Token导航 LogoToken导航TokenDH.com
开发敏感数据github未标认证来源可访问许可证需确认审计通过

pulumi-cdk-to-pulumi普卢米 cdk 至 普卢米

Agent Skill

pulumi-cdk-to-pulumi 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

9,425

周安装

385

GitHub Stars

41

下载量

3,049
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:pulumi-cdk-to-pulumi(普卢米 cdk 至 普卢米)
来源仓库:https://github.com/pulumi/agent-skills
仓库路径:skills/pulumi-cdk-to-pulumi
安装命令:
npx skills add https://github.com/pulumi/agent-skills --skill pulumi-cdk-to-pulumi
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/pulumi/agent-skills --skill pulumi-cdk-to-pulumi

简介

用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息。

  • 适合在需要围绕仓库状态、代码变更或协作事项进行整理时使用。
  • 可结合来源仓库和原始 README 核验具体用法。
  • 安装方式:通过 npx 从指定 GitHub 仓库添加技能。
  • 建议确认权限范围、维护状态及是否会触发联网或文件读写。

SKILL.md

CRITICAL SUCCESS REQUIREMENTS

The migration output MUST meet all of the following:

  1. Complete Resource Coverage

- Every CloudFormation resource synthesized by CDK MUST: - Be represented in the Pulumi program OR - Be explicitly justified in the final report.

  1. Successful Deployment

- The produced Pulumi program must be structurally valid and capable of a successful pulumi up (assuming proper config).

  1. Final Migration Report

- Always output a formal migration report suitable for a Pull Request. - Include: - CDK → Pulumi resource mapping - Provider decisions (aws-native vs aws) - Behavioral differences - Missing or manually required steps - Validation instructions

WHEN INFORMATION IS MISSING

If a user-provided CDK project is incomplete, ambiguous, or missing artifacts (such as cdk.out), ask targeted questions before generating Pulumi code.

MIGRATION WORKFLOW

Follow this workflow exactly and in this order:

1. INFORMATION GATHERING

1.1 Verify AWS Credentials (ESC)

Running AWS commands (e.g., aws cloudformation list-stack-resources) and CDK commands (e.g. cdk synth) requires credentials loaded via Pulumi ESC.

  • If the user has already provided an ESC environment, use it.
  • If no ESC environment is specified, ask the user which ESC environment to use before proceeding with AWS commands.

You MUST confirm the AWS region with the user. The cdk synth results may be incorrect if ran with the wrong AWS Region.

1.2 Synthesize CDK

Run/inspect:

npx cdk synth --quiet
  • ALWAYS run synth with --quiet to prevent the template from being output on stdout.

If failing, inspect cdk.json or package.json for custom synth behavior.

1.3 Identify CDK Stacks & Environments

Read cdk.out/manifest.json:

jq '.artifacts | to_entries | map(select(.value.type == "aws:cloudformation:stack") | {displayName: .key, environment: .value.environment}) | .[]' cdk.out/manifest.json

Example output:

{
  "displayName": "DataStack-dev",
  "environment": "aws://616138583583/us-east-2"
}
{
  "displayName": "AppStack-dev",
  "environment": "aws://616138583583/us-east-2"
}

In the Pulumi stack you create you MUST set both the aws:region and aws-native:region config variables. For example:

pulumi config set aws-native:region us-east-2 --stack dev
pulumi config set aws:region us-east-2 --stack dev

1.4 Build Resource Inventory

For each stack:

aws cloudformation list-stack-resources \
  --region <region> \
  --stack-name <stack> \
  --output json

1.5 Analyze CDK Structure

Extract:

  • Environment-specific conditionals
  • Stack dependencies & cross-stack references
  • Runtime config (context/env vars)
  • Construct types (L1, L2, L3)

2. CODE CONVERSION (CDK → PULUMI)

  • Perform the initial conversion using the cdk2pulumi tool. Follow cdk-convert.md to perform the conversion.
  • Read the conversion report and fill in any gaps. For example, if the conversion fails to convert a resource you have to convert it manually yourself.

2.1 Custom Resources Handling

CDK uses Lambda-backed Custom Resources for functionality not available in CloudFormation. In synthesized CloudFormation, these appear as:

  • Resource type: AWS::CloudFormation::CustomResource or Custom::<name>
  • Metadata contains aws:cdk:path with the handler name (e.g., aws-s3/auto-delete-objects-handler)

Default behavior: cdk2pulumi rewrites custom resources to aws-native:cloudformation:CustomResourceEmulator, which invokes the original Lambda. This works but has tradeoffs (Lambda dependency, cold starts, eventual consistency).

Migration strategies by handler type:

HandlerStrategy
aws-certificatemanager/dns-validated-certificate-handlerReplace with aws.acm.Certificate, aws.route53.Record, and aws.acm.CertificateValidation
aws-ec2/restrict-default-security-group-handlerReplace with aws.ec2.DefaultSecurityGroup resource with empty ingress/egress rules
aws-ecr/auto-delete-images-handlerReplace aws-native:ecr:Repository with aws.ecr.Repository with forceDelete: true
aws-s3/auto-delete-objects-handlerReplace aws-native:s3:Bucket with aws.s3.Bucket with forceDestroy: true
aws-s3/notifications-resource-handlerReplace with aws.s3.BucketNotification
aws-logs/log-retention-handlerReplace with aws.cloudwatch.LogGroup with explicit retentionInDays
aws-iam/oidc-handlerReplace with aws.iam.OpenIdConnectProvider
aws-route53/delete-existing-record-set-handlerReplace with aws.route53.Record with allowOverwrite: true
aws-dynamodb/replica-handlerReplace with aws.dynamodb.TableReplica

Cross-account/region handlers:

  • aws-cloudfront/edge-function → Use aws.lambda.Function with region: "us-east-1"
  • aws-route53/cross-account-zone-delegation-handler → Use separate aws provider with cross-account role assumption

Graceful degradation for unknown handlers:

  1. Keep the CustomResourceEmulator (default behavior)
  2. Document the custom resource in the migration report with:

- Original handler name and purpose (if discernible from CDK path) - Note that it uses Lambda invocation at runtime - Recommend user review for potential native replacement

2.2 Provider Strategy

  • Default: Use aws-native whenever the resource type is available.
  • Fallback: Use aws when aws-native does not support equivalent features.

