All skills
hashicorp avatar

/azure-image-builder

@4451cec official
by hashicorphashicorp/agent-skills880 stars
130

Build Azure managed images and Azure Compute Gallery images with Packer. Use when creating custom images for Azure VMs.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/azure-image-builder

This session only. Nothing lands on disk.

SKILL.md

≈35 tokens always: the name and description. ≈1k when used: this file.

Azure Image Builder

Build Azure managed images and Azure Compute Gallery images using Packer's azure-arm builder.

Reference: Azure ARM Builder

Note: Building Azure images incurs costs (compute, storage, data transfer). Builds typically take 15-45 minutes depending on provisioning and OS.

Basic Managed Image

packer {
  required_plugins {
    azure = {
      source  = "github.com/hashicorp/azure"
      version = "~> 2.0"
    }
  }
}

variable "client_id" {
  type      = string
  sensitive = true
}

variable "client_secret" {
  type      = string
  sensitive = true
}

variable "subscription_id" {
  type = string
}

variable "tenant_id" {
  type = string
}

variable "resource_group" {
  type    = string
  default = "packer-images-rg"
}

locals {
  timestamp = regex_replace(timestamp(), "[- TZ:]", "")
}

source "azure-arm" "ubuntu" {
  client_id       = var.client_id
  client_secret   = var.client_secret
  subscription_id = var.subscription_id
  tenant_id       = var.tenant_id

  managed_image_resource_group_name = var.resource_group
  managed_image_name                = "my-app-${local.timestamp}"

  os_type         = "Linux"
  image_publisher = "Canonical"
  image_offer     = "0001-com-ubuntu-server-jammy"
  image_sku       = "22_04-lts-gen2"

  location = "East US"
  vm_size  = "Standard_B2s"

  azure_tags = {
    Name      = "my-app"
    BuildDate = local.timestamp
  }
}

build {
  sources = ["source.azure-arm.ubuntu"]

  provisioner "shell" {
    inline = [
      "sudo apt-get update",
      "sudo apt-get upgrade -y",
    ]
  }
}

Azure Compute Gallery

source "azure-arm" "ubuntu" {
  client_id       = var.client_id
  client_secret   = var.client_secret
  subscription_id = var.subscription_id
  tenant_id       = var.tenant_id

  os_type         = "Linux"
  image_publisher = "Canonical"
  image_offer     = "0001-com-ubuntu-server-jammy"
  image_sku       = "22_04-lts-gen2"

  location = "East US"
  vm_size  = "Standard_B2s"

  shared_image_gallery_destination {
    resource_group       = "gallery-rg"
    gallery_name         = "myImageGallery"
    image_name           = "ubuntu-webapp"
    image_version        = "1.0.${formatdate("YYYYMMDD", timestamp())}"
    replication_regions  = ["East US", "West US 2"]
    storage_account_type = "Standard_LRS"
  }
}

Authentication

Service Principal

# Create service principal
az ad sp create-for-rbac \
  --name "packer-sp" \
  --role Contributor \
  --scopes /subscriptions/<subscription-id>

# Set environment variables
export ARM_CLIENT_ID="<client-id>"
export ARM_CLIENT_SECRET="<client-secret>"
export ARM_SUBSCRIPTION_ID="<subscription-id>"
export ARM_TENANT_ID="<tenant-id>"

Managed Identity

source "azure-arm" "ubuntu" {
  use_azure_cli_auth = true
  subscription_id    = var.subscription_id
  # ... rest of configuration
}

Build Commands

# Set authentication
export ARM_CLIENT_ID="your-client-id"
export ARM_CLIENT_SECRET="your-client-secret"
export ARM_SUBSCRIPTION_ID="your-subscription-id"
export ARM_TENANT_ID="your-tenant-id"

# Initialize plugins
packer init .

# Validate template
packer validate .

# Build image
packer build .

Common Issues

Authentication Failed

  • Verify service principal credentials
  • Ensure Contributor role on resource group
  • Check subscription and tenant IDs

Compute Gallery Version Exists

  • Image versions are immutable
  • Use unique version numbers with date/build number
  • Cannot overwrite existing versions

Timeout During Provisioning

  • Check network connectivity from build VM
  • Verify NSG rules allow required traffic
  • Increase timeout if needed

References

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides standard templates and instructions for building Azure virtual machine images using Packer. It follows security best practices by utilizing placeholders for credentials and marking sensitive variables for protection within the configuration.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 4451cec. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 months ago
metadata
{
  "lifecycle-status": "active"
}
  • azure
  • packer
  • image-builder
  • vm
  • infrastructure-as-code
  • managed-images
  • compute-gallery
  • hcl

README badge

README badge for hashicorp/agent-skills/azure-image-builder

Builds Azure managed images and Azure Compute Gallery images using Packer's azure-arm builder. Use this skill to create custom VM images for Azure with provisioning scripts, or to publish versioned images to a shared gallery for replication across regions.

Generated from the current SKILL.md.

Does this skill work with both managed images and Azure Compute Gallery?
Yes. The skill includes templates for building Azure managed images directly and for publishing to Azure Compute Gallery with replication across regions.
What authentication methods are supported?
The skill supports service principal authentication via client ID and secret, and managed identity authentication using Azure CLI credentials.
Can I reuse the same image version in Azure Compute Gallery?
No. Image versions in Compute Gallery are immutable. The skill recommends using unique version numbers with date or build number suffixes.
How long do builds typically take?
Builds typically take 15-45 minutes depending on provisioning steps and the OS, and incur charges for compute, storage, and data transfer.

Generated from the current SKILL.md. These answers refresh after source changes.