> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oleria.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Pulumi

> Connect your Pulumi organization to Oleria to continuously discover member and team access across your infrastructure as code platform.

Pulumi is an infrastructure as code platform for provisioning and managing cloud resources. Connect your Pulumi organization to Oleria to bring member and team access into your identity and access graph, without a dedicated Pulumi-specific integration.

## What Oleria discovers

* User accounts and profile attributes synced from your Pulumi organization.
* Team membership across your organization.

Oleria uses this data for dormant account detection and access reviews, refreshed on Pulumi's standard sync schedule.

## Prerequisites

* Admin access in Pulumi Cloud with permission to create an organization access token.
* Admin access on the Oleria platform to add a new integration.

<Note>
  The exact location of these settings can change over time. If the steps below don't match what you see, refer to Pulumi's own API documentation.
</Note>

## Get your SCIM credentials from Pulumi

<Steps>
  <Step title="Create an organization access token in Pulumi Cloud">
    Sign in to Pulumi Cloud as an admin, go to **Settings** → **Access Tokens**, and create an organization access token.
  </Step>

  <Step title="Copy your SCIM Base URL and Authentication token">
    Copy both values before you leave the page - you'll paste them into Oleria in the next section:

    * **SCIM Base URL** - the HTTPS API endpoint for your Pulumi organization.
    * **Authentication token** - the access token you generated.

    <Note>
      Copy the token now. Many applications display it only once. Store it securely and rotate it per your organization's security policy.
    </Note>
  </Step>
</Steps>

## Connect Pulumi to Oleria

<Steps>
  <Step title="Open the integration">
    Go to your Oleria workspace, select **Integrations**, then select the **Pulumi** tile.
  </Step>

  <Step title="Complete the connection form">
    Select **Continue** and fill in the connection form:

    | Field                | Notes                                                                                 |
    | :------------------- | :------------------------------------------------------------------------------------ |
    | Instance name        | Optional. Short, recognizable label for this connection (for example, `pulumi-prod`). |
    | SCIM Base URL        | Required. The HTTPS API endpoint copied from Pulumi.                                  |
    | Authentication token | Required. The access token issued by Pulumi.                                          |
  </Step>

  <Step title="Save the integration">
    Select **Connect** to validate the credentials and save the integration.
  </Step>
</Steps>

## Verify the integration

Confirm the new instance appears in your Oleria workspace under **Connected Integrations** with a status of **Healthy**. Oleria syncs users and teams from Pulumi on the standard SCIM provisioning schedule once the initial sync completes.

<Note>
  If Pulumi rotates your access token, update the Authentication token in Oleria by editing the integration.
</Note>

## Governance actions

Oleria can also invoke lifecycle actions in Pulumi when the token you provide has write access:

* Enable or disable a user account
* Add or remove a user from a group
* Create a new user or group

<Note>
  Many teams start with a read-only token for visibility, then grant write access once they're ready to automate remediation in Pulumi.
</Note>

## Contact us

For questions about this integration, contact us at [support@oleria.com](mailto:support@oleria.com).
