PluginBench
Skill
Official
Review
Audit score 70

aws-ami-builder

hashicorp/agent-skills

Build custom Amazon Machine Images (AMIs) with Packer's amazon-ebs builder for EC2 deployments.

What is aws-ami-builder?

This skill enables you to create custom AMIs using Packer's amazon-ebs builder. Use it when you need to build standardized, reusable machine images for EC2 instances with custom software, configurations, or patches baked in.

  • Build AMIs from source images (Ubuntu, Amazon Linux, etc.) using Packer templates
  • Apply provisioners (shell scripts, configuration management) during the build process
  • Copy AMIs across multiple AWS regions automatically
  • Filter and select source AMIs by name, virtualization type, and owner
  • Tag AMIs with metadata for organization and tracking
  • Validate templates and manage builds via command-line tools

How to install aws-ami-builder

npx skills add https://github.com/hashicorp/agent-skills --skill aws-ami-builder
Prerequisites
  • Packer installed and in PATH
  • AWS credentials configured (environment variables, ~/.aws/credentials, or IAM instance profile)
  • AWS IAM permissions to create EC2 instances, EBS volumes, and AMIs
  • VPC and security group allowing SSH access (port 22) for provisioning
Claude Code
Cursor
Windsurf
Cline

How to use aws-ami-builder

  1. 1.Create a Packer template file (e.g., main.pkr.hcl) with source and build blocks
  2. 2.Run `packer init .` to download required plugins
  3. 3.Run `packer validate .` to check template syntax
  4. 4.Run `packer build .` to start the AMI build process
  5. 5.Monitor the build logs; Packer will launch an EC2 instance, run provisioners, and create the AMI
  6. 6.Retrieve the AMI ID from the build output for use in EC2 deployments

Use cases

Good for
  • Create standardized application images with pre-installed dependencies and configurations
  • Build hardened base images with security patches and compliance requirements
  • Generate multi-region AMIs for disaster recovery and global deployments
  • Automate AMI creation as part of CI/CD pipelines
  • Build images with custom software stacks for specific workloads
Who it's for
  • DevOps engineers managing EC2 infrastructure
  • Platform teams building standardized machine images
  • Infrastructure-as-code practitioners using Packer
  • AWS architects designing scalable deployment strategies

aws-ami-builder FAQ

How long does an AMI build take?

Builds typically take 10-30 minutes depending on provisioning complexity, including EC2 instance launch, provisioner execution, and AMI creation.

What are the costs of building AMIs?

Building incurs AWS costs for EC2 instances, EBS storage, and data transfer. Using smaller instance types (t3.micro) and optimizing provisioners reduces costs.

How do I use different source AMIs?

Use source_ami_filter blocks to search by name, owner, and attributes. Examples for Ubuntu 22.04 and Amazon Linux 2023 are provided in the skill documentation.

Can I build AMIs in multiple regions?

Yes, use the ami_regions parameter in the source block to automatically copy the AMI to additional regions after the build completes.

How do I handle AMI name conflicts?

Use unique naming strategies like timestamps (my-app-${local.timestamp}) to avoid conflicts, since AMI names must be unique within a region.

Full instructions (SKILL.md)

Source of truth, from hashicorp/agent-skills.


name: aws-ami-builder description: Build Amazon Machine Images (AMIs) with Packer using the amazon-ebs builder. Use when creating custom AMIs for EC2 instances.

AWS AMI Builder

Build Amazon Machine Images (AMIs) using Packer's amazon-ebs builder.

Reference: Amazon EBS Builder

Note: Building AMIs incurs AWS costs (EC2 instances, EBS storage, data transfer). Builds typically take 10-30 minutes depending on provisioning complexity.

Basic AMI Template

packer {
  required_plugins {
    amazon = {
      source  = "github.com/hashicorp/amazon"
      version = "~> 1.3"
    }
  }
}

variable "region" {
  type    = string
  default = "us-west-2"
}

locals {
  timestamp = regex_replace(timestamp(), "[- TZ:]", "")
}

source "amazon-ebs" "ubuntu" {
  region        = var.region
  instance_type = "t3.micro"

  source_ami_filter {
    filters = {
      name                = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"
      root-device-type    = "ebs"
      virtualization-type = "hvm"
    }
    most_recent = true
    owners      = ["099720109477"] # Canonical
  }

  ssh_username = "ubuntu"
  ami_name     = "my-app-${local.timestamp}"

  tags = {
    Name      = "my-app"
    BuildDate = local.timestamp
  }
}

build {
  sources = ["source.amazon-ebs.ubuntu"]

  provisioner "shell" {
    inline = [
      "sudo apt-get update",
      "sudo apt-get upgrade -y",
    ]
  }
}

Common Source AMI Filters

Ubuntu 22.04 LTS

source_ami_filter {
  filters = {
    name                = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"
    root-device-type    = "ebs"
    virtualization-type = "hvm"
  }
  most_recent = true
  owners      = ["099720109477"] # Canonical
}

Amazon Linux 2023

source_ami_filter {
  filters = {
    name                = "al2023-ami-*-x86_64"
    root-device-type    = "ebs"
    virtualization-type = "hvm"
  }
  most_recent = true
  owners      = ["amazon"]
}

Multi-Region AMI

source "amazon-ebs" "ubuntu" {
  region        = "us-west-2"
  instance_type = "t3.micro"

  source_ami_filter {
    filters = {
      name = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"
    }
    most_recent = true
    owners      = ["099720109477"]
  }

  ssh_username = "ubuntu"
  ami_name     = "my-app-${local.timestamp}"

  # Copy to additional regions
  ami_regions = ["us-east-1", "us-east-2", "eu-west-1"]
}

Authentication

Packer uses AWS credential resolution:

  1. Environment variables: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY
  2. AWS credentials file: ~/.aws/credentials
  3. IAM instance profile (when running on EC2)
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_REGION="us-west-2"

packer build .

Build Commands

# Initialize plugins
packer init .

# Validate template
packer validate .

# Build AMI
packer build .

# Build with variables
packer build -var "region=us-east-1" .

Common Issues

SSH Timeout

  • Ensure security group allows SSH (port 22)
  • Verify subnet has internet access

AMI Already Exists

  • AMI names must be unique
  • Use timestamp in name: my-app-${local.timestamp}

Volume Size Too Small

  • Check source AMI's volume size
  • Set launch_block_device_mappings.volume_size accordingly

References