All skills
pulumi avatar

/cloudformation-to-pulumi

@2f41625 official
by pulumipulumi/agent-skills70 stars
6

Convert, migrate, or import AWS CloudFormation stacks or templates into Pulumi programs. Load this skill whenever a user wants to move from CloudFormation to Pulumi, convert a CFN template, import existing CloudFormation-managed resources into Pulumi, or asks about CloudFormation-to-Pulumi migration in any form. Also load when the user mentions cdk-importer in a migration context.

Use this Skill: https://skilld.dev/gh/pulumi/agent-skills/cloudformation-to-pulumi

This session only. Nothing lands on disk.

cfn-importer.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

CloudFormation Stack Importer Tool

This tool imports existing AWS resources from CloudFormation stacks into Pulumi state.

Installation

pulumi plugin install tool cdk-importer

Credentials

Running the cdk-importer tool requires credentials loaded via Pulumi ESC.

  • If the user has already provided an ESC environment, use it.
  • If no ESC environment is specified, ask the user which ESC environment to use before proceeding with using the tool.

You MUST confirm the AWS region with the user. The results may be incorrect if ran with the wrong AWS Region. The region can be set with the AWS_REGION environment variable

Commands

program import

Import into the selected Pulumi stack using an existing Pulumi program.

pulumi plugin run cdk-importer -- program import \
  --program-dir ./generated \
  --stack MyStack

Required flags:

  • --program-dir: Path to the Pulumi program (resource names must match CloudFormation Logical IDs)
  • --stack: CloudFormation stack name (can be specified multiple times or comma-separated)

Optional flags:

  • --import-file: Path to write a Pulumi bulk import file with failing resources (defaults to import.json when provided without a value)
  • --debug: Enable line by line logging of imported resources

Behavior:

  • Runs against the selected Pulumi stack.
  • With --import-file, writes the bulk import file after import. The file will only contain entries for resources that failed to import with <PLACEHOLDER> ids.
  • Can be run iteratively to progressively import resources.

Example Output:

[INFO] Getting stack resources component="cdk-importer" stack=NeoExample-Dev
[INFO] Starting up providers... component="cdk-importer"
[INFO] Importing stack... component="cdk-importer"
[INFO] Run complete component="cdk-importer" status="success" resourcesImported=50 resourcesFailedToImport=0 stack="NeoExample-Dev" importFile="/workspace/pulumi-example-app-neo/import.json" importFileExists=true

Import File Output

The generated import.json includes:

  • Full AWS resource metadata (type, logical name, provider reference, component bit, provider version)
  • Property subsets captured during provider interception

Resources with composite identifiers may show <PLACEHOLDER> IDs that need manual completion before running pulumi import --file import.json.

Unsupported Resources

Resources that cannot be imported:

  • CloudFormation Custom Resources (aws-native:cloudformation:CustomResourceEmulator)

Example Workflow

  1. Convert your CloudFormation template to Pulumi (using CloudFormation Logical IDs as resource names)

  2. Import into your Pulumi stack:

    pulumi plugin run cdk-importer -- program import \
      --program-dir ./pulumi-program-dir \
      --stack MyStack

Handling Failures

This tool may not support 100% of the CloudFormation resources in the stack. For unsupported resources it is necessary to find the import ID and import manually.

Example output:

[INFO] Getting stack resources component="cdk-importer" stack=NeoExample-Dev
[INFO] Starting up providers... component="cdk-importer"
[INFO] Importing stack... component="cdk-importer"
[INFO] Pulumi errors component="cdk-importer" details=urn:pulumi:dev::cdk-convert-example::aws:rds/proxyDefaultTargetGroup:ProxyDefaultTargetGroup::DatabaseDbClusterDbProxyProxyTargetGroupA552DCC1: Don't have an ID!: aws:rds/proxyDefaultTargetGroup:ProxyDefaultTargetGroup neo-example-dev-database-db-cluster-db-proxy-eede4daa urn:pulumi:dev::cdk-convert-example::aws:rds/proxyDefaultTargetGroup:ProxyDefaultTargetGroup::DatabaseDbClusterDbProxyProxyTargetGroupA552DCC1

update failed
[INFO] Run complete component="cdk-importer" status="failed" resourcesImported=69 resourcesFailedToImport=1 stack="NeoExample-Dev"
- operation failed

Example Failure Workflow:

  1. Import ran with error

  2. Review failures and run pulumi preview.

    • Any resources that fail to import should appear as creations in the preview.
    • Optionally run program import with the --import-file flag to generate a import.json file with the failing resources.
  3. Manually import remaining resources using cloudformation-id-lookup.md

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The analyzed skill is safe and presents no security issues. It instructs the agent on migrating AWS CloudFormation templates or stacks into Pulumi programs using native Pulumi commands and extensions.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/4 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 2f41625. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 6 months ago
  • TypeScript
  • cloudformation
  • pulumi
  • aws
  • migration
  • infrastructure-as-code
  • aws-native
  • import

README badge

README badge for pulumi/agent-skills/cloudformation-to-pulumi

Converts AWS CloudFormation templates and stacks into Pulumi programs, mapping CloudFormation resources to aws-native providers while preserving logical IDs for automated import. Handles intrinsic functions, conditions, parameters, and custom resources; supports both template files and live stack fetching from AWS.

Generated from the current SKILL.md.

Does this skill convert CloudFormation templates automatically?
No. There is no automated conversion tool. You must convert each CloudFormation resource manually to Pulumi TypeScript code, mapping intrinsic functions and conditions as you go.
Which Pulumi provider should I use for migrated resources?
Use aws-native by default for all resources, as CloudFormation types map 1:1 to aws-native. Only use the classic aws provider if aws-native lacks a required feature. This is mandatory for successful imports with cdk-importer.
Why does the Pulumi resource name have to match the CloudFormation Logical ID?
The cdk-importer tool matches resources by name to automatically import existing CloudFormation-managed resources into Pulumi. Renaming resources will cause import to fail.
What do I need before starting a migration?
You need the CloudFormation template (provided as a file or fetched from AWS by stack name) and AWS credentials configured via Pulumi ESC. You must also confirm the target AWS region.
How do I know the migration is complete?
After import, run pulumi preview and verify it shows no updates, replaces, creates, or deletes. The skill also requires a formal migration report documenting all resources and any that could not be migrated.

Generated from the current SKILL.md. These answers refresh after source changes.