<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Pulumi Blog: Devsecops</title><link>https://www.pulumi.com/blog/tag/devsecops/</link><description>Pulumi blog posts: Devsecops.</description><language>en-us</language><pubDate>Thu, 04 Dec 2025 07:56:40 +0000</pubDate><item><title>Future of the Cloud: 10 Trends Shaping 2026 and Beyond</title><link>https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/</link><pubDate>Thu, 04 Dec 2025 07:56:40 +0000</pubDate><guid>https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/index.png" /&gt;
&lt;p&gt;In 2026, several trends will dominate cloud computing, driving innovation, efficiency, and scalability. From Infrastructure as Code (IaC) to AI/ML, platform engineering to multi-cloud and hybrid strategies, and security practices, let&amp;rsquo;s explore the 10 biggest emerging trends.&lt;/p&gt;
&lt;h2 id="on-this-article"&gt;On This Article&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#1-cloud-will-become-a-business-necessity-by-2028"&gt;1. Cloud Will Become a Business Necessity by 2028&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#2-hyperscalers-accelerate-ai-driven-cloud-expansion"&gt;2. Hyperscalers Accelerate AI-Driven Cloud Expansion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#3-hybrid-and-multi-cloud-to-drive-innovation"&gt;3. Hybrid and Multi-Cloud to Drive Innovation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#4-enterprises-rebuild-their-cloud-foundations-to-operationalize-ai"&gt;4. Enterprises Rebuild Their Cloud Foundations to Operationalize AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#5-iac-drives-scalable-cloud-multi-cloud-and-ai-operations"&gt;5. IaC Drives Scalable Cloud, Multi-Cloud, and AI Operations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#6-devsecops-evolves-into-ai-integrated-security"&gt;6. DevSecOps Evolves Into AI-Integrated Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#7-platform-engineering--internal-developer-platforms-idps"&gt;7. Platform Engineering and Internal Developer Platforms&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#8-aiops-matures-into-a-cloud-operations-standard"&gt;8. AIOps Matures Into a Cloud Operations Standard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#9-kubernetes-dominance-and-increased-complexity"&gt;9. Kubernetes Dominance and Increased Complexity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#10-ai-code-assistants-in-the-enterprise"&gt;10. AI Code Assistants in the Enterprise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#the-future-of-cloud-reinvented-for-an-ai-first-decade"&gt;The Future of Cloud: Reinvented for an AI-First Decade&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="1-cloud-will-become-a-business-necessity-by-2028"&gt;1. Cloud Will Become a Business Necessity by 2028&lt;/h2&gt;
&lt;p&gt;According to &lt;a href="https://www.gartner.com/en/infrastructure-and-it-operations-leaders/topics/cloud-computing"&gt;Gartner&lt;/a&gt;, by 2028 the cloud will be the key driver for business innovation, and estimates that over 95% of new digital workloads will be deployed on cloud-native platforms.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/gartner-cloud-2028.png"
alt="The future of cloud computing. Credit: Gartner" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;The future of cloud computing. Credit: Gartner&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;According to McKinsey &amp;amp; Company&amp;rsquo;s &amp;ldquo;&lt;a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/in-search-of-cloud-value-can-generative-ai-transform-cloud-roi"&gt;In search of cloud value&lt;/a&gt;&amp;rdquo; report:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloud value is driven by innovation&lt;/strong&gt;, worth 5x more than cost savings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EBITDA uplift of 20–30% by 2030&lt;/strong&gt; for high-performing organizations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Asia leads in projected cloud value&lt;/strong&gt;, followed by the US and Europe.&lt;/li&gt;
&lt;li&gt;High-ROI organizations excel by aligning cloud strategy with business priorities, building strong cloud foundations, and using modern operating models.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Teams succeeding in this transition increasingly use Infrastructure as Code, automation, and unified governance frameworks like &lt;a href="https://www.pulumi.com/product/insights-governance/"&gt;Pulumi Insights + Policies&lt;/a&gt; to operationalize this value.&lt;/p&gt;
&lt;h2 id="2-hyperscalers-accelerate-ai-driven-cloud-expansion"&gt;2. Hyperscalers Accelerate AI-Driven Cloud Expansion&lt;/h2&gt;
&lt;p&gt;Hyperscalers are making the largest infrastructure investments in cloud history — nearly all centered on AI workloads, inference, and high-performance compute.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AWS&lt;/strong&gt; has integrated &lt;a href="https://www.aboutamazon.com/news/aws/anthropic-claude-4-opus-sonnet-amazon-bedrock"&gt;Anthropic’s Claude 3 and Claude 4 models into Amazon Bedrock&lt;/a&gt; for enterprise LLM workflows. “Claude Opus 4 and Claude Sonnet 4 are available today in Amazon Bedrock, enabling customers to build agents with stronger reasoning, memory, and tool use.” — AWS, May 2025&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Azure&lt;/strong&gt; revenue rose 33% year-over-year in Q3 (ended March 31), outperforming estimates of ~29.7%. &lt;a href="https://www.reuters.com/business/microsoft-beats-quarterly-revenue-estimates-ai-shift-bolsters-cloud-demand-2025-04-30/"&gt;AI contributed 16 percentage points to this growth&lt;/a&gt;, up from 13 points in the prior quarter. &amp;ldquo;Microsoft is on track to invest approximately $80 billion to build out AI-enabled datacenters to train AI models and deploy AI and cloud-based applications around the world,&amp;rdquo; said Brad Smith, the Microsoft Vice Chair and President.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Google Cloud&lt;/strong&gt; is committing &lt;a href="https://www.utilitydive.com/news/google-cloud-blackstone-aws-us-ai-data-center-buildouts/753202"&gt;$25 billion over two years for data center and AI infrastructure expansion&lt;/a&gt; across the PJM grid, with total capital expenditure for 2025 ranging from $75–85 billion. &amp;ldquo;As our CEO has said, in these early days of a very transformative technology, the risks of under-investing are dramatically higher than the risks of over-investing,&amp;rdquo; said Eunice Huang, Head of AI and Emerging Tech Policy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Oracle&lt;/strong&gt; anticipates 15–20% cloud revenue growth in FY 2026–2027 attributable to AI infrastructure demand, tied to its partnership in the &lt;a href="https://www.pcgamer.com/software/ai/openais-skyrocketing-spending-could-see-billions-of-dollars-in-silicon-headed-down-the-ai-mines-in-the-next-few-years-including-2-million-nvidia-chips-headed-to-texas-stargate-facility/"&gt;Stargate initiative&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As hyperscalers integrate AI deeper into their service layers, engineering teams must adapt with IaC-driven automation, reusable patterns, and policy controls to deploy cloud and AI infrastructure consistently.
See how organizations &lt;a href="https://www.pulumi.com/aws/#video"&gt;deploy AWS infrastructure at the speed of AI with Pulumi&lt;/a&gt; and &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Pulumi Policies&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="3-hybrid-and-multi-cloud-to-drive-innovation"&gt;3. Hybrid and Multi-Cloud to Drive Innovation&lt;/h2&gt;
&lt;p&gt;Hybrid and multi-cloud strategies are now mainstream:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hybrid cloud will grow from &lt;strong&gt;$130B to $310–330B&lt;/strong&gt; by 2030 (&lt;a href="https://www.businesswire.com/news/home/20250513124988/en/Hybrid-Cloud-Market-Analysis-Growth-Trends-and-Forecasts-Report-2024-2025-2030-Surging-Demand-for-Seamless-Interoperability-Between-Cloud-Services-and-Existing-Systems---ResearchAndMarkets.com"&gt;ResearchAndMarkets&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;87% of enterprises&lt;/strong&gt; run workloads across multiple clouds (&lt;a href="https://www.mordorintelligence.com/industry-reports/hybrid-cloud-market"&gt;Mordor Intelligence&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Gartner predicts that &lt;strong&gt;40% of enterprises&lt;/strong&gt; will adopt hybrid compute architectures in mission-critical workflows by 2028 (up from 8%).&lt;/li&gt;
&lt;/ul&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/most-popular-cloud-computing-infrastructure-by-industry.png"
alt="Most popular cloud computing infrastructure by industry. Credit: Cloud Worldwide Service, Forbes" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Credit: Cloud Worldwide Service, Forbes&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;As AI and regulatory requirements grow, organizations must deploy workloads across AWS, Azure, Google Cloud, on-prem, and edge — while maintaining consistent security, compliance, and configuration.&lt;/p&gt;
&lt;p&gt;Modern cloud teams use:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Infrastructure as Code&lt;/strong&gt; for consistent multi-cloud provisioning and environment standardization, forming the backbone of AI infrastructure orchestration&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reusable components and internal platforms&lt;/strong&gt; to define scalable architecture patterns and accelerate delivery across Kubernetes, AI/ML pipelines, and hybrid environments&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Policy-driven guardrails&lt;/strong&gt; to maintain cost, security, and compliance across environments, supporting cloud governance automation and modern cloud cost governance&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pulumi enables all three through its &lt;a href="https://www.pulumi.com/docs/iac/"&gt;multi-cloud IaC model&lt;/a&gt;, &lt;a href="https://www.pulumi.com/product/insights-governance#video"&gt;Pulumi Policies&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/product/internal-developer-platforms/#video"&gt;internal developer platform capabilities&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="4-enterprises-rebuild-their-cloud-foundations-to-operationalize-ai"&gt;4. Enterprises Rebuild Their Cloud Foundations to Operationalize AI&lt;/h2&gt;
&lt;p&gt;While hyperscalers are transforming the global cloud platform, enterprises face a different challenge: adapting their own cloud foundations to support AI at scale. Organizations are moving beyond prototypes and integrating AI into core products, internal workflows, and customer-facing systems, requiring new levels of automation, governance, and AI infrastructure orchestration.&lt;/p&gt;
&lt;p&gt;According to &lt;a href="https://www.networkworld.com/article/4058786/gartner-ai-spending-to-reach-1-5-trillion-dollars-this-year.html"&gt;Gartner&lt;/a&gt;, global AI infrastructure spending is expected to surpass &lt;strong&gt;$2 trillion in 2026&lt;/strong&gt;. &lt;a href="https://blogs.idc.com/2025/10/22/futurescape-2026-moving-into-the-agentic-future/"&gt;IDC predicts that by 2027&lt;/a&gt;, more than 50% of enterprises will use AI agents to drive core workflows, which requires scalable, secure, and automated cloud architectures to support model execution and orchestration.&lt;/p&gt;
&lt;p&gt;To enable this transition, enterprises are investing in:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;GPU provisioning and orchestration&lt;/strong&gt;, data pipelines, vector databases, feature stores, and LLM infrastructure needed for real-time AI workloads.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data pipelines, vector databases, and feature stores&lt;/strong&gt; needed for real-time AI workloads&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Model-serving infrastructure&lt;/strong&gt;, including gateways, inference routers, and autoscaling layers&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Strong identity, secrets, and access controls&lt;/strong&gt; as AI systems increase security exposure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automation through Infrastructure as Code&lt;/strong&gt; to ensure reproducibility and reduce drift&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Policy-driven governance&lt;/strong&gt; to secure cost, compliance, and architectural consistency&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As AI becomes deeply embedded across engineering organizations, teams are increasingly using software engineering approaches such as Infrastructure as Code, reusable components, platform engineering, and policy automation to standardize how AI infrastructure is deployed, scaled, and secured across clouds.&lt;/p&gt;
&lt;p&gt;To support this shift, Pulumi&amp;rsquo;s perspective on &lt;a href="https://www.pulumi.com/product/superintelligence-infrastructure/"&gt;Superintelligence Infrastructure&lt;/a&gt; explains why AI workloads, from pre-training to inference at massive scale, require dynamic infrastructure orchestration rather than static configuration.&lt;/p&gt;
&lt;h3 id="pulumi-users-increasingly-rely-on"&gt;Pulumi users increasingly rely on:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/iac/"&gt;Pulumi IaC&lt;/a&gt; for standardized AI infrastructure&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Pulumi ESC&lt;/a&gt; to manage all secrets and configuration at scale&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/insights-governance/"&gt;Pulumi Insights&lt;/a&gt; for visibility and misconfiguration analysis&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Pulumi Policies&lt;/a&gt; for AI-specific guardrails in code, cost detection, and to provide automated compliance protections&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="5-iac-drives-scalable-cloud-multi-cloud-and-ai-operations"&gt;5. IaC Drives Scalable Cloud, Multi-Cloud, and AI Operations&lt;/h2&gt;
&lt;p&gt;As cloud environments expand and AI workloads demand highly dynamic infrastructure, Infrastructure as Code (IaC) is becoming the foundation for scaling reliably across all environments. Organizations are increasingly adopting IaC in general-purpose languages to unify development and infrastructure workflows, reduce configuration drift, and deliver cloud resources at speed.&lt;/p&gt;
&lt;p&gt;Modern &lt;a href="https://www.pulumi.com/what-is/what-is-infrastructure-as-code/"&gt;Infrastructure as Code&lt;/a&gt; is advancing far beyond simple provisioning:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Standardizing multi-cloud and hybrid patterns&lt;/strong&gt; so teams can deploy consistently across AWS, Azure, Google Cloud, on-prem, and edge environments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Integrating seamlessly with cloud providers and third-party services&lt;/strong&gt;, including data platforms and messaging systems like CockroachDB, Confluent Cloud, and Kafka.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Providing deeper validation and type-safety&lt;/strong&gt;, ensuring parameters, dependencies, and security controls are correct before deployment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Improving cloud resource efficiency and visibility&lt;/strong&gt; with tools like &lt;a href="https://www.pulumi.com/docs/insights/discovery/"&gt;Pulumi Insights Discovery&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Embedding security and compliance through &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policy as Code&lt;/a&gt;&lt;/strong&gt;, enforcing guardrails, cost controls, and regulatory requirements automatically, enabling truly policy-driven cloud management.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enabling intelligent automation&lt;/strong&gt;, from unit and integration tests to auto-remediation policies and policy-driven approvals.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Incorporating AI-driven optimization and insights&lt;/strong&gt;, helping teams detect misconfigurations, analyze usage patterns, and generate infrastructure updates with tools like &lt;a href="https://www.pulumi.com/product/neo/"&gt;Pulumi Neo&lt;/a&gt; and &lt;a href="https://www.pulumi.com/blog/policy-next-gen/"&gt;Pulumi Policies&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As organizations scale both traditional cloud workloads and AI-driven systems, IaC has become critical for achieving secure, repeatable, and high-velocity operations across every environment.&lt;/p&gt;
&lt;h2 id="6-devsecops-evolves-into-ai-integrated-security"&gt;6. DevSecOps Evolves Into AI-Integrated Security&lt;/h2&gt;
