelines. Conduct regular audits to ensure data accuracy and implement strategies for handling missing or incomplete data.&lt;/p&gt;
&lt;h3 id="5-cultural-resistance"&gt;5. Cultural Resistance&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Challenge&lt;/strong&gt;: Resistance to change or skepticism about the benefits of AI within DevOps and in software development can impede successful integration.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Overcoming Strategy&lt;/strong&gt;: Foster a culture of innovation and continuous improvement. Provide clear communication about the benefits of AI, involve team members in the decision-making process, and showcase success stories to build confidence.&lt;/p&gt;
&lt;p&gt;Navigating these challenges requires a thoughtful and strategic approach, focusing on collaboration, skill development, and the gradual incorporation of AI into existing DevOps practices. Regular evaluation and adaptation are essential to ensure a successful and sustainable integration of AI in the DevOps environment.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;AI in DevOps can transform software development by making workflows more efficient, monitoring and security stronger, and overall effectiveness increased. Organizations that embrace AI/ML aim for better collaboration between teams, automating and intelligently managing infrastructure, reducing time-to-market, and increasing developer productivity and cost savings due to streamlining processes within their development lifecycle. AI and ML knowledge will become necessary skills expected to be applied to enhance and benefit the development, security, and operation teams as a whole. Follow the Pulumi Python + AI/ML series to upskill and get ahead:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/mlops-the-ai-challenge-is-cloud-not-code/"&gt;The Real AI challenge is Cloud, not Code!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/mlops-huggingface-llm-aws-sagemaker-python/"&gt;Deploy AI Models on Amazon SageMaker using Pulumi Python IaC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/deploy-ai-ml-vercel-app/"&gt;Deploying Your AI/ML Chatbot Frontend To Vercel Using Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="frequently-asked-questions"&gt;Frequently Asked Questions&lt;/h2&gt;
&lt;h3 id="can-ai-replace-devops"&gt;Can AI replace DevOps?&lt;/h3&gt;
&lt;p&gt;DevOps has not been taken over by AI yet. Rather, its use has made a difference in code quality and accelerated certain processes. Improvements to the quality of coding have been seen as one of the main benefits brought on through integration with artificial intelligence.&lt;/p&gt;
&lt;h3 id="what-is-an-example-of-ai-in-devops"&gt;What is an example of AI in DevOps?&lt;/h3&gt;
&lt;p&gt;AI can be utilized to make DevOps processes more efficient by creating test cases and pipelines, assessing infrastructure configurations for security concerns, and deploying applications. This technology includes machine learning algorithms, natural language processing systems, computer vision capabilities, chatbot programs, and virtual assistants. All are designed with one goal in mind – optimization of operations within development teams.&lt;/p&gt;
&lt;h3 id="what-is-the-future-of-devops"&gt;What is the future of DevOps?&lt;/h3&gt;
&lt;p&gt;Operations teams collaborating with developers to create quality products quickly and effectively is the goal for DevOps moving forward. The vision of this process involves both sides working together, resulting in an improved system and increased efficiency.&lt;/p&gt;</description><author>Sara Huddleston</author><author>Scott Lowe</author><category>devops</category><category>pulumi-events</category><category>ai</category><category>ml</category><category>community</category><category>platform-engineering</category></item><item><title>LangChain for DevOps: Learn LLM &amp; GenAI for Dev, Sec &amp; Ops</title><link>https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/</link><pubDate>Thu, 26 Oct 2023 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/generative-ai-apps-devops-talks-pulumi-user-group/index.png" /&gt;
&lt;p&gt;The emergence of DevOps revolutionized software development. Now, with AI powered tools like LangChain, these transformations are being accelerated. Unsurprisingly, our distinguished speaker at the launch of Pulumi&amp;rsquo;s in-person AI Talks, Patrick Debois, who coined the term &amp;ldquo;DevOps,&amp;rdquo; has recently tuned into LLM and GenAI Ops using the Langchain framework.&lt;/p&gt;
&lt;p&gt;This article unwraps the topics addressed during our &amp;ldquo;Generative AI, Apps, and DevOps | AI/ML Talks&amp;rdquo; event in Seattle, focusing on Langchain and GenAI for DevOps. You&amp;rsquo;ll be able to &lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#how-to-use-langchain-to-learn-llms-and-genai-for-devsecops"&gt;watch Patrick Debois teach LangChain to learn LLMs and GenAI&lt;/a&gt;, with code examples and lessons that are easily understood by traditional software engineering.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#what-is-langchain-used-for"&gt;What is LangChain used for?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#why-is-langchain-becoming-popular"&gt;Why is LangChain becoming popular?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#langchain-accelerating-devops"&gt;LangChain Accelerating DevOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#how-to-use-langchain-to-learn-llms-and-genai-for-devsecops"&gt;How to Use LangChain to Learn LLMs and GenAI for Dev(Sec)Ops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#real-world-applications-of-langchain-ai-in-devops"&gt;Real-World Applications of LangChain AI in DevOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#monitoring-and-anomaly-detection-with-langchain-ai"&gt;Monitoring and Anomaly Detection with LangChain AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#future-ai-apps-and-devops"&gt;Future: AI, Apps, and DevOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#conclusion"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/#frequently-asked-questions"&gt;Frequently Asked Questions&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="what-is-langchain-used-for"&gt;What is LangChain used for?&lt;/h2&gt;
