Guides
Procedures for setting up and running a Pulumi Cloud organization. Each guide is self-contained, so start with whichever matches what you are trying to do. For the model these guides configure, see Concepts.
Identity and single sign-on
- SAML SSO — connect Pulumi Cloud to Microsoft Entra ID, Okta, Google Workspace, Auth0, JumpCloud, or OneLogin.
- SCIM — automate user and team provisioning from your identity provider.
- OIDC issuers — let GitHub, GitLab, or a Kubernetes cluster exchange its own OIDC tokens for Pulumi Cloud credentials.
Security and compliance
- Export audit logs — stream your organization’s audit log to AWS S3 or Microsoft Sentinel.
- Customer managed keys — bring your own encryption key from an external key management system.
- Least privilege — apply least-privilege access across IaC, ESC, and CI/CD.