
Pulumi launches IDP to speed secure cloud infrastructure delivery
Pulumi IDP is built on the company's open-source infrastructure as code (IaC) technology and caters to organisations seeking to deliver cloud infrastructure at scale. According to Pulumi, the product allows engineering teams to move from initial ideas to cloud deployment within minutes, while embedding security, compliance, and organisational controls into the process.
The company stated that Pulumi IDP has been developed based on insights from a customer base of over 3,500 organisations and 350,000 users. Many customers have independently built internal developer platforms, leveraging Pulumi's IaC platform. Pulumi IDP aims to consolidate best practices from these implementations into a single, complete platform for software delivery with built-in security and governance.
James Forcier, Staff Software Engineer at CLEAR, commented on the platform's development, saying, "We've spent a lot of time building our internal developer platform. We moved from a lower-level Terraform and HCL-based interface to Pulumi, letting us use a custom, higher-level, and much simpler-to-use YAML schema we've defined. We've made cloud infrastructure really easy to use for our developers."
Gartner has predicted that 80% of large organisations will adopt internal developer platforms in the coming two years. Pulumi IDP seeks to balance a flexible approach that enables developer self-service with guardrails and structure provided by platform teams.
The platform allows teams to codify and enforce organisational best practices, publishing reusable infrastructure patterns as components, templates, and policies in a private organisation registry. This registry supports infrastructure definitions in TypeScript, Python, Go, C#, Java, or YAML, and includes features such as built-in documentation, search, semantic versioning, and usage tracking.
Developers, data scientists, and other users can use Pulumi IDP to provision and manage cloud infrastructure through multiple interfaces: a no-code user interface, low-code YAML-based CI/CD pipelines, infrastructure as code in their preferred language, or via a REST API. Projects can be grouped into 'Services', which serve as logical containers for infrastructure, configuration, secrets, documentation, and observability dashboards. Example use cases for Services include web applications, microservices, Jupyter notebooks, and data pipelines.
Pulumi IDP also addresses ongoing operational needs, supporting activities such as drift and policy detection, remediation of non-compliant infrastructure, auditing of outdated components, and change management during version upgrades. The platform features approval workflows to maintain organisational oversight and a new visual import tool for onboarding existing infrastructure into Pulumi management.
An advanced identity and access management system underpins Pulumi IDP, providing least-privilege access via custom roles, permissions, fine-grained access controls, and integration with SAML/SSO identity providers. These security features extend Pulumi's existing enterprise security foundation to support compliance requirements.
Pulumi IDP is available both as a managed SaaS offering and a self-hosted solution for organisations with complex compliance needs. It integrates with other Pulumi enterprise capabilities including Pulumi Copilot for AI-driven infrastructure management, Pulumi Deployments for workflow automation, Pulumi CrossGuard for policy enforcement, alongside a unified REST API and extensible data model.
Joe Duffy, Co-Founder and Chief Executive Officer of Pulumi, outlined the platform's value proposition: "CTOs, CIOs, and engineering leaders tell us that the pace of innovation is faster than ever. To succeed, developers must move fast – without breaking things. Pulumi IDP is the cloud infrastructure platform modern teams have been asking for: infrastructure-first, multi-cloud, immensely powerful and flexible, with built-in security and full visibility and controls. It turns the cloud into a competitive advantage."
Supporting perspectives from industry partners reflect the importance of visibility and standard workflows across internal developer platforms. Zachary Cook, Senior Manager of DevOps at Modivcare, remarked, "By integrating Pulumi Policy as Code with Insights Account Scanning and our developer portal, we're achieving the holy grail for Platform Engineering: instant visibility and governance over legacy infrastructure that isn't yet defined in IaC, while also accelerating our path to production for new cloud-native projects."
Justin Cormack, Chief Technology Officer at Docker, highlighted synergies between the companies: "Docker makes software supply chains more secure by standardising build, packaging, and shipping containerised applications - core to any modern internal developer platform. Pulumi complements this by enabling platform teams to define secure, reusable infrastructure patterns. Golden paths are incredibly important to our customers, and we're excited that Pulumi makes it easier to create and adopt them. Together, Docker and Pulumi help teams streamline developer workflows and accelerate delivery from code to cloud."
Pulumi IDP is now in public preview and is free to use for Pulumi customers and community members. General availability and additional enterprise pricing are expected later in the year.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Techday NZ
19 hours ago
- Techday NZ
Upwind named CNADR company of the year & praised by analysts
Upwind has been recognised by Frost & Sullivan and Gartner in 2025, including being named Company of the Year in the CNADR sector and cited across several analyst reports. Frost & Sullivan awarded Upwind the 2025 Company of the Year title in the Global Cloud-Native Application Detection & Response (CNADR) market, highlighting the company's growth and approach to cloud-native security. At the same time, Upwind featured in Gartner's 2025 Market Guide for Cloud-Native Application Protection Platforms (CNAPP) and was listed as a sample vendor on three of Gartner's 2025 Hype Cycles related to workload and network security, container technologies, and platform engineering. Analyst assessments Upwind was featured in the Hype Cycle for Workload and Network Security, the Hype Cycle for Container Technologies, and the Hype Cycle for Platform Engineering for 2025, all under the CNAPP category. In these reports, CNAPP is identified by Gartner as a technology with a "High Benefit Rating" expected to reach mainstream adoption within two to five years, citing rising demand for consolidated cloud-native security solutions across Kubernetes and multicloud environments. Gartner's 2025 Market Guide for CNAPP includes Upwind among the representative vendors in a sector that, according to the guide, is consolidating security capabilities to provide full-lifecycle protection, from development to runtime in modern multicloud landscapes. The guide notes that CNAPPs are geared to deliver integrated protection across dynamic, container-based application environments. "Upwind's real-time insights and support have enhanced our cloud security operations," said Sardorbek Pulatov, VP Engineering & Security at Vestiaire Collective. "Upwind saves us a significant amount of time, helping our team focus on the truly critical alerts while disregarding low-priority findings. With Upwind, we are able to identify any vulnerabilities and can prioritise them for remediation - helping us operate more efficiently and securely." Gartner also noted in its Market Guide for CNAPP that, "by 2029, 40% of enterprises that successfully implement zero trust within cloud service provider environments will rely on the advanced visibility and control capabilities offered by CNAPP solutions". Additionally, Upwind reports a customer rating of 4.9 out of 5 on Gartner Peer Insights for CNAPP, based on verified reviews. Frost & Sullivan's report flagged Upwind's rapid annual growth of over 4,000 percent year-on-year and its success in integrating previously disparate tools into a single platform, noting its efforts in runtime intelligence in particular. Technical approach and platform features Upwind's cloud security platform is designed using a Runtime-first approach. The company states that its architecture, which incorporates a lightweight eBPF-based sensor, enables full-stack visibility and real-time threat response without adding operational overhead for development teams. A key feature of the Upwind platform is the "Threat Stories" capability, which connects runtime signals, configuration data, audit logs, and identity information in a unified dashboard. This allows security teams to trace threats directly to the source code or deployment pipeline responsible for introducing vulnerabilities. "Security can't be bolted on after deployment. It has to be built in continuously, contextually, and with developers at the center," said Amiram Shachar, CEO and Co-Founder of Upwind. "To us, this wave of analyst recognition validates the strength of our vision, our product, and most importantly, our team. Upwind's momentum is driven by real customer adoption, technical innovation, and word-of-mouth from the people who use and love our platform. We're not building for the exit; we're building for impact. We're focused on solving real, complex problems for the teams building and securing the cloud. That's why engineers, platform teams, and SOCs are choosing Upwind to simplify, scale, and unify cloud-native security at the speed of modern development." Market context and future trends With the rising adoption of cloud-native technologies, industry analysts have pointed to a shift among organisations from fragmented toolchains toward more integrated platforms that offer visibility throughout the application lifecycle. Gartner's reports state that CNAPP platforms are becoming a preferred model for managing the security of dynamic cloud environments, particularly as companies increase their investments in DevSecOps, platform engineering, and generative AI systems. Frost & Sullivan described Upwind as impactful for its capability to merge detection, response, and protection services into a singular platform. The report credits Upwind with consolidating functions such as ADR (Application Detection and Response), CDR (Cloud Detection and Response), CWPP (Cloud Workload Protection Platforms), and CSPM (Cloud Security Posture Management), thereby supporting operational efficiency for customers.


Techday NZ
a day ago
- Techday NZ
Red Hat named leader in 2025 Gartner Magic Quadrant for containers
Red Hat has been named a Leader in the 2025 Gartner Magic Quadrant for Container Management for the third year in a row, following an evaluation of 15 vendors. This ongoing recognition highlights both the role of Red Hat OpenShift in enterprise container strategies and the company's approach to hybrid cloud environments. The Gartner Magic Quadrant recognised OpenShift for its Completeness of Vision and Ability to Execute. Red Hat OpenShift provides a platform for container management that supports operational consistency and standardisation among organisations implementing cloud-native approaches. The platform is designed to standardise, automate, and scale container projects across various settings including data centres, multiple cloud environments, and edge deployments. Red Hat credits this acknowledgment to OpenShift's integrated security features, advanced management capabilities, and emphasis on developer productivity. These characteristics are seen as benefits for IT teams seeking to modernise applications and improve delivery of business value. The Gartner Magic Quadrant for Container Management is based on specific criteria that examine each vendor's completeness of vision and ability to execute. According to Gartner, Leaders are those who execute effectively against their current vision and are positioned well for future developments. Red Hat has previously received similar recognition, having been named a Leader in Gartner's 2025 Magic Quadrant for Cloud-Native Application Platforms. Company comments "We believe being recognised as a Leader for the third consecutive year in the Gartner Magic Quadrant for Container Management validates Red Hat OpenShift's role as a cornerstone for modern IT strategies. Our platform empowers enterprises to standardise, automate and scale their container initiatives across any footprint, from the datacenter to multiple cloud environments, providing the flexibility and control needed to meet evolving business demands." This was stated by Mike Barrett, Vice President & General Manager, Hybrid Cloud Platforms at Red Hat. The company states that OpenShift is suitable for organisations that require deployment capabilities across different infrastructures, including both private data centres and public clouds, as well as edge locations. Security and operational management are integrated into the platform to help developers and IT operations teams manage their workloads efficiently. The report from Gartner provides analysis of multiple vendors offering container management solutions, with an emphasis on their strategic direction and capability to deliver support for modern container workloads. Gartner's methodology identifies Leaders as vendors who are successful in both the vision and execution aspects of the market. The Gartner Magic Quadrant is frequently referenced by IT professionals and procurement teams seeking independent assessments of technology vendors. The evaluation of Red Hat OpenShift considered its ability to help enterprises with complex IT requirements and support their migration to cloud-native architectures. Red Hat continues to position OpenShift as a platform for standardising container operations, both on-premises and in cloud environments. Its feature set includes automation, policy enforcement, and monitoring, all built on a foundation powered by Kubernetes. The recognition by Gartner further builds on Red Hat's presence in the enterprise IT market, where container management is seen as a key capability for organisations pursuing digital transformation and modernisation of software delivery practices. The ability to operate workload across multiple environments is monitored closely by businesses managing diverse infrastructure estates. Gartner's commentary on container management vendors does not constitute an endorsement, but serves as one of several independent reference points for organisations considering their options in the market.


