Pulumi v3.256.0

v3.256.0
Added 3
  • Add `--ignore-protect` flag to `pulumi up`, `pulumi preview` and `pulumi destroy` to allow deleting protected resources without unprotecting them in the state first
  • Add an optional `--export-env-vars` flag to the `env provider {aws,azure,gcp}-login` commands to also set the standard SDK environment variables referencing the login outputs
  • Add a `--server` flag to `pulumi package add`, `publish`, `get-schema`, `get-mapping`, `gen-sdk`, `info` and `pulumi schema check` that skips package resolution and uses the given URL as the plugin download URL
Fixed 17
  • Fix `pulumi login --insecure` not being reflected in the stack's service secrets manager state, which caused TLS verification failures against self-hosted backends using self-signed certificates
  • Scope current stack selection to the active backend so switching backends no longer surfaces stale stack errors
  • Parent an invoke written inside a component to that component, lower a component's outputs, and only import `fmt` when a component needs it in Go program generation
  • Parent an invoke written inside a component to that component in Python program generation so it resolves the component's providers
  • Defer output-form invokes that depend on a remote component whose resources are pending creation in Node.js by declaring invoke dependencies to the engine
  • Gate invokes on the created-ness of their declared dependencies, including the children of remote components, resolving them as unknown during previews that still have to create them
3.256.0 (2026-08-04)
Features
  • [cli] Add --ignore-protect flag to pulumi up, pulumi preview and pulumi destroy to allow deleting protected resources without unprotecting them in the state first #24053
  • [cli/env] Add an optional --export-env-vars flag to the env provider {aws,azure,gcp}-login commands to also set the standard SDK environment variables referencing the login outputs #24055
  • [cli] Add a --server flag to pulumi package add, publish, get-schema, get-mapping, gen-sdk, info and pulumi schema check that skips package resolution and uses the given URL as the plugin download URL #24107
Bug Fixes
  • [backend/service] Fix pulumi login --insecure not being reflected in the stack's service secrets manager state, which caused TLS verification failures against self-hosted backends using self-signed certificates #24134
  • [cli] Scope current stack selection to the active backend so switching backends no longer surfaces stale stack errors #23974
  • [programgen/go] Parent an invoke written inside a component to that component, lower a component's outputs, and only import fmt when a component needs it #24019
  • [programgen/python] Parent an invoke written inside a component to that component, so it resolves the component's providers #24018
  • [sdk/nodejs] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24042
  • [engine] Gate invokes on the created-ness of their declared dependencies, including the children of remote components, resolving them as unknown during previews that still have to create them #24040
  • [sdk/go] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24044
  • [pcl] Declare invoke dependencies to the engine so invokes that depend on pending resources, including remote components, resolve as unknown during previews #24041
  • [sdk/python] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24043
  • [cli/env] env provider no longer writes a new environment revision when the resulting definition is unchanged #24055
  • [sdk/go] Output-form invokes now infer their resource dependencies from their arguments, so they are skipped during preview while a dependent resource is pending creation and their results carry those dependencies #24054
  • [sdkgen/go] Fixes nested optional output conversions #24096
  • [engine] Fix a plugin process leak in NewPolicyAnalyzer when ConfigureStack fails after the plugin has booted #24106
  • [programgen/go] Avoid redundant applies when projecting properties from generated Go object outputs #24112
  • [backend/diy] Fix 403 errors writing to third-party S3-compatible backends (e.g. IBM COS, MinIO) by defaulting request_checksum_calculation to when_required when the s3:// backend URL sets a custom endpoint #24109
  • [programgen/nodejs] Avoid redundant applies when projecting properties from Node.js outputs #24119
  • [programgen/python] Avoid redundant applies when projecting properties from Python outputs #24120
  • [sdk] Fix apply erroring for skipped resources #24108
  • [cli] Retry rate-limited (HTTP 429) API requests when they are safe to retry, honoring the server's Retry-After header #24131
  • [cli] Exit non-zero from remote operations (pulumi up --remote, pulumi deployment run) when the deployment fails #24155
  • [cli/new] Resolve and install packages required by the program during pulumi new, as pulumi install does #24126
  • [cli] Make --remote not require a Pulumi.yaml file to be present #24128
  • [cli/import] Generate explicit providers in the import file resources #24135
  • [sdk/nodejs] Fix trustedDependencies parsing for bun #24145
  • [auto/go] ImportResources no longer leaks --stack into the converter's arguments when converter args are passed #24146
  • [auto/go] Fix ImportResources when GenerateCode(false) is set #24147
  • [sdk/go] Fix hooks and transforms causing panics with mocks #24161
  • [programgen/go] Fix plain invokes emitting nonexistent ...ArgsArgs argument types #24172
Improvements
  • [cli/import] Error when running pulumi import --from terraform in a Pulumi HCL project #23744
  • [programgen] Add ID type to PCL #22702
  • [engine] Give the resource monitor's Invoke its own response message, separating it from the one a provider returns #24100
  • [cli/do] Allow stateful resources to register their own provider resources based on provider inputs on the command line #24098
  • [cli] Refresh the first-login welcome message to link your Pulumi Cloud console and the Pulumi changelog #24122
  • [cli/do] Add support for the --provider argument for stateful operations #24132
  • [programgen/go] Better typing for maps, using known types rather than map[string]interface{} #24142
  • [cli/import] Serve the package-resolver service to state converters via resolver_target on ConvertStateRequest, so converters can resolve package specifications the same way the CLI does #24174
Miscellaneous
  • [cli] Retire the Pulumi AI mode of pulumi new (interactive choice and --ai/--language flags). The backing service has been shut down; use pulumi neo instead. #24116
  • [sdk/dotnet] Upgrade dotnet to v3.110.0 #24175
  • [yaml] Upgrade yaml to v1.38.1 #24175
View original

Upgraded? How did it go?

Discussion