&lt;p&gt;As AI becomes embedded across cloud-native systems, DevSecOps is entering a new era. Gartner predicts that by &lt;strong&gt;2028, over 50% of enterprises will use AI security platforms&lt;/strong&gt; to protect their AI investments. Below are the 3 key predictions for the future of DevSecOps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;AI-driven security automation&lt;/strong&gt;: Teams will increasingly rely on AI to detect threats, enforce policies, and generate secure infrastructure patches. See Pulumi’s capabilities in &lt;a href="https://www.pulumi.com/product/insights-governance/#video"&gt;AI-powered remediation&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;More focus on secrets management&lt;/strong&gt;: With AI systems accessing more sensitive data, secure secret storage will be essential. &lt;a href="https://www.pulumi.com/product/secrets-management/"&gt;Pulumi ESC&lt;/a&gt; helps teams centralize and govern credentials, keys, and tokens safely.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Greater cross-team collaboration&lt;/strong&gt;: Dev, Sec, and Ops workflows will converge under shared frameworks: IaC, policy automation, runtime scanning, and GitOps.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;As organizations increase their use of AI across cloud-native systems, the need for tightly aligned security, governance, and cloud governance automation becomes even more urgent. At the Gartner Data &amp;amp; Analytics Summit in Sydney, Carlie Idoine, VP Analyst at Gartner, emphasized this growing dependency:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;[AI]&amp;hellip; it doesn’t deliver value on its own – AI needs to be tightly aligned with data, analytics, and governance to enable intelligent, adaptive decisions and actions across the organization.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This perspective mirrors what we’re seeing across modern DevSecOps practices: AI can amplify security, but only when paired with strong foundations in secrets management, governance, and cross-team collaboration.&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Build for an AI-first cloud&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Pulumi gives teams infrastructure as code, reusable components, and policy guardrails to deliver consistently across every cloud and AI workload.&lt;/div&gt;
&lt;a href="https://app.pulumi.com/signup" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Get started
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="7-platform-engineering--internal-developer-platforms-idps"&gt;7. Platform Engineering &amp;amp; Internal Developer Platforms (IDPs)&lt;/h2&gt;
&lt;p&gt;According to &lt;a href="https://www.gartner.com/en/articles/what-is-platform-engineering"&gt;Gartner&lt;/a&gt;, &lt;strong&gt;by 2026, 80% of large software engineering organizations will establish platform engineering teams&lt;/strong&gt; as internal providers of reusable services, components, and tools for application delivery. Platform engineering will ultimately solve the central problem of cooperation between software developers and operators.&lt;/p&gt;
&lt;p&gt;Mid-size to large companies will begin or continue to invest in implementing &lt;a href="https://www.pulumi.com/blog/platform-engineering-pillars-3/"&gt;platform engineering practices&lt;/a&gt;, with large tech companies as first adopters. They will provide &lt;a href="https://www.pulumi.com/blog/announcing-pulumi-idp/"&gt;Internal Developer Platforms (IDP)&lt;/a&gt; to elevate the &lt;a href="https://www.pulumi.com/blog/developer-experience-business-critical/"&gt;Developer Experience&lt;/a&gt; (DX, sometimes referred to as DE or DevEx), helping them work faster, like abstracting the complexities of configuring, testing, and validation, deploying infrastructure, and scanning their code for security.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/developer-portal-platform-teams/platform-teams.png"
alt="Internal developer platform-in-a-box. Credit: Pulumi" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Internal developer platform-in-a-box. Credit: Pulumi&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;IDPs are reshaping how developers interact with cloud infrastructure, bringing together platform engineering, automation, and emerging AI platform engineering practices.&lt;/p&gt;
&lt;h2 id="8-aiops-matures-into-a-cloud-operations-standard"&gt;8. AIOps Matures into a Cloud Operations Standard&lt;/h2&gt;
&lt;p&gt;AIOps is becoming mainstream, helping teams predict failures, auto-scale infrastructure, and resolve incidents with minimal manual effort. As AI and automation continue to evolve, the fusion of these technologies will enable organizations to achieve unprecedented levels of efficiency and scalability.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Proactive Operations&lt;/strong&gt;: AI-powered tools will assist teams in foreseeing issues with greater accuracy, minimizing downtime, and reducing the firefighting nature of incident management. These tools will automatically detect anomalies, optimize performance, and trigger remediation actions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/automation-api/"&gt;Intelligent Automation&lt;/a&gt;&lt;/strong&gt;: Routine operational tasks like patching, monitoring, and resource scaling will be fully automated. AI-driven decision-making will allow for smarter resource allocation and optimization, dynamically adjusting infrastructure and workloads in response to real-time demands and predictions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/insights/"&gt;Data-Driven Insights&lt;/a&gt;&lt;/strong&gt;: AIOps will analyze vast amounts of operational data and provide actionable insights, enabling teams to focus on high-impact tasks such as improving system architecture and user experience. The AI-powered insights will also inform better strategic decisions, helping teams to continuously evolve their DevOps practices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Collaboration Across Teams&lt;/strong&gt;: AIOps will bridge the gap between DevOps, SecOps, and IT operations by bridging monitoring and automation. Cross-team collaboration will improve as AI systems consolidate and interpret data from various departments, allowing for a more cohesive approach to system management.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;AIOps features include observability, automation, and real-time analytics to bridge DevOps, SRE, and IT operations.&lt;/p&gt;
&lt;h2 id="9-kubernetes-dominance-and-increased-complexity"&gt;9. Kubernetes Dominance and Increased Complexity&lt;/h2&gt;
&lt;p&gt;Kubernetes will continue its ascent in 2026. According to &lt;a href="https://www.researchandmarkets.com/reports/6110428/kubernetes-global-strategic-business-report"&gt;Research &amp;amp; Markets&lt;/a&gt;, the global Kubernetes market was valued at USD 2.3 billion in 2024 and is projected to reach USD 8.2 billion by 2030, with a CAGR of 23.8% over the forecast period.&lt;/p&gt;
&lt;p&gt;The CNCF Annual Survey shows AI/ML workloads rapidly moving onto Kubernetes — including batch pipelines, model experimentation, real-time inference, and data preprocessing — even as only 41% of ML/AI developers are cloud-native today. This shift is accelerating as teams need flexible GPU scheduling, distributed pipelines, and portable execution environments.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/beyond-yaml-kubernetes-2026-automation-era/#the-2026-convergence-of-ai-platforms-and-policy-in-kubernetes"&gt;Kubernetes is also evolving in response to AI demands&lt;/a&gt;. Inference workloads, powered by LLMs and GPUs, now require low-latency execution closer to the user. This shift is pushing organizations to build intelligent orchestration layers that schedule AI pipelines across edge and core clusters, often leveraging Kubernetes as the common control plane for AI cluster orchestration.&lt;/p&gt;
&lt;p&gt;As we move into 2026, three patterns are becoming clear:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Kubernetes is evolving to support AI&lt;/strong&gt; through GPU-aware scheduling, Kubernetes GPU scheduling optimizations, and more advanced workload orchestration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Governance and consistency matter more than ever&lt;/strong&gt;, as teams struggle to secure and manage multi-cluster, multi-cloud environments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Platform engineering is essential&lt;/strong&gt;, providing curated patterns and automation rather than raw YAML to reduce cognitive load.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Kubernetes will remain a strategic foundation — but operating it effectively now depends on robust automation, strong security controls, and standardized delivery models that scale across clouds, clusters, and AI pipelines.&lt;/p&gt;
&lt;h2 id="10-ai-code-assistants-in-the-enterprise"&gt;10. AI Code Assistants in the Enterprise&lt;/h2&gt;
&lt;p&gt;AI-powered coding assistants like GitHub Copilot, Claude Code, Cursor, and others are rapidly becoming part of modern software development.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;By 2027, the use of AI assistants will dramatically increase developer velocity&lt;/strong&gt; to meet functional business requirements for 70% of new digital solutions in production (source: &lt;a href="https://www.digitalnewsasia.com/business/idc-reveals-its-top-predictions-cloud-2023-and-beyond"&gt;IDC&lt;/a&gt;).&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/ai_code_assistants_value.png"
alt="The value of AI code assistants. Credit: Gartner" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;The value of AI code assistants. Credit: Gartner&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;According to &lt;a href="https://www.gartner.com/en/newsroom/press-releases/2024-04-11-gartner-says-75-percent-of-enterprise-software-engineers-will-use-ai-code-assistants-by-2028"&gt;Gartner&lt;/a&gt;, &lt;strong&gt;by 2028, 75% of enterprise software engineers will use dedicated AI code assistants&lt;/strong&gt;, and 63% of organizations are currently piloting, deploying or beginning to use AI code assistants.&lt;/p&gt;
&lt;p&gt;As enterprise adoption of AI assistants increases, expectations are rising: they must not only generate code but also understand the state of infrastructure, configurations, and security posture. That means being able to answer questions about environments, surface misconfigurations, or act directly on infrastructure.&lt;/p&gt;
&lt;p&gt;One of the newest developments is the release of &lt;a href="https://www.pulumi.com/blog/pulumi-agent-skills/"&gt;Pulumi Agent Skills&lt;/a&gt;, a collection of infrastructure expertise packaged for use in AI coding assistants. These skills teach tools such as Claude Code, Cursor, or Gemini CLI to reason about Pulumi projects, reducing hallucination and improving outputs based on real infrastructure conventions and practices.&lt;/p&gt;
&lt;p&gt;Combined with infrastructure access via tools like &lt;a href="https://www.pulumi.com/blog/remote-mcp-server/"&gt;Pulumi’s Remote MCP Server&lt;/a&gt;, teams can build secure, AI-driven workflows where assistants provide insights and Pulumi Neo safely executes actions with previews, policies, and orchestration.&lt;/p&gt;
&lt;p&gt;AI code assistants are no longer experimental; they&amp;rsquo;re fast becoming a competitive advantage in cloud software development.&lt;/p&gt;
&lt;h2 id="the-future-of-cloud-reinvented-for-an-ai-first-decade"&gt;The Future of Cloud: Reinvented for an AI-First Decade&lt;/h2&gt;
&lt;p&gt;Cloud infrastructure is entering its most transformative era since the rise of Kubernetes. The trends shaping 2026 reveal a clear pattern: AI is no longer a workload — it’s becoming the organizing principle of cloud strategy.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI-native cloud architectures&lt;/strong&gt; that require elastic compute, GPU orchestration, fast data access, and governance built into every layer&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Infrastructure as Code as the operational backbone&lt;/strong&gt;, standardizing deployments across AI, cloud, and hybrid environments&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Platform engineering and IDPs&lt;/strong&gt; to enable self-service, gold-standard patterns, and automated guardrails&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security integrated into every pipeline&lt;/strong&gt;, with AI-assisted threat detection, strong secrets management, and policy-driven compliance&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AIOps and intelligent automation&lt;/strong&gt; are becoming standard for scaling modern cloud systems&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Kubernetes evolving for AI&lt;/strong&gt;, driving new orchestration patterns across edge, core, and inference clusters&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Multi-cloud and hybrid ecosystems&lt;/strong&gt; accelerating to support interoperability, resilience, and global workload placement&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Taken together, these shifts point to a new model of cloud operations that is intelligent, automated, policy-aware, and built on software engineering principles rather than manual configuration.&lt;/p&gt;
&lt;p&gt;Organizations that invest now in &lt;strong&gt;modern IaC&lt;/strong&gt;, &lt;strong&gt;unified governance&lt;/strong&gt;, &lt;strong&gt;reusable components&lt;/strong&gt;, and &lt;strong&gt;policy frameworks&lt;/strong&gt; — all core capabilities of the Pulumi Cloud platform — will be positioned to lead in an AI-first world. The gap between teams that modernize and those that do not will widen rapidly in 2026 and beyond.&lt;/p&gt;
&lt;a
href="https://www.pulumi.com/docs/get-started/"
class="btn btn-primary"
&gt;
Try Pulumi for Free
&lt;/a&gt;</description><author>Sara Huddleston</author><category>ai</category><category>cloud-native</category><category>infrastructure-as-code</category><category>cloud-computing</category><category>multi-cloud</category><category>platform-engineering</category><category>devops</category><category>devsecops</category><category>security</category><category>kubernetes</category></item><item><title>Integrating DevOps and Security in Platform Engineering</title><link>https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/</link><pubDate>Wed, 11 Dec 2024 07:41:06 +0000</pubDate><guid>https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/integrating-devops-and-security-for-scalable-platform-engineering/index.png" /&gt;
&lt;p&gt;Platform engineering has become essential for mid-to-large organizations, moving beyond a DevOps trend. Gartner predicts that by 2026, 80% of software companies will have internal platform services to streamline development. The goal is to empower developers with self-service tools while maintaining security, compliance, and reliability through DevSecOps practices.&lt;/p&gt;
&lt;p&gt;At PulumiUP Europe 2024, experts shared insights on aligning DevOps with security to build scalable, secure platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Jess Mink, Sr. Director of Platform Engineering at Honeycomb&lt;/li&gt;
&lt;li&gt;Kief Morris, Global Head of Infrastructure Engineering at ThoughtWorks&lt;/li&gt;
&lt;li&gt;Lindsay Jack, VP of Engineering &amp;amp; Security at Snyk&lt;/li&gt;
&lt;li&gt;Nariman Aga-Tagiyev, Application Security Architect at WiseFrog Security&lt;/li&gt;
&lt;li&gt;Komal Ali, Engineering Manager at Pulumi&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The panel discussed key strategies, challenges, and pillars of successful platform engineering.&lt;/p&gt;
