Skip to main content

Pulumi ESC

Environments, Secrets, and Configuration consumed by Pulumi stacks and apps. Tutorials, templates, examples, blog posts, and workshops for Pulumi ESC.

Browse all
Tutorials

Learn by doing

Templates

Bootstrap new projects

Examples

Browse real-world programs

From the blog

Keep your skills current

Blog PostOct 2024

Pulumi ESC and External Secrets Operator: The Perfect Solution for Today's Cloud-Native Secret Management

Learn how to manage Kubernetes secrets with Pulumi ESC and External Secrets Operator
Engin Diri
Blog PostJun 2026

Deploy a Private Hermes Agent on Render Securely with Pulumi, Modal, and Tailscale

Deploy a self-hosted Hermes agent as one Pulumi program across Render, Modal, and Tailscale — a code-executing AI agent with nothing on the public internet.
Engin Diri
Blog PostJan 2026

Deploy OpenClaw on AWS or Hetzner Securely with Pulumi and Tailscale

Deploy OpenClaw (formerly Moltbot/Clawdbot), an open-source AI assistant, to AWS and Hetzner using Pulumi with Tailscale for secure private access.
Engin Diri
Blog PostNov 2023

Secure your Kubernetes toolchain with Pulumi ESC and OIDC

With Pulumi and ESC, we provide an automated workflow that generates a kubeconfig on the fly for every command using short term credentials issued via OIDC.
Levi Blackstone and Eron Wright
Blog PostJun 2026

Fully Automated AI Inference on AWS, Azure, and Google Cloud with Pulumi

A zero-touch Ollama GPU inference server on AWS, Azure, or Google Cloud as one Pulumi program, with OIDC credentials from Pulumi ESC and no static keys.
Engin Diri
Blog PostDec 2024

Master Kubernetes Secrets with Pulumi ESC + Secrets Store CSI Driver

Learn how to manage Kubernetes secrets securely with Pulumi ESC and the Secrets Store CSI Driver.
Engin Diri
Blog PostFeb 2026

How We Load Data into Snowflake in Seconds with Pulumi

Learn how we load data into Snowflake in seconds using Firehose direct streaming and reusable Pulumi ComponentResources.
Pablo Seibelt and Lucas Crespo
Workshops

Get hands-on live — or catch a recording

The infrastructure as code platform for any cloud.