# AWS CloudFormation vs Pulumi

**Leader by Vioscale score:** Pulumi

| Attribute | AWS CloudFormation | Pulumi |
|---|---|---|
| **Vioscale score** | 60.3 (73% (medium)) | 69.2 (75% (high)) |
| activity.commits_last_30d | - | 100 |
| adoption.dependent_repos | - | 2,143 |
| adoption.github_stars | - | 25,610 |
| adoption.package_downloads_weekly | - | 1,787,798 |
| deployment.options | `{"cloud":true}` | `{"cloud":true}` |
| description.long | A managed service for provisioning and managing AWS and third-party cloud resources through declarative templates (JSON/YAML) or programmatic languages. Automates infrastructure deployment across regions and accounts, detects configuration drift, and provides automatic rollback on errors. | A cloud infrastructure management platform that lets teams define and deploy resources across multiple cloud providers using standard programming languages. Includes state management, policy enforcement, and tooling for discovering and migrating existing infrastructure. |
| features.capabilities | `{"hosting":"cloud","language":"JSON, YAML, TypeScript, Python, Java, .NET","paradigm":"declarative_dsl","multicloud":false,"policy_as_code":true,"drift_detection":true,"import_existing":true,"state_management":"vendor_managed","open_source_engine":false,"provider_ecosystem":true,"gitops_reconciliation":true,"managed_saas_offering":true}` | `{"hosting":"cloud","language":"TypeScript, Python, Go, C#, Java, YAML","paradigm":"general_language","multicloud":true,"policy_as_code":true,"drift_detection":true,"import_existing":true,"state_management":"vendor_managed","open_source_engine":true,"provider_ecosystem":true,"gitops_reconciliation":false,"managed_saas_offering":true}` |
| integrations.count | 21 | 6 |
| integrations.list | `[{"name":"MongoDB"},{"name":"Datadog"},{"name":"Atlassian Opsgenie"},{"name":"JFrog"},{"name":"Trend Micro"},{"name":"Splunk"},{"name":"Aqua Security"},{"name":"FireEye"},{"name":"Sysdig"},{"name":"Snyk"},{"name":"Check Point"},{"name":"Spot by NetApp"},{"name":"Gremlin"},{"name":"Stackery"},{"name":"Iridium"},{"name":"AWS CDK"},{"name":"AWS SAM (Serverless Application Model)"},{"name":"Visual Studio"},{"name":"Kiro"},{"name":"AWS CloudFormation Registry"},{"name":"AWS Partner Network (APN)"}]` | `[{"name":"AWS"},{"name":"Azure"},{"name":"Google Cloud"},{"name":"Terraform"},{"name":"CloudFormation"},{"name":"Azure Resource Manager"}]` |
| language.primary | - | Go |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"usage","plans":[{"free":false,"name":"Third-party Resources & Custom Hooks","summary":"$0.0009/handler operation after 1,000 free ops/month","features":["Unlimited AWS::* and Alexa::* resource operations (no handler charges)","Third-party resource provisioning","Custom hook support","Handler operation billing after free tier","Duration overage billing"],"components":[{"per":{"qty":1,"unit":"handler operation"},"kind":"metered","amount":0.0009,"currency":"USD"},{"per":{"qty":1,"unit":"second"},"kind":"metered","amount":0.00008,"currency":"USD","description":"Duration overage beyond 30 seconds per operation"}],"description":"Pay-per-operation model for third-party resource providers and custom hooks","contactSales":false,"includedLimits":{"free_handler_operations":"1,000/month","free_duration_per_operation":"30 seconds"}}],"summary":"Usage-based: $0.0009/handler operation + $0.00008/sec overage. 1,000 free operations/month. Data transfer at AWS rates.","currency":"USD","freeTier":true,"sourceUrl":"https://aws.amazon.com/cloudformation/pricing/","retrievedAt":"2026-08-14T16:36:19.015Z","startingPrice":{"amount":0.00008,"period":"month","currency":"USD"}}` | `{"type":"hybrid","plans":[{"free":false,"name":"Team Edition","summary":"Per resource-hour and per deployment-minute charges. Free credits included.","description":"Team edition with per-resource-hour and per-deployment-minute charges","contactSales":false,"includedLimits":{"free_credits":"included"}}],"summary":"Team Edition with per-resource-hour and deployment-minute metering. Bulk discounts available for >$20k/year spend. Free credits included.","currency":"USD","freeTier":true,"sourceUrl":"https://www.pulumi.com/blog/pricing-calculator-blog/","retrievedAt":"2026-08-14T21:36:29.976Z","billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | commercial |
