PluginBench
Skill
Official
Review
Audit score 70

azure-image-builder

hashicorp/agent-skills

Build custom Azure VM images with Packer's azure-arm builder.

What is azure-image-builder?

This skill enables building Azure managed images and Azure Compute Gallery images using Packer. Use it when you need to create custom, reusable VM images for Azure deployments with provisioning and configuration baked in.

  • Build Azure managed images with custom configurations
  • Publish images to Azure Compute Gallery with replication across regions
  • Authenticate via service principal or managed identity
  • Provision images with shell scripts and other provisioners
  • Tag images with metadata for organization and tracking
  • Support both Linux and Windows base images

How to install azure-image-builder

npx skills add https://github.com/hashicorp/agent-skills --skill azure-image-builder
Prerequisites
  • Packer installed and configured
  • Azure subscription with appropriate permissions
  • Service principal or managed identity with Contributor role on target resource groups
  • Azure CLI installed (for authentication setup)
Claude Code
Cursor
Windsurf
Cline

How to use azure-image-builder

  1. 1.Create a Packer template (.pkr.hcl) defining your source image and provisioners
  2. 2.Set Azure authentication variables (ARM_CLIENT_ID, ARM_CLIENT_SECRET, ARM_SUBSCRIPTION_ID, ARM_TENANT_ID) or use managed identity
  3. 3.Run 'packer init' to download required Azure plugins
  4. 4.Run 'packer validate' to check template syntax
  5. 5.Run 'packer build' to create the image (15-45 minutes typical)
  6. 6.Retrieve the built image from your resource group or Compute Gallery

Use cases

Good for
  • Create standardized application images for consistent VM deployments
  • Build golden images with pre-installed software and security patches
  • Distribute custom images across multiple Azure regions via Compute Gallery
  • Automate image creation in CI/CD pipelines for infrastructure-as-code workflows
  • Maintain versioned image libraries for compliance and rollback capabilities
Who it's for
  • Infrastructure engineers managing Azure VM deployments
  • DevOps teams automating image builds and distribution
  • Cloud architects designing standardized VM templates
  • Teams using Packer for multi-cloud image management

azure-image-builder FAQ

What are the costs of building Azure images?

Building incurs charges for compute (VM running during build), storage (temporary disks), and data transfer. Costs depend on VM size, build duration, and data processed.

Can I reuse the same image version in Azure Compute Gallery?

No, image versions are immutable. You must use unique version numbers; consider using date or build number suffixes like '1.0.20240115'.

What authentication methods are supported?

Service principal (with client ID and secret) or managed identity via 'use_azure_cli_auth = true' for simpler setup in Azure environments.

How do I replicate images across multiple Azure regions?

Use the 'shared_image_gallery_destination' block with 'replication_regions' parameter to automatically copy the image to specified regions.

What should I do if the build times out during provisioning?

Check network connectivity from the build VM, verify NSG rules allow required traffic, and increase timeout settings if needed.

Full instructions (SKILL.md)

Source of truth, from hashicorp/agent-skills.


name: azure-image-builder description: Build Azure managed images and Azure Compute Gallery images with Packer. Use when creating custom images for Azure VMs. metadata: lifecycle-status: active

Azure Image Builder

Build Azure managed images and Azure Compute Gallery images using Packer's azure-arm builder.

Reference: Azure ARM Builder

Note: Building Azure images incurs costs (compute, storage, data transfer). Builds typically take 15-45 minutes depending on provisioning and OS.

Basic Managed Image

packer {
  required_plugins {
    azure = {
      source  = "github.com/hashicorp/azure"
      version = "~> 2.0"
    }
  }
}

variable "client_id" {
  type      = string
  sensitive = true
}

variable "client_secret" {
  type      = string
  sensitive = true
}

variable "subscription_id" {
  type = string
}

variable "tenant_id" {
  type = string
}

variable "resource_group" {
  type    = string
  default = "packer-images-rg"
}

locals {
  timestamp = regex_replace(timestamp(), "[- TZ:]", "")
}

source "azure-arm" "ubuntu" {
  client_id       = var.client_id
  client_secret   = var.client_secret
  subscription_id = var.subscription_id
  tenant_id       = var.tenant_id

  managed_image_resource_group_name = var.resource_group
  managed_image_name                = "my-app-${local.timestamp}"

  os_type         = "Linux"
  image_publisher = "Canonical"
  image_offer     = "0001-com-ubuntu-server-jammy"
  image_sku       = "22_04-lts-gen2"

  location = "East US"
  vm_size  = "Standard_B2s"

  azure_tags = {
    Name      = "my-app"
    BuildDate = local.timestamp
  }
}

build {
  sources = ["source.azure-arm.ubuntu"]

  provisioner "shell" {
    inline = [
      "sudo apt-get update",
      "sudo apt-get upgrade -y",
    ]
  }
}

Azure Compute Gallery

source "azure-arm" "ubuntu" {
  client_id       = var.client_id
  client_secret   = var.client_secret
  subscription_id = var.subscription_id
  tenant_id       = var.tenant_id

  os_type         = "Linux"
  image_publisher = "Canonical"
  image_offer     = "0001-com-ubuntu-server-jammy"
  image_sku       = "22_04-lts-gen2"

  location = "East US"
  vm_size  = "Standard_B2s"

  shared_image_gallery_destination {
    resource_group       = "gallery-rg"
    gallery_name         = "myImageGallery"
    image_name           = "ubuntu-webapp"
    image_version        = "1.0.${formatdate("YYYYMMDD", timestamp())}"
    replication_regions  = ["East US", "West US 2"]
    storage_account_type = "Standard_LRS"
  }
}

Authentication

Service Principal

# Create service principal
az ad sp create-for-rbac \
  --name "packer-sp" \
  --role Contributor \
  --scopes /subscriptions/<subscription-id>

# Set environment variables
export ARM_CLIENT_ID="<client-id>"
export ARM_CLIENT_SECRET="<client-secret>"
export ARM_SUBSCRIPTION_ID="<subscription-id>"
export ARM_TENANT_ID="<tenant-id>"

Managed Identity

source "azure-arm" "ubuntu" {
  use_azure_cli_auth = true
  subscription_id    = var.subscription_id
  # ... rest of configuration
}

Build Commands

# Set authentication
export ARM_CLIENT_ID="your-client-id"
export ARM_CLIENT_SECRET="your-client-secret"
export ARM_SUBSCRIPTION_ID="your-subscription-id"
export ARM_TENANT_ID="your-tenant-id"

# Initialize plugins
packer init .

# Validate template
packer validate .

# Build image
packer build .

Common Issues

Authentication Failed

  • Verify service principal credentials
  • Ensure Contributor role on resource group
  • Check subscription and tenant IDs

Compute Gallery Version Exists

  • Image versions are immutable
  • Use unique version numbers with date/build number
  • Cannot overwrite existing versions

Timeout During Provisioning

  • Check network connectivity from build VM
  • Verify NSG rules allow required traffic
  • Increase timeout if needed

References