Techday NZ
3 days ago
- Techday NZ
Fortinet upgrades FortiRecon to boost proactive cyber defences
Fortinet has introduced substantial enhancements to its FortiRecon platform, aligning it more closely with the continuous threat exposure management (CTEM) framework to bolster organisations' abilities to address evolving cybersecurity risks. The new release incorporates expanded internal attack surface monitoring, adversary-centric dark web intelligence, and security orchestration into a unified system intended to help security teams proactively identify and prioritise exposures, validate risks, and speed up response times. These features are designed to reduce the chances and impact of security breaches by mirroring an attacker's viewpoint in security assessment and response. Attack surfaces and risk prioritisation Organisations are increasingly seeking strategies that address their growing attack surfaces, rising alert volumes, and the fragmentation of security operations. According to Gartner, "By 2026, organisations prioritising their security investments based on a continuous exposure management program will be three times less likely to suffer from a breach." FortiRecon's latest update integrates with the Fortinet artificial intelligence-driven security operations centre (SOC) platform and aims to cover all five pillars of the Gartner CTEM framework: scoping, discovery, prioritisation, validation, and mobilisation. This integration is designed to facilitate coordinated remediation between IT and security teams by centralising security operations. Nirav Shah, Senior Vice President, Products and Solutions at Fortinet, commented on the challenges facing security professionals: "Chief information security officers and security teams are overwhelmed by growing attack surfaces and an endless stream of unprioritised alerts. With the latest enhancements to FortiRecon, we're giving organisations an attacker's eye view of their internal and external exposures, backed by artificial intelligence-powered threat intelligence from FortiGuard Labs, real-world validation, and automated response. This allows organisations to cut through the noise, focus on what matters most, and measurably reduce risks and vulnerabilities before attackers can exploit them." Expanded capabilities The platform's enhancements consist of several core areas: Attack surface management: FortiRecon now provides continuous monitoring and an adversary's perspective of both internal and external digital attack surfaces. New features include National Vulnerability Database severity ratings and FortiRecon Active Exploitation severity ratings to optimise patch management processes. Adversary-centric intelligence: The updated platform offers actionable threat intelligence from sources such as dark web activity, ransomware trends, leaked credentials, exploited vulnerabilities, and data on at-risk vendors. Enhancements enable bulk downloads of indicators of compromise and provide stealer infection details to support security operations centres in accelerating breach detection and incident response. Brand protection: The platform continues to monitor for threats such as domain imitation, rogue mobile applications, phishing campaigns, and executive targeting, employing proprietary detection algorithms to identify and assist in remediating those threats, as well as monitoring public code repositories and open data exposures. Security orchestration: The addition of automated playbooks for threat investigation and response streamlines remediation workflows and reduces the time required for responding to incidents. Flexible deployment and recognition Existing customers using FortiFlex are able to deploy FortiRecon Cloud via their credits under a usage-based licensing arrangement. FortiFlex supports a wide customer base, including those managing hybrid and multi-cloud environments, as well as managed security service providers. Purchases via major cloud marketplaces can also contribute towards fulfilling cloud committed spend obligations. The operational effectiveness of FortiRecon has been noted in the KuppingerCole Leadership Compass for Attack Surface Management 2025 report, where Fortinet is named as an Overall Leader, Market Leader, and Innovation Leader. The report highlights FortiRecon's capabilities within environments governed by Centre for Internet Security controls, industrial control systems, Internet of Things devices, and operational technology. Integration with the broader portfolio of Fortinet Security Fabric, such as FortiGate NGFW, FortiSOAR, FortiSIEM, and FortiDAST, was also recognised. These enhancements mark the next stage in Fortinet's efforts to assist organisations in managing continuous threat exposure and streamlining their security operations through a centralised and coordinated platform.