&lt;p&gt;LangChain is an open-source Python framework designed to empower developers to construct robust generative AI applications. It facilitates the integration of advanced AI models such as OpenAI&amp;rsquo;s GPT, &lt;a href="https://gemini.google.com"&gt;Google&amp;rsquo;s Gemini&lt;/a&gt;, and &lt;a href="https://ai.meta.com/llama"&gt;Meta&amp;rsquo;s LLaMA&lt;/a&gt;. This versatile tool finds application in developing retrieval-augmented chatbots and other personalized assistants, utilizing technologies like ChatGPT. Furthermore, it enables tasks such as question-answering (GQA), summarization, code comprehension, API interactions, data cleansing, and much more.&lt;/p&gt;
&lt;h2 id="why-is-langchain-becoming-popular"&gt;Why is LangChain becoming popular?&lt;/h2&gt;
&lt;p&gt;The landscape of AI development is rapidly evolving, and LangChain is packed with incredible features for building LLM applications and tools. Developers with a wide range of expertise use LangChain for tasks such as managing interactions with language models, establishing seamless connections between diverse components, and integrating external resources like APIs and databases effortlessly.&lt;/p&gt;
&lt;p&gt;The LangChain platform hosts a diverse collection of APIs seamlessly integrated into applications. This enables developers to incorporate advanced language processing functionalities without the need for laborious construction from scratch.&lt;/p&gt;
&lt;h2 id="langchain-accelerating-devops"&gt;LangChain Accelerating DevOps&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/patrick-debois-langchain-ai-workshop.png"
alt="Patrick Debois at the Seattle Pulumi User Group, with a monitor showing OpenAI LangChain and code in Python" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Patrick Debois presenting the workshop Dev, Sec &amp;amp; Ops meet LangChain&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;LangChain can streamline the integration of large language models and data sources. By helping bring in AI capabilities, DevOps can revolutionize software development life cycles by making it easier for teams to handle challenges while optimizing resource allocation and usage through their cutting-edge, AI-powered solutions. This makes the &lt;a href="https://www.pulumi.com/docs/using-pulumi/automation-api/"&gt;automation of manual processes easier&lt;/a&gt; and the development of new resources far more accessible with faster utilization rates by leveraging artificial intelligence. Significantly important as &amp;ldquo;&lt;a href="https://www.pulumi.com/product/internal-developer-platforms/"&gt;Developer Velocity and Productivity&lt;/a&gt;&amp;rdquo; become business performance metrics across various industries.&lt;/p&gt;
&lt;p&gt;The features included in LangChain include chain interface memory functions for scalability within apps, control over dataflow, as storage – making code quality more reliable, plus seamless machine learning models integration, which allows them to build custom automated AI programs quickly. Thus providing users with an advanced but easy way of creating sophisticated solutions by combining their knowledge of coding and machine training models together.&lt;/p&gt;
&lt;h2 id="how-to-use-langchain-to-learn-llms-and-genai-for-devsecops"&gt;How to Use LangChain to Learn LLMs and GenAI for Dev(Sec)Ops&lt;/h2&gt;
&lt;p&gt;Patrick teaches in the way he would like to be taught. The workshop mainly uses the Langchain framework and basic Python knowledge. OpenAI will also need to be installed. You&amp;rsquo;ll learn essential skills in multiple use cases, applying Langchain for LLM application Development.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/iIl1bQnVwEs?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;You can see the breakdown of the lessons per role below, and find the code examples in the &lt;a href="https://github.com/jedi4ever/learning-llms-and-genai-for-dev-sec-ops/tree/main"&gt;Learning LLMs and GenAI for DevSecOps repo&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="developer"&gt;Developer&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Calling a simple LLM using OpenAI&lt;/li&gt;
&lt;li&gt;Looking at debugging in Langchain&lt;/li&gt;
&lt;li&gt;Chatting with OpenAI as a model&lt;/li&gt;
&lt;li&gt;Using prompt templates&lt;/li&gt;
&lt;li&gt;Use Docloader to read your local files and prepare them for the LLM&lt;/li&gt;
&lt;li&gt;Explain the calculation and use of embeddings&lt;/li&gt;
&lt;li&gt;Understand how splitting and chunking are important&lt;/li&gt;
&lt;li&gt;Loading embeddings and documents in a vector database&lt;/li&gt;
&lt;li&gt;Use a chain for Questions and Answers to implement the RAG pattern (Retrieval Augmented Generation)&lt;/li&gt;
&lt;li&gt;Show the use of OpenAI documentation to have the llm generate calls to find real-time information&lt;/li&gt;
&lt;li&gt;Implement an Agent and provide it with tools to get more real-time information&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="operations"&gt;Operations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Find out how many tokens you are using and the cost&lt;/li&gt;
&lt;li&gt;How to cache your calls to an LLM using exact matching or embeddings&lt;/li&gt;
&lt;li&gt;How to cache the calculation of embeddings and run the calculation locally&lt;/li&gt;
&lt;li&gt;Run your own local LLM (using Ollama)&lt;/li&gt;
&lt;li&gt;Track your calls and log them to a file (using a callback handler)&lt;/li&gt;
&lt;li&gt;Impose output structure (as JSON) and have the LLM retry if it&amp;rsquo;s not correct&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="security"&gt;Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Explain the OWASP top 10 for LLMS&lt;/li&gt;
&lt;li&gt;Show how simple prompt injection works and some mitigation strategies&lt;/li&gt;
&lt;li&gt;How to detect prompt injection using a 3rd party model from Hugging Face&lt;/li&gt;
&lt;li&gt;Detect project injection by using a prompt&lt;/li&gt;
&lt;li&gt;Check the answer LLMs provide and reflect if it is ok&lt;/li&gt;
&lt;li&gt;Use a Hugging Face model to detect if an LLM output was toxic&lt;/li&gt;
&lt;li&gt;Show a simple prompt for asking the LLM&amp;rsquo;s opinion on Kubernetes and Trivy vulnerabilities&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="real-world-applications-of-langchain-ai-in-devops"&gt;Real-World Applications of LangChain AI in DevOps&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/langchain-vector-similarity-search-in-a-rag-application.png"
alt="Vector similarity search in a RAG application" width="90%"&gt;&lt;figcaption&gt;
