Lumaft
Your state. Your infrastructure. A clearer view.
IaC illuminated.
Lumaft is a self-hosted, read-only view into Pulumi state held in self-managed backends, and reads Terraform and OpenTofu state from the same ones. It connects to S3 and S3-compatible backends while your state and deployment workflows stay where they are.
Lumaft is in development. No supported public release or image is currently published. No release date has been announced.
Visibility for the backend you already run
Pulumi already supports capable self-managed backends. Lumaft adds an operator-friendly view without asking you to replace them.
Your Pulumi CLI and automation remain responsible for infrastructure changes. Lumaft connects alongside them, reads the state and operational metadata it supports, and builds a bounded model for its console.
- No state migration and no replacement CI/CD pipeline.
- No apply, destroy, import, or refresh controls.
- Whole-state capture is off by default. Retained state downloads require separate recovery permission and an audit.
- Marked Pulumi secrets stay encrypted and are shown as redacted in normalized inventory. Whole-state recovery artifacts can contain sensitive values and need separate handling.
Pulumi state
S3 or S3-compatible
Operator view
Inventory and history
Useful on day one, intentionally bounded
Pulumi on S3
Connect one or more self-managed Pulumi backends that store state in AWS S3 or an S3-compatible object store.
Operational context
Inspect projects, stacks, resources, redacted outputs, update history, and active locks in one browser view.
Read-only by design
Use credentials scoped for observation. Lumaft does not apply, destroy, import, or refresh infrastructure.
Self-hosted
Run Lumaft in your environment while the Pulumi state and deployment pipeline you already operate stay in place.
Terraform and OpenTofu state
Observe Terraform and OpenTofu state in the same self-managed S3 backends, verified against Terraform 1.15.9 and OpenTofu 1.12.6. Terraform and OpenTofu can write native S3 lock files when locking is enabled, but Lumaft does not currently observe them. Backend-native update history remains unavailable for those engines.
Explore with Dino
Dino is Lumaft’s isolated local evaluation environment for exploring sample infrastructure evidence. It is not a production deployment.
Community is the complete core
The capabilities above are the core of Community, not a limited preview of a paid product. Everything in the core is and stays in Community. Paid editions add organizational leverage on top of that core; they never gate it.
Community
$0
The complete core. Unlimited users, backends, stacks and resources — no trial clock, no separate image, no provider-limited demo.
- Read-only S3 and S3-compatible observation
- Local authentication with administered local accounts
- Three fixed roles — administrator, viewer, and transcript-reader
- SQLite single-replica operation
- Backend diagnostics, inventory, resources, redacted outputs
- Durable per-stack timeline and cross-stack operations inbox
- Stable permission-checked links, URL and time state
- Coverage and gap explanations
- Strongly correlated preview / update comparison
- Resource history
- Guided first-run readiness
- In-app attention state
- Active locks and live invalidation
- Generic runner and developer ingestion
- Baseline versioned export
- Attributable retention policy changes and deletion audit
- Unconditional preservation interlock
- Up to 1 year of operation and resource history
- Dino evaluation
- Baseline security, in full
- Basic customer-local reliability summaries
Business
$199/mo · $1,990/yr
Everything in Community, plus wider retention. Further Business capability is under development and is listed here only when it ships.
- Custom roles composed from the permission catalogue
- Saved views
- Outbound notification delivery
- Advanced historical reliability segmentation
- Customer-operated PostgreSQL, single replica
- Wider retention, maximum 3,650 days
Enterprise
$499/mo · $4,990/yr
Everything in Business, plus legal-hold placement and best-effort support from the maintainer. Further Enterprise capability is under development and is listed here only when it ships.
- Federated identity — OIDC, SAML, SCIM, trusted-proxy
- Resource-scoped authorization
- Ability to place a legal hold
Enterprise Advanced Security
from $9,999/yr
For air-gapped, restricted, and regulated environments: the exact Enterprise capability set through an organization-wide offline-site licence. No additional runtime capability and no additional limit, ever — every offering receives identical application security controls and fixes.
Paid editions are not yet purchasable. Pricing is published ahead of availability, and questions about editions are welcome at sales@dekglas.com.
Edition boundaries may be refined while Lumaft is in development. Three commitments hold either way: the core never shrinks, security is never paid, and no downgrade ever deletes data.
Pulumi Cloud or Lumaft? Start with the constraint.
Pulumi Cloud and Lumaft solve different versions of the state-operations problem. The right answer depends on where your state may live, which capabilities you need, and who should operate the service.
Choose Pulumi Cloud when you can
Pulumi Cloud is an excellent service. If your team can place state there, its pricing works for your estate, and you want a managed platform with mature collaboration and governance, use it. You will get far more than a focused, read-only observer, without operating the service yourself.
Choose Lumaft when the state must stay with you
Lumaft is for teams whose policy, compliance boundary, cost model, or operating preference keeps them on self-managed backends. It adds focused visibility while leaving state and deployments under the controls they already operate.
What is published today
Lumaft is built for Pulumi state in self-managed S3 and S3-compatible backends. It is in development, and no release stage is scoped or announced.
The public image, installation guide, supported configuration, and release evidence will be published together with the first release. Until then there is nothing to download, and this page describes what Lumaft does rather than when you can run it.
In development
Pulumi · S3 · S3-compatible · Self-hosted · Community
Lumaft is an independent product by Dekglas. It is not affiliated with, sponsored by, or endorsed by Pulumi Corporation; IBM or HashiCorp; The Linux Foundation or the OpenTofu project; Amazon Web Services; Microsoft; Google; or the PostgreSQL project or PostgreSQL Community Association of Canada. Product names and trademarks belong to their respective owners.