--ignore-protect flag for delete; invokes pending remote components resolved
v3.256.0
3 features7 enhancements24 fixesThis release3 featuresNew capabilities7 enhancementsImprovements to existing features24 fixesBug fixesAI-tallied from the release notes
From the original release noteView original ↗
3.256.0 (2026-08-04)
Features
- [cli] Add
--ignore-protectflag topulumi up,pulumi previewandpulumi destroyto allow deleting protected resources without unprotecting them in the state first #24053 - [cli/env] Add an optional
--export-env-varsflag to theenv provider {aws,azure,gcp}-logincommands to also set the standard SDK environment variables referencing the login outputs #24055 - [cli] Add a
--serverflag topulumi package add,publish,get-schema,get-mapping,gen-sdk,infoandpulumi schema checkthat skips package resolution and uses the given URL as the plugin download URL #24107
Bug Fixes
- [backend/service] Fix
pulumi login --insecurenot being reflected in the stack's service secrets manager state, which caused TLS verification failures against self-hosted backends using self-signed certificates #24134 - [cli] Scope current stack selection to the active backend so switching backends no longer surfaces stale stack errors #23974
- [programgen/go] Parent an invoke written inside a component to that component, lower a component's outputs, and only import
fmtwhen a component needs it #24019 - [programgen/python] Parent an invoke written inside a component to that component, so it resolves the component's providers #24018
- [sdk/nodejs] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24042
- [engine] Gate invokes on the created-ness of their declared dependencies, including the children of remote components, resolving them as unknown during previews that still have to create them #24040
- [sdk/go] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24044
- [pcl] Declare invoke dependencies to the engine so invokes that depend on pending resources, including remote components, resolve as unknown during previews #24041
- [sdk/python] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24043
- [cli/env]
env providerno longer writes a new environment revision when the resulting definition is unchanged #24055 - [sdk/go] Output-form invokes now infer their resource dependencies from their arguments, so they are skipped during preview while a dependent resource is pending creation and their results carry those dependencies #24054
- [sdkgen/go] Fixes nested optional output conversions #24096
- [engine] Fix a plugin process leak in
NewPolicyAnalyzerwhenConfigureStackfails after the plugin has booted #24106 - [programgen/go] Avoid redundant applies when projecting properties from generated Go object outputs #24112
- [backend/diy] Fix 403 errors writing to third-party S3-compatible backends (e.g. IBM COS, MinIO) by defaulting request_checksum_calculation to when_required when the s3:// backend URL sets a custom endpoint #24109
- [programgen/nodejs] Avoid redundant applies when projecting properties from Node.js outputs #24119
- [programgen/python] Avoid redundant applies when projecting properties from Python outputs #24120
- [sdk] Fix apply erroring for skipped resources #24108
- [cli] Retry rate-limited (HTTP 429) API requests when they are safe to retry, honoring the server's Retry-After header #24131
- [cli] Exit non-zero from remote operations (
pulumi up --remote,pulumi deployment run) when the deployment fails #24155 - [cli/new] Resolve and install packages required by the program during
pulumi new, aspulumi installdoes #24126 - [cli] Make --remote not require a Pulumi.yaml file to be present #24128
- [cli/import] Generate explicit providers in the import file
resources#24135 - [sdk/nodejs] Fix trustedDependencies parsing for bun #24145
- [auto/go] ImportResources no longer leaks
--stackinto the converter's arguments when converter args are passed #24146 - [auto/go] Fix
ImportResourceswhenGenerateCode(false)is set #24147 - [sdk/go] Fix hooks and transforms causing panics with mocks #24161
- [programgen/go] Fix plain invokes emitting nonexistent
...ArgsArgsargument types #24172
Improvements
- [cli/import] Error when running
pulumi import --from terraformin a Pulumi HCL project #23744 - [programgen] Add
IDtype to PCL #22702 - [engine] Give the resource monitor's
Invokeits own response message, separating it from the one a provider returns #24100 - [cli/do] Allow stateful resources to register their own provider resources based on provider inputs on the command line #24098
- [cli] Refresh the first-login welcome message to link your Pulumi Cloud console and the Pulumi changelog #24122
- [cli/do] Add support for the
--providerargument for stateful operations #24132 - [programgen/go] Better typing for maps, using known types rather than
map[string]interface{}#24142 - [cli/import] Serve the package-resolver service to state converters via
resolver_targetonConvertStateRequest, so converters can resolve package specifications the same way the CLI does #24174
Miscellaneous
Fetched August 4, 2026