&lt;h2 id="in-this-article"&gt;In this article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#the-core-pillars-of-platform-engineering"&gt;The Core Pillars of Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#aligning-devops-and-security-for-secure-platform-engineering"&gt;Aligning DevOps and Security for Secure Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#shift-left-security"&gt;Shift Left Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#embrace-automation-and-standardization"&gt;Embrace Automation and Standardization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#prioritize-observability-and-monitoring"&gt;Prioritize Observability and Monitoring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#foster-a-culture-of-collaboration"&gt;Foster a Culture of Collaboration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#challenges-of-integrating-security-in-platform-engineering"&gt;Challenges of Integrating Security in Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#balancing-autonomy-and-control"&gt;Balancing Autonomy and Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#driving-adoption-and-changing-mindsets"&gt;Driving Adoption and Changing Mindsets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#adapting-to-evolving-needs-and-technologies"&gt;Adapting to Evolving Needs and Technologies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#measuring-success-in-secure-platform-engineering"&gt;Measuring Success in Secure Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/integrating-devops-and-security-for-scalable-platform-engineering/#the-future-of-secure-platform-engineering"&gt;The Future of Secure Platform Engineering&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-core-pillars-of-platform-engineering"&gt;The Core Pillars of Platform Engineering&lt;/h2&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/WUpyqn1Jfwg?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices/"&gt;Platform engineering teams&lt;/a&gt; comprise multiple professionals with many responsibilities and focus areas. According to our panel of experts, the core pillars of platform engineering include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/"&gt;Developer Experience (DevEx)&lt;/a&gt;&lt;/strong&gt;: Provide developers with the tools, frameworks, and abstractions they need to be productive and proactive without getting stuck in infrastructure or operational concerns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#an-effective-internal-developer-platform"&gt;Reliability and Scalability&lt;/a&gt;&lt;/strong&gt;: Ensure that the platform and infrastructure can support the organization&amp;rsquo;s needs, with the ability to scale up or down as required.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/"&gt;Security and Compliance&lt;/a&gt;&lt;/strong&gt;: Embed robust, accessible security and compliance frameworks into the development lifecycle while making it easy for developers to adhere to these policies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/automation-api/"&gt;Automation and Tooling&lt;/a&gt;&lt;/strong&gt;: Leverage &lt;a href="https://www.pulumi.com/product/infrastructure-as-code/"&gt;Infrastructure as Code (IaC)&lt;/a&gt; and automation to enforce standardized processes and consistency and reduce cognitive load and manual effort.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Observability and Monitoring&lt;/a&gt;&lt;/strong&gt;: Provide visibility into the platform&amp;rsquo;s health and performance, delivering actionable insights that allow teams to identify and resolve issues quickly.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These pillars work together to create a platform that empowers developers to innovate and deliver value to the organization and customers while maintaining the necessary controls and safeguards.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Jess Mink, Director of Platform Engineering at &lt;a href="https://www.pulumi.com/blog/observability-with-infrastructure-as-code/"&gt;Honeycomb&lt;/a&gt;, explains:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;The goal of platform engineering is to help the company run smoother and faster and unlock things people didn&amp;rsquo;t know were possible [&amp;hellip;] We tend to focus on tools and software, but it&amp;rsquo;s really about people, processes, and tools. If you consider this, platforms are responsible for social and technical support across the organization. A common pitfall is building tools no one uses because you didn’t meet people where they are.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="aligning-devops-and-security-for-secure-platform-engineering"&gt;Aligning DevOps and Security for Secure Platform Engineering&lt;/h2&gt;
&lt;p&gt;Integrating security into platform engineering ensures it becomes a proactive part of the development lifecycle and ensures that &amp;ldquo;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/"&gt;DevSecOps&lt;/a&gt;&amp;rdquo; is not an afterthought but a core consideration.&lt;/p&gt;
&lt;p&gt;Key best practices shared by the panel include:&lt;/p&gt;
&lt;h3 id="shift-left-security"&gt;Shift Left Security&lt;/h3&gt;
&lt;p&gt;One of the fundamental principles of DevSecOps is to &amp;ldquo;shift left&amp;rdquo; - that is, to integrate security earlier in the development process rather than waiting until the end. This can involve activities such as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Incorporating security requirements and threat modeling into the initial design phase&lt;/li&gt;
&lt;li&gt;Automating security scans and tests as part of the continuous integration (CI) pipeline&lt;/li&gt;
&lt;li&gt;Providing developers with secure coding guidelines and tools to &lt;a href="https://www.pulumi.com/blog/drift-detection/#why-pulumi-cloud-drift-detection-and-remediation"&gt;identify and remediate vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By addressing security concerns upfront, organizations can reduce the time and cost of remediating issues later in the development lifecycle.&lt;/p&gt;
&lt;h3 id="embrace-automation-and-standardization"&gt;Embrace Automation and Standardization&lt;/h3&gt;
&lt;p&gt;Consistency is key. Platform engineering teams should leverage automation and built-in safeguards and security processes. This may include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automating the provisioning of secure infrastructure and application environments&lt;/li&gt;
&lt;li&gt;Implementing Infrastructure as Code (IaC) to define and &lt;a href="https://www.pulumi.com/blog/pulumi-is-imperative-declarative-imperative/"&gt;manage infrastructure in a declarative&lt;/a&gt;, version-controlled manner&lt;/li&gt;
&lt;li&gt;Standardizing security controls, policies, and configurations across the platform&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By automating these tasks, platform engineering teams can reduce the risk of human error, improve visibility and auditability, and free up developers to focus on building features rather than managing infrastructure.&lt;/p&gt;
&lt;h3 id="prioritize-observability-and-monitoring"&gt;Prioritize Observability and Monitoring&lt;/h3&gt;
&lt;p&gt;Effective security requires visibility into the health and performance of the platform. Platform engineering teams should invest in robust observability and monitoring solutions to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/drift-detection/"&gt;Detect and respond&lt;/a&gt; to security incidents and anomalies in real-time&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Gain insights&lt;/a&gt; into the behavior and usage patterns of the platform&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/#policy-enforcement-ensuring-compliance-and-security"&gt;Identify and address&lt;/a&gt; vulnerabilities or misconfigurations proactively&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By integrating security-focused monitoring and alerting into the platform, organizations can quickly identify and mitigate threats while also providing developers with the necessary context to understand and address security-related issues.&lt;/p&gt;
&lt;h3 id="foster-a-culture-of-collaboration"&gt;Foster a Culture of Collaboration&lt;/h3&gt;
&lt;p&gt;Platform engineering is often referred to as being the practical application of DevOps practices. Integrating security practices often requires a cultural shift towards collaboration and shared responsibility between all teams in development, operations, and security, thus the name DevSecOps. Platform engineering teams can facilitate this by:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Treating &lt;a href="https://www.pulumi.com/blog/platform-engineering-cncf-maturity-model/#platforms-as-products-driving-success"&gt;Platforms as Products&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Involving security stakeholders in the design and planning of platform initiatives&lt;/li&gt;
&lt;li&gt;Providing security training and education to developers to empower them to make informed decisions&lt;/li&gt;
&lt;li&gt;Establishing communication channels and feedback loops between teams&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Kief Morris, Global Head of Infrastructure Engineering at &lt;a href="https://www.thoughtworks.com/en-us"&gt;ThoughtWorks&lt;/a&gt;, explains:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;There is a new way of thinking that is trying to avoid that &amp;ldquo;build it, and they will come mentality,&amp;rdquo; which leads to building it and nobody using it. One of the trends we are seeing is product thinking [&amp;hellip;]—using techniques like creating user personas of different types of users in the organization, conducting research to understand their needs, and talking with them.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Breaking silos and fostering communication helps organizations build secure, scalable platforms that support the needs of developers, platform engineers, architects, and security teams.&lt;/p&gt;
&lt;h2 id="challenges-of-integrating-security-in-platform-engineering"&gt;Challenges of Integrating Security in Platform Engineering&lt;/h2&gt;
&lt;p&gt;While the benefits of integrating DevOps and security in platform engineering are clear, the journey has expected challenges. Our panel of experts highlighted several key obstacles that organizations may face:&lt;/p&gt;
&lt;h3 id="balancing-autonomy-and-control"&gt;Balancing Autonomy and Control&lt;/h3&gt;
&lt;p&gt;The primary goal is to empower developers to be more productive and proactive. However, this autonomy needs to be balanced with necessary security controls and governance measures.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Jess Mink points out the importance of achieving harmony between developer autonomy and operational control, stating:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;It&amp;rsquo;s a delicate balance - you want to make things easy for developers, but you also need to maintain the right level of control and security. It&amp;rsquo;s about finding the right abstractions and interfaces that give developers the freedom they need while still ensuring the platform remains secure and compliant.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="driving-adoption-and-changing-mindsets"&gt;Driving Adoption and Changing Mindsets&lt;/h3&gt;
&lt;p&gt;Integrating security into the platform engineering workflow can often be met with resistance from developers accustomed to moving quickly and may view security as an obstacle to their productivity.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Nariman, a Software Security Architect, notes:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;The challenge is not just about the tools or the technology - it&amp;rsquo;s about changing the mindset and getting people to understand the importance of security. You need to find ways to motivate developers and make them feel like they&amp;rsquo;re part of the solution rather than just imposing more rules and processes.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Effective communication, education, and a focus on the business value of security are key to driving adoption and fostering a culture of shared responsibility.&lt;/p&gt;
&lt;h3 id="adapting-to-evolving-needs-and-technologies"&gt;Adapting to Evolving Needs and Technologies&lt;/h3&gt;
&lt;p&gt;As organizations grow and their technology stacks evolve, the demands on the platform engineering team can shift rapidly. Keeping up with these changes, while maintaining a secure and reliable platform, can be a significant challenge.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;Lindsay Jack, VP of Engineering for the Platform Division at &lt;a href="https://partners.snyk.io/English/solutions/solution/2908/pulumi"&gt;Snyk&lt;/a&gt;, explains:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;You might have a platform team that&amp;rsquo;s really good at a certain set of technologies, but then the organization starts moving in a new direction, and suddenly those skills don&amp;rsquo;t match up anymore. It&amp;rsquo;s about being agile and adaptable and making sure you have the right mix of skills and expertise to support the organization&amp;rsquo;s evolving needs&lt;/em&gt;.&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Fostering internal mobility, continuous learning, and a flexible, modular platform architecture can help platform engineering teams navigate these changes more effectively.&lt;/p&gt;
&lt;h2 id="measuring-success-in-secure-platform-engineering"&gt;Measuring Success in Secure Platform Engineering&lt;/h2&gt;
&lt;p&gt;Measuring the success of a platform engineering initiative can be complex as it involves balancing a range of technical, operational, and business-oriented metrics but also considers human factors. According to our panel, some key metrics to include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Developer Experience&lt;/strong&gt;: Metrics such as developer satisfaction surveys, time-to-onboard new developers, and the number of self-service platform capabilities can provide insights into the effectiveness of the platform in supporting developer productivity and autonomy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reliability and Scalability&lt;/strong&gt;: Monitoring service-level objectives (SLOs), incident response times, and the ability to handle increased traffic or user demands can help assess the platform&amp;rsquo;s reliability and scalability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security and Compliance&lt;/strong&gt;: Tracking the number of security incidents, the ratio of security issues found during threat modeling versus post-deployment, and the adoption of security best practices can indicate the platform&amp;rsquo;s security posture.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automation and Tooling&lt;/strong&gt;: Metrics like the percentage of infrastructure provisioned through code, the frequency of platform updates, and the time saved through automation can demonstrate the platform&amp;rsquo;s operational efficiency.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Observability and Monitoring&lt;/strong&gt;: Measuring the effectiveness of observability tools, the time to detect and resolve issues, and the quality of incident reports can &lt;a href="https://www.pulumi.com/blog/insights-cloud-account-discovery/"&gt;provide insights into the platform&amp;rsquo;s overall health&lt;/a&gt; and performance.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;p&gt;As Jess Mink emphasizes, it&amp;rsquo;s important not just to collect these metrics but to use them to drive meaningful action and improvement:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;em&gt;We look at all of those [metric categories] every quarter and write summaries that go up to the executive level. This creates visibility and a shared understanding of problems so that there&amp;rsquo;s room for movement and change in the right ways.&lt;/em&gt;&amp;rdquo;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="the-future-of-secure-platform-engineering"&gt;The Future of Secure Platform Engineering&lt;/h2&gt;
&lt;p&gt;Software development and infrastructure management are evolving, and the role of platform engineering will only become more critical to support it. By integrating DevOps and security practices, platform engineering teams can create scalable, secure platforms that empower developers to be more productive and innovate, delivering business value.&lt;/p&gt;
&lt;p&gt;Learn how Pulumi customers build secure, scalable platforms and empower their development teams:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tivity Health&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/"&gt;DevSecOps Game-Changer: Security Automation That Delivers Business Results&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;BMW Group&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/"&gt;Unified and Programmatic Approach to Infrastructure Management at BMW Using Pulumi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Lemonade&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/case-studies/lemonade/"&gt;How the DevOps team supports a much larger group of developers&lt;/a&gt; using by Pulumi to standardize infrastructure components and enforce best practices.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Discover platform engineering best practices in &lt;a href="https://www.pulumi.com/blog/the-guide-platform-engineering-idp-steps-best-practices/"&gt;The Guide to Platform Engineering: 7 Steps to Get It Right&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Build secure, scalable platforms with confidence—get started with the &lt;a href="https://info.pulumi.com/platform-engineering-workshop-series"&gt;Platform Engineering Workshop Series &amp;amp; Course&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;</description><author>Sara Huddleston</author><category>devsecops</category><category>platform-engineering</category><category>developer-experience</category><category>devops</category><category>security</category></item><item><title>DevSecOps Game-Changer: Security Automation That Delivers Business Results</title><link>https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/</link><pubDate>Thu, 21 Nov 2024 07:16:30 +0000</pubDate><guid>https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/devsecops-strategy-security-automation-tivity-health/index.png" /&gt;
&lt;p&gt;Organizations are under constant pressure to deliver new products and features faster than ever. But speed alone isn’t enough—businesses must also navigate the complex challenges of ensuring security and managing infrastructure costs effectively.&lt;/p&gt;
&lt;p&gt;Enter DevSecOps - the strategic integration of security practices into the DevOps workflow. By automating security processes, organizations can achieve improved speed, scalability, and business impact, all while ensuring security remains a priority.&lt;/p&gt;