&lt;p&gt;Vector similarity search in a RAG application. Credit to LangChain and Neo4J team&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;LangChain AI has practical applications in DevOps, particularly related to question-answering using documents as context, extraction, evaluation, and natural language processing tasks, all powered by AI tools. An interesting scenario is implementing &lt;a href="https://blog.langchain.dev/using-a-knowledge-graph-to-implement-a-devops-rag-application/"&gt;a knowledge graph based RAG application with LangChain&lt;/a&gt; to support the DevOps team.&lt;/p&gt;
&lt;p&gt;ChatGPT based on LLMs enabled with these AI tools is one of the foremost implementations at present. Tracking capabilities through LangChain enables developers to determine which prompts are more effective, thus supporting what artificial intelligence offers when integrated into development operations.&lt;/p&gt;
&lt;h2 id="monitoring-and-anomaly-detection-with-langchain-ai"&gt;Monitoring and Anomaly Detection with LangChain AI&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/monitoring-llm-langchain-whylabs.png"
alt="Monitoring LLM performance with LangChain and LangKit" width="90%"&gt;&lt;figcaption&gt;
&lt;p&gt;Monitoring LLM performance with LangChain and LangKit. Credit to WhyLabs&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;LangChain AI provides an efficient approach to DevOps through continuous monitoring, and anomaly detection. LangChain&amp;rsquo;s integration in DevOps allows for intelligent monitoring of various system parameters, application performance metrics, and log files. It can process large volumes of data generated by applications and infrastructure components. Through natural language processing (NLP) techniques, LangChain can interpret logs, error messages, and system alerts in real-time.&lt;/p&gt;
&lt;p&gt;LangChain&amp;rsquo;s AI-driven anomaly detection capabilities are pivotal in identifying deviations from expected behavior in the monitored data. By analyzing historical data patterns, LangChain can learn the normal behavior of the system and its components. When the system encounters an unusual event or behavior, LangChain can promptly detect it as an anomaly. These anomalies could be security threats, performance bottlenecks, code quality, or any irregularities within the system.&lt;/p&gt;
&lt;p&gt;Keep in mind that monitoring LLM performance is important to ensure you can rely on the model&amp;rsquo;s accuracy and relevance in real-world applications. Our customer &lt;a href="https://www.pulumi.com/case-studies/whylabs/"&gt;WhyLabs&lt;/a&gt; has a great article showing the significance of &lt;a href="https://whylabs.ai/blog/posts/monitoring-llm-performance-with-langchain-and-langkit"&gt;monitoring LLMs performance with LangChain and how to get started&lt;/a&gt; with monitoring.&lt;/p&gt;
&lt;h2 id="future-ai-apps-and-devops"&gt;Future: AI, Apps, and DevOps&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/what-is/what-is-platform-engineering/"&gt;Platform engineering&lt;/a&gt;, DevOps, or MLOps may be the next steps in the AI-driven software development future. AI tools are the gateway to giving developers access to big language models that allow them to create highly sophisticated solutions.&lt;/p&gt;
&lt;h3 id="accelerating-development-with-ai-powered-tools"&gt;Accelerating Development with AI-Powered Tools&lt;/h3&gt;
&lt;p&gt;AI-powered tools are revolutionizing the development process, enabling DevOps teams to access intelligent recommendations and improve code quality or obtain suggestions on new ways to accomplish goals. An example is the usage of &lt;a href="https://www.pulumi.com/product/neo/"&gt;Pulumi Neo&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Tools like LangChain, Amazon CodeGuru, and Pulumi AI provide actionable insights for efficient resource utilization while enforcing policy and compliance best practices. An &lt;a href="https://www.pulumi.com/blog/pulumi-insights-ai-cli/"&gt;IaC that leverages AI empowers teams&lt;/a&gt; to automate and more effectively manage infrastructure.&lt;/p&gt;
&lt;p&gt;Developers can reap multiple benefits from higher quality assessment of code lines, instantaneous detection of policy and security issues, useful cues on how to resolve problems, and improving code quality, productivity, and time management.&lt;/p&gt;
&lt;p&gt;AI has greatly impacted optimization during the review stage, providing developers with better insights into performance issues, code effectiveness, and &lt;a href="https://www.pulumi.com/blog/property-search/"&gt;resource utilization&lt;/a&gt; without any extra effort.&lt;/p&gt;
&lt;h3 id="security-and-vulnerability-management-with-ai"&gt;Security and Vulnerability Management with AI&lt;/h3&gt;
&lt;p&gt;The marriage of AI, machine learning, and DevOps/DevSecOps practices revolutionizes security and vulnerability management in software engineering. AI-enabled tools technologies not only strengthen the defenses of software systems but also enable organizations to stay one step ahead in ensuring successful deployments by removing manual processes through automation, using single sources of truth, enforcing least-privileged access through role-based access controls, and &lt;a href="https://www.pulumi.com/blog/remediation-policies/"&gt;automated remediation to correct configuration violations&lt;/a&gt; like auto-tagging, removing Internet access, and enabling storage encryption.&lt;/p&gt;
&lt;p&gt;DevSecOps can foster collaboration between developers, security, and operations and still enhance security and compliance best practices using Artificial Intelligence (AI) and Machine Learning techniques.&lt;/p&gt;
&lt;h3 id="leveraging-machine-learning-in-devops"&gt;Leveraging Machine Learning in DevOps&lt;/h3&gt;
&lt;p&gt;&lt;img src="https://www.pulumi.com/blog/generative-ai-apps-devops-talks-pulumi-user-group/ml-dev-ops-cycle.png" alt="MLOps (Machine Learning Operations) meets DevOps Infinity Loop as part of the software development lifecycle" title="MLOps (Machine Learning Operations) meets DevOps Infinity Loop"&gt;&lt;/p&gt;
&lt;p&gt;Applying Machine Learning in DevOps is a game-changer. Not only does it automate and enhance various processes but also brings an intelligent, predictive, and adaptive dimension to development workflows. By embracing these technologies, development teams can achieve higher efficiency, improve code quality, optimize performance, and seamlessly integrate with artificial intelligence, thereby shaping the future of software engineering.&lt;/p&gt;
