NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1488 most downloaded on PyPI
Pulumi's Python SDK
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 58 of the last 60 stable releases
7 versions withdrawn
withdrawn after publishing
8 years old
4969 releases · first in 2018
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
pulumi refresh now tries to install any missing plugins automatically like pulumi destroy and pulumi update do (fixes pulumi/pulumi#2669).
pulumi refresh now tries to install any missing plugins automatically like
pulumi destroy and pulumi update do (fixes pulumi/pulumi#2669).pulumi whoami now outputs the URL of the currently connected backend.pulumi preview --json --suppress-outputs.
Fixes pulumi/pulumi#2765.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix an issue where creating a first class provider would fail if any of the configuration values for the providers were secrets. (fixes pulumi/pulumi#
--diff or looking at details for a proposed
updated, the CLI might print text like: <{%reset%}> --outputs:--<{%reset%}> instead of just --outputs:--.\ are not converted to __5c__ in paths.error: could not deserialize deployment: unknown secrets provider type.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Pulumi now tells you much earlier when the --secrets-provider argument to up init or new has the wrong value. In addition, supported values are now li
--secrets-provider argument to
up init or new has the wrong value. In addition, supported values are
now listed in the help text. (fixes pulumi/pulumi#2727).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The Pulumi engine and Python and NodeJS SDKs now have support for tracking values as "secret" to ensure they are encrypted when being persisted in a s
The Pulumi engine and Python and NodeJS SDKs now have support for tracking values as "secret" to ensure they are
encrypted when being persisted in a state file. [pulumi/pulumi#397](https://github.com/pulumi/pulumi/issues/397)
Any existing value may be turned into a secret by calling pulumi.secret(<value>) (NodeJS) or
Output.secret(<value>) (Python). In both cases, the returned value is an output which may be passed around
like any other. If this value flows into a resource, the plaintext will not be stored in the state file, but instead
It will be encrypted, just like values added to config with pulumi config set --secret.
You can verify that values are being stored as you expect by running pulumi stack export, When values are encrypted
in the state file, they appear as an object with a special signature key and a ciphertext property.
When outputs of a stack are secrets, pulumi stack output will show [secret] as the value, by default. You can
pass --show-secrets to pulumi stack output in order to see the actual raw value.
When storing state with the Pulumi Service, you may now elect to use the passphrase based encryption for both secret
configuration values and values that are encrypted in a state file. To use this new feature, pass
--secrets-provider passphrase to pulumi new or pulumi stack init when you initally create the stack. When you
create the stack, you will be prompted for a passphrase (or if PULUMI_CONFIG_PASSPHRASE is set, it will be used).
This passphrase is used to generate a unique key for your stack, and config values and encrypted state values are
encrypted using AES-256-GCM. The key is derived from your passphrase, and while information to re-create it when
provided with your passphrase is stored in both the Pulumi.<stack-name>.yaml file and the state file for your stack,
this information can not be used to recover the key. When using this mode, the Pulumi Service is unable to decrypt
either your secret configuration values or and secret values in your state file.
We will be adding gestures to move existing stacks managed by the service to use passphrase based encryption soon as well as gestures to change the passphrase for an existing stack.
** Note **
Stacks with encrypted secrets in their state files can only be managed by 0.17.11 or later of the CLI. Attempting to use a previous version of the CLI with these stacks will result in an error.
Fixes #397
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixes issue introduced in 0.17.9 where local-login broke on Windows due to the new support for s3://, azblob:// and gs:// save locations.
s3://, azblob:// and gs:// save locations.npm about missing description, repository, and license fields in package.json are
now suppressed when npm install is run from pulumi new (via npm install --loglevel=error).@pulumi/pulumi
more reliable when running on Node 12.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
pulumi login now supports s3://, azblob:// and gs:// paths (on top of file://) for storing stack information. These are passed the location of a desir
pulumi login now supports s3://, azblob:// and gs:// paths (on top of file://) for
storing stack information. These are passed the location of a desired bucket for each respective
cloud provider (i.e. pulumi login s3://mybucket). Pulumi artifacts (like the
xxx.checkpoint.json file) will then be stored in that bucket. Credentials for accessing the
bucket operate in the normal manner for each cloud provider. i.e. for AWS this can come from the
environment, or your .aws/credentials file, etc.PULUMI_SKIP_UPDATE_CHECK to 1 or true.pulumi new <template> -s <existing-stack>.--json flag (-j for short) to the preview command. This allows basic serialization of a plan,
including the anticipated set of deployment steps, list of diagnostics messages, and summary information.
Each step includes deeply serialized information about the resource state and step metadata itself. This
is part of ongoing work tracked in pulumi/pulumi#2390.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add a new ignoreChanges option to resource options to allow specifying a list of properties to ignore for purposes of updates or replacements. #2657
ignoreChanges option to resource options to allow specifying a list of properties to
ignore for purposes of updates or replacements. #2657pulumi/actions container to DockerHub with new SDK releases #2646Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →