windows-builder
hashicorp/agent-skills
Build Windows images with Packer using WinRM and PowerShell provisioners for AWS, Azure, and VMware.
What is windows-builder?
This skill provides platform-agnostic patterns for building Windows images with Packer. It configures WinRM communication, sets up PowerShell provisioners for software installation and Windows Updates, and includes cleanup and troubleshooting guidance. Use it when creating Windows AMIs, Azure images, or VMware templates.
- Configure WinRM communicator for AWS, Azure, and VMware sources
- Install software and features via PowerShell provisioners using Chocolatey or Windows Features
- Apply Windows Updates with automatic reboots and timeout handling
- Clean up temporary files and Windows Update cache post-build
- Troubleshoot common issues like WinRM timeouts and execution policy errors
How to install windows-builder
npx skills add https://github.com/hashicorp/agent-skills --skill windows-builder- Packer installed and configured
- Cloud provider credentials (AWS, Azure, or VMware access)
- Understanding of HCL (HashiCorp Configuration Language)
- Network access to WinRM ports 5985/5986 from Packer runner
How to use windows-builder
- 1.Define a Windows source block (amazon-ebs, azure-arm, or vsphere-iso) with WinRM communicator settings
- 2.Create a setup-winrm.ps1 script to configure WinRM on the base image via user_data_file
- 3.Add provisioner blocks for software installation using PowerShell inline commands or scripts
- 4.Include a windows-restart provisioner after Windows Updates with appropriate timeout
- 5.Add cleanup provisioners to remove temporary files and update caches
- 6.Run packer build and monitor for WinRM connection and provisioner timeouts
- 7.Verify the resulting image and test before deploying to production
Use cases
- Build Windows Server 2022 AMIs for AWS with pre-installed applications
- Create Azure managed images with IIS and custom software configured
- Automate Windows Update patching across base images before deployment
- Generate VMware templates with standardized software and security configurations
- Reduce manual image preparation time from hours to automated builds
- Infrastructure engineers building Windows images at scale
- DevOps teams automating Windows AMI and Azure image creation
- System administrators standardizing Windows server configurations
- Cloud platform teams managing Windows template libraries
windows-builder FAQ
Windows Updates are the primary cause of long build times, often taking 1-2 hours. Use pre-patched base images when available and set provisioner timeouts to 2h or more.
Always verify cleanup in your cloud provider console. Failed builds may leave instances or snapshots running, incurring costs. Manually terminate or delete orphaned resources.
Increase winrm_timeout to 15m or more, verify security group rules allow ports 5985/5986, and check that the user_data setup script completed successfully.
Yes, the skill includes examples for AWS, Azure, and VMware. The WinRM communicator and PowerShell provisioners work across all three platforms with platform-specific source block configuration.
Use PowerShell provisioners with direct installation commands, MSI files, or Windows Features (Install-WindowsFeature). Chocolatey is optional but recommended for simplicity.
Full instructions (SKILL.md)
Source of truth, from hashicorp/agent-skills.
name: windows-builder description: Build Windows images with Packer using WinRM communicator and PowerShell provisioners. Use when creating Windows AMIs, Azure images, or VMware templates. metadata: lifecycle-status: active
Windows Builder
Platform-agnostic patterns for building Windows images with Packer.
Reference: WinRM Communicator
Note: Windows builds incur significant costs and time. Expect 45-120 minutes per build due to Windows Updates. Failed builds may leave resources running - always verify cleanup.
WinRM Communicator Setup