&lt;p&gt;ML models can evaluate past outcomes from compilation/builds plus performance metrics within an operation so that developers may leverage these insights when writing code accordingly with machine learning algorithms, allowing them to identify vulnerabilities or issues faster through root cause analysis while ameliorating system security against outside attacks like hackers or DDOS activity thus boosting overall system productivity thanks to AI implementation into existing processes.&lt;/p&gt;
&lt;h3 id="implementing-ai-models-into-devops-key-considerations"&gt;Implementing AI models into DevOps: Key Considerations&lt;/h3&gt;
&lt;p&gt;When considering AI, it&amp;rsquo;s essential to assess data quality, integration complexity, cost savings, and ethical/legal considerations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Ensuring the data used for training these AI tools are precise, exhaustive, and up-to-date will help gain more reliable results.&lt;/li&gt;
&lt;li&gt;An important aspect of the implementation process is integrating existing DevOps instruments and guaranteeing scalability, depending on the company&amp;rsquo;s necessities.&lt;/li&gt;
&lt;li&gt;Ensuring that all laws applicable when working with such technology.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;AI and ML are rapidly becoming a necessity, which can greatly enhance and benefit Development, Security, and Operation teams. At first glance, it may appear daunting or out of reach, but tools like Langchain and Pulumi can make it easier to get started. Follow the Pulumi Python + AI/ML series to upskill and get ahead:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/mlops-the-ai-challenge-is-cloud-not-code/"&gt;The Real AI challenge is Cloud, not Code!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/mlops-huggingface-llm-aws-sagemaker-python/"&gt;Deploy AI Models on Amazon SageMaker using Pulumi Python IaC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/deploy-ai-ml-vercel-app/"&gt;Deploying Your AI/ML Chatbot Frontend To Vercel Using Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="frequently-asked-questions"&gt;Frequently Asked Questions&lt;/h2&gt;
&lt;h3 id="who-is-patrick-debois"&gt;Who is Patrick Debois?&lt;/h3&gt;
&lt;p&gt;Patrick Debois is a highly accomplished technologist whose expertise spans the domains of Development (Dev), Security (Sec), and Operations (Ops). Acknowledged as a respected confidant within the developer, security, and operations communities, Patrick is presently deeply engrossed in the realm of Artificial Intelligence and Machine Learning, continually pushing the boundaries of his technical acumen.&lt;/p&gt;
&lt;p&gt;He was the organizer of the inaugural DevOpsDays in 2009. He is credited with coining &amp;ldquo;DevOps&amp;rdquo; and co-authoring the renowned DevOps Handbook. In the past, Patrick has collaborated with esteemed technology organizations such as &lt;a href="https://www.pulumi.com/case-studies/atlassian/"&gt;Atlassian&lt;/a&gt; and Snyk. Currently, he wears dual hats as the Vice President of Engineering and a Distinguished Engineer at Showpad.&lt;/p&gt;
&lt;h3 id="is-langchain-free"&gt;Is LangChain Free?&lt;/h3&gt;
&lt;p&gt;Yes, LangChain is an open-source framework, free to use and modify.&lt;/p&gt;
&lt;h3 id="how-does-langchain-work"&gt;How Does LangChain Work?&lt;/h3&gt;
&lt;p&gt;LangChain is a meticulously designed open-source framework tailored to simplify the creation of applications powered by large language models (LLMs). First, you will need to have a language model or you can use a public language model or train your own.&lt;/p&gt;
&lt;p&gt;Once you have a language model ready, you can start building applications. The framework offers an array of tools and APIs, simplifying the process of connecting language models to diverse data sources, interacting with their environment, and constructing intricate applications.&lt;/p&gt;
&lt;p&gt;LangChain operates by linking together various components, referred to as links, to establish a workflow. Each link in the chain performs a task and is connected in a sequence, enabling the output of one link to serve as the input for the subsequent one. This sequential linking allows the chain to execute intricate tasks by combining simple tasks seamlessly.&lt;/p&gt;
&lt;p&gt;See &lt;a href="https://python.langchain.com/docs/get_started/introduction"&gt;LangChain&amp;rsquo;s get started&lt;/a&gt; docs for more information.&lt;/p&gt;
&lt;h3 id="does-chatgpt-use-langchain"&gt;Does ChatGPT use LangChain?&lt;/h3&gt;
&lt;p&gt;ChatGPT utilizes LangChain to create custom artificial intelligence (AI). This allows for an individualized experience.&lt;/p&gt;</description><author>Sara Huddleston</author><author>Kat Morgan</author><category>pulumi-events</category><category>community</category><category>ai</category><category>devops</category><category>langchain</category><category>ml</category></item><item><title>Announcing the Speaker Lineup for PulumiUP 2023</title><link>https://www.pulumi.com/blog/announcing-speaker-lineup-pulumiup-2023/</link><pubDate>Wed, 24 May 2023 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/announcing-speaker-lineup-pulumiup-2023/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/announcing-speaker-lineup-pulumiup-2023/index.png" /&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/pulumi-up/"&gt;PulumiUP&lt;/a&gt; is our virtual user conference for the Pulumi community and anyone interested in Infrastructure as Code. Every year, we strive to build a program packed with technical talks, demos, and best practices with the goal of leaving you with new learnings and inspiration that will help you become a better cloud engineer. You&amp;rsquo;ll hear from industry leaders and experts about IaC, software engineering, DevOps, Platform engineering, and AI.&lt;/p&gt;
&lt;p&gt;We hope you&amp;rsquo;ll &lt;a href="https://www.pulumi.com/pulumi-up/"&gt;join us virtually&lt;/a&gt; and take this opportunity to grow your knowledge and become infrastructure as code stars.&lt;/p&gt;
&lt;h2 id="get-ready-for-amazing-launches-and-demos"&gt;Get Ready for Amazing Launches and Demos&lt;/h2&gt;
&lt;p&gt;Learn about Pulumi&amp;rsquo;s newest features across the core IaC SDKs and Pulumi Cloud.
