azure-image-builder
hashicorp/agent-skills
Build custom Azure VM images with Packer's azure-arm builder.
What is azure-image-builder?
This skill enables building Azure managed images and Azure Compute Gallery images using Packer. Use it when you need to create custom, reusable VM images for Azure deployments with provisioning and configuration baked in.
- Build Azure managed images with custom configurations
- Publish images to Azure Compute Gallery with replication across regions
- Authenticate via service principal or managed identity
- Provision images with shell scripts and other provisioners
- Tag images with metadata for organization and tracking
- Support both Linux and Windows base images
How to install azure-image-builder
npx skills add https://github.com/hashicorp/agent-skills --skill azure-image-builder- Packer installed and configured
- Azure subscription with appropriate permissions
- Service principal or managed identity with Contributor role on target resource groups
- Azure CLI installed (for authentication setup)
How to use azure-image-builder
- 1.Create a Packer template (.pkr.hcl) defining your source image and provisioners
- 2.Set Azure authentication variables (ARM_CLIENT_ID, ARM_CLIENT_SECRET, ARM_SUBSCRIPTION_ID, ARM_TENANT_ID) or use managed identity
- 3.Run 'packer init' to download required Azure plugins
- 4.Run 'packer validate' to check template syntax
- 5.Run 'packer build' to create the image (15-45 minutes typical)
- 6.Retrieve the built image from your resource group or Compute Gallery
Use cases
- Create standardized application images for consistent VM deployments
- Build golden images with pre-installed software and security patches
- Distribute custom images across multiple Azure regions via Compute Gallery
- Automate image creation in CI/CD pipelines for infrastructure-as-code workflows
- Maintain versioned image libraries for compliance and rollback capabilities
- Infrastructure engineers managing Azure VM deployments
- DevOps teams automating image builds and distribution
- Cloud architects designing standardized VM templates
- Teams using Packer for multi-cloud image management
azure-image-builder FAQ
Building incurs charges for compute (VM running during build), storage (temporary disks), and data transfer. Costs depend on VM size, build duration, and data processed.
No, image versions are immutable. You must use unique version numbers; consider using date or build number suffixes like '1.0.20240115'.
Service principal (with client ID and secret) or managed identity via 'use_azure_cli_auth = true' for simpler setup in Azure environments.
Use the 'shared_image_gallery_destination' block with 'replication_regions' parameter to automatically copy the image to specified regions.
Check network connectivity from the build VM, verify NSG rules allow required traffic, and increase timeout settings if needed.
Full instructions (SKILL.md)
Source of truth, from hashicorp/agent-skills.
name: azure-image-builder description: Build Azure managed images and Azure Compute Gallery images with Packer. Use when creating custom images for Azure VMs. metadata: lifecycle-status: active
Azure Image Builder
Build Azure managed images and Azure Compute Gallery images using Packer's azure-arm builder.
Reference: Azure ARM Builder
Note: Building Azure images incurs costs (compute, storage, data transfer). Builds typically take 15-45 minutes depending on provisioning and OS.
Basic Managed Image
packer {
required_plugins {
azure = {
source = "github.com/hashicorp/azure"
version = "~> 2.0"
}
}
}
variable "client_id" {
type = string
sensitive = true
}
variable "client_secret" {
type = string
sensitive = true
}
variable "subscription_id" {
type = string
}
variable "tenant_id" {
type = string
}
variable "resource_group" {
type = string
default = "packer-images-rg"
}
locals {
timestamp = regex_replace(timestamp(), "[- TZ:]", "")
}
source "azure-arm" "ubuntu" {
client_id = var.client_id
client_secret = var.client_secret
subscription_id = var.subscription_id
tenant_id = var.tenant_id
managed_image_resource_group_name = var.resource_group
managed_image_name = "my-app-${local.timestamp}"
os_type = "Linux"
image_publisher = "Canonical"
image_offer = "0001-com-ubuntu-server-jammy"
image_sku = "22_04-lts-gen2"
location = "East US"
vm_size = "Standard_B2s"
azure_tags = {
Name = "my-app"
BuildDate = local.timestamp
}
}
build {
sources = ["source.azure-arm.ubuntu"]
provisioner "shell" {
inline = [
"sudo apt-get update",
"sudo apt-get upgrade -y",
]
}
}
Azure Compute Gallery
source "azure-arm" "ubuntu" {
client_id = var.client_id
client_secret = var.client_secret
subscription_id = var.subscription_id
tenant_id = var.tenant_id
os_type = "Linux"
image_publisher = "Canonical"
image_offer = "0001-com-ubuntu-server-jammy"
image_sku = "22_04-lts-gen2"
location = "East US"
vm_size = "Standard_B2s"
shared_image_gallery_destination {
resource_group = "gallery-rg"
gallery_name = "myImageGallery"
image_name = "ubuntu-webapp"
image_version = "1.0.${formatdate("YYYYMMDD", timestamp())}"
replication_regions = ["East US", "West US 2"]
storage_account_type = "Standard_LRS"
}
}
Authentication
Service Principal
# Create service principal
az ad sp create-for-rbac \
--name "packer-sp" \
--role Contributor \
--scopes /subscriptions/<subscription-id>
# Set environment variables
export ARM_CLIENT_ID="<client-id>"
export ARM_CLIENT_SECRET="<client-secret>"
export ARM_SUBSCRIPTION_ID="<subscription-id>"
export ARM_TENANT_ID="<tenant-id>"
Managed Identity
source "azure-arm" "ubuntu" {
use_azure_cli_auth = true
subscription_id = var.subscription_id
# ... rest of configuration
}
Build Commands
# Set authentication
export ARM_CLIENT_ID="your-client-id"
export ARM_CLIENT_SECRET="your-client-secret"
export ARM_SUBSCRIPTION_ID="your-subscription-id"
export ARM_TENANT_ID="your-tenant-id"
# Initialize plugins
packer init .
# Validate template
packer validate .
# Build image
packer build .
Common Issues
Authentication Failed
- Verify service principal credentials
- Ensure Contributor role on resource group
- Check subscription and tenant IDs
Compute Gallery Version Exists
- Image versions are immutable
- Use unique version numbers with date/build number
- Cannot overwrite existing versions
Timeout During Provisioning
- Check network connectivity from build VM
- Verify NSG rules allow required traffic
- Increase timeout if needed
References
Related skills
More from hashicorp/agent-skills and the wider catalog.

azure-verified-modules
Azure Verified Modules (AVM) requirements and best practices for Terraform module certification

new-terraform-provider
Scaffold a new Terraform provider project with Plugin Framework boilerplate.

provider-actions
Implement imperative Terraform Provider actions at lifecycle events using the Plugin Framework.

provider-docs
Create and validate Terraform provider documentation for Registry using HashiCorp patterns and tfplugindocs.

provider-resources
Implement Terraform Provider resources and data sources using the Plugin Framework with CRUD operations, schema design, and acceptance tests.

provider-test-patterns
Terraform provider acceptance test patterns using terraform-plugin-testing with the Plugin Framework.