pulumi-terraform-to-pulumi

von pulumi

Migrieren Sie Terraform-/OpenTofu-Projekte zu Pulumi, einschließlich der Übersetzung von HCL-Quellcode und/oder des Importierens von Terraform-Status in einen Pulumi-Stack. Verwenden Sie, wenn ein Benutzer…

npx skills add https://github.com/pulumi/agent-skills --skill pulumi-terraform-to-pulumi

Migrating from Terraform to Pulumi

Critical constraints — read before acting:

  • Do NOT run pulumi convert — use the terraform-migrate plugin instead, which preserves state mapping.
  • Do NOT run pulumi package add terraform-module — this is for a different workflow.
  • Do NOT create the Pulumi project under /workspace — create it inside the checked-out repo.
  • Replace ${terraform_dir} and ${pulumi_dir} below with the actual paths confirmed with the user.

First establish scope and plan the migration by working out with the user:

  • where the Terraform sources are (${terraform_dir})
  • where the migrated Pulumi project lives (${pulumi_dir})
  • what is the target Pulumi language (such as TypeScript, Python, YAML)
  • whether migration aims to setup Pulumi stack states, or only translate source code

Confirm the plan with the user before proceeding.

Create a new Pulumi project in ${pulumi_dir} in the chosen language. Edit sources to be empty and not declare any resources. Ensure a Pulumi stack exists.

You must run pulumi_up tool before proceeding to ensure initial stack state is written.

If no local .tfstate file exists in ${terraform_dir}, the state may be in a remote backend (S3, Pulumi Cloud, Terraform Cloud, etc.). Pull it before proceeding:

cd ${terraform_dir} && terraform state pull > terraform.tfstate

This works for all backends, including Pulumi Cloud. If terraform is not available, try tofu state pull instead.

Now produce a draft Pulumi state translation:

pulumi plugin run terraform-migrate -- stack \
    --from ${terraform_dir} \
    --to ${pulumi_dir} \
    --out /tmp/pulumi-state.json \
    --plugins /tmp/required-providers.json

Do NOT install the plugin as it will auto-install as needed.

Sometimes terraform-migrate plugin fails because tofu refresh is not authorized. DO NOT skip this step. Work with the user to find or build a Pulumi ESC environment that provides the necessary credentials so the command can succeed. If setting up an ESC environment is not feasible, inform the user that the migration cannot proceed automatically.

Read the generated /tmp/required-providers.json and install all these Pulumi providers into the new project, respecting the suggested versions even if they downgrade an already installed provider. The file will contain records such as [{"name":"aws","version":"7.12.0"}].

Install providers as project dependencies using the language-specific package manager (NOT pulumi plugin install, which only downloads plugins without adding dependencies):

# TypeScript/JavaScript
npm install @pulumi/aws@7.12.0

# Python
pip install pulumi_aws==7.12.0

# Go
go get github.com/pulumi/pulumi-aws/sdk/v7@v7.12.0

# C#
dotnet add package Pulumi.Aws --version 7.12.0

Import the translated state draft (/tmp/pulumi-state.json) into the Pulumi stack:

pulumi stack import --file /tmp/pulumi-state.json

Translate source code to match both the Terraform source and the translated state. Aim for exact match. You can consult the state draft /tmp/pulumi-state.json for Pulumi resource types and names to use.

Iterate on fixing the source code until pulumi_preview tool confirms that there are no changes to make and the diff is empty or almost empty. Provider diffs or diffs on tags may be OK.

Offer the user to link an ESC environment to the stack so that each Pulumi stack can seamlessly have access to the provider credentials it needs.

When all looks good, create a Pull Request with the migrated source code.

