Azure Image Builder

作者 hashicorpf706481af9b8无许可证890 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3天前更新

Build Azure managed images and Azure Compute Gallery images with Packer. Use when creating custom images for Azure VMs.

仅含说明DevOps & Cloud
AI 生成的概览

使用 Packer 的 azure-arm 构建器创建 Azure 托管映像和 Azure Compute Gallery 映像。

功能
该技能提供 Packer HCL 模板和指导,用于通过 azure-arm 构建器构建自定义 Azure 虚拟机映像。内容涵盖托管映像输出、带复制区域的 Azure Compute Gallery 目标、服务主体与托管标识身份验证,以及 packer init、validate 和 build 命令。还列出了常见问题,例如身份验证失败、库版本不可变和预配超时。
适用场景
适用于为虚拟机创建自定义 Azure 映像时,无论是托管映像还是发布到 Azure Compute Gallery 的版本。适合需要在 Azure 上进行可重复的 Packer 映像构建的团队。
运行要求
需要 Packer 及 HashiCorp Azure 插件、Azure 凭据(服务主体客户端 ID、密钥、订阅和租户 ID,或 CLI/托管标识身份验证),以及访问 Azure 的网络连接。构建会产生 Azure 计算、存储和数据传输费用。不包含脚本,仅为说明文档。

Azure Image Builder

Build Azure managed images and Azure Compute Gallery images using Packer's azure-arm builder.

Reference: Azure ARM Builder

Note: Building Azure images incurs costs (compute, storage, data transfer). Builds typically take 15-45 minutes depending on provisioning and OS.

Basic Managed Image

hcl
packer {  required_plugins {    azure = {      source  = "github.com/hashicorp/azure"      version = "~> 2.0"    }  }}
variable "client_id" {  type      = string  sensitive = true}
variable "client_secret" {  type      = string  sensitive = true}
variable "subscription_id" {  type = string}
variable "tenant_id" {  type = string}
variable "resource_group" {  type    = string  default = "packer-images-rg"}
locals {  timestamp = regex_replace(timestamp(), "[- TZ:]", "")}
source "azure-arm" "ubuntu" {  client_id       = var.client_id  client_secret   = var.client_secret  subscription_id = var.subscription_id  tenant_id       = var.tenant_id
  managed_image_resource_group_name = var.resource_group  managed_image_name                = "my-app-${local.timestamp}"
  os_type         = "Linux"  image_publisher = "Canonical"  image_offer     = "0001-com-ubuntu-server-jammy"  image_sku       = "22_04-lts-gen2"
  location = "East US"  vm_size  = "Standard_B2s"
  azure_tags = {    Name      = "my-app"    BuildDate = local.timestamp  }}
build {  sources = ["source.azure-arm.ubuntu"]
  provisioner "shell" {    inline = [      "sudo apt-get update",      "sudo apt-get upgrade -y",    ]  }}

Azure Compute Gallery

hcl
source "azure-arm" "ubuntu" {  client_id       = var.client_id  client_secret   = var.client_secret  subscription_id = var.subscription_id  tenant_id       = var.tenant_id
  os_type         = "Linux"  image_publisher = "Canonical"  image_offer     = "0001-com-ubuntu-server-jammy"  image_sku       = "22_04-lts-gen2"
  location = "East US"  vm_size  = "Standard_B2s"
  shared_image_gallery_destination {    resource_group       = "gallery-rg"    gallery_name         = "myImageGallery"    image_name           = "ubuntu-webapp"    image_version        = "1.0.${formatdate("YYYYMMDD", timestamp())}"    replication_regions  = ["East US", "West US 2"]    storage_account_type = "Standard_LRS"  }}

Authentication

Service Principal

bash
# Create service principalaz ad sp create-for-rbac \  --name "packer-sp" \  --role Contributor \  --scopes /subscriptions/<subscription-id>
# Set environment variablesexport ARM_CLIENT_ID="<client-id>"export ARM_CLIENT_SECRET="<client-secret>"export ARM_SUBSCRIPTION_ID="<subscription-id>"export ARM_TENANT_ID="<tenant-id>"

Managed Identity

hcl
source "azure-arm" "ubuntu" {  use_azure_cli_auth = true  subscription_id    = var.subscription_id  # ... rest of configuration}

Build Commands

bash
# Set authenticationexport ARM_CLIENT_ID="your-client-id"export ARM_CLIENT_SECRET="your-client-secret"export ARM_SUBSCRIPTION_ID="your-subscription-id"export ARM_TENANT_ID="your-tenant-id"
# Initialize pluginspacker init .
# Validate templatepacker validate .
# Build imagepacker build .

Common Issues

Authentication Failed

  • Verify service principal credentials
  • Ensure Contributor role on resource group
  • Check subscription and tenant IDs

Compute Gallery Version Exists

  • Image versions are immutable
  • Use unique version numbers with date/build number
  • Cannot overwrite existing versions

Timeout During Provisioning

  • Check network connectivity from build VM
  • Verify NSG rules allow required traffic
  • Increase timeout if needed

References

来源与署名

来源:hashicorp/agent-skills位于plugins/packer/skills/azure-image-builder提交f706481

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架