Pulumi ESC Environments and Secrets Prompt
Centralize configuration and secrets with Pulumi ESC — composable environments, dynamic cloud credentials via OIDC, and consumption from Pulumi, Terraform, and plain shells — without scattering secrets across stacks.
- Target user
- Platform teams unifying config/secrets across IaC tools and CI
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior platform engineer who has rolled out Pulumi ESC (Environments, Secrets, and Configuration) as the single source of truth for config and short-lived credentials across multiple IaC tools. I will provide: - Where my config/secrets live today (stack config, Vault, SSM, .env files) - Which tools consume them (Pulumi, Terraform, kubectl, CI runners, app runtime) - My cloud(s) and current credential model (long-lived keys vs OIDC) - Environments and teams that need scoped access Your job: 1. **Why ESC** — explain the model: environments are composable YAML documents that resolve config + secrets, support imports/inheritance, and can mint dynamic credentials at open time. Compare to plain Pulumi config and to Vault for my case. 2. **Environment design** — propose a hierarchy: base environments (org defaults), per-cloud credential environments, per-app environments that `imports:` the bases. Show the tree and one composed environment. 3. **Dynamic credentials via OIDC** — configure `aws-login`/`gcp-login`/`azure-login` providers so opening an environment exchanges an OIDC token for short-lived cloud credentials — eliminating static keys. Show the config. 4. **Secrets handling** — mark values secret, integrate external secret stores (Vault, 1Password, cloud secret managers) as providers, and explain how interpolation and `fn::` functions compose values. 5. **Multi-tool consumption** — show how the same environment feeds: Pulumi stacks (`environment:` in stack config), Terraform (via `esc run -- terraform ...` exporting env vars/`TF_VAR_`), kubectl, and CI runners (`esc open --format dotenv`). 6. **Access control** — RBAC on environments by team, and how to avoid over-broad imports that leak prod secrets into dev. 7. **Auditing and rotation** — what ESC logs, how dynamic creds remove rotation burden, and how to detect stale static secrets to delete. 8. **Migration plan** — phased move from my current store to ESC without a flag day, with a fallback. Output as: (a) environment hierarchy diagram, (b) annotated base + app environment YAML, (c) the OIDC dynamic-credential config, (d) consumption snippets for Pulumi, Terraform, and CI, (e) a migration runbook. Default to dynamic, short-lived credentials over static keys everywhere it is possible.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Pulumi Secrets Provider Migration & Key Rotation Prompt
Migrate a Pulumi stack's secrets provider (passphrase to KMS/Vault or between clouds) and rotate the encryption key so all encrypted config and state secrets are re-wrapped without leaking plaintext.
-
CloudFormation Dynamic References for SSM & Secrets Manager Prompt
Replace hardcoded secrets and config in CloudFormation templates with resolve dynamic references to SSM Parameter Store and Secrets Manager, including versioning, rotation, and no-echo handling.
-
Pulumi Transformations & Aliases Refactor Prompt
Refactor Pulumi resource names, parents, and structure at scale using aliases and stack transformations so URNs change on paper but no live resource is destroyed or replaced.
-
Pulumi Refresh & Drift Remediation Prompt
Detect and safely reconcile out-of-band drift between a Pulumi stack's state and live cloud reality — deciding per resource whether to adopt, revert, or ignore the change without triggering an unwanted replace.
More Infrastructure as Code prompts & error guides
Browse every Infrastructure as Code prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.