And watch hands-on demos by the Pulumi team:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Joe Duffy, Co-founder and CEO&lt;/li&gt;
&lt;li&gt;Luke Hoban, Co-creator of TypeScript and CTO&lt;/li&gt;
&lt;li&gt;Meagan Cojocar, Principal Product Manager&lt;/li&gt;
&lt;li&gt;Evan Boyle, Engineering Manager&lt;/li&gt;
&lt;li&gt;Zaid Ajaj, Software Engineer&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="final-speakers-announced"&gt;Final Speakers Announced&lt;/h2&gt;
&lt;p&gt;You&amp;rsquo;ll hear from innovators, leaders, and experts from multiple industries and learn about infrastructure as code, software engineering, and cloud engineering.&lt;/p&gt;
&lt;h3 id="sam-cogan---solution-architect-wtw"&gt;Sam Cogan - Solution Architect, WTW&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Talk: Keeping your Infrastructure Code DRY (Don&amp;rsquo;t Repeat Yourself)&lt;/em&gt;&lt;br&gt;
Sam is a Solution Architect with &lt;a href="https://www.wtwco.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;WTW&lt;/a&gt; and a Microsoft Azure MVP. Sam is focused on delivering applications into the cloud using IaaS, PaaS, Serverless, Containers, and Kubernetes. Sam is particularly focused on automation and DevOps, including Infrastructure as Code, Cloud automation tooling, PowerShell, and CI/CD tooling.&lt;/p&gt;
&lt;h3 id="dennis-sauvé---devops-engineer-washington-trust-bank"&gt;Dennis Sauvé - DevOps Engineer, Washington Trust Bank&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Talk: How a Bank Modernized its Software Engineering with Infrastructure as Code Automation&lt;/em&gt;&lt;br&gt;
Dennis is a development operations engineer at &lt;a href="https://www.watrust.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Washington Trust Bank&lt;/a&gt; in Spokane, WA. With years of experience in software development and cloud engineering, he works to streamline deployment pipelines and create solutions for developers.&lt;/p&gt;
&lt;h3 id="ala-shiban---co-founder--ceo-klotho"&gt;Ala Shiban - Co-Founder &amp;amp; CEO, Klotho&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Talk: Creating a &amp;lsquo;Cloud-Aware&amp;rsquo; Code Solution&lt;/em&gt;&lt;br&gt;
Ala is the co-founder of &lt;a href="https://klo.dev/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Klotho&lt;/a&gt;, a startup that transforms plain code to cloud-native code. He started his journey on Commodore64 with cassette tapes and (much) more recently worked on distributed systems, developer tools, and large-scale web, cloud, and microservice backends.&lt;/p&gt;
&lt;p&gt;He&amp;rsquo;s led smaller teams and larger organizations at Microsoft&amp;rsquo;s Developer Division and Riot Games&amp;rsquo; Infrastructure Platform organization.&lt;/p&gt;
&lt;h3 id="matt-stephenson---sr-principal-software-engineer-starburst-data"&gt;Matt Stephenson - Sr. Principal Software Engineer, Starburst Data&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Talk: Creating Infrastructure Automation Magic with Code&lt;/em&gt;&lt;br&gt;
Matt is a Sr. Principal Software Engineer at &lt;a href="https://www.starburst.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Starburst Data&lt;/a&gt;. He&amp;rsquo;s responsible for Starburst&amp;rsquo;s infrastructure architecture. He&amp;rsquo;s worked at many tech companies, including Square, Oracle, Google, and Amazon. Aside from technology, Matt is a pilot and helps build The Man for Burning Man each year.&lt;/p&gt;
&lt;h3 id="tim-holm---co-founder--cto-nitric"&gt;Tim Holm - Co-Founder &amp;amp; CTO, Nitric&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Talk: Engineering a Multi-cloud Platform&lt;/em&gt;&lt;br&gt;
Tim Holm is the Co-founder and CTO at &lt;a href="https://nitric.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Nitric&lt;/a&gt;, with 12 years of experience in software engineering and cloud development. In disciplines ranging from Server and Storage Virtualisation and Automation, Mobile Application development, Full-stack application development, and Cloud infrastructure automation. Before founding Nitric, Tim worked to deliver critical infrastructure projects in Government and Fintech.&lt;/p&gt;
&lt;p&gt;In his spare time, Tim enjoys video games, building Lego, and mountain biking.&lt;/p&gt;
&lt;h3 id="tyler-scheuble---head-of-platform-people-data-labs"&gt;Tyler Scheuble - Head of Platform, People Data Labs&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Talk: Using Monorepos to Level-up your Infrastructure as Code and Software Delivery&lt;/em&gt;&lt;br&gt;
Tyler possesses a genuine enthusiasm for technology. At &lt;a href="https://www.peopledatalabs.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;People Data Labs&lt;/a&gt;, he has designed petabyte-scale data pipelines and high-performance APIs with demanding availability requirements, which informed his approach to leading the development of the next generation of the startup&amp;rsquo;s development pipelines and environments.&lt;/p&gt;
&lt;p&gt;Tyler is passionate about finding simple solutions to cross-cutting concerns such as security, observability, and development velocity.&lt;/p&gt;
&lt;h3 id="sefi-genis---co-founder--cto-firefly"&gt;Sefi Genis - Co-Founder &amp;amp; CTO, Firefly&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Talk: Lessons Learned from Writing Thousands of Lines of IaC&lt;/em&gt;&lt;br&gt;
Sefi is the CTO and Co-Founder at &lt;a href="https://www.gofirefly.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Firefly&lt;/a&gt;. He started his career in the 8200 Unit of the Israeli Intelligence Corps and then continued on to security and developer tooling companies.&lt;/p&gt;
&lt;p&gt;Sefi was a founding engineer at Dome9 Security (later acquired by Checkpoint), where he led the Backend Infrastructure of the product post-acquisition. Before founding Firefly, he became Head of Engineering in an Israeli cybersecurity startup company. Today he is building Firefly to help engineers manage the new reality of cloud-native operations.&lt;/p&gt;
&lt;h2 id="panel-discussion---ai-and-the-future-of-cloud-development"&gt;Panel Discussion - AI and the Future of Cloud Development&lt;/h2&gt;
&lt;p&gt;Prepare yourself for the future of cloud development! Gain valuable insights from industry experts in our panel discussion, where we explore the transformative impact of AI on the cloud infrastructure and software engineering industries. The panel discussion will be moderated by CEO Joe Duffy. These are the panelists:&lt;/p&gt;
