Windows Builder

作者 hashicorpf706481af9b8无许可证890 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3天前更新

Build Windows images with Packer using WinRM communicator and PowerShell provisioners. Use when creating Windows AMIs, Azure images, or VMware templates.

仅含说明DevOps & Cloud
AI 生成的概览

提供使用 WinRM 通信器和 PowerShell 配置器构建 Windows 镜像的 Packer 模式。

功能
该技能记录了使用 Packer 构建 Windows 机器镜像的通用模式,涵盖 AWS 和 Azure 源的 WinRM 通信器配置、用于安装软件和 Windows 更新的 PowerShell 配置器以及清理步骤。它还列出了常见问题,例如 WinRM 超时、PowerShell 执行策略和构建时间过长。该技能仅包含说明,产出的是配置指导而非文件。
适用场景
在需要使用 Packer 创建 Windows AMI、Azure 托管镜像或 VMware 模板时使用。它也适用于排查 WinRM 连接、PowerShell 配置或 Windows 构建耗时过长的问题。
运行要求
需要 Packer 以及 AWS 或 Azure 等目标平台;Azure 示例引用了 client_id、client_secret、subscription_id 和 tenant_id 变量。需要网络访问以获取基础镜像和软件包源。该技能不附带脚本;WinRM 设置脚本仅以内联示例形式展示。

Windows Builder

Platform-agnostic patterns for building Windows images with Packer.

Reference: WinRM Communicator

Note: Windows builds incur significant costs and time. Expect 45-120 minutes per build due to Windows Updates. Failed builds may leave resources running - always verify cleanup.

WinRM Communicator Setup

Windows requires WinRM for Packer communication.

AWS Example

hcl
source "amazon-ebs" "windows" {  region        = "us-west-2"  instance_type = "t3.medium"
  source_ami_filter {    filters = {      name = "Windows_Server-2022-English-Full-Base-*"    }    most_recent = true    owners      = ["amazon"]  }
  ami_name = "windows-server-2022-${local.timestamp}"
  communicator   = "winrm"  winrm_username = "Administrator"  winrm_use_ssl  = true  winrm_insecure = true  winrm_timeout  = "15m"
  user_data_file = "scripts/setup-winrm.ps1"}

WinRM Setup Script (scripts/setup-winrm.ps1)

powershell
<powershell># Configure WinRMwinrm quickconfig -qwinrm set winrm/config '@{MaxTimeoutms="1800000"}'winrm set winrm/config/service '@{AllowUnencrypted="true"}'winrm set winrm/config/service/auth '@{Basic="true"}'
# Configure firewallnetsh advfirewall firewall add rule name="WinRM 5985" protocol=TCP dir=in localport=5985 action=allownetsh advfirewall firewall add rule name="WinRM 5986" protocol=TCP dir=in localport=5986 action=allow
# Restart WinRMnet stop winrmnet start winrm</powershell>

Azure Example

hcl
source "azure-arm" "windows" {  client_id       = var.client_id  client_secret   = var.client_secret  subscription_id = var.subscription_id  tenant_id       = var.tenant_id
  managed_image_resource_group_name = "images-rg"  managed_image_name                = "windows-${local.timestamp}"
  os_type         = "Windows"  image_publisher = "MicrosoftWindowsServer"  image_offer     = "WindowsServer"  image_sku       = "2022-datacenter-g2"
  location = "East US"  vm_size  = "Standard_D2s_v3"
  # Azure auto-configures WinRM  communicator   = "winrm"  winrm_use_ssl  = true  winrm_insecure = true  winrm_timeout  = "15m"  winrm_username = "packer"}

PowerShell Provisioners

Install Software

hcl
build {  sources = ["source.amazon-ebs.windows"]
  # Install Chocolatey  provisioner "powershell" {    inline = [      "Set-ExecutionPolicy Bypass -Scope Process -Force",      "iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))"    ]  }
  # Install applications  provisioner "powershell" {    inline = [      "choco install -y googlechrome",      "choco install -y 7zip",    ]  }
  # Install IIS  provisioner "powershell" {    inline = [      "Install-WindowsFeature -Name Web-Server -IncludeManagementTools"    ]  }}

Windows Updates

hcl
provisioner "powershell" {  inline = [    "Install-PackageProvider -Name NuGet -Force",    "Install-Module -Name PSWindowsUpdate -Force",    "Import-Module PSWindowsUpdate",    "Get-WindowsUpdate -Install -AcceptAll -AutoReboot",  ]  timeout = "2h"}
# Wait for rebootsprovisioner "windows-restart" {  restart_timeout = "30m"}

Cleanup

hcl
provisioner "powershell" {  inline = [    "# Clear temp files",    "Remove-Item -Path 'C:\\Windows\\Temp\\*' -Recurse -Force -ErrorAction SilentlyContinue",    "# Clear Windows Update cache",    "Stop-Service -Name wuauserv -Force",    "Remove-Item -Path 'C:\\Windows\\SoftwareDistribution\\*' -Recurse -Force -ErrorAction SilentlyContinue",    "Start-Service -Name wuauserv",  ]}

Common Issues

WinRM Timeout

  • Increase winrm_timeout to 15m or more
  • Verify security group allows ports 5985/5986
  • Check user data script completed successfully

PowerShell Execution Policy

hcl
provisioner "powershell" {  inline = [    "Set-ExecutionPolicy Bypass -Scope Process -Force",    "# Your commands here",  ]}

Long Build Times

  • Windows Updates can take 1-2 hours
  • Use pre-patched base images when available
  • Set provisioner timeout = "2h"

References

来源与署名

来源:hashicorp/agent-skills位于plugins/packer/skills/windows-builder提交f706481

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架