PluginBench
Skill
Official
Review
Audit score 70

windows-builder

hashicorp/agent-skills

Build Windows images with Packer using WinRM and PowerShell provisioners for AWS, Azure, and VMware.

What is windows-builder?

This skill provides platform-agnostic patterns for building Windows images with Packer. It configures WinRM communication, sets up PowerShell provisioners for software installation and Windows Updates, and includes cleanup and troubleshooting guidance. Use it when creating Windows AMIs, Azure images, or VMware templates.

  • Configure WinRM communicator for AWS, Azure, and VMware sources
  • Install software and features via PowerShell provisioners using Chocolatey or Windows Features
  • Apply Windows Updates with automatic reboots and timeout handling
  • Clean up temporary files and Windows Update cache post-build
  • Troubleshoot common issues like WinRM timeouts and execution policy errors

How to install windows-builder

npx skills add https://github.com/hashicorp/agent-skills --skill windows-builder
Prerequisites
  • Packer installed and configured
  • Cloud provider credentials (AWS, Azure, or VMware access)
  • Understanding of HCL (HashiCorp Configuration Language)
  • Network access to WinRM ports 5985/5986 from Packer runner
Claude Code
Cursor
Windsurf
Cline

How to use windows-builder

  1. 1.Define a Windows source block (amazon-ebs, azure-arm, or vsphere-iso) with WinRM communicator settings
  2. 2.Create a setup-winrm.ps1 script to configure WinRM on the base image via user_data_file
  3. 3.Add provisioner blocks for software installation using PowerShell inline commands or scripts
  4. 4.Include a windows-restart provisioner after Windows Updates with appropriate timeout
  5. 5.Add cleanup provisioners to remove temporary files and update caches
  6. 6.Run packer build and monitor for WinRM connection and provisioner timeouts
  7. 7.Verify the resulting image and test before deploying to production

Use cases

Good for
  • Build Windows Server 2022 AMIs for AWS with pre-installed applications
  • Create Azure managed images with IIS and custom software configured
  • Automate Windows Update patching across base images before deployment
  • Generate VMware templates with standardized software and security configurations
  • Reduce manual image preparation time from hours to automated builds
Who it's for
  • Infrastructure engineers building Windows images at scale
  • DevOps teams automating Windows AMI and Azure image creation
  • System administrators standardizing Windows server configurations
  • Cloud platform teams managing Windows template libraries

windows-builder FAQ

Why do Windows builds take 45-120 minutes?

Windows Updates are the primary cause of long build times, often taking 1-2 hours. Use pre-patched base images when available and set provisioner timeouts to 2h or more.

What should I do if a build fails and leaves resources running?

Always verify cleanup in your cloud provider console. Failed builds may leave instances or snapshots running, incurring costs. Manually terminate or delete orphaned resources.

How do I fix WinRM timeout errors?

Increase winrm_timeout to 15m or more, verify security group rules allow ports 5985/5986, and check that the user_data setup script completed successfully.

Can I use this skill for non-AWS platforms?

Yes, the skill includes examples for AWS, Azure, and VMware. The WinRM communicator and PowerShell provisioners work across all three platforms with platform-specific source block configuration.

How do I install applications without Chocolatey?

Use PowerShell provisioners with direct installation commands, MSI files, or Windows Features (Install-WindowsFeature). Chocolatey is optional but recommended for simplicity.

Full instructions (SKILL.md)

Source of truth, from hashicorp/agent-skills.


name: windows-builder description: Build Windows images with Packer using WinRM communicator and PowerShell provisioners. Use when creating Windows AMIs, Azure images, or VMware templates. metadata: lifecycle-status: active

Windows Builder

Platform-agnostic patterns for building Windows images with Packer.

Reference: WinRM Communicator

Note: Windows builds incur significant costs and time. Expect 45-120 minutes per build due to Windows Updates. Failed builds may leave resources running - always verify cleanup.

WinRM Communicator Setup

Windows requires WinRM for Packer communication.

