Push To Registry

作者 hashicorpf706481af9b8无许可证890 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3天前更新

Push Packer build metadata to HCP Packer registry for tracking and managing image lifecycle. Use when integrating Packer builds with HCP Packer for version control and governance.

仅含说明DevOps & Cloud
AI 生成的概览

配置 Packer 构建,将镜像构建元数据推送到 HCP Packer 注册表,用于版本跟踪与治理。

功能
该技能提供在 Packer 模板中添加 hcp_packer_registry 块的说明,以便将构建元数据推送到 HCP Packer 注册表。内容涵盖 bucket 与 build 标签、使用 HCP 服务主体凭据进行身份验证、CI/CD 集成、在 Terraform 中查询制品,以及常见问题排查和最佳实践。它产出的是配置指导和 HCL、YAML、Terraform 示例片段,而不是可执行脚本。
适用场景
当需要将 Packer 镜像构建与 HCP Packer 集成以实现版本控制、生命周期跟踪或治理时使用。也适用于为 Packer 构建设置注册表身份验证、标签或 CI/CD 自动化。
运行要求
需要 Packer 1.7.7 或更高版本,并能访问 HCP API 网络。需要 HCP 服务主体凭据:HCP_CLIENT_ID、HCP_CLIENT_SECRET、HCP_ORGANIZATION_ID 和 HCP_PROJECT_ID,并在项目上具有 Contributor 角色。不包含脚本,仅为说明文档。

Push to HCP Packer Registry

Configure Packer templates to push build metadata to HCP Packer registry.

Reference: HCP Packer Registry

Note: HCP Packer is free for basic use. Builds push metadata only (not actual images), adding minimal overhead (<1 minute).

Basic Registry Configuration

hcl
packer {  required_version = ">= 1.7.7"}
variable "image_name" {  type    = string  default = "web-server"}
locals {  timestamp = regex_replace(timestamp(), "[- TZ:]", "")}
source "amazon-ebs" "ubuntu" {  region        = "us-west-2"  instance_type = "t3.micro"
  source_ami_filter {    filters = {      name = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"    }    most_recent = true    owners      = ["099720109477"]  }
  ssh_username = "ubuntu"  ami_name     = "${var.image_name}-${local.timestamp}"}
build {  sources = ["source.amazon-ebs.ubuntu"]
  hcp_packer_registry {    bucket_name = var.image_name    description = "Ubuntu 22.04 base image for web servers"
    bucket_labels = {      "os"   = "ubuntu"      "team" = "platform"    }
    build_labels = {      "build-time" = local.timestamp    }  }
  provisioner "shell" {    inline = [      "sudo apt-get update",      "sudo apt-get upgrade -y",    ]  }}

Authentication

Set environment variables before building:

bash
export HCP_CLIENT_ID="your-service-principal-client-id"export HCP_CLIENT_SECRET="your-service-principal-secret"export HCP_ORGANIZATION_ID="your-org-id"export HCP_PROJECT_ID="your-project-id"
packer build .

Create HCP Service Principal

  1. Navigate to HCP → Access Control (IAM)
  2. Create Service Principal
  3. Grant "Contributor" role on project
  4. Generate client secret
  5. Save client ID and secret

Registry Configuration Options

bucket_name (required)

The image identifier. Must stay consistent across builds!

hcl
bucket_name = "web-server"  # Keep this constant

bucket_labels (optional)

Metadata at bucket level. Updates with each build.

hcl
bucket_labels = {  "os"        = "ubuntu"  "team"      = "platform"  "component" = "web"}

build_labels (optional)

Metadata for each iteration. Immutable after build completes.

hcl
build_labels = {  "build-time" = local.timestamp  "git-commit" = var.git_commit}

CI/CD Integration

GitHub Actions

yaml
name: Build and Push to HCP Packer
on:  push:    branches: [main]
env:  HCP_CLIENT_ID: ${{ secrets.HCP_CLIENT_ID }}  HCP_CLIENT_SECRET: ${{ secrets.HCP_CLIENT_SECRET }}  HCP_ORGANIZATION_ID: ${{ secrets.HCP_ORGANIZATION_ID }}  HCP_PROJECT_ID: ${{ secrets.HCP_PROJECT_ID }}
jobs:  build:    runs-on: ubuntu-latest    steps:      - uses: actions/checkout@v4      - uses: hashicorp/setup-packer@main
      - name: Build and push        run: |          packer init .          packer build \            -var "git_commit=${{ github.sha }}" \            .

Querying in Terraform

hcl
data "hcp_packer_artifact" "ubuntu" {  bucket_name  = "web-server"  channel_name = "production"  platform     = "aws"  region       = "us-west-2"}
resource "aws_instance" "web" {  ami           = data.hcp_packer_artifact.ubuntu.external_identifier  instance_type = "t3.micro"
  tags = {    PackerBucket = data.hcp_packer_artifact.ubuntu.bucket_name  }}

Common Issues

Authentication Failed

  • Verify HCP_CLIENT_ID and HCP_CLIENT_SECRET
  • Ensure service principal has Contributor role
  • Check organization and project IDs

Bucket Name Mismatch

  • Keep bucket_name consistent across builds
  • Don't include timestamps in bucket_name
  • Creates new bucket if name changes

Build Fails

  • Packer fails immediately if can't push metadata
  • Prevents drift between artifacts and registry
  • Check network connectivity to HCP API

Best Practices

  • Consistent bucket names - Never change for same image type
  • Meaningful labels - Use for versions, teams, compliance
  • CI/CD automation - Automate builds and registry pushes
  • Immutable build labels - Put changing data (git SHA, date) in build_labels

References

来源与署名

来源:hashicorp/agent-skills位于plugins/packer/skills/push-to-registry提交f706481

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架