All skills
pulumi avatar

/pulumi-cdk-to-pulumi

@2f41625 official
by pulumipulumi/agent-skills70 stars
6

Load this skill when a user wants to migrate, convert, port, translate, or move an AWS CDK application (including CDK stacks, constructs, or CloudFormation-synthesized templates) to Pulumi. Phrases such as "convert CDK to Pulumi", "migrate CDK app", "port CDK stacks", "replace CDK with Pulumi", "stop using CDK". Do NOT load for general CDK questions, CDK-only help, or CDK vs Pulumi comparisons where no migration is requested.

Use this Skill: https://skilld.dev/gh/pulumi/agent-skills/pulumi-cdk-to-pulumi

This session only. Nothing lands on disk.

cloudformation-id-lookup.md

≈720 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Pulumi Import ID Lookup (cdk2pulumi ids)

This tool looks up the required Pulumi import ID format for AWS resources, helping you understand what identifier shape is needed when importing existing AWS resources into Pulumi.

Prerequisites

  • The tool must be installed: pulumi plugin install tool cdk2pulumi
  • Run via: pulumi plugin run cdk2pulumi -- ids <resource-type>

Usage

Look Up by Pulumi Resource Token or CloudFormation type

pulumi plugin run cdk2pulumi -- ids aws-native:s3:Bucket
pulumi plugin run cdk2pulumi -- ids AWS::S3::Bucket

Understanding the Output

The tool returns two key pieces of information:

1. Import ID Format

Shows the structure of the ID required by Pulumi's import command. Examples:

  • Single-part ID: <BucketName> - Just the bucket name
  • Composite ID: <FunctionName>|<StatementId> - Multiple parts separated by delimiters
  • Complex ID: <CertificateAuthorityArn>|<CertificateArn> - ARNs or other identifiers

2. Finding the ID Hint

Provides guidance on how to obtain the actual ID value from AWS:

  • Single-part IDs: "Use the CloudFormation PhysicalResourceId"
    • Find this in CloudFormation via aws cloudformation describe-stack-resources or aws cloudformation list-stack-resources
  • Composite IDs: Shows an aws cloudcontrol list-resources command example
    • May include --resource-model '{...}' when the Cloud Control API requires input parameters
    • Example: aws cloudcontrol list-resources --type-name AWS::Lambda::Permission --resource-model '{"FunctionName":"my-function"}'

Examples

Simple Resource (S3 Bucket)

$ pulumi plugin run cdk2pulumi -- ids AWS::S3::Bucket
Import ID format: <BucketName>
Finding the ID: Use the CloudFormation PhysicalResourceId

Composite ID (Lambda Permission)

$ pulumi plugin run cdk2pulumi -- ids AWS::Lambda::Permission
Import ID format: <FunctionName>|<StatementId>
Finding the ID: aws cloudcontrol list-resources --type-name AWS::Lambda::Permission --resource-model '{"FunctionName":"<function-name>"}'

Complex Resource (ACM PCA Certificate)

$ pulumi plugin run cdk2pulumi -- ids AWS::ACMPCA::Certificate
Import ID format: <CertificateAuthorityArn>|<CertificateArn>
Finding the ID: aws cloudcontrol list-resources --type-name AWS::ACMPCA::Certificate --resource-model '{"CertificateAuthorityArn":"<ca-arn>"}'

Tips for Running

  • Always use -- to separate Pulumi CLI arguments from plugin arguments
  • For composite IDs, pay attention to the delimiter (usually |, /, or :)
  • When the hint shows --resource-model, you'll need to provide known properties to list the resources
  • The PhysicalResourceId from CloudFormation is often the simplest way to find single-part IDs
  • Some resources may require multiple API calls to construct the full composite ID

Source: SKILL.md on GitHub

No alerts16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill automates the migration of AWS CDK applications to Pulumi by executing official Pulumi conversion tools and AWS CLI commands. It handles AWS resource discovery and CloudFormation template processing. The primary security considerations involve standard infrastructure tool behaviors and a surface for indirect prompt injection via local CDK configuration files.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    4/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 2f41625. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 6 months ago
  • TypeScript
  • aws-cdk
  • pulumi
  • migration
  • cloudformation
  • infrastructure-as-code
  • iac

README badge

README badge for pulumi/agent-skills/pulumi-cdk-to-pulumi

Converts AWS CDK applications (stacks, constructs, CloudFormation templates) to Pulumi using the cdk2pulumi tool, then optionally imports existing resources for Pulumi management. Handles resource mapping, custom resources (Lambda-backed), assets, bundling, and multi-stack environments with a structured migration workflow and PR-ready report.

Generated from the current SKILL.md.

What CDK constructs does this skill handle?
The skill converts AWS CDK stacks, L1/L2/L3 constructs, and CloudFormation-synthesized templates to Pulumi TypeScript. It uses the cdk2pulumi tool for automated conversion and handles custom resources, assets, bundling, and cross-stack references.
Does this skill import existing AWS resources or just convert code?
The skill first converts CDK code to Pulumi code. Resource import is optional and performed after conversion using the cdk-importer tool to make Pulumi manage existing cloud resources.
What happens with CDK Custom Resources?
Custom Resources are converted to aws-native:cloudformation:CustomResourceEmulator by default, which invokes the original Lambda handler. The skill provides strategies to replace specific handlers (e.g. auto-delete-objects, certificate validation) with native Pulumi resources where practical.
Does this handle Docker images and bundled assets in CDK?
Yes. Docker images are migrated to docker-build.Image. Static files use pulumi.FileArchive or pulumi.FileAsset. For bundled artifacts (NodejsFunction, PythonFunction, etc.), the skill detects the bundling step and documents it—you must decide whether to replicate the build in CI/CD, use command.local.Command, or pre-build separately.
Does this skill require AWS credentials or ESC setup?
Yes. The skill runs cdk synth and AWS CLI commands to inventory resources, which requires AWS credentials loaded via Pulumi ESC. You must specify the ESC environment and confirm the AWS region before migration begins.

Generated from the current SKILL.md. These answers refresh after source changes.