pulumi-tls
A Pulumi package to create TLS resources in Pulumi programs.
Decision gist · record as of 2026-08-14
Yes, if you use Pulumi for infrastructure-as-code and need to manage TLS resources programmatically. The package is actively maintained, has no security vulnerabilities, carries a permissive license, and integrates cleanly into Pulumi workflows. Install only if you have Pulumi CLI already set up and a Pulumi project initialized.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Pulumi CLI to be installed first and a Pulumi project initialized; Python >=3.9 required.
- Low install friction with a pure-Python wheel distribution.
- Active maintenance with a recent release (23 days old) and ongoing repository activity.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows use in commercial and open-source projects with minimal restrictions; you must retain license notices but can modify and distribute freely.
last release 2026-07-22 (23 days) · last repo commit 2026-08-14 · 15 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 3,997,998 downloads/mo, #2,404 on PyPI
Alternatives
Verify before relying
pip install pulumi-tls
import pulumi
import pulumi_tls as tls
private_key = tls.PrivateKey('my_key', algorithm='RSA')- Whether the package works with all Pulumi stack backends or has known limitations with specific cloud providers.
- Performance characteristics when managing large numbers of TLS resources in a single program.
What it is and what it does
pulumi-tls is a Pulumi resource provider that brings TLS certificate and key management into your infrastructure-as-code workflows. It lets you declaratively create, rotate, and manage cryptographic resources—private keys, certificates, certificate signing requests—as part of your cloud infrastructure definition, alongside compute, networking, and storage resources.
The package integrates with Pulumi's strongly-typed SDK and works across multiple languages (Python, TypeScript/Node.js, Go, .NET). For Python users, it requires the Pulumi CLI and a Pulumi project context; it depends on pulumi, parver, semver, and typing-extensions. It's maintained actively and carries no known security vulnerabilities.
Use it for
- Generate self-signed certificates and private keys for testing and development environments within Pulumi programs.
- Automate TLS certificate provisioning as part of a larger cloud infrastructure deployment pipeline.
- Create certificate signing requests and manage certificate lifecycle alongside other infrastructure resources.
- Integrate TLS resource creation into multi-language Pulumi stacks for consistent certificate management.
- Manage cryptographic material in a version-controlled, reproducible infrastructure-as-code workflow.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you use Pulumi for infrastructure-as-code and need to manage TLS resources programmatically.
The package is actively maintained, has no security vulnerabilities, carries a permissive license, and integrates cleanly into Pulumi workflows. Install only if you have Pulumi CLI already set up and a Pulumi project initialized.
Install
pulumi-tls on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Active maintenance with a recent release (23 days old) and ongoing repository activity. Depends on pulumi, parver, semver, and typing-extensions—all standard, lightweight dependencies.
Requires Pulumi CLI to be installed first and a Pulumi project initialized; Python >=3.9 required.
License in practice
Apache-2.0 permissive license allows use in commercial and open-source projects with minimal restrictions; you must retain license notices but can modify and distribute freely.
Quickstart
pip install pulumi-tls
import pulumi
import pulumi_tls as tls
private_key = tls.PrivateKey('my_key', algorithm='RSA')
Verify before relying
- Whether the package works with all Pulumi stack backends or has known limitations with specific cloud providers.
- Performance characteristics when managing large numbers of TLS resources in a single program.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesparverpulumisemvertyping-extensions |
| Maintenance | Actively maintained 23 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 3,997,998 / month, #2,404 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: pulumi_tls-5.5.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pulumi tls provider”
- pulumi-tlsPulumi resource provider for creating and managing TLS keys and…
- pulumi-vaultPulumi resource provider for HashiCorp Vault that lets you define and…
- pulumiverse-timeA Pulumi resource provider that lets you manage time-based resources…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also pulumi-docker · pulumi-gitlab · pulumi-random · pulumi-vault · pulumi-postgresql · pulumi-cloudflare · pulumi-datadog · pulumi-keycloak · pulumi-pulumiservice · pulumiverse-grafana