Get started with Discovery & governance
Discovery is the resource-scanning product in Pulumi Cloud that helps you discover, understand, manage, and improve your cloud infrastructure. It improves security, compliance, and efficiency through AI-powered asset and compliance management.
Discovery gives you the tools to:
Discover: Scan and sync all your cloud infrastructure – including resources provisioned manually or through other tools like Terraform, CloudFormation, Kubernetes and ARM – to bring everything under a single pane of glass. Gain complete visibility across clouds, regions, and accounts.
Understand: Analyze your cloud infrastructure with powerful search and AI-driven insights. Use natural language queries to find resources, identify underutilized or untagged assets, and uncover trends that help you align with business goals.
Manage: Group related resources into logical units that reflect your business priorities. Use these groupings to identify policy violations, enforce tagging standards, and ensure compliance across your organization.
Improve: Optimize your cloud infrastructure with actionable recommendations. Detect and remediate security violations, reduce costs by identifying inefficient resources, and enforce compliance policies.
If you only want to enforce policies on your Pulumi IaC stacks, skip ahead to Enforce policy as code.
This guide will take you through the following steps to get started with Discovery:
- Confirm the prerequisites for connecting your cloud accounts.
- Connect a cloud account and run your first discovery scan.
- Manage your accounts and launch scans on demand.
- Search and explore your resources on the Resources page, including with natural language queries.
- Apply the Pulumi Best Practices policy pack to your discovered resources and your Pulumi stacks.