Windows requires WinRM for Packer communication.
AWS Example
source "amazon-ebs" "windows" {
region = "us-west-2"
instance_type = "t3.medium"
source_ami_filter {
filters = {
name = "Windows_Server-2022-English-Full-Base-*"
}
most_recent = true
owners = ["amazon"]
}
ami_name = "windows-server-2022-${local.timestamp}"
communicator = "winrm"
winrm_username = "Administrator"
winrm_use_ssl = true
winrm_insecure = true
winrm_timeout = "15m"
user_data_file = "scripts/setup-winrm.ps1"
}
WinRM Setup Script (scripts/setup-winrm.ps1)
<powershell>
# Configure WinRM
winrm quickconfig -q
winrm set winrm/config '@{MaxTimeoutms="1800000"}'
winrm set winrm/config/service '@{AllowUnencrypted="true"}'
winrm set winrm/config/service/auth '@{Basic="true"}'
# Configure firewall
netsh advfirewall firewall add rule name="WinRM 5985" protocol=TCP dir=in localport=5985 action=allow
netsh advfirewall firewall add rule name="WinRM 5986" protocol=TCP dir=in localport=5986 action=allow
# Restart WinRM
net stop winrm
net start winrm
</powershell>
Azure Example
source "azure-arm" "windows" {
client_id = var.client_id
client_secret = var.client_secret
subscription_id = var.subscription_id
tenant_id = var.tenant_id
managed_image_resource_group_name = "images-rg"
managed_image_name = "windows-${local.timestamp}"
os_type = "Windows"
image_publisher = "MicrosoftWindowsServer"
image_offer = "WindowsServer"
image_sku = "2022-datacenter-g2"
location = "East US"
vm_size = "Standard_D2s_v3"
# Azure auto-configures WinRM
communicator = "winrm"
winrm_use_ssl = true
winrm_insecure = true
winrm_timeout = "15m"
winrm_username = "packer"
}
PowerShell Provisioners
Install Software
build {
sources = ["source.amazon-ebs.windows"]
# Install Chocolatey
provisioner "powershell" {
inline = [
"Set-ExecutionPolicy Bypass -Scope Process -Force",
"iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))"
]
}
# Install applications
provisioner "powershell" {
inline = [
"choco install -y googlechrome",
"choco install -y 7zip",
]
}
# Install IIS
provisioner "powershell" {
inline = [
"Install-WindowsFeature -Name Web-Server -IncludeManagementTools"
]
}
}
Windows Updates
provisioner "powershell" {
inline = [
"Install-PackageProvider -Name NuGet -Force",
"Install-Module -Name PSWindowsUpdate -Force",
"Import-Module PSWindowsUpdate",
"Get-WindowsUpdate -Install -AcceptAll -AutoReboot",
]
timeout = "2h"
}
# Wait for reboots
provisioner "windows-restart" {
restart_timeout = "30m"
}
Cleanup
provisioner "powershell" {
inline = [
"# Clear temp files",
"Remove-Item -Path 'C:\\Windows\\Temp\\*' -Recurse -Force -ErrorAction SilentlyContinue",
"# Clear Windows Update cache",
"Stop-Service -Name wuauserv -Force",
"Remove-Item -Path 'C:\\Windows\\SoftwareDistribution\\*' -Recurse -Force -ErrorAction SilentlyContinue",
"Start-Service -Name wuauserv",
]
}
Common Issues
WinRM Timeout
- Increase
winrm_timeoutto 15m or more - Verify security group allows ports 5985/5986
- Check user data script completed successfully
PowerShell Execution Policy
provisioner "powershell" {
inline = [
"Set-ExecutionPolicy Bypass -Scope Process -Force",
"# Your commands here",
]
}
Long Build Times
- Windows Updates can take 1-2 hours
- Use pre-patched base images when available
- Set provisioner
timeout = "2h"
References
Related skills
More from hashicorp/agent-skills and the wider catalog.

aws-ami-builder
Build custom Amazon Machine Images (AMIs) with Packer's amazon-ebs builder for EC2 deployments.

azure-image-builder
Build custom Azure VM images with Packer's azure-arm builder.

azure-verified-modules
Azure Verified Modules (AVM) requirements and best practices for Terraform module certification

new-terraform-provider
Scaffold a new Terraform provider project with Plugin Framework boilerplate.

gen-paylink-govilo
Upload files to Govilo and generate paid unlock links via Bot API.

ultracite
Zero-config linting and formatting for JavaScript/TypeScript projects with Oxlint, Biome, or ESLint.