Pulumi ESC
Secrets composition layer: pull from Vault/AWS/Doppler and expose to any runtime
Pricing: Free tier (Pulumi Cloud Individual, $0); ESC metered per secret from $0.50/secret/mo (Team) and $0.75/secret/mo (Enterprise), on top of base tiers Team $40/mo and Enterprise $400/mo
Reviewed by the CyberSecTool editorial team against the public sources cited below · Last reviewed April 2026 · How we review listings
What is Pulumi ESC?
Pulumi ESC (Environments, Secrets, Configuration) is a secrets and configuration platform that lets you compose environments from multiple secret sources (AWS, Vault, Doppler, 1Password) and expose them as environment variables, files, or direct SDK calls. ESC is tightly integrated with Pulumi's infrastructure-as-code platform but works as a standalone tool too.
- ✓ Sits cleanly on top of existing secrets stores. No migration needed
- ✓ Composition model makes multi-cloud environments simple
- ✓ Strong fit if you already use Pulumi for IaC
- ✓ OIDC-based auth eliminates static Pulumi tokens
- • Newer product; smaller community than Doppler/Infisical
- • Best value only realized if you adopt Pulumi IaC too
- • Per-user pricing at the Team tier is steep
- • No self-hosted option
Reported in public reviews and vendor documentation. See sources below.
Key Features
Are you Pulumi ESC? Improve this listing with screenshots, case studies and more.
Sources & references
Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.
Spot an error, or do you represent Pulumi ESC? Request a correction.
Quick Info
| Pricing | Free tier (Pulumi Cloud Individual, $0); ESC metered per secret from $0.50/secret/mo (Team) and $0.75/secret/mo (Enterprise), on top of base tiers Team $40/mo and Enterprise $400/mo |
| Model | Per-user tiers |
| Founded | 2024 |
| Cloud | Yes |
| Self-Hosted | No |
Last updated: Apr 23, 2026