AWS Example

source "amazon-ebs" "windows" {
  region        = "us-west-2"
  instance_type = "t3.medium"

  source_ami_filter {
    filters = {
      name = "Windows_Server-2022-English-Full-Base-*"
    }
    most_recent = true
    owners      = ["amazon"]
  }

  ami_name = "windows-server-2022-${local.timestamp}"

  communicator   = "winrm"
  winrm_username = "Administrator"
  winrm_use_ssl  = true
  winrm_insecure = true
  winrm_timeout  = "15m"

  user_data_file = "scripts/setup-winrm.ps1"
}

WinRM Setup Script (scripts/setup-winrm.ps1)

<powershell>
# Configure WinRM
winrm quickconfig -q
winrm set winrm/config '@{MaxTimeoutms="1800000"}'
winrm set winrm/config/service '@{AllowUnencrypted="true"}'
winrm set winrm/config/service/auth '@{Basic="true"}'

# Configure firewall
netsh advfirewall firewall add rule name="WinRM 5985" protocol=TCP dir=in localport=5985 action=allow
netsh advfirewall firewall add rule name="WinRM 5986" protocol=TCP dir=in localport=5986 action=allow

# Restart WinRM
net stop winrm
net start winrm
</powershell>

Azure Example

source "azure-arm" "windows" {
  client_id       = var.client_id
  client_secret   = var.client_secret
  subscription_id = var.subscription_id
  tenant_id       = var.tenant_id

  managed_image_resource_group_name = "images-rg"
  managed_image_name                = "windows-${local.timestamp}"

  os_type         = "Windows"
  image_publisher = "MicrosoftWindowsServer"
  image_offer     = "WindowsServer"
  image_sku       = "2022-datacenter-g2"

  location = "East US"
  vm_size  = "Standard_D2s_v3"

  # Azure auto-configures WinRM
  communicator   = "winrm"
  winrm_use_ssl  = true
  winrm_insecure = true
  winrm_timeout  = "15m"
  winrm_username = "packer"
}

PowerShell Provisioners

Install Software

build {
  sources = ["source.amazon-ebs.windows"]

  # Install Chocolatey
  provisioner "powershell" {
    inline = [
      "Set-ExecutionPolicy Bypass -Scope Process -Force",
      "iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))"
    ]
  }

  # Install applications
  provisioner "powershell" {
    inline = [
      "choco install -y googlechrome",
      "choco install -y 7zip",
    ]
  }

  # Install IIS
  provisioner "powershell" {
    inline = [
      "Install-WindowsFeature -Name Web-Server -IncludeManagementTools"
    ]
  }
}

Windows Updates

provisioner "powershell" {
  inline = [
    "Install-PackageProvider -Name NuGet -Force",
    "Install-Module -Name PSWindowsUpdate -Force",
    "Import-Module PSWindowsUpdate",
    "Get-WindowsUpdate -Install -AcceptAll -AutoReboot",
  ]
  timeout = "2h"
}

# Wait for reboots
provisioner "windows-restart" {
  restart_timeout = "30m"
}

Cleanup

provisioner "powershell" {
  inline = [
    "# Clear temp files",
    "Remove-Item -Path 'C:\\Windows\\Temp\\*' -Recurse -Force -ErrorAction SilentlyContinue",
    "# Clear Windows Update cache",
    "Stop-Service -Name wuauserv -Force",
    "Remove-Item -Path 'C:\\Windows\\SoftwareDistribution\\*' -Recurse -Force -ErrorAction SilentlyContinue",
    "Start-Service -Name wuauserv",
  ]
}

Common Issues

WinRM Timeout

  • Increase winrm_timeout to 15m or more
  • Verify security group allows ports 5985/5986
  • Check user data script completed successfully

PowerShell Execution Policy

provisioner "powershell" {
  inline = [
    "Set-ExecutionPolicy Bypass -Scope Process -Force",
    "# Your commands here",
  ]
}

Long Build Times

  • Windows Updates can take 1-2 hours
  • Use pre-patched base images when available
  • Set provisioner timeout = "2h"

References