Mehr Skills von pulumi

package-usage
pulumi
Verfolgen, welche Stacks in einer Pulumi-Organisation ein bestimmtes Paket und in welchen Versionen verwenden. Für organisationsweite Audits, um veraltete oder nicht gewartete…
official
pulumi-automation-api
pulumi
Programmatische Orchestrierung von Pulumi-Infrastrukturoperationen über mehrere Stacks und Anwendungen hinweg. Unterstützt sowohl lokale Quellen (bestehende Pulumi-Projekte) als auch Inline-Quellen (eingebettete Programme), wodurch flexible Bereitstellungsmuster von einfachen bis zu komplexen Multi-Stack-Szenarien ermöglicht werden. Handhabt Multi-Stack-Orchestrierung mit Abhängigkeitssequenzierung, parallelen unabhängigen Bereitstellungen und stackübergreifender Ausgabeweitergabe für koordinierte Infrastrukturbereitstellung. Bietet programmatische...
official
pulumi-best-practices
pulumi
Umfassende Best Practices für das Schreiben zuverlässiger, wartbarer Pulumi-Infrastrukturcode. Vermeiden Sie die Erstellung von Ressourcen innerhalb von apply()-Callbacks; übergeben Sie Output-Objekte direkt als Eingaben, um Abhängigkeitsverfolgung und Vorschau-Sichtbarkeit zu erhalten. Verwenden Sie ComponentResource-Klassen, um verwandte Ressourcen in wiederverwendbare logische Einheiten mit korrekter Eltern-Kind-Hierarchie über parent: this zu gruppieren. Verschlüsseln Sie Secrets von Anfang an mit dem --secret-Flag oder config.requireSecret(), um das Durchsickern von Anmeldeinformationen in Zustandsdateien zu verhindern...
official
pulumi-component
pulumi
Wiederverwendbare Infrastrukturkomponenten mit Mehrsprachenunterstützung, sinnvollen Standardeinstellungen und Kompositionsmustern. Erfordert vier Kernelemente: ComponentResource erweitern, Standardparameter akzeptieren, parent: this für alle Kinder setzen und registerOutputs() am Ende des Konstruktors aufrufen. Args-Schnittstellen müssen Input<T>-Wrapper verwenden, Union-Typen und Funktionen vermeiden und Strukturen flach halten, um die SDK-Generierung für mehrere Sprachen zu unterstützen. Nur wesentliche Ausgaben als öffentliche Eigenschaften verfügbar machen; ausblenden...
official
pulumi-debug-failed-operation
pulumi
Debuggen Sie ein fehlgeschlagenes Pulumi-Update oder Preview: Lesen Sie den bereits aufgezeichneten Fehler von Pulumi, finden Sie die Ursache und beheben Sie ihn. Laden Sie diese Fähigkeit, wenn der Benutzer darum bittet…
official
pulumi-esc
pulumi
Zentralisierte Verwaltung von Secrets, Konfiguration und dynamischen Anmeldeinformationen für Pulumi-Infrastruktur und -Anwendungen. Unterstützt Umgebungskomposition durch Importe und Schichtung, mit reservierten Schlüsseln für environmentVariables , pulumiConfig und files . Erzeugt kurzlebige Anmeldeinformationen über OIDC für AWS, Azure und GCP; integriert mit AWS Secrets Manager, Azure Key Vault, HashiCorp Vault und 1Password. Zu den CLI-Kernbefehlen gehören pulumi env init , pulumi env edit , pulumi env open (zeigt...
official
pulumi-neo-handoff
pulumi
Übergabe des aktuellen Threads an eine neue Pulumi Neo-Aufgabe als Einweg-Transfer. Verwenden Sie dies, wenn der Benutzer explizit darum bittet, den aktuellen Thread zu übergeben, zu senden, zu transferieren oder fortzusetzen…
official
pulumi-overview
pulumi
Verwenden Sie diese Fähigkeit für jede Aufgabe, die Cloud-Infrastruktur oder SaaS-Konfiguration erstellt, ändert, überprüft oder zerstört, von einmaligen CLI-Operationen bis hin zu vollständigen…
official