Product1 distinct publisher3 min readPublished
Pulumi's research preview builds a threat model before it looks for anything, then leans on two inputs its own post treats as conditional, the infrastructure code behind a resource and the runtime telemetry around it.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Take the platform engineer who owns three AWS accounts and a Snowflake warehouse that finance stood up in a console two years ago. Pulumi says the agent reads the infrastructure code behind a resource, Pulumi's or Terraform's, for the semantics a cloud API never carries, including the comments around a declaration and the commit and review history [4]. It also says, in the same sentence: when available [4]. Where there is code, a finding can arrive attached to the file that produced it. Snowflake warehouses sit on Pulumi's own list of discoverable inventory, explicitly including resources provisioned outside IaC [8], so for that one the finding arrives as prose and the remediation is somebody's afternoon.
The post promises six planes of evidence and the list as published runs to five [14]. Three of the five are things Pulumi already holds or can read from a cloud API, and two depend on artifacts you may not have in the accounts where drift collects, the source for intent and the telemetry for runtime state [15]. The reference graph is the load-bearing one. Pulumi says it records which workload carries which identity and which identity reaches which data, read through a Context API shipped the same week, where a single query walks relationships across the estate and returns every result with the path that reached it [5]. A returned path is what separates a misconfiguration from an attack path, and Pulumi's second pass is built on that distinction, saying a resource matters only insofar as an attacker can use it [12].
Pulumi's case for the whole thing is that cloud estates carry exploitable flaws code analysis alone cannot find, often as severe as the ones in source, and that offensive agents will reach them [10]. That may well be true, and the post carries no preview findings and no false-positive rate to weigh them against. The right number to judge this on isn't findings count. The intended workflow is triage, ownership, a tighter estate; what a posture report tends to get in practice is one read-through, tickets for the top three items, and no second run. The measurements that would settle it are median time from finding to merged change, and the share of last month's findings that are gone on this month's run. Pulumi claims the report is immediately actionable because of its IaC technology [2], and actionable is a measurable word if you agree to measure it.
The grid to draw before the preview call has two axes: whether a finding comes with a path an attacker could walk, and whether the resource is owned by code you can change. Path plus code is the quadrant the product is sold on. Path without code is where the labour actually lands, and the hours there are the real price. Code without path is policy debt you can batch against the built-in rules [7]. Neither path nor code is the noise that gets a tool muted in month three.
One step is worth taking before any vendor demo. Pulumi says the first pass works out your crown jewels, which accounts hold production data and where the trust boundaries sit, and that without it a development sandbox would be treated like a production database [13]. Write your own version of that list on one page first, then read the agent's. Every severity downstream is priced off that first pass, so a disagreement there rewrites the entire ranking beneath it.
Ranked by verification strength, evidence, and original report placement.
Pulumi opened a research preview of Pulumi Neo Security, an agent that can find exploitable flaws in cloud infrastructure.
Pulumi says Neo Security starts with a threat model of the cloud estate, then works systematically through every potential point of attack, and that the resulting security posture report is immediately actionable thanks to Pulumi's infrastructure as code technology.
The intent plane reads the infrastructure code that created a resource, whether Pulumi or Terraform IaC, for semantics a cloud API does not know, including comments surrounding resources, resource declarations and relationships, logic and naming, and code commit and review history. Pulumi qualifies this plane with the words 'when available'.
The reference graph plane tells Neo which workload carries which identity, which identity reaches which data, and which stack manages which discovered resource; Neo Security reads it through the Context API Pulumi shipped earlier the same week, where a single query walks relationships across the estate and returns every result with the path that reached it.
The runtime state plane covers information not statically known from code or infrastructure metadata, including logs and metrics, uptime information and boot logs for servers, and network traffic, which Pulumi says is enabled by Neo having access to any tools a platform engineer would.
Pulumi's discovery and governance capabilities ship over 150 built-in policies, many of them security rules, mapped to CIS Controls, NIST SP 800-53, HITRUST CSF and PCI DSS; enterprises can write their own, and Neo Security uses existing scanned resources and their violations as well as the policy definitions to discover potential risks beyond known violations.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Identical Helm charts, three clouds, one OOMKill loop: portability is a claim about YAML1 distinct publisher
product
Pulumi turns its Terraform-compatibility claim into a diff against tofu1 distinct publisher
build
One provider block and an AMI filter: testing Terraform portability against on-prem hardware1 distinct publisher
build
North v3 puts AI bills and purchasing authority in the same engine1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor post, nothing outside it
Everything traceable here traces to Pulumi's blog, and the post stops mid-sentence at the section that would have shown a report. The mechanism is described precisely enough to be checked by someone with access, which is worth something; nothing in the story has actually been checked.
Gated preview, no named users
Two shipping events exist and both are Pulumi's own: the preview itself and the Context API it depends on. Access runs through 'contact us', no design partner is named, and no estate has publicly been scanned. That is a launch, not yet uptake.
Capability claims outrun shown results
'Complete visibility' and an agent that proves attack paths sit at one end; a gated preview with no published finding sits at the other. The post is also self-undercutting in a way worth naming: the two planes that would separate this from ordinary posture scanning — code intent and runtime telemetry — are the two it hedges, one with 'when available' and one on whatever tooling Neo is handed.
The only source sells the product
The story's single voice is the vendor, publishing a launch that ends in a contact-us gate and a threat argument that happens to describe exactly what the vendor's context graph is positioned to see. That is not disqualifying — first-party posts are the right place for mechanism — but no one in this story has an interest in finding the agent wrong.
Clear on the pitch, dark on the outcome
What Pulumi announced and how it says the agent works are documented well enough to quote confidently. Whether the attack paths hold up, how noisy the short list is, and what happens when the conditional planes are missing are all unanswerable from what we have — and the truncated post means even the vendor's own example is unavailable.