&lt;p&gt;Tivity Health, a leading health and fitness solutions provider, has embraced this DevSecOps approach using Pulumi, a modern infrastructure as code (IaC) platform. During PulumiUP 2024, David Giambruno, Tivity Health&amp;rsquo;s VP of Engineering and DevOps, shared how, by leveraging Pulumi, he led the transformation that continuously drives remarkable results in speed, cost savings, and security.&lt;/p&gt;
&lt;h2 id="on-this-article"&gt;On this article:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#the-beginning-from-data-center-to-the-cloud"&gt;The Beginning: From Data Center to the Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#embracing-pulumi-the-power-of-automation-productivity-and-security"&gt;Embracing Pulumi: The Power of Automation, Productivity, and Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#driving-business-impact-through-security-automation"&gt;Driving Business Impact Through Security Automation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#fostering-devops-culture-through-cross-functional-collaboration"&gt;Fostering DevOps Culture Through Cross-Functional Collaboration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#lessons-learned-navigating-the-cultural-shift"&gt;Lessons Learned: Navigating the Cultural Shift&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/devsecops-strategy-security-automation-tivity-health/#the-future-of-devsecops-and-pulumi-at-tivity-health"&gt;The Future of DevSecOps and Pulumi at Tivity Health&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-beginning-from-data-center-to-the-cloud"&gt;The Beginning: From Data Center to the Cloud&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.tivityhealth.com/"&gt;Tivity Health&lt;/a&gt;&amp;rsquo;s journey began with a strategic decision to transition from a traditional data center environment to a cloud-native architecture. Rather than opting for a &amp;ldquo;lift and shift&amp;rdquo; approach, they made the bold choice to go directly to a cloud-native model, embracing the principles of DevSecOps along the way.&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/35vAiKdDux4?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;p&gt;The need to &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/"&gt;automate infrastructure deployment&lt;/a&gt; and management was fundamental. Giambruno explained, &amp;ldquo;&lt;em&gt;If you can&amp;rsquo;t automate it, we don&amp;rsquo;t need it.&lt;/em&gt;&amp;rdquo; This philosophy drove the team to seek out a solution that would not only streamline their operations but also empower their developers to focus on building innovative products for their customers.&lt;/p&gt;
&lt;h2 id="embracing-pulumi-the-power-of-automation-productivity-and-security"&gt;Embracing Pulumi: The Power of Automation, Productivity, and Security&lt;/h2&gt;
&lt;p&gt;Tivity Health&amp;rsquo;s search for the right tool led them to Pulumi, a unified platform for all the infrastructure needs that allows teams to use general programming languages, such as TypeScript, Python, Java, and Go, to define and manage their cloud infrastructure. Giambruno and his team immediately recognized Pulumi&amp;rsquo;s ability to deliver on their key requirements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Automation&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/docs/iac/"&gt;Pulumi&amp;rsquo;s infrastructure as code (IaC)&lt;/a&gt; approach enabled Tivity Health to automate the deployment and management of its cloud environments, reducing the time and effort required for these tasks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Productivity&lt;/strong&gt;: using Pulumi&amp;rsquo;s general-purpose programming languages allowed developers to define, deploy, and manage infrastructure within their existing tools.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security&lt;/strong&gt;: Pulumi&amp;rsquo;s security features allowed Tivity Health to integrate &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/"&gt;security practices&lt;/a&gt; into its infrastructure deployment processes, reducing the risk of security breaches and ensuring compliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cost Optimization&lt;/strong&gt;: Pulumi&amp;rsquo;s ability to automate the spin-up and teardown of cloud environments on demand has led to significant cost reductions for Tivity Health.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Giambruno describes Pulumi as a &amp;ldquo;three-dimensional&amp;rdquo; tool, offering a versatile set of capabilities that have been instrumental in transforming Tivity Health&amp;rsquo;s operations. &amp;ldquo;&lt;em&gt;The ability to use those dimensions in lots of different ways to do the automation is what really makes a difference to the teams&lt;/em&gt;,&amp;rdquo; he says.&lt;/p&gt;
&lt;h2 id="driving-business-impact-through-security-automation"&gt;Driving Business Impact Through Security Automation&lt;/h2&gt;
&lt;p&gt;By adopting Pulumi and DevSecOps automation, Tivity Health realized significant business benefits:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Speed and Agility&lt;/strong&gt;: By automating its infrastructure deployment and management processes, Tivity Health has dramatically &lt;a href="https://www.pulumi.com/case-studies/unity/"&gt;reduced the time&lt;/a&gt; required to spin up new environments or change existing ones. &amp;ldquo;&lt;em&gt;We run it through automation and boom, it&amp;rsquo;s out, it&amp;rsquo;s done&lt;/em&gt;,&amp;rdquo; Giambruno says. This newfound speed and agility have empowered Tivity Health&amp;rsquo;s developers to focus on building products and features rather than getting bogged down in infrastructure-related tasks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cost Optimization&lt;/strong&gt;: Tivity Health&amp;rsquo;s cloud-native approach and Pulumi&amp;rsquo;s automation capabilities have resulted in &lt;a href="https://www.pulumi.com/case-studies/lemonade/"&gt;significant cost savings&lt;/a&gt;. The company estimates that its annual cloud spend has decreased from $9.5 million in its data center days to just $2 million—a staggering 79% reduction. These cost savings have allowed Tivity Health to redirect resources towards more strategic initiatives that drive business growth.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Improved Security and Compliance&lt;/strong&gt;: Tivity Health&amp;rsquo;s DevSecOps strategy, anchored by Pulumi, has strengthened its security posture and &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies/"&gt;compliance efforts&lt;/a&gt;. By integrating security directly into its infrastructure workflows, Tivity Health has improved its security posture. Automation ensures that security measures are enforced consistently across their cloud environments, reducing risks and improving compliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="fostering-devops-culture-through-cross-functional-collaboration"&gt;Fostering DevOps Culture Through Cross-Functional Collaboration&lt;/h2&gt;
&lt;p&gt;Using Pulumi provided more than technical benefits. It also enabled better collaboration between the development, security, and operations teams. By providing a common language and framework for infrastructure management, Pulumi has helped break down silos and align these traditionally disparate groups towards a shared goal of delivering secure, high-quality products faster.&lt;/p&gt;
&lt;h2 id="lessons-learned-navigating-the-cultural-shift"&gt;Lessons Learned: Navigating the Cultural Shift&lt;/h2&gt;
&lt;p&gt;Transitioning to DevSecOps and cloud-native practices required a cultural shift at Tivity Health. Giambrono acknowledges that this cultural shift was not without its challenges. He emphasizes the importance of addressing the human element of change, offering the following advice for organizations embarking on a similar journey:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Start with a proof of concepts&lt;/strong&gt;: Giambruno recommends beginning with a small-scale proof of concepts to demonstrate the capabilities and benefits of the new technologies and processes to help alleviate fears and build confidence among team members.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Empower developers and make them feel safe&lt;/strong&gt;: By involving developers in the process and ensuring they feel comfortable with the new tools and workflows, Tivity Health gained user buy-in and overall support for the new DevSecOps approach.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secure buy-in from business and financial stakeholders&lt;/strong&gt;: Address the concerns of business and financial stakeholders early on, such as the impact on costs and the ability to deliver tangible results. This is crucial for securing the necessary support and resources.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Celebrate successes and build momentum&lt;/strong&gt;: Giambruno highlights the importance of celebrating the team&amp;rsquo;s achievements along the way, even when there are bumps on the road, as this helps build enthusiasm and keep the momentum going.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-future-of-devsecops-and-pulumi-at-tivity-health"&gt;The Future of DevSecOps and Pulumi at Tivity Health&lt;/h2&gt;
&lt;p&gt;As Tivity Health continues to refine its DevSecOps strategy, Giambruno is optimistic about the future. He envisions a world where the company&amp;rsquo;s ability to deploy new products and features rapidly will give Tivity Health a significant competitive edge, allowing it to better serve its customers and drive business growth.&lt;/p&gt;
&lt;p&gt;Looking ahead, Giambruno is particularly enthusiastic about the potential of Pulumi&amp;rsquo;s AI-powered capabilities, which he believes will further streamline and optimize the company&amp;rsquo;s infrastructure management processes. &amp;ldquo;&lt;em&gt;I&amp;rsquo;m super looking forward to the tests we&amp;rsquo;re going to do, like when we acquire someone and then taking them in, &amp;lsquo;Borg-ing&amp;rsquo; them into our automation and seeing how much we can take out of their operating cost as fast as possible&lt;/em&gt;,&amp;rdquo; he says.&lt;/p&gt;
&lt;p&gt;Tivity Health&amp;rsquo;s journey with Pulumi is a powerful example of how the right tool, DevSecOps strategy, and automation can drive tangible business results. By focusing on automation, security, and collaboration, organizations can achieve faster, cheaper, and better cloud deployments—putting them on the path to long-term success in an increasingly competitive, cloud-native world.&lt;/p&gt;
&lt;p&gt;To learn more about Pulumi and how it can transform your software development and infrastructure management:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Get started with &lt;a href="https://www.pulumi.com/tutorials/"&gt;Pulumi Tutorials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Attend an &lt;a href="https://www.pulumi.com/resources/#upcoming"&gt;upcoming workshop&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Try out the &lt;a href="https://www.pulumi.com/product/neo/"&gt;Pulumi Neo&lt;/a&gt; code assistant to accelerate your infrastructure as code journey&lt;/li&gt;
&lt;/ul&gt;</description><author>Sara Huddleston</author><category>security</category><category>devsecops</category><category>devops</category><category>infrastructure-as-code</category><category>platform-engineering</category><category>infrastructure-lifecycle-management</category><category>developer-experience</category></item><item><title>Pulumi Patterns and Practices Platform (P3): Some Assembly Required</title><link>https://www.pulumi.com/blog/p3-some-assembly-required/</link><pubDate>Mon, 11 Nov 2024 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/p3-some-assembly-required/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/p3-some-assembly-required/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Note: This post discusses Pulumi Copilot, which Pulumi Neo has replaced. &lt;a href="https://www.pulumi.com/docs/ai/"&gt;Learn about Neo →&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Setting up an internal developer platform (IDP) can be a daunting task. There are a lot of tools out there that do some of the work for you, but none of them do all of it. Pulumi P3 is no different. Pulumi Patterns &amp;amp; Practices Platform (P3) is a &lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/"&gt;reference architecture&lt;/a&gt; that we will be describing, and providing code for, through this series of articles.&lt;/p&gt;
&lt;p&gt;We will never try to sell you on the idea that you can simply download a package, click next a few times, and achieve transformative success. That’s because any effective IDP will require some customization and integration to work within your environment.&lt;/p&gt;
&lt;p&gt;Tools that purport to have it all figured out have only figured out how to manipulate you into a false narrative they have constructed in a vacuum, where all your organizational needs fit neatly into a few boxes they’ve decided on for you. And also charge you for. In addition to everything else you’re being charged for. Ultimately you’ll still need to build a lot yourself and these products rarely give guidance on how to do that.&lt;/p&gt;
&lt;p&gt;When we first started hearing about our customers using Pulumi as an internal developer platform (IDP), we were frankly surprised, as our goals were primarily for Pulumi to be the best developer experience in infrastructure. But it makes sense. All the parts are there, some assembly required. Our goal with Pulumi Patterns and Practices Platform (P3) is to help with that assembly process.&lt;/p&gt;
&lt;p&gt;Starting with our &lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/"&gt;previous blog post&lt;/a&gt; on the topic, and continuing here, we are examining this use case, and attempting to formalize that into a collection of reusable components and some guidance on how you can skip the marketing pitches and pricing charts, and get straight to the hard work of building your own highly customized internal developer platform with Pulumi at its core.&lt;/p&gt;
&lt;h2 id="pulumi-p3-bill-of-materials"&gt;Pulumi P3: Bill of Materials&lt;/h2&gt;
&lt;p&gt;Previously we identified the &lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#an-effective-internal-developer-platform"&gt;essential qualities of an effective IDP&lt;/a&gt;. Those were consistency, reproducibility, visibility, security and compliance, auditability, developer experience. In the &lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#a-holistic-view-of-the-patterns-and-practices-platform-reference-architecture"&gt;last half of the post&lt;/a&gt; we discussed which parts of Pulumi could be used to meet those needs. That looks like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Consistency&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/learn/abstraction-encapsulation/component-resources/"&gt;component resources&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/developer-portals/templates/"&gt;organization templates&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/drift/"&gt;drift detection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reproducibility&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/learn/building-with-pulumi/understanding-stacks/"&gt;stacks&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/"&gt;deployments&lt;/a&gt;, &lt;a href="https://www.pulumi.com/registry/packages/snowflake/api-docs/dynamictable/"&gt;versioned data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Visibility&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt;, &lt;a href="https://www.pulumi.com/product/copilot/"&gt;Pulumi Copilot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security and Compliance&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/teams/"&gt;RBAC&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/teams/#github-based-teams"&gt;GitHub Teams&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/saml/"&gt;SAML-SSO&lt;/a&gt;, &lt;a href="https://www.pulumi.com/product/esc/"&gt;Pulumi ESC&lt;/a&gt;, &lt;a href="https://www.pulumi.com/crossguard/"&gt;Pulumi Crossguard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Auditability&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/audit-logs/"&gt;audit logging&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Developer Experience&lt;/strong&gt;: &lt;a href="https://www.pulumi.com/docs/languages-sdks/"&gt;Python/Go/JavaScript/C#&lt;/a&gt;, &lt;a href="https://www.pulumi.com/blog/next-level-iac-breakpoint-debugging/"&gt;popular IDE support&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/cli/"&gt;command-line tools&lt;/a&gt;, &lt;a href="https://www.pulumi.com/automation/"&gt;deeply hackable&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That’s all great, and much of that is already built-into Pulumi without the need for you to do anything at all. So, what parts do you actually need to set up and configure? Here’s the bill of materials (BOM) to set up your own instance of Pulumi P3:&lt;/p&gt;
&lt;h3 id="bill-of-materials"&gt;Bill of Materials:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Authentication and Identity Management&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A GitHub organization that matches your Pulumi Cloud organization&lt;/li&gt;
&lt;li&gt;GitHub Teams users and roles that match your organizational structure and security needs&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Secrets, Configuration, and Policy&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pulumi ESC environments to manage secrets across clouds&lt;/li&gt;
&lt;li&gt;Pulumi Crossguard policy packs that capture your company policies&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Developer Experience&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A set of reusable multi-language components for cross-cutting concerns/common services&lt;/li&gt;
&lt;li&gt;A set of organization templates that match your common use cases&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let’s go through each of those and briefly discuss what it looks like to set that up.&lt;/p&gt;
&lt;h2 id="authentication-and-identity-management"&gt;Authentication and identity management&lt;/h2&gt;
&lt;p&gt;We highly recommend using GitHub for code management. So much so that we have deeply integrated GitHub into Pulumi Cloud across a number of features. While we support &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/organizations/#gitlab-identity-provider"&gt;alternatives such as GitLab&lt;/a&gt;, this will be the easiest and more feature-rich way to configure your platform.&lt;/p&gt;
&lt;p&gt;In Pulumi Cloud, you have the ability to create organizations. A &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/organizations/"&gt;Pulumi Cloud organization&lt;/a&gt; can help you manage teams, roles, stacks, settings, and provide a dashboard across the entire organization. Pulumi Cloud also allows you to use a variety of identity providers to log in, including GitHub.&lt;/p&gt;
&lt;p&gt;For simplicity’s sake, we suggest that you start with your GitHub organization. &lt;a href="https://docs.github.com/en/organizations/collaborating-with-groups-in-organizations/creating-a-new-organization-from-scratch"&gt;Create the GitHub organization&lt;/a&gt;, &lt;a href="https://docs.github.com/en/organizations/organizing-members-into-teams/about-teams"&gt;set up teams&lt;/a&gt;, and &lt;a href="https://docs.github.com/en/organizations/organizing-members-into-teams/adding-organization-members-to-a-team"&gt;add members&lt;/a&gt; to those teams, assigning either admin or user &lt;a href="https://docs.github.com/en/enterprise-cloud@latest/organizations/managing-peoples-access-to-your-organization-with-roles/using-organization-roles"&gt;roles&lt;/a&gt; to each member.&lt;/p&gt;
&lt;p&gt;Next, in Pulumi Cloud, create an organization &lt;em&gt;&lt;strong&gt;with exactly the same name&lt;/strong&gt;&lt;/em&gt; as your GitHub organization, and choose GitHub as your identity provider. When a Pulumi organization is backed by a GitHub organization, then only members of that GitHub organization may be added to the Pulumi organization. Similarly, as soon as someone loses access to the GitHub organization, they will no longer have access to the Pulumi organization. You will also be able to &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/teams/#github-based-teams"&gt;import your GitHub teams&lt;/a&gt; directly into Pulumi Cloud. Then assign your users to the same roles in Pulumi Cloud teams as they have in the associated GitHub teams.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/p3-some-assembly-required/teams-gh-pulumi.png"
alt="Figure: Mapping GitHub orgs, teams, and roles to Pulumi"&gt;&lt;figcaption&gt;
&lt;p&gt;Figure: Mapping GitHub orgs, teams, and roles to Pulumi&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Finally, you can &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/teams/#granting-access-to-stacks-within-teams"&gt;map teams to stacks&lt;/a&gt; to grant access at specific permission levels. If you’re not familiar with &lt;a href="https://www.pulumi.com/docs/concepts/stack/"&gt;Pulumi Stacks&lt;/a&gt;, a stack is a materialized instance of a specific set of cloud resources, as defined in a Pulumi program.&lt;/p&gt;
&lt;h2 id="pulumi-esc-managing-credentials-configuration-and-other-secrets"&gt;Pulumi ESC: Managing credentials, configuration, and other secrets&lt;/h2&gt;
&lt;p&gt;In order to deploy a stack you will need secrets such as cloud credentials and other configuration values that are provided to the deployment engine. Pulumi ESC is a secure system for managing secrets. They are organized by &lt;em&gt;&lt;a href="https://www.pulumi.com/docs/concepts/environments/"&gt;environments&lt;/a&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;An example set of environments might look something like this:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; AWS login/credentials&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# aws-creds ESC environment&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;values&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;creds&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;fn::open::aws-login&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;oidc&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;roleArn&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;arn:aws:iam::123456789012:role/pulumi-environments-oidc&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;sessionName&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;pulumi-environments-session&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;duration&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;1h&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;environmentVariables&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;AWS_ACCESS_KEY_ID&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${aws.creds.accessKeyId}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;AWS_SECRET_ACCESS_KEY&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${aws.creds.secretAccessKey}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;AWS_SESSION_TOKEN&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${aws.creds.sessionToken}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; Default production environment to use &lt;code&gt;us-east-1&lt;/code&gt; region&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# aws-production ESC environment&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;imports&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="l"&gt;aws-creds&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;values&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;aws&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;region&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;us-east-1&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;pulumiConfig&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;aws:region&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${aws.region}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; Default staging environment to use &lt;code&gt;us-west-2&lt;/code&gt; region&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# aws-staging ESC environment&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;imports&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="l"&gt;aws-creds&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;values&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;aws&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;region&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;us-west-2&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;pulumiConfig&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;aws:region&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${aws.region}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here we define three environments for AWS:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;aws-creds&lt;/code&gt;: sets up login via OpenID Connect (OIDC) and provides standard environment variables containing AWS credentials to the Pulumi program&lt;/li&gt;
&lt;li&gt;&lt;code&gt;aws-production&lt;/code&gt;: imports everything from &lt;code&gt;aws-creds&lt;/code&gt; then sets the region to &lt;code&gt;us-east-1&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;aws-staging&lt;/code&gt;: does the same, but sets the region to &lt;code&gt;us-west-2&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Using that in a Pulumi program is as simple as adding the following settings to your stack config:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Pulumi.staging.yaml&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;environment&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="l"&gt;aws-staging&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this manner, you can configure separate environments for staging and production, with a complex set of configuration values and secrets, using different environments for each one. From the developer’s perspective they would only need to change &lt;code&gt;aws-staging&lt;/code&gt; to &lt;code&gt;aws-production&lt;/code&gt; when they go to deploy their stack.&lt;/p&gt;
&lt;p&gt;Another strong benefit of this approach is that all secrets will be encrypted both in-flight and at-rest. Pulumi waits until the last moment to decrypt secrets at runtime. By default, uses automatic, per-stack encryption keys provided by Pulumi Cloud, but you could use a &lt;a href="https://www.pulumi.com/docs/concepts/secrets/#configuring-secrets-encryption"&gt;provider of your own choosing&lt;/a&gt; instead.&lt;/p&gt;
&lt;h2 id="pulumi-crossguard-policy-as-code"&gt;Pulumi Crossguard: Policy-as-Code&lt;/h2&gt;
&lt;p&gt;Pulumi Crossguard allows you to check and enforce policies on your deployments. Policies are rules, written in code, that run during deployments to check that the resources are conforming to the necessary criteria. You can use off-the-shelf policies like &lt;a href="https://www.pulumi.com/docs/using-pulumi/crossguard/awsguard"&gt;AWSGuard&lt;/a&gt; and &lt;a href="https://github.com/pulumi/compliance-policies/"&gt;Pulumi Compliance-Ready Policies&lt;/a&gt; or write your own.&lt;/p&gt;
&lt;p&gt;Either way you end up with a &lt;em&gt;policy pack&lt;/em&gt; that you can apply to your entire Pulumi organization via Pulumi Cloud.&lt;/p&gt;
&lt;p&gt;Here’s an example policy that checks for the presence of a tag &lt;code&gt;user:Stack&lt;/code&gt; on a S3 bucket:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;pulumi_policy&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;EnforcementLevel&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;PolicyPack&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ResourceValidationPolicy&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;s3_check_required_tags&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;aws:s3/bucket:Bucket&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt; &lt;span class="ow"&gt;or&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;user:Stack&amp;#34;&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;]):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;S3 Bucket is missing required user:Stack tag.&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;PolicyPack&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;bucket-tags&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;enforcement_level&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;EnforcementLevel&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MANDATORY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;policies&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ResourceValidationPolicy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;s3-tags&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Ensure required tags are present on S3 buckets.&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;validate&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;s3_check_required_tags&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;),&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If the tag isn&amp;rsquo;t on the resource, it blocks the deployment with an error message. The error message would look something like this:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;Policies:
❌ bucket-tags@v0.0.1
- [mandatory] s3-tags (aws:s3/bucket:Bucket: my-bucket)
Ensure required tags are present on S3 buckets.
S3 Bucket is missing required user:Stack tag.
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This allows you to implement company-specific policies that can be as simple or complex as you need them to be.&lt;/p&gt;
&lt;p&gt;To apply this across your entire organization, you can &lt;a href="https://www.pulumi.com/docs/using-pulumi/crossguard/get-started/#enforcing-a-policy-pack"&gt;publish this policy pack to Pulumi Cloud&lt;/a&gt;, with the following commands:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-shell" data-lang="shell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ pulumi policy publish myorg
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ pulumi policy &lt;span class="nb"&gt;enable&lt;/span&gt; myorg/my-policy-pack latest
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Some other great features of Crossguard are the ability to &lt;a href="https://www.pulumi.com/docs/using-pulumi/crossguard/faq/#how-do-i-version-a-policy-pack"&gt;version policies&lt;/a&gt;, define multiple &lt;a href="https://www.pulumi.com/docs/using-pulumi/crossguard/core-concepts/#policy-groups"&gt;policy groups&lt;/a&gt;, and create &lt;a href="https://www.pulumi.com/blog/remediation-policies/"&gt;remediation policies&lt;/a&gt; that automatically fix policy violations when possible. We will cover these topics in a future post where we go deeper on how to use policies effectively.&lt;/p&gt;
&lt;h2 id="multi-language-components-mlc"&gt;Multi-Language Components (MLC)&lt;/h2&gt;
&lt;p&gt;In Pulumi, a &lt;em&gt;&lt;a href="https://www.pulumi.com/docs/concepts/resources/components/"&gt;component resource&lt;/a&gt;&lt;/em&gt; is something that your developers can import in their Pulumi program, instantiate and modify. These are made available via a &lt;em&gt;&lt;a href="https://www.pulumi.com/docs/concepts/resources/providers/"&gt;provider&lt;/a&gt;&lt;/em&gt;, which is in turn, made available to Pulumi via a &lt;em&gt;&lt;a href="https://www.pulumi.com/docs/using-pulumi/pulumi-packages/"&gt;provider package&lt;/a&gt;&lt;/em&gt;. There are many of these already available in the &lt;a href="https://www.pulumi.com/registry/"&gt;Pulumi Registry&lt;/a&gt;. However, in a custom internal developer platform you can define your own components, and bake appropriate settings/configuration directly into the underlying code.&lt;/p&gt;
&lt;p&gt;A &lt;em&gt;multi-language component (MLC)&lt;/em&gt; is even more useful. You can author your component in your language of choice and then generate a SDK that surfaces that component into all of the languages that Pulumi supports. For example, your platform team might be comfortable writing in Python, but the developers that write your microservices might use Go, and the developers who write the front-end apps might use Node.js. Both teams might need to deploy apps and infrastructure into your Kubernetes cluster. With multi-language components you can write a component in Python that abstracts away all the details of your custom Kubernetes cluster, and make that available to both teams, in both Go, Node.js, and any other language that Pulumi supports.&lt;/p&gt;
&lt;p&gt;To build a MLC, you&amp;rsquo;ll follow these basic steps to create the component, provider, provider package, and generate the multi-language SDK:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Fork one of the component provider boilerplate repos for &lt;a href="https://github.com/pulumi/pulumi-component-provider-py-boilerplate"&gt;Python&lt;/a&gt;, &lt;a href="https://github.com/pulumi/pulumi-component-provider-ts-boilerplate"&gt;TypeScript&lt;/a&gt;, or &lt;a href="https://github.com/pulumi/pulumi-component-provider-go-boilerplate"&gt;Go&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Update the package and code-generator configuration files, which name your component and package, define the inputs and outputs, and declare the dependencies.&lt;/li&gt;
&lt;li&gt;Implement the component in your preferred language.&lt;/li&gt;
&lt;li&gt;Generate an SDK for the other languages.&lt;/li&gt;
&lt;li&gt;Deploy the package.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Here’s a quick example of creating a custom S3 Bucket component in Python, that complies with the tagging policy we built earlier:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;pulumi_aws&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;s3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;TaggedBucket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pulumi&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ComponentResource&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="fm"&gt;__init__&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;opts&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;None&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;super&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="fm"&gt;__init__&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;mycorp:index:TaggedBucket&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kc"&gt;None&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;opts&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;# Create a bucket and add a custom tag to it.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;bucket&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;s3&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Bucket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s1"&gt;-bucket&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;tags&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s1"&gt;&amp;#39;user:Stack&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;pulumi&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get_stack&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;opts&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ResourceOptions&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;parent&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;register_outputs&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s1"&gt;&amp;#39;bucket&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s1"&gt;&amp;#39;websiteUrl&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;website_endpoint&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s1"&gt;&amp;#39;bucketDnsName&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;bucketDomainName&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;})&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This shows the component implementation in isolation from the provider/packaging/SDK boilerplate. In this code sample, we’re creating a component called &lt;code&gt;TaggedBucket&lt;/code&gt; that creates a S3 bucket, and adds a tag &lt;code&gt;user:Stack&lt;/code&gt; with the current stack name as its value. A developer could now use this in a TypeScript Pulumi program as such, and this resource would automatically have the tags added to it.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;import&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="nx"&gt;as&lt;/span&gt; &lt;span class="nx"&gt;mycorp&lt;/span&gt; &lt;span class="nx"&gt;from&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;mycorp/mycorp-components&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;taggedBucket&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;mycorp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;TaggedBucket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;example&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;export&lt;/span&gt; &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;bucket&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;taggedBucket&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;bucket&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;export&lt;/span&gt; &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;taggedBucket&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;websiteUrl&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;export&lt;/span&gt; &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;dnsName&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;taggedBucket&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;bucketDnsName&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If you want to see how to create MLCs in more detail, check out &lt;a href="https://www.youtube.com/watch?v=_RXvNS5N8A8"&gt;this video&lt;/a&gt; that walks you through the entire process, and &lt;a href="https://github.com/jaxxstorm/pulumi-productionapp"&gt;this repo&lt;/a&gt; for the code shown in the video. In a follow-up post in this series, we will build some reference MLCs that do things like implement a time-to-live (TTL) for stacks in your staging environment, automate drift detection, and automatically instrument your developer’s deployments with observability tools integrated by default.&lt;/p&gt;
&lt;h2 id="organization-templates-and-the-new-project-wizard"&gt;Organization templates and the New Project Wizard&lt;/h2&gt;
&lt;p&gt;The final piece that ties all this together are &lt;em&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/developer-portals/templates/"&gt;organization templates&lt;/a&gt;&lt;/em&gt;. You may have used some of our &lt;a href="https://www.pulumi.com/templates/"&gt;built-in templates&lt;/a&gt; when you learned how to use Pulumi. These are great for basic use cases, but the real magic happens when you bring together your custom components and custom security environments to create personalized templates which represent the internal use cases for your organization.&lt;/p&gt;
&lt;p&gt;Pulumi’s &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/developer-portals/new-project-wizard/"&gt;New Project Wizard&lt;/a&gt; reads these templates and provides an in-browser way to create a new project and deploy it. Running one of these templates will commit and push code to GitHub, and trigger an initial deployment – all in a few clicks and without leaving the browser.&lt;/p&gt;
&lt;p&gt;Each template needs the following parts:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A &lt;code&gt;Pulumi.yaml&lt;/code&gt; describing the template and its configuration values&lt;/li&gt;
&lt;li&gt;A GitHub repo (public or private) containing the code for the templated Pulumi program&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Here’s an example of a simple template using the components and environments we described above.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Pulumi.yaml&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${PROJECT}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;description&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;${DESCRIPTION}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;runtime&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;python&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;template&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;description&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;A Python Pulumi program that creates a tagged bucket.&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;&amp;#34;&amp;#34;__main__.py: A minimal Pulumi program&amp;#34;&amp;#34;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;mycorp&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Create an AWS resource (S3 Bucket)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;tagged_bucket&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;mycorp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TaggedBucket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;my-bucket&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Export the name of the bucket&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pulumi&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;export&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;bucket_name&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;tagged_bucket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Pulumi.production.yaml&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;environment&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="l"&gt;aws-production&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Pulumi.staging.yaml&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;environment&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="l"&gt;aws-staging&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The &lt;code&gt;Pulumi.yaml&lt;/code&gt; sets up the template and will populate the name and description from the settings provided during the template dialogue. The custom &lt;code&gt;TaggedBucket&lt;/code&gt; component will create an S3 bucket, which will be tagged with &lt;code&gt;user:Stack&lt;/code&gt; set to the name of the stack. Default stack configurations are provided for the &lt;code&gt;staging&lt;/code&gt; and &lt;code&gt;production&lt;/code&gt; environments which map to our two ESC environments, &lt;code&gt;aws-production&lt;/code&gt; and &lt;code&gt;aws-staging&lt;/code&gt;.&lt;/p&gt;
&lt;h2 id="how-it-all-works-together"&gt;How it all works together&lt;/h2&gt;
&lt;p&gt;With all of that in place, from the developer’s perspective, all they need to do is create a new project from the template, answering three questions: the stack name, the name of the project, and an optional description.&lt;/p&gt;
&lt;p&gt;If the developer names the stack &lt;code&gt;staging&lt;/code&gt; it will automatically apply the &lt;code&gt;aws-staging&lt;/code&gt; ESC environment, which will include the AWS credentials and set the region to &lt;code&gt;us-west-2&lt;/code&gt;. However, if the developer names the stack &lt;code&gt;production&lt;/code&gt; it will get the &lt;code&gt;aws-production&lt;/code&gt; ESC environment setting it to use the &lt;code&gt;us-east-1&lt;/code&gt; region. The name of the stack will be stored in a tag on the resource.&lt;/p&gt;
&lt;p&gt;Pulumi Crossguard will apply the &lt;code&gt;bucket-tags&lt;/code&gt; policy check to see if the resource has the required &lt;code&gt;user:Stack&lt;/code&gt; tag set and will allow the deployment to proceed only if it has that tag. If a developer created a standard S3 Bucket instead of using our internal &lt;code&gt;TaggedBucket&lt;/code&gt; component, and failed to add the required tag, they will get an error message from our custom policy when they try to deploy.&lt;/p&gt;
&lt;p&gt;Later, we can create additional automation that might do something like delete anything tagged &lt;code&gt;staging&lt;/code&gt; after two weeks, or run drift detection on anything tagged &lt;code&gt;production&lt;/code&gt;. We will be exploring these concepts in more detail in later posts.&lt;/p&gt;
&lt;h3 id="more-to-come"&gt;More to Come&lt;/h3&gt;
&lt;p&gt;While setting up the Pulumi Patterns and Practices Platform (P3) reference architecture is not a simple click-to-deploy, hopefully this high-level tour of the various parts you need to assemble shows that really, it is only a matter of creating a few carefully constructed YAML files and snippets of code, and wiring them together properly. You can start small and build out your platform over time.&lt;/p&gt;
&lt;p&gt;The next few posts in this series will go beyond these simple examples, showing much more complicated implementations of all of these pieces, and recommend some best practices for managing your infrastructure with this platform.&lt;/p&gt;
&lt;p&gt;And if you are already ready to get your hands on Pulumi after this introduction, feel free to &lt;a href="https://www.pulumi.com/signup/"&gt;create an account&lt;/a&gt; and follow some of our &lt;a href="https://www.pulumi.com/docs/get-started/"&gt;Getting Started&lt;/a&gt; guides to see how easy simple use cases are and begin to imagine how that same developer experience will scale up to your entire organization.&lt;/p&gt;
&lt;p&gt;To learn more, you can watch the following video which provides a high level overview of how Pulumi works:&lt;/p&gt;
&lt;div class="rounded-md shadow border border-gray-300 w-3/4 mx-auto my-4" style="position: relative; padding-bottom: 40.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe
src="//www.youtube.com/embed/Q8tw6YTD3ac?rel=0"
style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;"
allowfullscreen=""
title="Introduction to Pulumi in Three Minutes"
srcdoc="&lt;style&gt;*{padding:0;margin:0;overflow:hidden}html,body{height:100%}img{position:absolute;width:100%;top:0;bottom:0;margin:auto}&lt;/style&gt;&lt;a href=https://www.youtube.com/embed/Q8tw6YTD3ac?autoplay=1&gt;&lt;img src='https://www.pulumi.com/images/home/youtube-getting-started.png' alt='Introduction to Pulumi in Three Minutes'&gt;&lt;/a&gt;"&gt;
&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="pulumi-cloud"&gt;Pulumi Cloud&lt;/h2&gt;
&lt;p&gt;The Pulumi Cloud is a fully managed service that helps you adopt Pulumi&amp;rsquo;s open source SDK with ease. It provides built-in state and secrets management, integrates with source control and CI/CD, and offers a web console and API that make it easier to visualize and manage infrastructure. It is free for individual use, with features available for teams.&lt;/p&gt;
&lt;p&gt;&lt;a class="btn btn-secondary" href="https://app.pulumi.com/signup" target="_blank"&gt;Create an Account&lt;/a&gt;&lt;/p&gt;</description><author>Troy Howard</author><category>platform-engineering</category><category>patterns-and-practices-platform</category><category>developer-experience</category><category>devsecops</category><category>architecture</category><category>enterprise</category><category>devops</category></item><item><title>PulumiUP 2024: Dive Into the Future of Cloud, Platform Engineering, and AI/ML</title><link>https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/</link><pubDate>Wed, 11 Sep 2024 07:04:40 +0000</pubDate><guid>https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/index.png" /&gt;
&lt;p&gt;PulumiUP 2024 is just around the corner! It will be held on September 18th, starting at 8 AM PT | 15:00 UTC +0, and with over 5,500 engineers from all over the world already registered, this is shaping up to be the must-attend event for cloud professionals, platform engineers, and AI/ML enthusiasts alike. From entry-level engineers to tech executives, this event brings together professionals from companies of all sizes to explore the latest innovations and best practices in &lt;strong&gt;Cloud and IaC&lt;/strong&gt;, &lt;strong&gt;Platform Engineering &amp;amp; DevOps&lt;/strong&gt;, and &lt;strong&gt;AI/ML&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;If you haven’t registered yet, now’s the time! &lt;a href="https://conference.pulumi.com/schedule/?utm_source=PulumiUP&amp;amp;utm_medium=web&amp;amp;utm_campaign=FY2025Q1_Event_PulumiUP"&gt;Start building your schedule today&lt;/a&gt;, select the talks you want to watch live and on-demand and add them to your schedule.&lt;/p&gt;
&lt;h2 id="pulumiup-at-glance"&gt;PulumiUP at Glance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#main-track-keynote-cloud-culture-talks-and-more"&gt;Main Track: Keynote, Cloud Culture Talks, and More&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#aiml-track-highlights"&gt;AI/ML Track Highlights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#platform-engineering-and-devops-track-highlights"&gt;Platform Engineering and DevOps Track Highlights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#cloud-and-iac-track-highlights"&gt;Cloud and IaC Track Highlights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#workshops-and-hands-on-learning"&gt;Workshops and Hands-On Learning&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#amazing-partners-and-sponsors"&gt;Amazing Partners and Sponsors&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/#build-your-schedule-now"&gt;Build Your Schedule Now&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="main-track-keynote-cloud-culture-talks-and-more"&gt;Main Track: Keynote, Cloud Culture Talks, and More&lt;/h2&gt;
&lt;p&gt;In the Main Track, you’ll hear directly from the Pulumi leadership team about exciting product innovations. Don’t miss the Cloud Culture talks focused on the human side of technology and collaboration.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/pulumiup-2024-keynote/"&gt;Keynote and New Product Announcements&lt;/a&gt;&lt;/strong&gt; - Joe Duffy (Co-founder and CEO), Luke Hoban (CTO), and other key Pulumi leaders will unveil new products and innovations shaping the next wave of cloud development. Expect to see live demos showcasing how these tools can revolutionize your workflows, from cloud infrastructure to security automation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/9Xf6DJMvQ08"&gt;Why Care About Building a Cloud Center of Excellence?&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Alex Radu (VP Product &amp;amp; Marketing Manager, Public Cloud, J.P. Morgan) discusses why building a Cloud Center of Excellence is essential for long-term cloud strategy success.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/30wTCwfj3cc"&gt;What Is &amp;lsquo;HugOps&amp;rsquo; and Why Is It Important?&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Rees Pozzi (Senior Platform Engineer, Kainos) explores the meaning and importance of &amp;ldquo;HugOps,&amp;rdquo; a practice promoting empathy and collaboration in the tech world but also by all those impacted by it.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="aiml-track-highlights"&gt;AI/ML Track Highlights&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://conference.pulumi.com/talks/panel-ai-cloud-development/"&gt;&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/pulumiup_2024-ai-cloud-development.png"
