All skills
pulumi avatar

/cloudformation-to-pulumi

@2f41625 official
by pulumipulumi/agent-skills70 stars
6

Convert, migrate, or import AWS CloudFormation stacks or templates into Pulumi programs. Load this skill whenever a user wants to move from CloudFormation to Pulumi, convert a CFN template, import existing CloudFormation-managed resources into Pulumi, or asks about CloudFormation-to-Pulumi migration in any form. Also load when the user mentions cdk-importer in a migration context.

Use this Skill: https://skilld.dev/gh/pulumi/agent-skills/cloudformation-to-pulumi

This session only. Nothing lands on disk.

cloudformation-id-lookup.md

≈720 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Pulumi Import ID Lookup (cdk2pulumi ids)

This tool looks up the required Pulumi import ID format for AWS resources, helping you understand what identifier shape is needed when importing existing AWS resources into Pulumi.

Prerequisites

  • The tool must be installed: pulumi plugin install tool cdk2pulumi
  • Run via: pulumi plugin run cdk2pulumi -- ids <resource-type>

Usage

Look Up by Pulumi Resource Token or CloudFormation type

pulumi plugin run cdk2pulumi -- ids aws-native:s3:Bucket
pulumi plugin run cdk2pulumi -- ids AWS::S3::Bucket

Understanding the Output

The tool returns two key pieces of information:

1. Import ID Format

Shows the structure of the ID required by Pulumi's import command. Examples:

  • Single-part ID: <BucketName> - Just the bucket name
  • Composite ID: <FunctionName>|<StatementId> - Multiple parts separated by delimiters
  • Complex ID: <CertificateAuthorityArn>|<CertificateArn> - ARNs or other identifiers

2. Finding the ID Hint

Provides guidance on how to obtain the actual ID value from AWS:

  • Single-part IDs: "Use the CloudFormation PhysicalResourceId"
    • Find this in CloudFormation via aws cloudformation describe-stack-resources or aws cloudformation list-stack-resources
  • Composite IDs: Shows an aws cloudcontrol list-resources command example
    • May include --resource-model '{...}' when the Cloud Control API requires input parameters
    • Example: aws cloudcontrol list-resources --type-name AWS::Lambda::Permission --resource-model '{"FunctionName":"my-function"}'

Examples

Simple Resource (S3 Bucket)

$ pulumi plugin run cdk2pulumi -- ids AWS::S3::Bucket
Import ID format: <BucketName>
Finding the ID: Use the CloudFormation PhysicalResourceId

Composite ID (Lambda Permission)

$ pulumi plugin run cdk2pulumi -- ids AWS::Lambda::Permission
Import ID format: <FunctionName>|<StatementId>
Finding the ID: aws cloudcontrol list-resources --type-name AWS::Lambda::Permission --resource-model '{"FunctionName":"<function-name>"}'

Complex Resource (ACM PCA Certificate)

$ pulumi plugin run cdk2pulumi -- ids AWS::ACMPCA::Certificate
Import ID format: <CertificateAuthorityArn>|<CertificateArn>
Finding the ID: aws cloudcontrol list-resources --type-name AWS::ACMPCA::Certificate --resource-model '{"CertificateAuthorityArn":"<ca-arn>"}'

Tips for Running

  • Always use -- to separate Pulumi CLI arguments from plugin arguments
  • For composite IDs, pay attention to the delimiter (usually |, /, or :)
  • When the hint shows --resource-model, you'll need to provide known properties to list the resources
  • The PhysicalResourceId from CloudFormation is often the simplest way to find single-part IDs
  • Some resources may require multiple API calls to construct the full composite ID

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The analyzed skill is safe and presents no security issues. It instructs the agent on migrating AWS CloudFormation templates or stacks into Pulumi programs using native Pulumi commands and extensions.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/4 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 2f41625. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 6 months ago
  • TypeScript
  • cloudformation
  • pulumi
  • aws
  • migration
  • infrastructure-as-code
  • aws-native
  • import

README badge

README badge for pulumi/agent-skills/cloudformation-to-pulumi

Converts AWS CloudFormation templates and stacks into Pulumi programs, mapping CloudFormation resources to aws-native providers while preserving logical IDs for automated import. Handles intrinsic functions, conditions, parameters, and custom resources; supports both template files and live stack fetching from AWS.

Generated from the current SKILL.md.

Does this skill convert CloudFormation templates automatically?
No. There is no automated conversion tool. You must convert each CloudFormation resource manually to Pulumi TypeScript code, mapping intrinsic functions and conditions as you go.
Which Pulumi provider should I use for migrated resources?
Use aws-native by default for all resources, as CloudFormation types map 1:1 to aws-native. Only use the classic aws provider if aws-native lacks a required feature. This is mandatory for successful imports with cdk-importer.
Why does the Pulumi resource name have to match the CloudFormation Logical ID?
The cdk-importer tool matches resources by name to automatically import existing CloudFormation-managed resources into Pulumi. Renaming resources will cause import to fail.
What do I need before starting a migration?
You need the CloudFormation template (provided as a file or fetched from AWS by stack name) and AWS credentials configured via Pulumi ESC. You must also confirm the target AWS region.
How do I know the migration is complete?
After import, run pulumi preview and verify it shows no updates, replaces, creates, or deletes. The skill also requires a formal migration report documenting all resources and any that could not be migrated.

Generated from the current SKILL.md. These answers refresh after source changes.