Announcing the Second Edition of Infrastructure as Code
infrastructure-as-code.com
infrastructure-as-code.com
Is the Pulumi/CDK code too dynamic to support static analysis?
I have to be honest, I hadn't messed around with Terraform before, but I've been working with Ansible/CloudFormation and Pulumi is just on another level. There are so many hacks you need to do to work around CloudFormation peculiarities, and separating stack creation and manipulation into two separate formats is frustrating at best.
Going to have to play around Pulumi more seriously when it's time to stand up more servers.
Could you speak more to some of the ways it was easier to work with? How was the transition and what was the migration strategy?
3 weeks ago I set up our AWS infrastructure with Terraform but somehow I never got it to work correctly (somehow the AWS Elastic Beanstalk health checker never turned green).
Just this week I decided to migrate to Pulumi and after a few very explanatory good error messages I got it to work. I'd say Pulumi's error messages are superior.
Another major benefit of Pulumi is that you can use typescript (and others) to script your setup. Terraform supports some scripting [1] but you have to take a few hours to learn it, and it never will be as powerful as plain ts/js/py.
[1] https://www.hashicorp.com/blog/hashicorp-terraform-0-12-prev...
Where I'm at, we just so happen to only be in the initial phases of a cloud strategy, and it happens to align with Pulumi's current support of AWS. So Pulumi's execution of a multi-vendor solution will bear keeping a close eye upon.
We're likely in for a few years yet of fragmented API wars amongst the cloud vendors, before the value extraction from uncoordinated API's levels off enough that a more universal API is adopted for a progressively-larger "core cloud" of defined services (we're kind of seeing that with cloud object storage for example), W3C-style.
A better analogy, would be if e.g. the NFS protocol spec wasn't enough to use NFS file systems, but required vendor support to work correctly.
In some quick searching, Pulumi has a high level (and assumedly biased) comparison between Terraform and itself: https://www.pulumi.com/docs/intro/vs/terraform/
Let's say your websites homepage only uses http but the login form is over https. You can MiTM the homepage, and change the login link to haX0r.xyz and then proxy the login.