Comprehensive performance and reliability guide for Pulumi infrastructure as code, designed for AI agents and LLMs. Contains 46 rules across 8 categories, prioritized by impact to guide automated refactoring and code generation.
When to Apply
Reference these guidelines when:
Writing new Pulumi infrastructure code
Designing component abstractions for reuse
Configuring secrets and sensitive values
Organizing stacks and cross-stack references
Setting up CI/CD pipelines for infrastructure
Rule Categories by Priority
Priority
Category
Impact
Prefix
1
State Management and Backend
CRITICAL
pstate-
2
Resource Graph Optimization
CRITICAL
graph-
3
Component Design
HIGH
pcomp-
4
Secrets and Configuration
HIGH
secrets-
5
Stack Organization
MEDIUM-HIGH
stack-
6
Resource Options and Lifecycle
MEDIUM
lifecycle-
7
Testing and Validation
MEDIUM
test-
8
Automation and CI/CD
LOW-MEDIUM
auto-
Quick Reference
1. State Management and Backend (CRITICAL)
pstate-backend-selection - Use managed backend for production stacks
pstate-checkpoint-skipping - Enable checkpoint skipping for large stacks
pstate-stack-size - Keep stacks under 500 resources
pstate-refresh-targeting - Use targeted refresh instead of full stack
pstate-export-import - Use state export/import for migrations
pstate-import-existing - Import existing resources before managing
2. Resource Graph Optimization (CRITICAL)
graph-parallel-resources - Structure resources for maximum parallelism
graph-output-dependencies - Use outputs to express true dependencies
graph-explicit-depends - Use dependsOn only for external dependencies
graph-avoid-apply-side-effects - Avoid side effects in apply functions
graph-conditional-resources - Use conditional logic at resource level
lifecycle-delete-before-replace - Use deleteBeforeReplace for unique constraints
lifecycle-retain-on-delete - Use retainOnDelete for shared resources
lifecycle-ignore-changes - Use ignoreChanges for externally managed properties
lifecycle-replace-on-changes - Use replaceOnChanges for immutable dependencies
lifecycle-aliases - Use aliases for safe resource renaming
lifecycle-custom-timeouts - Set custom timeouts for long-running resources
7. Testing and Validation (MEDIUM)
test-unit-mocking - Use mocks for fast unit tests
test-property-policies - Use policy as code for property testing
test-integration-ephemeral - Use ephemeral stacks for integration tests
test-preview-assertions - Assert on preview results before deployment
test-stack-reference-mocking - Mock stack references in unit tests
8. Automation and CI/CD (LOW-MEDIUM)
auto-automation-api-workflows - Use Automation API for complex workflows
auto-inline-programs - Use inline programs for dynamic infrastructure
auto-ci-cd-preview - Run preview in PR checks
auto-deployments-api - Use Pulumi Deployments for GitOps
auto-review-stacks - Use review stacks for PR environments
auto-drift-detection - Enable drift detection for production
How to Use
Read individual reference files for detailed explanations and code examples:
Section definitions - Category structure and impact levels
Rule template - Template for adding new rules
Full Compiled Document
For the complete guide with all rules expanded: AGENTS.md
1---2name: pulumi3description: Pulumi Best Practices4---5# Pulumi Best Practices67Comprehensive performance and reliability guide for Pulumi infrastructure as code, designed for AI agents and LLMs. Contains 46 rules across 8 categories, prioritized by impact to guide automated refactoring and code generation.89## When to Apply1011Reference these guidelines when:12- Writing new Pulumi infrastructure code13- Designing component abstractions for reuse14- Configuring secrets and sensitive values15- Organizing stacks and cross-stack references16- Setting up CI/CD pipelines for infrastructure1718## Rule Categories by Priority1920| Priority | Category | Impact | Prefix |21|----------|----------|--------|--------|22| 1 | State Management and Backend | CRITICAL | `pstate-` |23| 2 | Resource Graph Optimization | CRITICAL | `graph-` |24| 3 | Component Design | HIGH | `pcomp-` |25| 4 | Secrets and Configuration | HIGH | `secrets-` |26| 5 | Stack Organization | MEDIUM-HIGH | `stack-` |27| 6 | Resource Options and Lifecycle | MEDIUM | `lifecycle-` |28| 7 | Testing and Validation | MEDIUM | `test-` |29| 8 | Automation and CI/CD | LOW-MEDIUM | `auto-` |3031## Quick Reference3233### 1. State Management and Backend (CRITICAL)3435- `pstate-backend-selection` - Use managed backend for production stacks36- `pstate-checkpoint-skipping` - Enable checkpoint skipping for large stacks37- `pstate-stack-size` - Keep stacks under 500 resources38- `pstate-refresh-targeting` - Use targeted refresh instead of full stack39- `pstate-export-import` - Use state export/import for migrations40- `pstate-import-existing` - Import existing resources before managing4142### 2. Resource Graph Optimization (CRITICAL)4344- `graph-parallel-resources` - Structure resources for maximum parallelism45- `graph-output-dependencies` - Use outputs to express true dependencies46- `graph-explicit-depends` - Use dependsOn only for external dependencies47- `graph-avoid-apply-side-effects` - Avoid side effects in apply functions48- `graph-conditional-resources` - Use conditional logic at resource level49- `graph-stack-references-minimal` - Minimize stack reference depth5051### 3. Component Design (HIGH)5253- `pcomp-component-resources` - Use ComponentResource for reusable abstractions54- `pcomp-parent-child` - Pass parent option to child resources55- `pcomp-unique-naming` - Use name prefix pattern for unique resource names56- `pcomp-register-outputs` - Register component outputs explicitly57- `pcomp-multi-language` - Design components for multi-language consumption58- `pcomp-transformations` - Use transformations for cross-cutting concerns5960### 4. Secrets and Configuration (HIGH)6162- `secrets-use-secret-config` - Use secret config for sensitive values63- `secrets-avoid-state-exposure` - Prevent secret leakage in state64- `secrets-external-providers` - Use external secret managers for production65- `secrets-generate-random` - Generate secrets with random provider66- `secrets-provider-rotation` - Rotate secrets provider when team members leave67- `secrets-environment-isolation` - Isolate secrets by environment6869### 5. Stack Organization (MEDIUM-HIGH)7071- `stack-separation-by-lifecycle` - Separate stacks by deployment lifecycle72- `stack-references-parameterized` - Parameterize stack references73- `stack-output-minimal` - Export only required outputs74- `stack-naming-conventions` - Use consistent stack naming convention7576### 6. Resource Options and Lifecycle (MEDIUM)7778- `lifecycle-protect-stateful` - Protect stateful resources79- `lifecycle-delete-before-replace` - Use deleteBeforeReplace for unique constraints80- `lifecycle-retain-on-delete` - Use retainOnDelete for shared resources81- `lifecycle-ignore-changes` - Use ignoreChanges for externally managed properties82- `lifecycle-replace-on-changes` - Use replaceOnChanges for immutable dependencies83- `lifecycle-aliases` - Use aliases for safe resource renaming84- `lifecycle-custom-timeouts` - Set custom timeouts for long-running resources8586### 7. Testing and Validation (MEDIUM)8788- `test-unit-mocking` - Use mocks for fast unit tests89- `test-property-policies` - Use policy as code for property testing90- `test-integration-ephemeral` - Use ephemeral stacks for integration tests91- `test-preview-assertions` - Assert on preview results before deployment92- `test-stack-reference-mocking` - Mock stack references in unit tests9394### 8. Automation and CI/CD (LOW-MEDIUM)9596- `auto-automation-api-workflows` - Use Automation API for complex workflows97- `auto-inline-programs` - Use inline programs for dynamic infrastructure98- `auto-ci-cd-preview` - Run preview in PR checks99- `auto-deployments-api` - Use Pulumi Deployments for GitOps100- `auto-review-stacks` - Use review stacks for PR environments101- `auto-drift-detection` - Enable drift detection for production102103## How to Use104105Read individual reference files for detailed explanations and code examples:106107- [Section definitions](references/_sections.md) - Category structure and impact levels108- [Rule template](assets/templates/_template.md) - Template for adding new rules109110## Full Compiled Document111112For the complete guide with all rules expanded: `AGENTS.md`
Run npx skillmds@latest add comeonoliver/pulumi in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Pulumi Best Practices It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
ComeOnOliver (@comeonoliver) published this skill. Their other Agent Skills are listed on their SkillMD profile.