All skills
pulumi avatar

/pulumi-cdk-to-pulumi

@2f41625 official
by pulumipulumi/agent-skills70 stars
6

Load this skill when a user wants to migrate, convert, port, translate, or move an AWS CDK application (including CDK stacks, constructs, or CloudFormation-synthesized templates) to Pulumi. Phrases such as "convert CDK to Pulumi", "migrate CDK app", "port CDK stacks", "replace CDK with Pulumi", "stop using CDK". Do NOT load for general CDK questions, CDK-only help, or CDK vs Pulumi comparisons where no migration is requested.

Use this Skill: https://skilld.dev/gh/pulumi/agent-skills/pulumi-cdk-to-pulumi

This session only. Nothing lands on disk.

cdk-importer.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Pulumi CDK Importer Tool

This tool assists migrating CDK-managed infrastructure to Pulumi. It imports existing AWS resources from CloudFormation stacks into Pulumi state.

Installation

pulumi plugin install tool cdk-importer

Credentials

Running the cdk-importer tool requires credentials loaded via Pulumi ESC.

  • If the user has already provided an ESC environment, use it.
  • If no ESC environment is specified, ask the user which ESC environment to use before proceeding with using the tool.

You MUST confirm the AWS region with the user. The results may be incorrect if ran with the wrong AWS Region. The region can be set with the AWS_REGION environment variable

Commands

program import

Import into the selected Pulumi stack using an existing generated Pulumi program.

pulumi plugin run cdk-importer -- program import \
  --program-dir ./generated \
  --stack MyStack

Required flags:

  • --program-dir: Path to an existing Pulumi program generated from a CDK app
  • --stack: CloudFormation stack name (can be specified multiple times or comma-separated)

Optional flags:

  • --import-file: Path to write a Pulumi bulk import file with failing resources (defaults to import.json when provided without a value)
  • --debug: Enable line by line logging of imported resources

Behavior:

  • Runs against the selected Pulumi stack.
  • With --import-file, writes the bulk import file after import. The file will only contain entries for resources that failed to import with <PLACEHOLDER> ids.
  • Can be run iteratively to progressively import resources.

Example Output:

[INFO] Getting stack resources component="cdk-importer" stack=NeoExample-Dev
[INFO] Starting up providers... component="cdk-importer"
[INFO] Importing stack... component="cdk-importer"
[INFO] Run complete component="cdk-importer" status="success" resourcesImported=50 resourcesFailedToImport=0 stack="NeoExample-Dev" importFile="/workspace/pulumi-example-app-neo/import.json" importFileExists=true

Import File Output

The generated import.json includes:

  • Full AWS resource metadata (type, logical name, provider reference, component bit, provider version)
  • Property subsets captured during provider interception

Resources with composite identifiers may show <PLACEHOLDER> IDs that need manual completion before running pulumi import --file import.json.

Unsupported Resources

Resources that cannot be imported:

  • CFN Custom Resources (aws-native:cloudformation:CustomResourceEmulator)

Example Workflow

  1. Generate a Pulumi program from your CDK app using cdk2pulumi

  2. Import into your real stack:

    pulumi plugin run cdk-importer -- program import \
      --program-dir ./pulumi-program-dir \
      --stack CdkStack

Handling Failures

This tool may not support 100% of the CloudFormation resources in the stack. For unsupported resources it is necessary to find the import ID and import manually.

Example output:

[INFO] Getting stack resources component="cdk-importer" stack=NeoExample-Dev
[INFO] Starting up providers... component="cdk-importer"
[INFO] Importing stack... component="cdk-importer"
[INFO] Pulumi errors component="cdk-importer" details=urn:pulumi:dev::cdk-convert-example::aws:rds/proxyDefaultTargetGroup:ProxyDefaultTargetGroup::DatabaseDbClusterDbProxyProxyTargetGroupA552DCC1: Don't have an ID!: aws:rds/proxyDefaultTargetGroup:ProxyDefaultTargetGroup neo-example-dev-database-db-cluster-db-proxy-eede4daa urn:pulumi:dev::cdk-convert-example::aws:rds/proxyDefaultTargetGroup:ProxyDefaultTargetGroup::DatabaseDbClusterDbProxyProxyTargetGroupA552DCC1

update failed
[INFO] Run complete component="cdk-importer" status="failed" resourcesImported=69 resourcesFailedToImport=1 stack="NeoExample-Dev"
- operation failed

Example Failure Workflow:

  1. Import ran with error

  2. Review failures and run pulumi preview.

    • Any resources that fail to import should appear as creations in the preview.
    • Optionally run program import with the --import-file flag to generate a import.json file with the failing resources.
  3. Manually import remaining resources

Source: SKILL.md on GitHub

No alerts16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill automates the migration of AWS CDK applications to Pulumi by executing official Pulumi conversion tools and AWS CLI commands. It handles AWS resource discovery and CloudFormation template processing. The primary security considerations involve standard infrastructure tool behaviors and a surface for indirect prompt injection via local CDK configuration files.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    4/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 2f41625. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 6 months ago
  • TypeScript
  • aws-cdk
  • pulumi
  • migration
  • cloudformation
  • infrastructure-as-code
  • iac

README badge

README badge for pulumi/agent-skills/pulumi-cdk-to-pulumi

Converts AWS CDK applications (stacks, constructs, CloudFormation templates) to Pulumi using the cdk2pulumi tool, then optionally imports existing resources for Pulumi management. Handles resource mapping, custom resources (Lambda-backed), assets, bundling, and multi-stack environments with a structured migration workflow and PR-ready report.

Generated from the current SKILL.md.

What CDK constructs does this skill handle?
The skill converts AWS CDK stacks, L1/L2/L3 constructs, and CloudFormation-synthesized templates to Pulumi TypeScript. It uses the cdk2pulumi tool for automated conversion and handles custom resources, assets, bundling, and cross-stack references.
Does this skill import existing AWS resources or just convert code?
The skill first converts CDK code to Pulumi code. Resource import is optional and performed after conversion using the cdk-importer tool to make Pulumi manage existing cloud resources.
What happens with CDK Custom Resources?
Custom Resources are converted to aws-native:cloudformation:CustomResourceEmulator by default, which invokes the original Lambda handler. The skill provides strategies to replace specific handlers (e.g. auto-delete-objects, certificate validation) with native Pulumi resources where practical.
Does this handle Docker images and bundled assets in CDK?
Yes. Docker images are migrated to docker-build.Image. Static files use pulumi.FileArchive or pulumi.FileAsset. For bundled artifacts (NodejsFunction, PythonFunction, etc.), the skill detects the bundling step and documents it—you must decide whether to replicate the build in CI/CD, use command.local.Command, or pre-build separately.
Does this skill require AWS credentials or ESC setup?
Yes. The skill runs cdk synth and AWS CLI commands to inventory resources, which requires AWS credentials loaded via Pulumi ESC. You must specify the ESC environment and confirm the AWS region before migration begins.

Generated from the current SKILL.md. These answers refresh after source changes.