alt="Panelists of AI for Cloud Development" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Panel: AI for Cloud Development&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;AI is transforming how we approach development and infrastructure, and PulumiUP offers an incredible lineup of talks and panels on the topic.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/4IWGNoNVbiM"&gt;Data Privacy Challenges with Large Language Models&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Aditi Godbole (Data Science, AI &amp;amp; ML Leader, SAP) will address the critical question of managing data privacy, addressing LLM basics, AI data privacy fundamentals, and specific privacy issues in LLMs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/CoZM9BCJcJ4"&gt;Pulumi Powered AI/ML on Kubernetes&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jason Smith (App Modernization Specialist, Google Cloud) will show you how to serve an open-source LLM with a RAG on Kubernetes and set up a Kubernetes environment for AI/ML workloads with Pulumi.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/WoM8Bj76_Fw"&gt;AI Tools for Developers&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jim Clark (Principal Software Engineer, Docker) will explore how Tools can enhance the capabilities of AI assistants and show how the combination of AI, Tools, and containerized runtimes, can enhance interactions between developers and their tools.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/2mlb2jEBkoo"&gt;The AI Governance Challenge&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Patty O&amp;rsquo;Callaghan (Technical Director, Charles River) will explore the complexities of AI governance and how to navigate them.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/panel-ai-in-cloud-development/"&gt;Panel Discussion: &amp;ldquo;AI for Cloud Development&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; - Luke Hoban (CTO, Pulumi), Phillip Carter (Principal Product Manager, Honeycomb), Giri Sreenivas (CPO, Docker), Clare Liguori (Senior Principal Software Engineer, AWS) and Meagan Cojocar (Principal Product Manager, Pulumi) will provide diverse perspectives on how AI is shaping cloud infrastructure.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="platform-engineering-and-devops-track-highlights"&gt;Platform Engineering and DevOps Track Highlights&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/pulumiup_2024-secrets-policies-automating-cybersecurity.png"
alt="Panelists of Secrets and Policies—Automating Cybersecurity" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Panel: Secrets and Policies—Automating Cybersecurity&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;The Platform Engineering &amp;amp; DevOps track at PulumiUP is perfect for anyone looking to automate infrastructure, secure their systems, and scale their environments with ease. This track features talks and panels on cutting-edge technologies and practices.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/WZD1z2ldweY"&gt;Moving Mountains: How IaC Unlocks Massive Refactoring Possibilities&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Shaun Verch (Infrastructure Engineer, Oso) will show you how infrastructure as code can transform large-scale refactoring projects.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/1Q3XPmenthg"&gt;Using Pulumi to Empower Kubernetes Fleet Management&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Blake Romano (Senior Software Engineer, Imagine Learning) will show you how Imagine Learning leverages Pulumi to manage a fleet of Kubernetes clusters and other platform resources quickly and reliably, and how it revolutionized their workflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/f2r9rS9U2CA"&gt;Streamline Your Infrastructure Deployment with GitOps and Pulumi Operator&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Sam Cogan (Solutions Architect &amp;amp; Azure MVP, WTW) will highlight how you can define your infrastructure in Git, and have Pulumi automatically reconcile it into deployed infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/EQwpC02CQ9k"&gt;Is This a Platform? Platform Engineering Before PMF&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jk Jensen (Team Lead, Staff Software Engineer, MystenLabs) will share how they built their service platform around Pulumi to help engineers and researchers move from prototypes to deployed environments, enabling their teams to iterate more quickly and develop an increasing number of systems without additional complexity.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/events/security-automation-faster-cheaper-better/"&gt;Security Automation—Faster. Cheaper. Better.&lt;/a&gt;&amp;quot;&lt;/strong&gt; - David Giambruno (VP of Engineering and DevOps, Tivity Health) and Joe Duffy (Founder/CEO, Pulumi) will discuss security automation and how these efforts impacted speed and agility, cost optimization and improved security and compliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/CGE8VXgkjug"&gt;Meet Devs Where They Are: Why IaC Must Be Real Code&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jeremy Adams (Head of Ecosystems, Dagger) will present why real code (that teams already use for applications) is essential for both IaC and CI/CD pipelines, and to meet modern DevOps best practices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/2a-wlUnBY1g"&gt;Security of IaC Pipelines and Infrastructure Governance With Policies-As-Code&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Marina Novikova (Senior Partner Solutions Architect, AWS) and Andy Taylor (Senior Networking Specialist/ Solutions Architect, AWS) will explore security best practices for IaC pipelines and infrastructure governance using policies-as-code, cover best practices for handling sensitive information like access keys, tokens and encryption keys, and scaling and automating your DevSecOps.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/secrets-policies-automating-cybersecurity/"&gt;Panel Discussion: &amp;ldquo;Secrets and Policies—Automating Cybersecurity&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; - Arun Loganathan (Senior Product Manager, Pulumi), Maya Kaczorowski (PM of Security), Jason Meller (VP, Product, 1Password), and Ofir Cohen (CTO, Container Security, Wiz) will explore the intersection of innovation and security, offering insights into how AI is reshaping the threat landscape and how organizations can stay ahead.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="cloud-and-iac-track-highlights"&gt;Cloud and IaC Track Highlights&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumiup-global-cloud-iac-platform-engineering-ai-conference/pulumiup_2024-infrastructure-as-code.png"
alt="Panelists of Infrastructure as Code - Can we do better?" width="100%"&gt;&lt;figcaption&gt;
&lt;p&gt;Panel: Infrastructure as Code - Can we do better?&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;The Cloud and IaC track is ideal for those wanting to deepen their understanding of infrastructure as code and its impact on modern cloud computing. Learn from industry pioneers and see where the future of IaC is headed.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/blog/from-cdk-pulumi-evolution-of-sst/"&gt;From CDK to Pulumi: Evolution of SST&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Dax Raad (Founding Engineer, SST) and Jay V (Founder, SST) will share insights into the early development of their product, initially built on AWS Cloud Development Kit (CDK), the challenges they encountered and the groundbreaking decision to transition to Pulumi.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/blog/unified-programmatic-approach-infrastructure-management-bmw-using-pulumi/"&gt;Unified Software Development at BMW Software Factory with Pulumi&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Jan-Peter Alten (Expert Software Engineer, DevOps, BMW Group) will showcase how BMW uses Pulumi to unify their software development processes, resulting in an increase in developer productivity, streamlined infrastructure management, and enhanced scalability, security, and compliance across their complex software ecosystem.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/E077QbXPOZE"&gt;Stacking Accounts: Multi-Account Deployments in a Single Stack for Monitoring, Management, and More&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Denis Willett (Software Engineer, North Carolina Institute for Climate Studies) will explain how they use Pulumi for managing 60+PB of environmental data across AWS, GCP, and Azure and leverage multi-account deployments in a single stack via the Pulumi Automation API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://youtu.be/C5ZuEVXesOk"&gt;Industrialize the Configuration of Your GitHub Repositories With IaC&lt;/a&gt;&amp;quot;&lt;/strong&gt; - Alexandre Nédélec (Software Engineer, Avanade) will live code using the GitHub, Azure native, and Azure AD Pulumi providers to create a GitHub repository and configure its pipeline to deploy to Azure using OpenID Connect.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/events/panel-infrastructure-as-code-can-we-do-better/"&gt;Panel Discussion: &amp;ldquo;Infrastructure as Code — Can We Do Better?&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; - Joe Duffy (Co-Founder and CEO, Pulumi), Brian Grant (CTO, Stealth), Elad Ben-Israel (Co-Founder and CEO, Winglang), Adam Jacob (Co-Founder and CEO, System Initiative), and Luke Hoban (CTO, Pulumi) will discuss the past, the present, and the future of Infrastructure as Code and the overall infrastructure technologies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="workshops-and-hands-on-learning"&gt;Workshops and Hands-On Learning&lt;/h2&gt;
&lt;p&gt;Want to get hands-on experience? Our live workshops are designed to deepen your understanding of trending topics, Pulumi, and its applications.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/managing-team-secrets-with-1password-pulumi-esc/"&gt;Managing Team Secrets with 1Password &amp;amp; Pulumi ESC&lt;/a&gt;&amp;quot;&lt;/strong&gt; on September 25, led by Phil Johnston (1Password) and Diana Esteves (Pulumi).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/securing-iac-pipelines-in-regulated-industries/"&gt;Securing IaC Pipelines in Regulated Industries&lt;/a&gt;&amp;quot;&lt;/strong&gt; on September 26, led by Josh Kodroff (Pulumi) and Marina Novikova (AWS).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/deploy-tailscale-infrastructure-with-pulumi/"&gt;Deploy Tailscale infrastructure in AWS with Pulumi&lt;/a&gt;&amp;quot;&lt;/strong&gt; on October 15, led by Diana Esteves (Pulumi) and Lee Briggs (Tailscale).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;quot;&lt;a href="https://www.pulumi.com/resources/observability-as-code-for-ai-apps-new-relic/"&gt;Observability as Code for AI Apps with New Relic and Pulumi&lt;/a&gt;&amp;quot;&lt;/strong&gt; on October 30, led by Diana Esteves (Pulumi) and Harry Kimpel (New Relic).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="amazing-partners-and-sponsors"&gt;Amazing Partners and Sponsors&lt;/h2&gt;
&lt;p&gt;Thank you to our amazing customers, sponsors, and partners for supporting PulumiUP!&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://aws.amazon.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;AWS&lt;/a&gt;&lt;/strong&gt; The world&amp;rsquo;s most comprehensive and broadly adopted cloud, offering over 200 fully featured services from data centers globally.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://cloud.google.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Google Cloud&lt;/a&gt;&lt;/strong&gt; Help developers build quickly, securely, and cost effectively with the next generation of modern infrastructure designed to meet specific workload and industry needs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://newrelic.com/instant-observability/pulumi/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;New Relic&lt;/a&gt;&lt;/strong&gt; Data for engineers to monitor, debug, and improve their entire stack.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docker.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Docker&lt;/a&gt;&lt;/strong&gt; Accelerate how you build, share, and run applications.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://1password.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;1Password&lt;/a&gt;&lt;/strong&gt; Streamline how you manage SSH keys, API tokens, and other infrastructure secrets throughout the entire software development life cycle.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://tailscale.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Tailscale&lt;/a&gt;&lt;/strong&gt; Make creating software-defined networks easy: securely connecting users, services, and devices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://pinecone.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Pinecone&lt;/a&gt;&lt;/strong&gt; Build remarkable GenAI applications fast, with lower cost, better performance, and greater ease of use at any scale.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://wiz.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Wiz&lt;/a&gt;&lt;/strong&gt; Secure everything you build and run in the cloud.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://honeycomb.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Honeycomb&lt;/a&gt;&lt;/strong&gt; Observability that helps solve problems you couldn’t before.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://mystenlabs.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Mysten Labs&lt;/a&gt;&lt;/strong&gt; Building critical infrastructure to enable a more decentralized internet.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://imaginelearning.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Imagine Learning&lt;/a&gt;&lt;/strong&gt; Empowering educators to inspire breakthrough moments in every student’s unique learning journey with digital-first, K–12 education solutions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://dagger.io/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Dagger&lt;/a&gt;&lt;/strong&gt; Powerful, programmable open source CI/CD engine that runs your pipelines in containers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://osohq.com/?utm_source=Pulumi.com&amp;amp;utm_medium=Website&amp;amp;utm_campaign=PulumiUP"&gt;Oso&lt;/a&gt;&lt;/strong&gt; Authorization as a service.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="build-your-schedule-now"&gt;Build Your Schedule Now&lt;/h2&gt;
&lt;p&gt;With so many compelling topics across AI/ML, Platform Engineering, DevOps, and Cloud and IaC, now is the time to &lt;a href="https://conference.pulumi.com/schedule/?utm_source=PulumiUP&amp;amp;utm_medium=web&amp;amp;utm_campaign=FY2025Q1_Event_PulumiUP"&gt;build your PulumiUP schedule&lt;/a&gt;. Select the sessions that match your goals and interests to maximize your experience. Plus, you&amp;rsquo;ll receive a link to watch your chosen panel discussions and tech talks on-demand!&lt;/p&gt;
&lt;p&gt;Haven’t registered yet? It’s not too late! Join 5,500 engineers worldwide in this groundbreaking event and gain the insights you need to drive innovation at your company. &lt;a href="https://www.pulumi.com/pulumi-up/"&gt;Register now-&amp;gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We can’t wait to see you there!&lt;/p&gt;</description><author>Sara Huddleston</author><category>pulumi-events</category><category>announcements</category><category>platform-engineering</category><category>ai</category><category>cloud-computing</category><category>infrastructure-as-code</category><category>devsecops</category><category>community</category></item><item><title>Pulumi Patterns and Practices Platform (P3): A reference architecture for large-scale organizations</title><link>https://www.pulumi.com/blog/pulumi-patterns-and-practices/</link><pubDate>Mon, 05 Aug 2024 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/pulumi-patterns-and-practices/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumi-patterns-and-practices/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Note: This post discusses Pulumi Copilot, which Pulumi Neo has replaced. &lt;a href="https://www.pulumi.com/docs/ai/"&gt;Learn about Neo →&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Infrastructure management is all fun and games until you find yourself scrolling through 1000+ resources in your AWS console. Worse, when one rogue product team wants to use Azure and your data team wants to be on GCP, you&amp;rsquo;re ARM wrestling in Azure and watching your economies of scale tip the wrong direction as you&amp;rsquo;re copy-pasting CloudFormation templates into yet another git repo. This. Needs. To. Be. A. Platform!&lt;/p&gt;
&lt;p&gt;And in that moment of overwhelm, you will be sold to, nurture-emailed every week, and told all your problems will be solved by implementing an IDP (internal developer platform, as if you&amp;rsquo;ve never seen this acronym before). An IDP that costs a lot of money and a lot of time to implement beyond default settings. An IDP that really only solves half of your problems. Your internal team offers to build something that feels more like welding together random pieces of code into an abstract found-art sculpture built from junkyard refuse, already 5 years out of date. How long will this investment be useful before you have to start over?&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s exhausting. If there was a good solution on the market, you wouldn&amp;rsquo;t be reading this article. So let&amp;rsquo;s talk about what you really need, and how Pulumi can help.&lt;/p&gt;
&lt;h2 id="an-effective-internal-developer-platform"&gt;An effective internal developer platform&lt;/h2&gt;
&lt;p&gt;There are quite a few &lt;a href="https://en.wikipedia.org/wiki/Listicle"&gt;listicles&lt;/a&gt; out there professing to authoritatively tell you the 5, or 7, or 11 essential components of an internal developer platform. Personally, I trust our customers to tell us, and here&amp;rsquo;s what they have said they need:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#consistency"&gt;Consistency:&lt;/a&gt;&lt;/strong&gt; Bring some order to the chaos. As your company and your infrastructure grows, it gets more and more complicated to maintain consistency. You might already have established design patterns that you want to replicate, but don&amp;rsquo;t have any way to encode those practices in your current tools. There&amp;rsquo;s a lot of copy/paste of reusable blocks, but no way to apply &lt;a href="https://www.youtube.com/watch?v=5xw04T20lto&amp;amp;t=7s"&gt;DRY principles&lt;/a&gt; or to modularize/templatize the important parts (hint: all the parts are important!).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#reproducibility"&gt;Reproducibility:&lt;/a&gt;&lt;/strong&gt; Repeatable behaviors, who dat? If you run your deploy twice do you get the same results each time? What if you replicate your production environment to create a test environment, are they actually identical? How much more work does it take to get them to be? Will you get the same version of the training dataset every time you run your AI workloads? It&amp;rsquo;s anyone&amp;rsquo;s guess. A lack of reproducibility slows down development, makes debugging more difficult, and makes that reuse we just talked about harder to achieve.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#visibility"&gt;Visibility:&lt;/a&gt;&lt;/strong&gt; When your node count, and user count starts to go beyond about 50-100 resources (computing or human) you quickly run into a problem of visibility. It can be very difficult to get a handle on what&amp;rsquo;s happening, how many resources you have, where they are, and how much they cost. Any system that purports to be able to manage 1000 nodes or more must have deeply integrated analytics, dashboards, charts, and be searchable, across all your clouds, all your users, and every kind of resource.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#security-and-compliance"&gt;Security and Compliance:&lt;/a&gt;&lt;/strong&gt; Good fences make good neighbors. RBAC, policy-as-code, excellent secrets management, integration with your existing identity providers. These are the things you need to build security and policy guardrails you can rely on. Without them? It&amp;rsquo;s just a powder keg of liability waiting to catch a spark.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#auditability"&gt;Auditability:&lt;/a&gt;&lt;/strong&gt; What happened and who did it? This is like a high-stakes game of &lt;a href="https://en.wikipedia.org/wiki/Cluedo"&gt;Clue&lt;/a&gt;. How quickly can you figure out who ran that bad deployment? Was it &lt;em&gt;Colonel Mustard&lt;/em&gt; in the &lt;em&gt;library&lt;/em&gt; with the &lt;em&gt;candlestick&lt;/em&gt;? Or Blake the new Front-End Developer with overly-broad permissions in AWS? Being able to answer these questions needs to happen quickly. Quickly, like minutes, not hours or days. And it might have happened 6 months ago. Oof.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/pulumi-patterns-and-practices/#auditability"&gt;Developer Experience:&lt;/a&gt;&lt;/strong&gt; In the ideal world, developers drive their own DevOps. The platform team provides self-service tools and streamlined workflows that allow your engineers to provision new resources, so your team doesn&amp;rsquo;t have to. And you know, if the developers don&amp;rsquo;t like the user experience, they won&amp;rsquo;t use it at all, and will invent their own tools. You will have ROGUE SYSTEMS to hunt down and argue against in tedious overly-technical meetings. This is not what you want. We need to keep the developers happy to prevent this.&lt;/p&gt;
&lt;h2 id="a-holistic-view-of-the-patterns-and-practices-platform-reference-architecture"&gt;A holistic view of the Patterns and Practices Platform reference architecture&lt;/h2&gt;
&lt;p&gt;Pulumi has a broad surface area of &lt;a href="https://www.pulumi.com/product/"&gt;products and features&lt;/a&gt; that address these needs. Designed with integration in mind from the beginning, our tools orchestrate well, presenting a smooth and streamlined workflow for both operations teams and developer teams.&lt;/p&gt;
&lt;p&gt;We have an idea of how you can use all the Pulumi products together to deliver a comprehensive internal platform for security, infrastructure management, and deployments. Call it an &lt;a href="https://www.pulumi.com/what-is/what-is-platform-engineering/"&gt;internal platform for developer platform engineers&lt;/a&gt; (IPfDPE), if you want. We call it the realization of a vision we&amp;rsquo;ve been working hard to build for many years.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pulumi Patterns and Practices Platform (P3)&lt;/strong&gt; is a reference architecture that we will be describing, and providing code for, through this series of articles. We&amp;rsquo;ll be diving deep into not just what you can do with our tools, but how to do it, and provide code for a reference implementation that you can use to jump start the process.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s a quick overview to give you an idea of how we&amp;rsquo;ll be addressing those needs in Pulumi Patterns and Practices Platform (P3).&lt;/p&gt;
&lt;h3 id="consistency"&gt;Consistency&lt;/h3&gt;
&lt;p&gt;Pulumi can help bring consistency to your software catalog by encoding design patterns into reusable &lt;em&gt;&lt;a href="https://www.pulumi.com/learn/abstraction-encapsulation/component-resources/"&gt;component resources&lt;/a&gt;&lt;/em&gt; and by building custom &lt;em&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/developer-portals/templates/"&gt;organization templates&lt;/a&gt;&lt;/em&gt; that provide a no-code or low-code way to start a new project. Templates help get projects off the ground faster and ensure consistent code structure, policy compliance, and best practices.&lt;/p&gt;
&lt;figure&gt;
&lt;div class="my-4"&gt;
&lt;video class="flex outline-none rounded-lg w-full" title="The New Project Wizard in Pulumi Cloud"
autoplay muted playsinline
loop &gt;
&lt;source src="npw-720p.mp4" /&gt;
&lt;/video&gt;
&lt;/div&gt;
&lt;figcaption&gt;&lt;p&gt;Figure: An internal developer portal using custom templates in Pulumi Cloud&lt;/p&gt;&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Beyond that, because Pulumi is &lt;a href="https://www.pulumi.com/blog/deploy-to-multiple-regions/"&gt;multi-cloud&lt;/a&gt; (AWS, Azure, Google Cloud, and more) and &lt;a href="https://www.pulumi.com/blog/pulumiup-pulumi-packages-multi-language-components/"&gt;multi-language&lt;/a&gt; (JavaScript, Python, Go, C#, Java) you can enjoy the same consistency across all your environments and all your developer teams, regardless of the languages they prefer, or cloud tooling they need.&lt;/p&gt;
&lt;p&gt;Another core aspect of consistency is &lt;em&gt;&lt;a href="https://www.pulumi.com/docs/pulumi-cloud/deployments/drift/"&gt;drift detection&lt;/a&gt;&lt;/em&gt;. Pulumi automatically detects and remediates cloud resources that have deviated from the expected state stored in Pulumi Cloud. This tech is better than ibuprofen at getting rid of developer-created headaches.&lt;/p&gt;
&lt;h3 id="reproducibility"&gt;Reproducibility&lt;/h3&gt;
&lt;p&gt;Since 2010, scientists have felt that we are in a crisis – a &lt;em&gt;&lt;a href="https://en.wikipedia.org/wiki/Replication_crisis"&gt;reproducibility crisis&lt;/a&gt;&lt;/em&gt; – wherein we cannot easily reproduce an experiment in order to verify published results. Similarly, the software industry is entering into a reproducibility crisis of its own, especially around AI training workflows, where it is increasingly difficult to recreate crucial build and prod environments. &lt;a href="https://www.pulumi.com/learn/building-with-pulumi/understanding-stacks/"&gt;Pulumi Stacks&lt;/a&gt; make it very easy to manage both configuration and state across multiple environments, and make &lt;a href="https://www.pulumi.com/blog/simple-reproducible-kubernetes-deployments/"&gt;reproducing a deployment&lt;/a&gt; within Pulumi a matter of a few basic operations.&lt;/p&gt;
&lt;p&gt;You can use Pulumi programs to capture &lt;em&gt;&lt;strong&gt;all&lt;/strong&gt;&lt;/em&gt; of the necessary resources for an AI training workload, including things like versioned data using &lt;a href="https://www.pulumi.com/registry/packages/snowflake/api-docs/dynamictable/"&gt;dynamic tables&lt;/a&gt; with time-travel functionality in &lt;a href="https://www.pulumi.com/case-studies/snowflake/"&gt;Snowflake&lt;/a&gt;. That means you can be sure that not only will your deployment be on the infrastructure you need, it will also have the exact version of data, every time, which is essential to A/B testing and debugging your models.&lt;/p&gt;
&lt;h3 id="visibility"&gt;Visibility&lt;/h3&gt;
&lt;p&gt;Every resource under management by Pulumi is visible within &lt;a href="https://www.pulumi.com/product/pulumi-insights/"&gt;Pulumi Insights&lt;/a&gt;. From this single-pane-of-glass interface, you can search for resources across all cloud environments. &lt;a href="https://www.pulumi.com/product/copilot/"&gt;Pulumi Copilot&lt;/a&gt; provides a state-of-the-art AI chat interface to ask complex questions and get immediate results. Pulumi Insight&amp;rsquo;s analytics gives you the ability to identify anomalies or trends in resource usage and dig into cost, security, and compliance concerns.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/uploads/pulumi-insights-search.gif"
alt="Figure: Search for any resource with Pulumi Insights"&gt;&lt;figcaption&gt;
&lt;p&gt;Figure: Search for any resource with Pulumi Insights&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3 id="security-and-compliance"&gt;Security and Compliance&lt;/h3&gt;
&lt;p&gt;In the modern parlance, when you say DevOps, you mean DevSecOps. Pulumi is designed to be secure by default. Pulumi Cloud offers full &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/teams/"&gt;role-based access control (RBAC) functionality&lt;/a&gt; including deep integration with &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/teams/#github-based-teams"&gt;GitHub teams&lt;/a&gt; and &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/access-management/saml/"&gt;SAML-based SSO&lt;/a&gt;, managed secrets and flexibly-defined secure environments with &lt;a href="https://www.pulumi.com/product/esc/"&gt;Pulumi ESC&lt;/a&gt;, and policy-as-code provided by &lt;a href="https://www.pulumi.com/crossguard/"&gt;Pulumi Crossguard&lt;/a&gt;. Most importantly all of these features are deeply integrated across the platform, creating an air-tight system with all the guardrails you need for managing security and access.&lt;/p&gt;
&lt;h3 id="auditability"&gt;Auditability&lt;/h3&gt;
&lt;p&gt;Every action a user takes in Pulumi can be tracked via the &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/audit-logs/"&gt;audit log&lt;/a&gt; which is searchable in two clicks from the Pulumi Cloud homepage dashboard. Audit logs can be filtered by user with one more click. Creating automated backups of your audit logs is a &lt;a href="https://www.pulumi.com/docs/pulumi-cloud/audit-logs/#automated-export"&gt;first-class feature&lt;/a&gt;. You will never have to worry about responding quickly when someone asks about an event that happened in your system. Also, each deployment and update has logs directly visible from the Pulumi Cloud app, regardless of how it was initiated.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/images/docs/guides/self-hosted/auditlogs.png"
alt="Figure: Viewing the audit log in Pulumi Cloud"&gt;&lt;figcaption&gt;
&lt;p&gt;Figure: Viewing the audit log in Pulumi Cloud&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3 id="developer-experience"&gt;Developer Experience&lt;/h3&gt;
&lt;p&gt;Probably the most compelling aspect of Pulumi is the developer experience. &lt;a href="https://www.pulumi.com/testimonials/"&gt;Developers love Pulumi&lt;/a&gt;, because they get to use their preferred tools. General purpose programming languages, visual IDEs, command-line tools, and products with an API-driven architecture are what developers want, and it&amp;rsquo;s what Pulumi delivers in spades.&lt;/p&gt;
&lt;p&gt;With Pulumi templates and custom internal component resources in place, &lt;a href="https://www.pulumi.com/blog/software-developer-experience-devex-devx-devops-culture/#how-does-devex-intersect-with-devops"&gt;developers can drive their own DevOps&lt;/a&gt;, provisioning their own infrastructure resources and managing their own deployments directly, reducing bottlenecks in platform teams. Product engineering teams can self-service with a stream-lined workflow that stays compliant with company policy by default. Deep in the code of their favorite programming languages, your developers will never even know they are following the company rules.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://www.pulumi.com/blog/pulumi-patterns-and-practices/pulumi-ide.png"
alt="Figure: Using C# to write a Pulumi program in VS Code"&gt;&lt;figcaption&gt;
&lt;p&gt;Figure: Using C# to write a Pulumi program in VS Code&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3 id="more-to-come"&gt;More to Come&lt;/h3&gt;
&lt;p&gt;So now that we&amp;rsquo;ve made a case for how Pulumi can be applied to meet the most pressing needs of a larger organization, hopefully you will realize that the Pulumi Patterns and Practices Platform (P3) reference architecture we are presenting here is more than just infrastructure-as-code. P3 is a Pulumi-powered platform for teams, where your developer portal is not just a catalog of software, but a fully functional control-plane across all your cloud environments.&lt;/p&gt;
&lt;p&gt;Stay tuned for the following series of posts where we will use Pulumi to implement the P3 reference architecture for a fully-featured internal developer platform (IDP, or IPfDPE if you prefer). That said, you may already have invested in some popular in cloud-native tools like &lt;a href="https://www.pulumi.com/blog/pulumi-in-a-cloud-native-world/#the-kebap-stack-reference-architecture"&gt;Backstage&lt;/a&gt; or &lt;a href="https://www.pulumi.com/blog/kubernetes-4-0-even-more-kubernetes-native/"&gt;Kubernetes&lt;/a&gt;. Pulumi plays well with others, and you will be delighted to see &lt;a href="https://www.pulumi.com/blog/pulumi-in-a-cloud-native-world"&gt;how you can use Pulumi to cover the gaps&lt;/a&gt; in the &lt;a href="https://www.cncf.io/"&gt;CNCF&lt;/a&gt; ecosystem.&lt;/p&gt;
&lt;p&gt;And if you are already ready to get your hands on Pulumi after this introduction, feel free to &lt;a href="https://www.pulumi.com/signup/"&gt;create an account&lt;/a&gt; and follow some of our &lt;a href="https://www.pulumi.com/docs/get-started/"&gt;Getting Started&lt;/a&gt; guides to see how easy simple use cases are and begin to imagine how that same developer experience will scale up to your entire organization.&lt;/p&gt;
&lt;p&gt;To learn more, you can watch the following video which provides a high level overview of how Pulumi works:&lt;/p&gt;
&lt;div class="rounded-md shadow border border-gray-300 w-3/4 mx-auto my-4" style="position: relative; padding-bottom: 40.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe
src="//www.youtube.com/embed/Q8tw6YTD3ac?rel=0"
style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;"
allowfullscreen=""
title="Introduction to Pulumi in Three Minutes"
srcdoc="&lt;style&gt;*{padding:0;margin:0;overflow:hidden}html,body{height:100%}img{position:absolute;width:100%;top:0;bottom:0;margin:auto}&lt;/style&gt;&lt;a href=https://www.youtube.com/embed/Q8tw6YTD3ac?autoplay=1&gt;&lt;img src='https://www.pulumi.com/images/home/youtube-getting-started.png' alt='Introduction to Pulumi in Three Minutes'&gt;&lt;/a&gt;"&gt;
&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="pulumi-cloud"&gt;Pulumi Cloud&lt;/h2&gt;
&lt;p&gt;The Pulumi Cloud is a fully managed service that helps you adopt Pulumi&amp;rsquo;s open source SDK with ease. It provides built-in state and secrets management, integrates with source control and CI/CD, and offers a web console and API that make it easier to visualize and manage infrastructure. It is free for individual use, with features available for teams.&lt;/p&gt;
&lt;p&gt;&lt;a class="btn btn-secondary" href="https://app.pulumi.com/signup" target="_blank"&gt;Create an Account&lt;/a&gt;&lt;/p&gt;</description><author>Troy Howard</author><category>platform-engineering</category><category>patterns-and-practices-platform</category><category>developer-experience</category><category>devsecops</category><category>architecture</category><category>enterprise</category><category>devops</category></item></channel></rss>