Pulumi ESC provides centralized environments, secrets, and configuration management and orchestration that helps streamline operations, improve traceability, and ensure consistent security practices. Pull and sync secrets with any secrets store, and consume secrets in any application, tool, or CI/CD platform.
Pulumi ESC is a centralized secrets management & orchestration service that makes it easy to securely access, share, and manage secrets on any cloud using your favorite programming languages. You can pull and sync secrets with any secrets store - including HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, 1Password, and more - and consume secrets in any application, tool, or CI/CD platform. Pulumi ESC leverages the same Pulumi Cloud identity, RBAC, Teams, SAML/SCIM, OIDC, and scoped access tokens used for Pulumi IaC to ensure secrets management complies with enterprise security policies. Every time secrets or configuration values are accessed or changed, the action is fully logged for auditing. So you can trust (and prove) your secrets are secure. Pulumi ESC makes it easy for developers to access secrets via a CLI, API, Kubernetes operator, the Pulumi Cloud UI, and in-code with Typescript/Javascript, Python, and Go SDKs.
Highlights
Frictionless Security
Easy-to-use single source of truth for all configuration and secrets with guardrails. Seamlessly adopt short-lived dynamic secrets.
Improve Developer Efficiency
Never have downtime over changed configuration. Change once and have it updated everywhere.
Control Access and Compliance
Enforce least-privileged access through role-based access controls. All changes are fully logged for auditing.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing bundles secrets management pricing into two parts. The base Pulumi ESC unit gives you a set allotment of 2,500 secrets under a contract commitment. The Additional ESC Secrets unit scales your capacity beyond that base, billed per secret per month. A secret can be either a static secret or a dynamic credential. Together, these dimensions let you commit to a starting capacity and add more as your usage grows.
Top-of-mind questions for buyers
What counts as one secret for billing purposes?
A secret includes both static secrets and dynamic credentials. In the ESC Document Editor, each definition of fn::secret:* and fn::open::* counts as a secret. Only secrets from the latest environment revision count toward your total. This applies to both the base 2,500 allotment and additional secrets.
What happens if I use more than the 2,500 secrets in the base unit?
You add capacity through the Additional ESC Secrets unit, billed per secret per month. The base Pulumi ESC unit covers your first 2,500 secrets. Beyond that, each extra secret adds to your monthly charge under the additional unit.
How do the two ESC dimensions combine on my bill?
Both dimensions bill together on the same invoice. The base Pulumi ESC unit provides your 2,500-secret commitment. The Additional ESC Secrets unit charges per secret per month for anything above that. Your total combines the committed base plus any additional secrets used.
pulumi.com
Helpful?
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Enterprise Support Available including 12x5, 12x7 and 24x7 Options.
Customers with Enterprise Support Agreements can contact support@pulumi.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Pulumi is the AI-native infrastructure platform. Cloud engineering teams define, deploy, and manage cloud infrastructure as code using general-purpose programming languages like Python, TypeScript, Go, C#, and Java so infrastructure evolves the same way software does and speaks the same language as AI coding agents. Pulumi works across AWS and hundreds of cloud and service providers.
This product has charges associated with it for seller support. Instead of relying on domain-specific languages, Pulumi enables modern software engineering practices such as version control, testing, and reuse when working with cloud infrastructure across providers like AWS, Azure, and Google Cloud. Pulumi is a modern Infrastructure as Code (IaC) tool designed to simplify cloud resource management by allowing developers to use general-purpose programming languages instead of specialized configuration files.
This product has charges associated with it for seller support. Instead of relying on domain-specific languages, Pulumi enables modern software engineering practices such as version control, testing, and reuse when working with cloud infrastructure across providers like AWS, Azure, and Google Cloud. Pulumi is a modern Infrastructure as Code (IaC) tool designed to simplify cloud resource management by allowing developers to use general-purpose programming languages instead of specialized configuration files.
The Pulumi Model Context Protocol (MCP) server enables AI-powered code assistants like Cursor, Claude Code, and others. Describe cloud architecture in natural language and automatically generate, validate, and deploy Pulumi code.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.