2.3 Assets & Bundling

CDK uses Assets and Bundling to handle deployment artifacts. These are processed by the CDK CLI before CloudFormation deployment and appear in the cdk.out directory alongside *.assets.json metadata files. CloudFormation templates contain hard-coded references to asset locations (S3 bucket/key or ECR repo/tag).

# Inspect asset definitions
jq '.files, .dockerImages' cdk.out/*.assets.json

Migration strategies by asset type:

Asset TypeDetectionPulumi Migration
Docker ImagedockerImages in assets.jsonUse docker-build.Image to build and push. Replace hard-coded ECR URI with image output.
File with build commandfiles with executable fieldFlag to user - build command needs setup in Pulumi
Static filefiles without executable, no bundling in CDK sourceUse pulumi.FileArchive or pulumi.FileAsset
Bundled filefiles without executable, but CDK source uses bundlingFlag to user - bundling needs setup in Pulumi

Detecting Bundling in CDK Source:

Check the CDK source code for bundling constructs (NodejsFunction, PythonFunction, GoFunction, or resources using the bundling option). If bundling is used, the build step needs to be replicated in Pulumi for ongoing development - otherwise source changes would require manually re-running cdk synth.

When bundling is detected, inform the user:

Build Step Detected: This CDK application uses <BUNDLING_TYPE> which builds deployable artifacts during synthesis. This build step needs to be replicated in Pulumi for ongoing development. Options: 1. CI/CD Pipeline (Recommended): Move the build step to your CI pipeline and reference the pre-built artifact in Pulumi 2. Pulumi Command Provider: Use command.local.Command to run the build command during pulumi up 3. Pre-build Script: Create a build script that runs before pulumi up and outputs to a known location Each option has tradeoffs around caching, reproducibility, and deployment speed. For production workloads, option 1 is typically preferred.

2.4 TypeScript Handling for aws-native

aws-native outputs often include undefined. Avoid ! non-null assertions. Always safely unwrap with .apply():

// ❌ WRONG - Will cause TypeScript errors
functionName: lambdaFunction.functionName!,

// ✅ CORRECT - Handle undefined safely
functionName: lambdaFunction.functionName.apply(name => name || ""),

2.5 Environment Logic Preservation

Carry forward all conditional behaviors:

if (currentEnv.createVpc) {
  // create resources
} else {
  const vpcId = pulumi.output(currentEnv.vpcId);
}

3. Resource Import (optional)

After conversion you can optionally import the existing resources to now be managed by Pulumi. If the user does not request this you should suggest this as a follow up step to conversion.

  • Always start with automated import using the cdk-importer tool. Follow cdk-importer.md to perform the automated import.
  • For any resources that fail to import with the automated tool, import them manually.

If you need to manually import resources:

3.1 Running preview after import

After performing an import you need to run pulumi preview to ensure there are no changes. No changes means:

  • NO updates
  • NO replaces
  • NO creates
  • NO deletes

If there are changes you must investigate and update the program until there are no changes.

Working with the User

If the user asks for help planning or performing a CDK to Pulumi migration use the information above to guide the user towards the automated migration approach.

For Detailed Documentation

When the user wants to deviate from the recommended path detailed above, use the web-fetch tool to get content from the official Pulumi documentation -> https://www.pulumi.com/docs/iac/guides/migration/migrating-to-pulumi/migrating-from-cdk/migrating-existing-cdk-app

This documentation covers topics:

  • Migration Strategy

- Convert vs. Rewrite - Import vs. Rehydrate - Best Practices

  • Handling Multiple CDK Stacks
  • Handling CDK Stages
  • Code organization
  • Converting CDK Constructs
  • Execution Strategies

- Automated Migration (recommended) - Manual Migration

OUTPUT FORMAT (REQUIRED)

When performing a migration, always produce:

  1. Overview (high-level description)
  2. Migration Plan Summary
  3. Pulumi Code Outputs (TypeScript; structured by file)
  4. Resource Mapping Table (CDK → Pulumi)
  5. Custom Resources Summary (if any):

- Handlers migrated to native Pulumi resources - Handlers kept as CustomResourceEmulator with rationale - Any handlers requiring user attention

  1. Assets & Bundling Summary (if any):

- Migrated: Assets successfully converted (e.g., Docker images → docker-build.Image, static files → pulumi.FileArchive) - Requires attention: Assets with bundling steps, options presented, and decision if made

  1. Final Migration Report (PR-ready)
  2. Next Steps (optional refactors)

Keep code syntactically valid and clearly separated by files.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.9%
按下载量换算1,095

Claude

30.34%
按下载量换算925

Cursor

18.79%
按下载量换算573

Gemini CLI

9.5%
按下载量换算290

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills