
How We Eliminated Long-Lived CI Secrets Across 70+ Repos
Learn how Pulumi eliminated static CI secrets across 70+ repos using Pulumi ESC and OIDC, reducing supply chain attack risk with short-lived credentials.
Boris Schlosser
6 min readPage 2 of 6

Learn how Pulumi eliminated static CI secrets across 70+ repos using Pulumi ESC and OIDC, reducing supply chain attack risk with short-lived credentials.
Boris Schlosser
6 min read
Mark configuration values as final in Pulumi ESC to prevent child environments from overriding them with fn::final.

2 authors
2 min read
Learn how we load data into Snowflake in seconds using Firehose direct streaming and reusable Pulumi ComponentResources.

2 authors
13 min read
The terraform-state provider for Pulumi ESC lets you read outputs from Terraform state files directly into your ESC environments.
Claire Gaestel
2 min read
Validate configuration values against JSON Schema with fn::validate in Pulumi ESC.

2 authors
2 min readDeploy OpenClaw (formerly Moltbot/Clawdbot), an open-source AI assistant, to AWS and Hetzner using Pulumi with Tailscale for secure private access.
Engin Diri
We’re introducing the new and improved Pulumi ESC Editor in the Console, designed to make managing secrets and configuration easier, faster, and more intuitive.


3 authors
Apply feature flagging to infrastructure with Pulumi. Control rollouts, reduce deployment risk, and automate updates using ESC or LaunchDarkly.
Elisabeth Lichtie
ESC Connect enables you to integrate any custom or proprietary secret source with Pulumi ESC through simple HTTPS adapters, without waiting for native support.
Claire Gaestel
Prevent accidental deletion of critical environments with the new deletion protection feature for Pulumi ESC.
Fausto Núñez Alberro
Page 2 of 6