pulumi-terraform-to-pulumi

bởi pulumi

Di chuyển các dự án Terraform/OpenTofu sang Pulumi, bao gồm dịch mã nguồn HCL và/hoặc nhập trạng thái Terraform vào một stack Pulumi. Sử dụng khi người dùng…

npx skills add https://github.com/pulumi/agent-skills --skill pulumi-terraform-to-pulumi

Migrating from Terraform to Pulumi

Critical constraints — read before acting:

  • Do NOT run pulumi convert — use the terraform-migrate plugin instead, which preserves state mapping.
  • Do NOT run pulumi package add terraform-module — this is for a different workflow.
  • Do NOT create the Pulumi project under /workspace — create it inside the checked-out repo.
  • Replace ${terraform_dir} and ${pulumi_dir} below with the actual paths confirmed with the user.

First establish scope and plan the migration by working out with the user:

  • where the Terraform sources are (${terraform_dir})
  • where the migrated Pulumi project lives (${pulumi_dir})
  • what is the target Pulumi language (such as TypeScript, Python, YAML)
  • whether migration aims to setup Pulumi stack states, or only translate source code

Confirm the plan with the user before proceeding.

Create a new Pulumi project in ${pulumi_dir} in the chosen language. Edit sources to be empty and not declare any resources. Ensure a Pulumi stack exists.

You must run pulumi_up tool before proceeding to ensure initial stack state is written.

If no local .tfstate file exists in ${terraform_dir}, the state may be in a remote backend (S3, Pulumi Cloud, Terraform Cloud, etc.). Pull it before proceeding:

cd ${terraform_dir} && terraform state pull > terraform.tfstate

This works for all backends, including Pulumi Cloud. If terraform is not available, try tofu state pull instead.

Now produce a draft Pulumi state translation:

pulumi plugin run terraform-migrate -- stack \
    --from ${terraform_dir} \
    --to ${pulumi_dir} \
    --out /tmp/pulumi-state.json \
    --plugins /tmp/required-providers.json

Do NOT install the plugin as it will auto-install as needed.

Sometimes terraform-migrate plugin fails because tofu refresh is not authorized. DO NOT skip this step. Work with the user to find or build a Pulumi ESC environment that provides the necessary credentials so the command can succeed. If setting up an ESC environment is not feasible, inform the user that the migration cannot proceed automatically.

Read the generated /tmp/required-providers.json and install all these Pulumi providers into the new project, respecting the suggested versions even if they downgrade an already installed provider. The file will contain records such as [{"name":"aws","version":"7.12.0"}].

Install providers as project dependencies using the language-specific package manager (NOT pulumi plugin install, which only downloads plugins without adding dependencies):

# TypeScript/JavaScript
npm install @pulumi/aws@7.12.0

# Python
pip install pulumi_aws==7.12.0

# Go
go get github.com/pulumi/pulumi-aws/sdk/v7@v7.12.0

# C#
dotnet add package Pulumi.Aws --version 7.12.0

Import the translated state draft (/tmp/pulumi-state.json) into the Pulumi stack:

pulumi stack import --file /tmp/pulumi-state.json

Translate source code to match both the Terraform source and the translated state. Aim for exact match. You can consult the state draft /tmp/pulumi-state.json for Pulumi resource types and names to use.

Iterate on fixing the source code until pulumi_preview tool confirms that there are no changes to make and the diff is empty or almost empty. Provider diffs or diffs on tags may be OK.

Offer the user to link an ESC environment to the stack so that each Pulumi stack can seamlessly have access to the provider credentials it needs.

When all looks good, create a Pull Request with the migrated source code.

Thêm skills từ pulumi

package-usage
pulumi
Theo dõi các stack trong một tổ chức Pulumi sử dụng một gói cụ thể và ở phiên bản nào. Dùng để kiểm tra chéo giữa các stack, xác định các gói lỗi thời hoặc không được bảo trì…
official
pulumi-automation-api
pulumi
Điều phối lập trình các hoạt động hạ tầng Pulumi trên nhiều stack và ứng dụng. Hỗ trợ cả kiến trúc nguồn cục bộ (dự án Pulumi hiện có) và nguồn nội tuyến (chương trình nhúng), cho phép các mẫu triển khai linh hoạt từ đơn giản đến phức tạp với nhiều stack. Xử lý điều phối nhiều stack với trình tự phụ thuộc, triển khai độc lập song song và truyền đầu ra giữa các stack để cung cấp hạ tầng phối hợp. Cung cấp lập trình...
official
pulumi-best-practices
pulumi
Các phương pháp hay nhất toàn diện để viết mã cơ sở hạ tầng Pulumi đáng tin cậy và dễ bảo trì. Tránh tạo tài nguyên bên trong các callback apply(); truyền trực tiếp các đối tượng Output làm đầu vào để duy trì khả năng theo dõi phụ thuộc và hiển thị xem trước. Sử dụng các lớp ComponentResource để nhóm các tài nguyên liên quan thành các đơn vị logic có thể tái sử dụng với hệ thống phân cấp cha-con phù hợp thông qua parent: this. Mã hóa bí mật ngay từ đầu bằng cờ --secret hoặc config.requireSecret() để ngăn rò rỉ thông tin xác thực trong các tệp trạng thái...
official
pulumi-component
pulumi
Các thành phần cơ sở hạ tầng có thể tái sử dụng với hỗ trợ đa ngôn ngữ, các giá trị mặc định hợp lý và các mẫu tổ hợp. Yêu cầu bốn yếu tố cốt lõi: mở rộng ComponentResource, chấp nhận các tham số tiêu chuẩn, đặt parent: this trên tất cả các thành phần con và gọi registerOutputs() ở cuối hàm tạo. Các giao diện Args phải sử dụng trình bao bọc Input<T>, tránh các kiểu union và hàm, đồng thời giữ cấu trúc phẳng để hỗ trợ tạo SDK đa ngôn ngữ. Chỉ hiển thị các đầu ra thiết yếu dưới dạng thuộc tính công khai; ẩn...
official
pulumi-debug-failed-operation
pulumi
Gỡ lỗi một bản cập nhật hoặc xem trước Pulumi bị lỗi: đọc lỗi mà Pulumi đã ghi lại, tìm nguyên nhân gây ra lỗi và sửa nó. Tải kỹ năng này khi người dùng yêu cầu…
official
pulumi-esc
pulumi
Quản lý tập trung các bí mật, cấu hình và thông tin xác thực động cho cơ sở hạ tầng và ứng dụng Pulumi. Hỗ trợ tổng hợp môi trường thông qua import và phân lớp, với các khóa dành riêng cho environmentVariables, pulumiConfig và files. Tạo thông tin xác thực ngắn hạn qua OIDC cho AWS, Azure và GCP; tích hợp với AWS Secrets Manager, Azure Key Vault, HashiCorp Vault và 1Password. Các lệnh CLI chính bao gồm pulumi env init, pulumi env edit, pulumi env open (hiển thị...
official
pulumi-neo-handoff
pulumi
Chuyển luồng hiện tại sang một tác vụ Pulumi Neo mới dưới dạng chuyển giao một chiều. Sử dụng khi người dùng yêu cầu rõ ràng việc chuyển giao, gửi, chuyển tiếp hoặc tiếp tục hiện tại…
official
pulumi-overview
pulumi
Sử dụng kỹ năng này cho bất kỳ tác vụ nào tạo, sửa đổi, kiểm tra hoặc hủy bỏ cơ sở hạ tầng đám mây hoặc cấu hình SaaS, từ các thao tác CLI đơn lẻ đến toàn bộ…
official