| pricing.price_level | low | low |
| pricing.transparent | yes | yes |
| release.cadence_days | - | 5 |
| release.history | - | `[{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.259.0","date":"2026-08-19T20:04:11Z","type":"stable","version":"v3.259.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.258.0","date":"2026-08-17T19:04:32Z","type":"stable","version":"v3.258.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.257.0","date":"2026-08-13T14:42:12Z","type":"stable","version":"v3.257.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.256.0","date":"2026-08-04T19:34:54Z","type":"stable","version":"v3.256.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.255.0","date":"2026-07-28T13:37:19Z","type":"stable","version":"v3.255.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.254.0","date":"2026-07-23T15:10:53Z","type":"stable","version":"v3.254.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.253.0","date":"2026-07-14T11:30:57Z","type":"stable","version":"v3.253.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.252.0","date":"2026-07-13T12:34:06Z","type":"stable","version":"v3.252.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.251.0","date":"2026-07-08T12:41:08Z","type":"stable","version":"v3.251.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.250.0","date":"2026-07-02T00:47:36Z","type":"stable","version":"v3.250.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.249.0","date":"2026-07-01T14:20:03Z","type":"stable","version":"v3.249.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.248.0","date":"2026-06-24T14:50:37Z","type":"stable","version":"v3.248.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.247.0","date":"2026-06-18T14:11:01Z","type":"stable","version":"v3.247.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.246.0","date":"2026-06-11T19:51:29Z","type":"stable","version":"v3.246.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.245.0","date":"2026-06-04T08:53:06Z","type":"stable","version":"v3.245.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.244.0","date":"2026-05-28T18:13:39Z","type":"stable","version":"v3.244.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.243.0","date":"2026-05-22T21:38:01Z","type":"stable","version":"v3.243.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.242.0","date":"2026-05-19T12:39:19Z","type":"stable","version":"v3.242.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.241.0","date":"2026-05-18T16:31:27Z","type":"stable","version":"v3.241.0"},{"url":"https://github.com/pulumi/pulumi/releases/tag/v3.239.0","date":"2026-05-14T12:56:20Z","type":"stable","version":"v3.239.0"}]` |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | yes |
| security.fedramp | yes | - |
| security.gdpr | yes | - |
| security.hipaa | yes | - |
| security.pci | yes | - |
| security.scorecard | - | 7.2 |
| security.soc2 | - | yes |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=npm&package_name=%40pulumi%2Fpulumi&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (Infrastructure as Code Tools)

| Capability | AWS CloudFormation | Pulumi |
|---|:--:|:--:|
| **Core** |  |  |
| Paradigm | Declarative DSL | General language |
| Language | JSON, YAML, TypeScript, Python, Java, .NET | TypeScript, Python, Go, C#, Java, YAML |
| **Portability** |  |  |
| Multicloud / cloud-agnostic | ✗ | ✓ |
| **Architecture** |  |  |
| State management | Vendor-managed | Vendor-managed |
| **Extensibility** |  |  |
| Pluggable provider ecosystem | ✓ | ✓ |
| **Governance** |  |  |
| Policy as code | ✓ | ✓ |
| **Ops** |  |  |
| Drift detection | ✓ | ✓ |
| GitOps continuous reconciliation | ✓ | ✗ |
| **Deployment** |  |  |
| Managed SaaS offering | ✓ | ✓ |
| Hosting | Cloud only | Cloud only |
| **Adoption** |  |  |
| Import existing resources | ✓ | ✓ |
| **Licensing** |  |  |
| Open-source engine | ✗ | ✓ |
| **Ecosystem** |  |  |
| CNCF maturity | - | - |

*Source: Vioscale. Generated 2026-09-01T15:16:26.766Z. "-" = undocumented, not absent.*
