Prerequisites
- A Pulumi Cloud account that belongs to the organization you want CloudThinker to inspect.
- Permission to authorize CloudThinker through Pulumi’s OAuth flow.
The tools read the organization your Pulumi account defaults to. Authorize with the account that belongs to the organization holding the stacks you care about, or the agent reports an empty inventory.
Setup
1
Open CloudThinker
Go to Connections → Pulumi in your workspace.
2
Start the OAuth flow
Click Connect to open Pulumi’s authorization page.
3
Authorize CloudThinker
Sign in to the Pulumi account that can see the stacks you want, then approve access.
4
Return to CloudThinker
CloudThinker stores the OAuth tokens and the connection shows a Connected status.
Connection details
Pulumi uses OAuth, so there are no fields to fill in. CloudThinker stores the tokens automatically once the authorization completes.Required permissions
CloudThinker inherits the Pulumi access granted during OAuth.- Read operations cover stacks, managed resources, policy violations, organization members, Neo task history, and Registry schemas.
- Deployments and Pulumi Neo need matching Pulumi access and explicit approval in CloudThinker, because both change cloud resources.
Agent capabilities
Once connected, Alex can:Verify the connection
Example prompts
Approval-gated tools
Four Pulumi tools change real state, so CloudThinker asks before each call: deploy to AWS, and the three tools that drive Pulumi Neo (bridge, continue a task, reset a conversation). The agent names the stack and the effect, then waits for your answer. Everything else on this connection reads. Reading a stack never triggers a prompt, so an inventory or policy question completes in one turn.Troubleshooting
The OAuth flow does not complete
The OAuth flow does not complete
Your browser may be signed in to a different Pulumi account. Sign in to the intended account at app.pulumi.com, then retry Connect in CloudThinker.
The agent reports no stacks
The agent reports no stacks
Pulumi answers for the organization your account defaults to. Confirm that account is a member of the organization holding the stacks, then reconnect with the right account.
The agent says it lacks access to an organization
The agent says it lacks access to an organization
The token reaches only the organizations your Pulumi user belongs to. Add the user to the organization in Pulumi, or reconnect with an account that already belongs to it.
A deployment prompt keeps asking for confirmation
A deployment prompt keeps asking for confirmation
That is the approval gate, and it is per call. Answer the prompt in the conversation. See Approval for how CloudThinker handles gated tools.
A new Pulumi tool is missing
A new Pulumi tool is missing
CloudThinker exposes a reviewed list of Pulumi tools. A tool Pulumi releases later stays hidden until CloudThinker reviews it and decides whether it needs approval.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Keep the gate on — leave deployment and Pulumi Neo approval-gated; they are the only tools here that can change your cloud.
- Reconnect deliberately — the connection reaches whatever the authorizing account reaches, so switch accounts by removing the connection and authorizing again.
Related
Alex Agent
Cloud infrastructure and cost analysis
Approval
How CloudThinker gates tools that change state