&lt;h3 id="amanda-silver---cvp-developer-tools-microsoft"&gt;Amanda Silver - CVP Developer Tools, Microsoft&lt;/h3&gt;
&lt;p&gt;Amanda is the CVP of PM for &lt;a href="https://developer.microsoft.com/en-us/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Microsoft&amp;rsquo;s Developer Division&lt;/a&gt;, including the Visual Studio family of products, .NET, TypeScript, and our developer platforms. She has been key to Microsoft&amp;rsquo;s transformation to contribute to open source with the introduction of TypeScript, Visual Studio Code, and the acquisition of both Xamarin and GitHub. She believes that a tight digital feedback loop with zero distance between end-users and engineering teams is a critical element of great product development.&lt;/p&gt;
&lt;h3 id="beyang-liu---co-founder---cto-sourcegraph"&gt;Beyang Liu - Co-Founder &amp;amp; CTO, Sourcegraph&lt;/h3&gt;
&lt;p&gt;Beyang is the CTO and co-founder of Sourcegraph. Prior to Sourcegraph, Beyang was a software engineer at Palantir Technologies, where he developed new data analysis software on a small, customer-facing team working with Fortune 500 companies. Beyang studied Computer Science at Stanford, where he published research in probabilistic graphical models and computer vision at the Stanford AI Lab and thoroughly enjoyed his compilers course.&lt;/p&gt;
&lt;h3 id="luke-hoban---typescript-co-creator-and-cto-pulumi"&gt;Luke Hoban - TypeScript Co-Creator and CTO, Pulumi&lt;/h3&gt;
&lt;p&gt;Luke is CTO at Pulumi. He has worked on developer tools his entire career. He started out on Visual Studio, C#, and .NET in the early 2000s, later joined the ECMAScript standards body as a representative of Microsoft and then became one of the co-founders of the TypeScript programming language.&lt;/p&gt;
&lt;h2 id="featured-partners"&gt;Featured Partners&lt;/h2&gt;
&lt;p&gt;Thank you to our amazing partners for supporting PulumiUP! Visit these booths for tech talks, demos and Q&amp;amp;A about your favorite cloud platforms and developer tools:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aws.amazon.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;AWS&lt;/a&gt; - Solutions Architects will be on hand to demo the latest AWS and Pulumi capabilities and help you get the most from the AWS platform.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Google Cloud&lt;/a&gt; - Customer Engineers will help you accelerate your cloud journey with helpful tips and Q&amp;amp;A.&lt;/li&gt;
&lt;li&gt;&lt;a href="http://azure.microsoft.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Microsoft&lt;/a&gt; - Cloud Advocates will be available to show you how to kickstart your projects on Azure.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.equinix.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Equinix&lt;/a&gt; - Stop by the Equinix booth to learn all about the new Equinix Pulumi provider.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://circleci.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;CircleCI&lt;/a&gt; - Stop by the CircleCI booth to learn best practices for adopting CI/CD in your organization.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://developer.newrelic.com/pulumi/get-started-pulumi/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;New Relic&lt;/a&gt; - The New Relic team will demonstrate how to get started with Observability as Code with Pulumi and New Relic.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.gofirefly.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Firefly&lt;/a&gt; - If you have existing cloud resources you can convert them to Pulumi code easily with Firefly. Stop by the Firefly booth for a demo.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nitric.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Nitric&lt;/a&gt; - The Nitric team will be on site to show you how to create cloud-agnostic infrastructure code from your application code.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://klo.dev/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Klotho&lt;/a&gt; - The Klotho team will show you how devops teams an application teams can easily collaborate to moderize and scale infrastructure without disruptions.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.getport.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Port&lt;/a&gt; - Join the Port team to learn how to setup a self-service portal for your developers.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Want to attend PulumiUP 2023? &lt;a href="https://www.pulumi.com/pulumi-up/"&gt;Register now!&lt;/a&gt;&lt;/p&gt;</description><author>George Huang</author><author>Sara Huddleston</author><author>Isaac Harris</author><category>announcements</category><category>pulumi-events</category></item><item><title>Join a Pulumi User Group (PUG) Meetup!</title><link>https://www.pulumi.com/blog/join-pulumi-user-group-community/</link><pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/join-pulumi-user-group-community/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/join-pulumi-user-group-community/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.fd29ca76b1ea49dbd3f6703cc46ae6138b0ed98cabf8d2c60a23a474880f964d.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Hi everyone,&lt;/p&gt;
&lt;p&gt;After several great years on Meetup, the Pulumi Community is moving to a new home: &lt;a href="https://luma.com/pulumi"&gt;Luma&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This wasn&amp;rsquo;t an easy decision. Together we&amp;rsquo;ve built 38 Pulumi User Groups across 14 countries, with nearly 10,000 members between them. Meetup is where that community took shape, and we&amp;rsquo;re grateful for everything that happened there.&lt;/p&gt;
&lt;p&gt;We want to make it as easy as possible for you to show up. All upcoming events and workshops will be published on Luma going forward.&lt;/p&gt;
&lt;p&gt;Follow us at &lt;a href="https://luma.com/pulumi"&gt;luma.com/pulumi&lt;/a&gt; so you don&amp;rsquo;t miss out.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;We have a global community made up of people from many different countries, but we also have many local communities. We want to enable our users to meet, share knowledge and ideas, answer questions, and learn about Pulumi and best practices. For that reason, we created the &lt;a href="https://luma.com/pulumi"&gt;Pulumi User Groups, aka PUGs&lt;/a&gt; on Meetup.&lt;/p&gt;
