All skills
pulumi avatar

/pulumi-cdk-to-pulumi

@2f41625 official
by pulumipulumi/agent-skills70 stars
6

Load this skill when a user wants to migrate, convert, port, translate, or move an AWS CDK application (including CDK stacks, constructs, or CloudFormation-synthesized templates) to Pulumi. Phrases such as "convert CDK to Pulumi", "migrate CDK app", "port CDK stacks", "replace CDK with Pulumi", "stop using CDK". Do NOT load for general CDK questions, CDK-only help, or CDK vs Pulumi comparisons where no migration is requested.

Use this Skill: https://skilld.dev/gh/pulumi/agent-skills/pulumi-cdk-to-pulumi

This session only. Nothing lands on disk.

cdk-convert.md

≈726 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Pulumi CDK Conversion Tool (cdk2pulumi)

This tool plugin converts AWS CDK Cloud Assemblies to Pulumi YAML programs.

Prerequisites

  • The tool must be installed: pulumi plugin install tool cdk2pulumi
  • All commands run through the Pulumi CLI using: pulumi plugin run cdk2pulumi -- <args>
  • A CDK Cloud Assembly (typically in cdk.out directory) must exist for conversion operations

Commands

1. Convert CDK Assembly to Pulumi YAML

Converts a CDK Cloud Assembly to a Pulumi YAML program (Pulumi.yaml) with an accompanying conversion report (Pulumi.yaml.report.json).

Basic conversion:

pulumi plugin run cdk2pulumi -- --assembly path/to/cdk.out

Required flags:

  • --assembly: Path to the synthesized CDK Cloud Assembly (typically cdk.out directory). By default this will convert the entire CDK application (i.e. all stacks and stages)

Optional flags:

  • --stacks: Comma separated list of CDK Stacks to convert
  • --stage: Filter conversion to a specific CDK Stage
  • --skip-custom: Skip converting CDK custom resources

Important Notes:

  • Cross-stack references in partially converted stacks become config placeholders: ${external.<stack>.<output>}
  • Set these with: pulumi config set external.<stack>.<output> <value> before deployment
  • CDK custom resources are rewritten to aws-native:cloudformation:CustomResourceEmulator
  • The generated code will use the original CDK logical IDS. DO NOT update these otherwise automated import will FAIL

Common Workflows

Converting a CDK Application to Pulumi

  1. Synthesize the CDK app to generate the Cloud Assembly:

    cdk synth
  2. Convert the assembly to Pulumi YAML:

    pulumi plugin run cdk2pulumi -- --assembly cdk.out
  3. Review the conversion report at Pulumi.yaml.report.json to identify any resources that didn't convert 1:1

  4. Set any required config for cross-stack references:

    pulumi config set external.<stack>.<output> <value>
  5. Convert the Pulumi YAML program to the target language:

    pulumi convert --from yaml --generate-only --language typescript --out ./generated-program

    NOTE: after converting to another language you need to remove or rename the Pulumi.yaml file, otherwise it will still be treated as the main application

  6. Preview the Pulumi program:

    pulumi preview

Tips for Running

  • Always use -- to separate Pulumi CLI arguments from plugin arguments
  • The --assembly flag expects a directory path (typically cdk.out), not a file
  • When converting specific stacks, use comma-separated names without spaces: --stacks Stack1,Stack2
  • For multi-stage CDK apps, use --stage <name> to target nested assemblies
  • The tool outputs to Pulumi.yaml by default; use --out to specify a different location

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill automates the migration of AWS CDK applications to Pulumi by executing official Pulumi conversion tools and AWS CLI commands. It handles AWS resource discovery and CloudFormation template processing. The primary security considerations involve standard infrastructure tool behaviors and a surface for indirect prompt injection via local CDK configuration files.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    4/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 2f41625. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 6 months ago
  • TypeScript
  • aws-cdk
  • pulumi
  • migration
  • cloudformation
  • infrastructure-as-code
  • iac

README badge

README badge for pulumi/agent-skills/pulumi-cdk-to-pulumi

Converts AWS CDK applications (stacks, constructs, CloudFormation templates) to Pulumi using the cdk2pulumi tool, then optionally imports existing resources for Pulumi management. Handles resource mapping, custom resources (Lambda-backed), assets, bundling, and multi-stack environments with a structured migration workflow and PR-ready report.

Generated from the current SKILL.md.

What CDK constructs does this skill handle?
The skill converts AWS CDK stacks, L1/L2/L3 constructs, and CloudFormation-synthesized templates to Pulumi TypeScript. It uses the cdk2pulumi tool for automated conversion and handles custom resources, assets, bundling, and cross-stack references.
Does this skill import existing AWS resources or just convert code?
The skill first converts CDK code to Pulumi code. Resource import is optional and performed after conversion using the cdk-importer tool to make Pulumi manage existing cloud resources.
What happens with CDK Custom Resources?
Custom Resources are converted to aws-native:cloudformation:CustomResourceEmulator by default, which invokes the original Lambda handler. The skill provides strategies to replace specific handlers (e.g. auto-delete-objects, certificate validation) with native Pulumi resources where practical.
Does this handle Docker images and bundled assets in CDK?
Yes. Docker images are migrated to docker-build.Image. Static files use pulumi.FileArchive or pulumi.FileAsset. For bundled artifacts (NodejsFunction, PythonFunction, etc.), the skill detects the bundling step and documents it—you must decide whether to replicate the build in CI/CD, use command.local.Command, or pre-build separately.
Does this skill require AWS credentials or ESC setup?
Yes. The skill runs cdk synth and AWS CLI commands to inventory resources, which requires AWS credentials loaded via Pulumi ESC. You must specify the ESC environment and confirm the AWS region before migration begins.

Generated from the current SKILL.md. These answers refresh after source changes.