Pulumi Terraform To Pulumi

pulumi/agent-skills/migration/skills/pulumi-terraform-to-pulumi

by pulumi900eacf4444fNo license70 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated yesterday

Migrate Terraform/OpenTofu projects to Pulumi, including translating HCL source code and/or importing Terraform state into a Pulumi stack. Use when a user wants to convert Terraform to Pulumi, migrate from HCL, or import tfstate into Pulumi. Do NOT trigger for general Terraform-vs-Pulumi comparisons or questions about using both tools side-by-side.

Instructions onlyDevOps & Cloud
AI-generated overview

Migrates Terraform or OpenTofu projects to Pulumi by translating HCL source and importing Terraform state into a Pulumi stack.

What it does
This skill guides an agent through converting a Terraform/OpenTofu project into a Pulumi project in a chosen language. It creates an empty Pulumi project and stack, pulls remote Terraform state when no local state file exists, runs the terraform-migrate plugin to produce a draft Pulumi state translation, installs the required Pulumi providers, and imports the translated state into the stack. It then translates the source code to match the Terraform source and translated state, iterating until preview shows an empty or nearly empty diff, and finally opens a pull request with the migrated code.
When to use it
Use when a user wants to convert Terraform or OpenTofu HCL to Pulumi, migrate from HCL, or import tfstate into a Pulumi stack. It is not intended for general Terraform-versus-Pulumi comparisons or questions about using both tools side by side.
Requirements
Requires the Pulumi CLI with the terraform-migrate plugin (auto-installed), the pulumi_up and pulumi_preview tools, and either the terraform or tofu CLI for pulling state. Provider credentials are needed for refresh, potentially supplied through a Pulumi ESC environment, plus network access and a language-specific package manager (npm, pip, go, or dotnet). It ships no scripts; it is instructions only.

Migrating from Terraform to Pulumi

Critical constraints — read before acting:

  • Do NOT run pulumi convert — use the terraform-migrate plugin instead, which preserves state mapping.
  • Do NOT run pulumi package add terraform-module — this is for a different workflow.
  • Do NOT create the Pulumi project under /workspace — create it inside the checked-out repo.
  • Replace ${terraform_dir} and ${pulumi_dir} below with the actual paths confirmed with the user.

First establish scope and plan the migration by working out with the user:

  • where the Terraform sources are (${terraform_dir})
  • where the migrated Pulumi project lives (${pulumi_dir})
  • what is the target Pulumi language (such as TypeScript, Python, YAML)
  • whether migration aims to setup Pulumi stack states, or only translate source code

Confirm the plan with the user before proceeding.

Create a new Pulumi project in ${pulumi_dir} in the chosen language. Edit sources to be empty and not declare any resources. Ensure a Pulumi stack exists.

You must run pulumi_up tool before proceeding to ensure initial stack state is written.

If no local .tfstate file exists in ${terraform_dir}, the state may be in a remote backend (S3, Pulumi Cloud, Terraform Cloud, etc.). Pull it before proceeding:

cd ${terraform_dir} && terraform state pull > terraform.tfstate

This works for all backends, including Pulumi Cloud. If terraform is not available, try tofu state pull instead.

Now produce a draft Pulumi state translation:

pulumi plugin run terraform-migrate -- stack \    --from ${terraform_dir} \    --to ${pulumi_dir} \    --out /tmp/pulumi-state.json \    --plugins /tmp/required-providers.json

Do NOT install the plugin as it will auto-install as needed.

Sometimes terraform-migrate plugin fails because tofu refresh is not authorized. DO NOT skip this step. Work with the user to find or build a Pulumi ESC environment that provides the necessary credentials so the command can succeed. If setting up an ESC environment is not feasible, inform the user that the migration cannot proceed automatically.

Read the generated /tmp/required-providers.json and install all these Pulumi providers into the new project, respecting the suggested versions even if they downgrade an already installed provider. The file will contain records such as [{"name":"aws","version":"7.12.0"}].

Install providers as project dependencies using the language-specific package manager (NOT pulumi plugin install, which only downloads plugins without adding dependencies):

# TypeScript/JavaScriptnpm install @pulumi/[email protected]
# Pythonpip install pulumi_aws==7.12.0
# Gogo get github.com/pulumi/pulumi-aws/sdk/[email protected]
# C#dotnet add package Pulumi.Aws --version 7.12.0

Import the translated state draft (/tmp/pulumi-state.json) into the Pulumi stack:

pulumi stack import --file /tmp/pulumi-state.json

Translate source code to match both the Terraform source and the translated state. Aim for exact match. You can consult the state draft /tmp/pulumi-state.json for Pulumi resource types and names to use.

Iterate on fixing the source code until pulumi_preview tool confirms that there are no changes to make and the diff is empty or almost empty. Provider diffs or diffs on tags may be OK.

Offer the user to link an ESC environment to the stack so that each Pulumi stack can seamlessly have access to the provider credentials it needs.

When all looks good, create a Pull Request with the migrated source code.

Source and attribution

Source:pulumi/agent-skillsinmigration/skills/pulumi-terraform-to-pulumiat commit900eacf

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal