Bringing Existing AWS Resources Under Pulumi Management with `pulumi import`
Learn how to import an existing AWS S3 bucket into a Pulumi stack so you can manage it declaratively without disrupting the live resource.
15 Sept 2026, 13:45 UTC

Problem: Managing Legacy Cloud Assets Declaratively
Teams often inherit resources that were created manually or via scripts before adopting infrastructure‑as‑code. Those assets live outside Pulumi’s state, making it hard to run pulumi preview or pulumi up without risking accidental changes.
Thesis: Use pulumi import to bring existing resources into Pulumi safely
The import command maps a live resource’s identifier to a Pulumi resource type, creates a matching entry in the stack’s state file, and leaves the actual cloud object untouched. After import you can treat the resource like any other Pulumi‑managed asset.
How the import works
- Run
pulumi import <package>:<type>:<name> <identifier>from the stack directory. - The command reads the live resource, writes a new URN to the state, and outputs a placeholder resource block that you can copy into your Pulumi program.
- No create, update, or delete operations are performed on the cloud resource during import.
Worked example: Importing an existing AWS S3 bucket
- Ensure the AWS provider is installed and configured with appropriate credentials.
- Identify the bucket’s ARN, e.g.
arn:aws:s3:::my‑legacy‑bucket. - Run the import command:
pulumi import aws:s3/bucket:Bucket my-legacy-bucket arn:aws:s3:::my-legacy-bucket - Pulumi responds with a generated resource snippet similar to:
const myLegacyBucket = new aws.s3.Bucket('my-legacy-bucket', { bucket: 'my-legacy-bucket', }); - Copy that snippet into your Pulumi program (e.g.
index.ts) and runpulumi preview. The preview should show no pending changes for the bucket. - Optionally run
pulumi upto persist the state; again, no changes are applied to the bucket.
Trade‑offs and limitations
- Import only captures the resource’s current state. Any configuration drift that occurs after import must be corrected manually or via a subsequent Pulumi update.
- If the underlying resource is modified outside Pulumi, the stack will drift and
pulumi previewwill flag differences. - Not every resource type supports import; consult the provider’s documentation to confirm that the desired type implements the
importinterface. - Import does not modify tags, IAM policies, or other attributes unless you explicitly define them in your Pulumi code after import.
Actionable closing
Start by importing a low‑risk resource such as an S3 bucket or a VPC subnet. Verify the preview shows no changes, then bring the resource under version control. Repeat the process for other legacy assets, gradually moving your entire environment into Pulumi’s declarative model while keeping production workloads untouched.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.