&lt;p&gt;Members of PUGs will have access to a global network of experts who can offer help, advice, and support on using Pulumi effectively. The PUGs will also feature regular in-person meetups, webinars, in-person and virtual workshops, and other events to help members stay up-to-date with the latest cloud infrastructure and Pulumi developments.&lt;/p&gt;
&lt;h2 id="23-pulumi-user-groups-pugs-meetups-in-10-countries"&gt;23 Pulumi User Groups (PUGs) Meetups in 10 countries&lt;/h2&gt;
&lt;p&gt;PUGs are led by Pulumi employees and &lt;a href="https://www.pulumi.com/community/puluminaries/"&gt;Puluminaries&lt;/a&gt;, who are passionate community members that are experts in topics related to cloud infrastructure, Pulumi Cloud, cloud-native software development, and much more, and are willing to share their knowledge with the community.&lt;/p&gt;
&lt;h3 id="united-states-pulumi-user-groups"&gt;United States Pulumi User Groups&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Seattle Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;New York Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;San Francisco Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;San Diego Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Austin Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Denver Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Chicago Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Columbus Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Philadelphia Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Boston Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Detroit Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Nashville Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="south-america-pulumi-user-groups"&gt;South America Pulumi User Groups&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;São Paulo Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="european-pulumi-user-groups"&gt;European Pulumi User Groups&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;London Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Oslo Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Berlin Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Munich Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Prague Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="middle-east-pulumi-user-groups"&gt;Middle East Pulumi User Groups&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Tel Aviv Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="asia-pulumi-user-groups"&gt;Asia Pulumi User Groups&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Singapore Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="oceania-pulumi-user-groups"&gt;Oceania Pulumi User Groups&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Australia Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://luma.com/pulumi"&gt;Auckland Pulumi User Group&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-first-pug-in-person"&gt;The First PUG in person&lt;/h2&gt;
&lt;p&gt;Our very first in-person PUG meetup took place in London, UK. The event was well-attended by developers, cloud architects, and other infrastructure enthusiasts. The attendees had the opportunity to network with other like-minded professionals and learn more about Pulumi&amp;rsquo;s tools and features from expert speakers.&lt;/p&gt;
&lt;p&gt;During the meetup, attendees heard from several speakers, including Joe Duffy, Co-Founder &amp;amp; CEO at Pulumi, who was there to speak about Infrastructure as Code that writes itself after the release of &lt;a href="https://www.pulumi.com/blog/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt;, which happened that same day.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://www.pulumi.com/blog/join-pulumi-user-group-community/pulumi-user-group-pug-london-joe-duffy.png" alt="Photo of Pulumi CEO Joe Duffy speaking at a Pulumi User Group (PUG) in London, UK"&gt;&lt;/p&gt;
&lt;p&gt;Other speakers included Liam Hampton, Sr. Regional Cloud Advocate at Microsoft, who spoke about Microsoft Azure and IaC, and Sam Cogan, Director of Solution Architecture at Willis Towers Watson, who spoke about building a library of reusable modules you can repeatedly reuse in your IaC projects.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://www.pulumi.com/blog/join-pulumi-user-group-community/pulumi-user-group-pug-london-sam-cogan.png" alt="Photo of Sam Cogan speaking at a Pulumi User Group (PUG) in London, UK"&gt;&lt;/p&gt;
&lt;p&gt;Overall, the first PUG meetup was a huge success, and attendees left feeling inspired and energized about Pulumi&amp;rsquo;s tools and the community&amp;rsquo;s possibilities. With the launch of PUGs, Pulumi is demonstrating its commitment to building a strong and supportive community of professionals passionate about cloud infrastructure.&lt;/p&gt;
&lt;h2 id="more-pugs-and-events-to-come"&gt;More PUGs and events to come&lt;/h2&gt;
&lt;p&gt;We are planning more in-person PUG events for the months to come. With PUGs, you&amp;rsquo;ll have the opportunity to connect with like-minded professionals, share knowledge and best practices, and stay up-to-date with the latest developments in cloud infrastructure and Pulumi.&lt;/p&gt;
&lt;p&gt;Join the &lt;a href="https://luma.com/pulumi"&gt;Pulumi User Groups&lt;/a&gt; in your local area, or if there isn’t one yet, you are welcome to join the &lt;a href="https://slack.pulumi.com/"&gt;Pulumi Slack community&lt;/a&gt; and meet people from all over the world.&lt;/p&gt;</description><author>Sara Huddleston</author><category>announcements</category><category>community</category><category>pulumi-events</category></item><item><title>International Women's Day: Celebrating our Women in Tech</title><link>https://www.pulumi.com/blog/international-women-day-celebrating-women-in-tech/</link><pubDate>Wed, 08 Mar 2023 13:00:00 -0800</pubDate><guid>https://www.pulumi.com/blog/international-women-day-celebrating-women-in-tech/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/international-women-day-celebrating-women-in-tech/index.png" /&gt;
&lt;p&gt;Today is International Women&amp;rsquo;s Day, and this year the theme is #EmbraceEquity - which means creating an equitable environment. An equitable work environment means understanding that everyone, regardless of gender, religion, ethnicity, background, or resources, brings strength to the workforce and that opportunities should be given to them based on their individual needs.&lt;/p&gt;
&lt;p&gt;For Pulumi, it means a work environment where everyone can share ideas and respect them even when disagreeing. Women&amp;rsquo;s experiences - as well as men&amp;rsquo;s and nonbinary&amp;rsquo;s experiences - inform the direction of digital technology and innovation.&lt;/p&gt;
&lt;p&gt;Being International Women&amp;rsquo;s Day, today we focus on women in tech.&lt;/p&gt;
&lt;h2 id="women-in-tech-stats-awareness"&gt;Women in Tech Stats Awareness&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Women earn an average of 17% (US) to 13% (EU) less than men&lt;/strong&gt;, according to &lt;a href="https://www.gao.gov/products/gao-23-106041"&gt;U.S. Census Bureau&lt;/a&gt; and &lt;a href="https://commission.europa.eu/strategy-and-policy/policies/justice-and-fundamental-rights/gender-equality/equal-pay/gender-pay-gap-situation-eu_en"&gt;European Commission&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;60% of women in tech said a parent or teacher encouraged them&lt;/strong&gt;. &lt;a href="https://www.logitech.com/en-us/mx/women-who-master.html#read-the-report"&gt;Logitech and Girls Who Code&amp;rsquo;s report&lt;/a&gt; on understanding the barriers women face in tech noted the importance of having role models and people encouraging them.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;In small companies, 30.2% of employees are women&lt;/strong&gt;, according to the &lt;a href="https://anitab.org/research-and-impact/top-companies/2020-results/"&gt;report Top Companies for Women Technologists&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;75% of women in tech are asked to handle more administrative tasks&lt;/strong&gt; compared to their male colleagues, according to &lt;a href="https://www.navisite.com/wp-content/uploads/2022/04/Gender-Divide-in-Tech-Infographic.pdf"&gt;Navisite&amp;rsquo;s survey&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Below, you can meet some of Pulumi&amp;rsquo;s tech women - their experience, why they chose tech, and advice to thrive.&lt;/p&gt;
&lt;h2 id="pulumis-women-in-tech"&gt;Pulumi&amp;rsquo;s Women in Tech&lt;/h2&gt;
&lt;h3 id="sarah-hughes-software-engineer"&gt;Sarah Hughes, Software Engineer&lt;/h3&gt;
&lt;p&gt;&amp;ldquo;I was lucky enough to go to high school with a ton of other girls who were into tech, so I took AP Computer Science in a class that was close to a 50/50 split. It really helped to start from scratch on equal footing. (Almost) everyone knew absolutely nothing, and it was obvious that our strengths and weaknesses were completely independent of gender.&amp;rdquo;&lt;/p&gt;
&lt;h3 id="lina-desloge-account-executive"&gt;Lina Desloge, Account Executive&lt;/h3&gt;
&lt;p&gt;&amp;ldquo;I have always enjoyed problem-solving and working with people&amp;hellip;which is what ultimately led me to a technical product. The advice I would give my younger self is don&amp;rsquo;t worry, just start!&amp;rdquo;&lt;/p&gt;
&lt;h3 id="kelsey-dirks-customer-success-manager"&gt;Kelsey Dirks, Customer Success Manager&lt;/h3&gt;
&lt;p&gt;&amp;ldquo;When I entered university, I chose Electrical Engineering as my major. I soon learned coding was not my specialty and switched to Communications, but I loved the people in the classes. It was clear both the professors and students were passionate about their craft. I knew that when I left university, I wanted to work with these types of people, but I had no idea in what capacity. Over the years, my experience led me to be a Customer Success Manager.&lt;/p&gt;
&lt;p&gt;What I would tell my younger self is to not stress about trying to figure everything out right away. Every job will have its ups and downs, but when it comes to a career, trust that it will all work out. The biggest piece of advice I can give to women entering the tech field is don’t be afraid to lean on your female support system. If you aren’t able to advocate for yourself, your sisters in STEM will.&amp;rdquo;&lt;/p&gt;
&lt;h3 id="jonelle-boyd-ux-designer"&gt;Jonelle Boyd, UX Designer&lt;/h3&gt;
&lt;p&gt;&amp;ldquo;If I could give advice to women entering the tech field, I would tell them don’t be afraid of change. Whether that be a role change or a job change, because every new opportunity is a chance to learn and grow. I’ve changed roles as well as worked at a variety of different places during my career and I’ve learned something new in every position. There’s tremendous value in having a wide range of experience, so never be afraid of making that change.&amp;rdquo;&lt;/p&gt;
&lt;h3 id="casey-huang-software-engineer"&gt;Casey Huang, Software Engineer&lt;/h3&gt;
&lt;p&gt;&amp;ldquo;To my younger self - At some point, you’ve heard people sell working in the tech industry by saying the hours are more flexible - you’re not chained to your desk 9 to 5, you can leave early as long as you get your work done. This is somewhat true, but you should know: there is always more work to do. Some of it is important enough to move the business needle. Some of it isn’t as important, but you just care a lot about it. It’ll be up to you to define your boundaries, and it will be up to you to defend them. But it’s okay; if your work environment is truly a good fit for you, they’ll follow your lead and support you. You can’t min/max life like you like to do in video games. What you’re doing is good enough. Don’t be so afraid of making mistakes. If anything, you’ll learn faster that way.&amp;rdquo;&lt;/p&gt;
&lt;h3 id="guinevere-saenger-software-engineer"&gt;Guinevere Saenger, Software Engineer&lt;/h3&gt;
&lt;p&gt;&amp;ldquo;Working in tech provides me with significant financial independence, professional respect, and a flexible work schedule. These are worthwhile for anyone to have, but especially so for women.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re always looking for more amazing talent to &lt;a href="https://www.pulumi.com/community"&gt;join us in our community&lt;/a&gt; and as &lt;a href="https://www.pulumi.com/careers"&gt;part of the Pulumi team&lt;/a&gt;.&lt;/p&gt;</description><author>Sara Huddleston</author><category>pulumi-culture</category><category>community</category></item></channel></rss>