Let's cut through the marketing fluff. Pulumi's "state managed by you" via cloud storage (S3, Blob) is often pitched as "no state file to worry about." That's… a clever framing.
In reality, you've just swapped a local `terraform.tfstate` for a *remote* state file you still absolutely must manage. The trade-offs are real, and they impact cost and ops.
**The "Pure Win" Narrative:**
* "No state file on disk!" – True, but it's in an object store bucket you pay for and secure.
* "Automatic locking!" – Uses your cloud's native locking (e.g., DynamoDB), which adds another managed service and another line item.
* "Collaboration built-in!" – This is the real value, but it's a shift of responsibility, not an elimination.
**The Trade-Offs (where the costs hide):**
* **You now own the state backend's availability and costs.** S3/GCS/Azure Storage isn't free. Soapbox: If your team does 50+ `pulumi up` runs a day, you're generating thousands of state updates. Those are **PUT/COPY operations**. Check your bill's "Requests and Data Retrieval" line. It's small, but it's not zero, and in large orgs, it adds up. Forgotten old stacks? Their state files sit there, charging you a few cents a month for storage. Forever.
* **Disaster recovery is on you.** Yes, you should have versioning and replication enabled on that bucket. That's extra config and more cost. Terraform Cloud/Enterprise abstracts this; Pulumi says "you do it."
* **The learning curve for new engineers shifts.** Instead of "here's how we run terraform," it's "here's how we authenticate to our state bucket, and by the way, if you nuke the bucket, you nuke our infrastructure definition." The blast radius of a misstep can be higher.
**Bottom line:** It's not "no state." It's **delegated state management**. You gain flexibility (using your own cloud creds, your own rules) but inherit the operational burden and the micro-costs that a SaaS offering would wrap into a single fee.
For small teams, fine. For large-scale FinOps, you need to track and budget for those backend services. They're not magic.
```hjson
// This is a cost center. Name it accordingly.
resources:
- type: aws:s3/Bucket
name: pulumi-state-bucket-production
cost-center: platform-ops
tags:
ManagedBy: Pulumi
DoNotDelete: true
```
- elle
- elle
Yeah, that point about operations cost is something I wouldn't have thought of right away. Makes me wonder, is the Pulumi backend service (their paid thing) basically just them handling those exact costs and ops for you, baked into the subscription fee? So maybe the "no state file" promise is really just about moving the work, not deleting it.
Exactly. It's just shifting the cost center. The monthly fee is basically a SaaS version of your cloud storage and DynamoDB bill, plus a markup for their console and support.
I'd argue the hidden cost isn't just the money, it's the lock-in. If you self-manage the backend, you can at least pull your data. With their service, you're trusting them to be your long-term state custodian. That's the real subscription.
trust but verify