One year ago, my team and I made what felt like a bold (some might say risky) decision. While the infrastructure-as-code (IaC) world is dominated by Terraform, we chose Pulumi for a complex Azure infrastructure for an AI-driven project.
Today, after countless deployments, several hours of fixing broken environments and ultimately transformative successes, I can confidently say Pulumi has not only proven itself worthy but has become our preferred choice for complex infrastructure challenges.
Here's the fundamental insight that took us too long to grasp: Pulumi isn't just "infrastructure as code" — it's infrastructure as real code, with all the power and responsibility that entails using a programming language.
This distinction might seem subtle, but it fundamentally changed our approach to provisioning infrastructure. You're not learning a domain-specific language to declare infrastructure; you're using actual programming languages to build it, which changes everything.
After managing production workloads at scale, we can share a balanced perspective: Pulumi has evolved into a mature, powerful tool that excels in specific scenarios — particularly when you need the full power of programming languages for managing your infrastructure.
As a Nearform team working closely with Microsoft Azure (we're proud Azure partners), we needed an IaC solution that could handle the complexity of modern cloud architectures while enabling our development team to contribute meaningfully to infrastructure management. What started as an experiment has evolved into a cornerstone of our infrastructure strategy.
This isn't another "getting started with Pulumi" guide. Instead, I want to share the unvarnished truth about our journey — the chaos of early adoption, the failures that taught us crucial lessons and the practices that transformed Pulumi from a promising tool into a production powerhouse.
If you're evaluating IaC tools or struggling with Pulumi adoption, this is the guide we wish we'd had a year ago.
How Pulumi stacks up today
Before diving into our journey, let's address the elephant in the room: how does Pulumi compare to its competitors in 2025? The landscape has shifted considerably since we wrote this blog post in 2022. The IaC landscape has evolved, Pulumi has matured significantly, and we've accumulated battle scars and wisdom that only come from running production workloads at scale.
| Feature | Pulumi | Terraform | CDK for Terraform |
|---|---|---|---|
| Language support | Python, TypeScript, Go, C#, Java, YAML | HCL (proprietary) | TypeScript, Python, Java, C#, Go |
| Type safety | Full type safety in supported languages | Limited (HCL constraints) | Full type safety |
| Testing capabilities | Native unit/integration testing | Requires external tools | Native testing support |
| Provider coverage | 100% coverage via native providers | Extensive, mature ecosystem | Depends on Terraform providers |
| State management | Managed service or self-hosted | Self-managed or Terraform Cloud | Uses Terraform state |
| Secret management | Built-in encryption | Requires external tools | Inherits Terraform approach |
| Learning curve | Moderate (if you know the language) | Moderate (new DSL) | Steep (abstraction layers) |
| Community maturity | Growing rapidly | Very mature | Smaller, growing |
| Policy as code | CrossGuard with multi-language support | Sentinel (Enterprise plan only) | Limited |
| Enterprise features | RBAC, audit logs, policy as code | Comprehensive (with Enterprise plan) | Limited |
| Abstraction | Component resource (Use Multi Language Component) | Modules | Uses Terraform |
A note on other IaC tools: You might wonder why we haven't included tools like AWS CloudFormation, Azure Bicep/ARM templates, or other cloud-native solutions in our comparison. While these are excellent tools with strong adoption in their respective ecosystems, they didn't align with our specific requirements. CloudFormation and Bicep are cloud-specific solutions that wouldn't support our multi-cloud strategy, and as template-based declarative tools, they wouldn't have provided the programming language benefits that were central to our decision criteria. Our evaluation focused on tools that could leverage our team's existing Python expertise while supporting infrastructure patterns across multiple cloud providers.
The expanding Pulumi ecosystem
One aspect that has matured significantly since 2022 is Pulumi's ecosystem. While our journey focused primarily on core infrastructure provisioning, it's worth noting that Pulumi now offers a comprehensive platform of tools that teams can adopt as their needs grow:
-
The ecosystem has evolved to include CrossGuard for policy-as-code enforcement, allowing organisations to codify compliance requirements that automatically validate deployments across any language.
-
Pulumi ESC (Environments, Secrets and Configuration) provides a centralised solution for managing configuration hierarchies and secrets across multiple environments and teams.
-
For organisations seeking deeper infrastructure insights, Pulumi Insights offers real-time visibility into cloud spend, resource utilisation and optimisation opportunities.
-
Teams looking to build internal developer platforms can leverage Pulumi IDP’s capabilities to create self-service infrastructure templates.
-
The platform now supports three distinct types of packages: Native Providers that offer immediate access to cloud features; Bridged Providers that allow integration with the Terraform ecosystem; Component Packages that enable sharing of higher-level infrastructure patterns across teams and organisations.
-
Cross-language consumption: Components written in one language can now be used in any Pulumi language.
While my team and I haven't adopted all these tools in our stack, their availability represents the maturing ecosystem around Pulumi. Organisations can start with basic infrastructure-as-code and gradually adopt additional platform features as their needs evolve, without having to switch tools or rewrite existing infrastructure.
Performance improvements include slashing deployment time by 40%
What's particularly noteworthy is Pulumi's performance improvements. The Azure Native provider v3, released in 2024, brought substantial performance enhancements that transformed our deployment experience.
We saw deployment times cut by up to 40% for large Azure infrastructures, thanks to optimised resource batching and parallel processing improvements. The provider now handles resource dependencies more intelligently, reducing unnecessary API calls and wait times.
Recent benchmarks show enormous Python performance improvements, with 3x increases for loading provider libraries and provisioning the infrastructure. Additionally, the new refresh and destroy experiences have dramatically reduced operation times. The native providers, especially for Azure, now offer same-day support for new cloud features — a game-changer for teams working with cutting-edge services.
But specifications only tell part of the story. Let me share what it's really like to use Pulumi in production.
Why we chose Pulumi (setting the stage)
Our requirements seemed straightforward enough:
- Build a complex Azure infrastructure supporting AI-driven applications
- Enable our development team to contribute to infrastructure without extensive DevOps training
- Ensure infrastructure could be tested, versioned and reused across environments
- Implement robust secret management without additional tooling
As a small team, we needed to maximise efficiency. The promise of using Python (our team's primary language) for infrastructure was compelling. Unlike Terraform's HCL, which would require learning a new DSL or CDK for Terraform with its abstraction overhead, Pulumi offered direct access to cloud resources using familiar programming constructs.
The decision seemed obvious at the time. Looking back, we were right about the destination but naive about the journey.

What's next?
In this series, I'll take you through our complete Pulumi journey:
- Part 1 (this article): Understanding the current IaC landscape and why we chose Pulumi
- Part 2: The chaos of learning Pulumi in production - our mistakes, failures, and the turning point — coming soon!
- Part 3: Battle-tested best practices and our final verdict on when to use (and not use) Pulumi — coming soon!
The story continues with real examples of what went wrong, why it went wrong and how we transformed our approach. If you're considering using Pulumi or struggling with your implementation, Part 2 will show you exactly what to expect and how to avoid our mistakes.
But wait - there's more.
Nearform publishes real-world learnings on data & AI, engineering, and digital strategy - with more merged in weekly.
Insights
Perspectives on AI in engineering, product development, and strategy, for enterprise executives.
Community
Deep dives and tutorials by engineers, for engineers.
You may also like

Stop losing filter state: Shareable URLs for AG grid with ag-grid-url-sync

