PluginBench
Skill
Official
Review
Audit score 70

aws-ami-builder

hashicorp/agent-skills

Build custom Amazon Machine Images (AMIs) with Packer's amazon-ebs builder for EC2 deployments.

What is aws-ami-builder?

This skill enables you to create custom AMIs using HashiCorp Packer's amazon-ebs builder. Use it when you need to bake applications, configurations, and dependencies into reusable EC2 images. Builds typically take 10–30 minutes and incur AWS costs for compute and storage.

  • Define AMI templates in HCL with source AMI filters for Ubuntu, Amazon Linux, and other distributions
  • Provision instances with shell scripts, file uploads, and other provisioners during the build
  • Copy built AMIs to multiple AWS regions automatically
  • Tag and manage AMI metadata for tracking and organization
  • Validate templates and manage Packer plugin dependencies
  • Authenticate using environment variables, AWS credentials file, or IAM instance profiles

How to install aws-ami-builder

npx skills add https://github.com/hashicorp/agent-skills --skill aws-ami-builder
Prerequisites
  • Packer installed and in PATH
  • AWS account with EC2, EBS, and AMI permissions
  • AWS credentials configured via environment variables, ~/.aws/credentials, or IAM instance profile
  • Security group allowing SSH access (port 22) to build instances
Claude Code
Cursor
Windsurf
Cline

How to use aws-ami-builder

  1. 1.Create a Packer HCL template (.pkr.hcl) with source and build blocks
  2. 2.Run `packer init .` to download required plugins
  3. 3.Run `packer validate .` to check template syntax
  4. 4.Run `packer build .` to launch the build instance, provision it, and create the AMI
  5. 5.Verify the AMI in the AWS console or retrieve its ID from build output

Use cases

Good for
  • Create standardized application images with pre-installed dependencies for consistent deployments
  • Build hardened base images with security patches and compliance configurations
  • Generate multi-region AMIs for disaster recovery and global application distribution
  • Automate image creation in CI/CD pipelines to replace manual snapshot processes
  • Maintain versioned AMI catalogs with timestamps for rollback and audit trails
Who it's for
  • DevOps engineers building infrastructure-as-code pipelines
  • Cloud architects designing AMI strategies for EC2 deployments
  • Platform teams standardizing application images across environments
  • Infrastructure automation specialists integrating Packer into CI/CD systems

aws-ami-builder FAQ

How much does it cost to build an AMI?

Costs depend on instance type, build duration, and EBS storage. A t3.micro build typically costs $0.01–0.05 per build. Refer to AWS pricing for your region and instance type.

Can I build AMIs in multiple regions at once?

Yes, use the `ami_regions` parameter to copy the built AMI to additional regions automatically after the primary build completes.

How do I avoid 'AMI already exists' errors?

Use dynamic naming with timestamps or build IDs, such as `ami_name = "my-app-${local.timestamp}"`, to ensure unique AMI names.

What if the SSH connection times out during the build?

Verify the security group allows inbound SSH (port 22), ensure the subnet has internet access, and check that the source AMI uses a compatible SSH username (e.g., 'ubuntu' for Ubuntu AMIs).

Can I use Packer to build AMIs from custom source AMIs?

Yes, replace the `source_ami_filter` block with a static `source_ami` ID, or adjust the filter to match your custom AMI's name and owner.

Full instructions (SKILL.md)

Source of truth, from hashicorp/agent-skills.


name: aws-ami-builder description: Build Amazon Machine Images (AMIs) with Packer using the amazon-ebs builder. Use when creating custom AMIs for EC2 instances. metadata: lifecycle-status: active

AWS AMI Builder

Build Amazon Machine Images (AMIs) using Packer's amazon-ebs builder.

Reference: Amazon EBS Builder

Note: Building AMIs incurs AWS costs (EC2 instances, EBS storage, data transfer). Builds typically take 10-30 minutes depending on provisioning complexity.

Basic AMI Template

packer {
  required_plugins {
    amazon = {
      source  = "github.com/hashicorp/amazon"
      version = "~> 1.3"
    }
  }
}

variable "region" {
  type    = string
  default = "us-west-2"
}

locals {
  timestamp = regex_replace(timestamp(), "[- TZ:]", "")
}

source "amazon-ebs" "ubuntu" {
  region        = var.region
  instance_type = "t3.micro"

  source_ami_filter {
    filters = {
      name                = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"
      root-device-type    = "ebs"
      virtualization-type = "hvm"
    }
    most_recent = true
    owners      = ["099720109477"] # Canonical
  }

  ssh_username = "ubuntu"
  ami_name     = "my-app-${local.timestamp}"

  tags = {
    Name      = "my-app"
    BuildDate = local.timestamp
  }
}

build {
  sources = ["source.amazon-ebs.ubuntu"]

  provisioner "shell" {
    inline = [
      "sudo apt-get update",
      "sudo apt-get upgrade -y",
    ]
  }
}

Common Source AMI Filters

Ubuntu 22.04 LTS

source_ami_filter {
  filters = {
    name                = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"
    root-device-type    = "ebs"
    virtualization-type = "hvm"
  }
  most_recent = true
  owners      = ["099720109477"] # Canonical
}

Amazon Linux 2023

source_ami_filter {
  filters = {
    name                = "al2023-ami-*-x86_64"
    root-device-type    = "ebs"
    virtualization-type = "hvm"
  }
  most_recent = true
  owners      = ["amazon"]
}

Multi-Region AMI

source "amazon-ebs" "ubuntu" {
  region        = "us-west-2"
  instance_type = "t3.micro"

  source_ami_filter {
    filters = {
      name = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"
    }
    most_recent = true
    owners      = ["099720109477"]
  }

  ssh_username = "ubuntu"
  ami_name     = "my-app-${local.timestamp}"

  # Copy to additional regions
  ami_regions = ["us-east-1", "us-east-2", "eu-west-1"]
}

Authentication

Packer uses AWS credential resolution:

  1. Environment variables: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY
  2. AWS credentials file: ~/.aws/credentials
  3. IAM instance profile (when running on EC2)
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_REGION="us-west-2"

packer build .

Build Commands

# Initialize plugins
packer init .

# Validate template
packer validate .

# Build AMI
packer build .

# Build with variables
packer build -var "region=us-east-1" .

Common Issues

SSH Timeout

  • Ensure security group allows SSH (port 22)
  • Verify subnet has internet access

AMI Already Exists

  • AMI names must be unique
  • Use timestamp in name: my-app-${local.timestamp}

Volume Size Too Small

  • Check source AMI's volume size
  • Set launch_block_device_mappings.volume_size accordingly

References