Azure Image Builder

作者 hashicorpf706481af9b8無授權條款890 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 天前更新

Build Azure managed images and Azure Compute Gallery images with Packer. Use when creating custom images for Azure VMs.

僅含說明DevOps & Cloud
AI 產生的概覽

使用 Packer 的 azure-arm 建置器建立 Azure 受控映像與 Azure Compute Gallery 映像。

功能
此技能提供 Packer HCL 範本與指引,用於透過 azure-arm 建置器建立自訂 Azure 虛擬機器映像。內容涵蓋受控映像輸出、含複寫區域的 Azure Compute Gallery 目的地、服務主體與受控識別驗證,以及 packer init、validate 和 build 命令。也列出常見問題,例如驗證失敗、資源庫版本不可變與佈建逾時。
適用情境
適用於為虛擬機器建立自訂 Azure 映像時,無論是受控映像或發佈至 Azure Compute Gallery 的版本。適合需要在 Azure 上進行可重複 Packer 映像建置的團隊。
執行需求
需要 Packer 與 HashiCorp Azure 外掛、Azure 認證(服務主體用戶端 ID、密碼、訂用帳戶與租用戶 ID,或 CLI/受控識別驗證),以及連線至 Azure 的網路存取。建置會產生 Azure 運算、儲存與資料傳輸費用。不含指令碼,僅為說明文件。

Azure Image Builder

Build Azure managed images and Azure Compute Gallery images using Packer's azure-arm builder.

Reference: Azure ARM Builder

Note: Building Azure images incurs costs (compute, storage, data transfer). Builds typically take 15-45 minutes depending on provisioning and OS.

Basic Managed Image

hcl
packer {  required_plugins {    azure = {      source  = "github.com/hashicorp/azure"      version = "~> 2.0"    }  }}
variable "client_id" {  type      = string  sensitive = true}
variable "client_secret" {  type      = string  sensitive = true}
variable "subscription_id" {  type = string}
variable "tenant_id" {  type = string}
variable "resource_group" {  type    = string  default = "packer-images-rg"}
locals {  timestamp = regex_replace(timestamp(), "[- TZ:]", "")}
source "azure-arm" "ubuntu" {  client_id       = var.client_id  client_secret   = var.client_secret  subscription_id = var.subscription_id  tenant_id       = var.tenant_id
  managed_image_resource_group_name = var.resource_group  managed_image_name                = "my-app-${local.timestamp}"
  os_type         = "Linux"  image_publisher = "Canonical"  image_offer     = "0001-com-ubuntu-server-jammy"  image_sku       = "22_04-lts-gen2"
  location = "East US"  vm_size  = "Standard_B2s"
  azure_tags = {    Name      = "my-app"    BuildDate = local.timestamp  }}
build {  sources = ["source.azure-arm.ubuntu"]
  provisioner "shell" {    inline = [      "sudo apt-get update",      "sudo apt-get upgrade -y",    ]  }}

Azure Compute Gallery

hcl
source "azure-arm" "ubuntu" {  client_id       = var.client_id  client_secret   = var.client_secret  subscription_id = var.subscription_id  tenant_id       = var.tenant_id
  os_type         = "Linux"  image_publisher = "Canonical"  image_offer     = "0001-com-ubuntu-server-jammy"  image_sku       = "22_04-lts-gen2"
  location = "East US"  vm_size  = "Standard_B2s"
  shared_image_gallery_destination {    resource_group       = "gallery-rg"    gallery_name         = "myImageGallery"    image_name           = "ubuntu-webapp"    image_version        = "1.0.${formatdate("YYYYMMDD", timestamp())}"    replication_regions  = ["East US", "West US 2"]    storage_account_type = "Standard_LRS"  }}

Authentication

Service Principal

bash
# Create service principalaz ad sp create-for-rbac \  --name "packer-sp" \  --role Contributor \  --scopes /subscriptions/<subscription-id>
# Set environment variablesexport ARM_CLIENT_ID="<client-id>"export ARM_CLIENT_SECRET="<client-secret>"export ARM_SUBSCRIPTION_ID="<subscription-id>"export ARM_TENANT_ID="<tenant-id>"

Managed Identity

hcl
source "azure-arm" "ubuntu" {  use_azure_cli_auth = true  subscription_id    = var.subscription_id  # ... rest of configuration}

Build Commands

bash
# Set authenticationexport ARM_CLIENT_ID="your-client-id"export ARM_CLIENT_SECRET="your-client-secret"export ARM_SUBSCRIPTION_ID="your-subscription-id"export ARM_TENANT_ID="your-tenant-id"
# Initialize pluginspacker init .
# Validate templatepacker validate .
# Build imagepacker build .

Common Issues

Authentication Failed

  • Verify service principal credentials
  • Ensure Contributor role on resource group
  • Check subscription and tenant IDs

Compute Gallery Version Exists

  • Image versions are immutable
  • Use unique version numbers with date/build number
  • Cannot overwrite existing versions

Timeout During Provisioning

  • Check network connectivity from build VM
  • Verify NSG rules allow required traffic
  • Increase timeout if needed

References

來源與署名

來源:hashicorp/agent-skills位於plugins/packer/skills/azure-image-builder提交f706481

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架