Push To Registry

作者 hashicorpf706481af9b8無授權條款890 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 天前更新

Push Packer build metadata to HCP Packer registry for tracking and managing image lifecycle. Use when integrating Packer builds with HCP Packer for version control and governance.

僅含說明DevOps & Cloud
AI 產生的概覽

設定 Packer 建置,將映像建置中繼資料推送至 HCP Packer 登錄,以進行版本追蹤與治理。

功能
此技能提供在 Packer 範本中加入 hcp_packer_registry 區塊的說明,以便將建置中繼資料推送至 HCP Packer 登錄。內容涵蓋 bucket 與 build 標籤、使用 HCP 服務主體認證進行身分驗證、CI/CD 整合、在 Terraform 中查詢成品,以及常見問題排解與最佳實務。它產出的是設定指引與 HCL、YAML、Terraform 範例片段,而非可執行的指令碼。
適用情境
當需要將 Packer 映像建置與 HCP Packer 整合以進行版本控制、生命週期追蹤或治理時使用。也適用於為 Packer 建置設定登錄認證、標籤或 CI/CD 自動化。
執行需求
需要 Packer 1.7.7 或更新版本,並能存取 HCP API 網路。需要 HCP 服務主體認證:HCP_CLIENT_ID、HCP_CLIENT_SECRET、HCP_ORGANIZATION_ID 與 HCP_PROJECT_ID,並在專案上具備 Contributor 角色。不包含指令碼,僅為說明文件。

Push to HCP Packer Registry

Configure Packer templates to push build metadata to HCP Packer registry.

Reference: HCP Packer Registry

Note: HCP Packer is free for basic use. Builds push metadata only (not actual images), adding minimal overhead (<1 minute).

Basic Registry Configuration

hcl
packer {  required_version = ">= 1.7.7"}
variable "image_name" {  type    = string  default = "web-server"}
locals {  timestamp = regex_replace(timestamp(), "[- TZ:]", "")}
source "amazon-ebs" "ubuntu" {  region        = "us-west-2"  instance_type = "t3.micro"
  source_ami_filter {    filters = {      name = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"    }    most_recent = true    owners      = ["099720109477"]  }
  ssh_username = "ubuntu"  ami_name     = "${var.image_name}-${local.timestamp}"}
build {  sources = ["source.amazon-ebs.ubuntu"]
  hcp_packer_registry {    bucket_name = var.image_name    description = "Ubuntu 22.04 base image for web servers"
    bucket_labels = {      "os"   = "ubuntu"      "team" = "platform"    }
    build_labels = {      "build-time" = local.timestamp    }  }
  provisioner "shell" {    inline = [      "sudo apt-get update",      "sudo apt-get upgrade -y",    ]  }}

Authentication

Set environment variables before building:

bash
export HCP_CLIENT_ID="your-service-principal-client-id"export HCP_CLIENT_SECRET="your-service-principal-secret"export HCP_ORGANIZATION_ID="your-org-id"export HCP_PROJECT_ID="your-project-id"
packer build .

Create HCP Service Principal

  1. Navigate to HCP → Access Control (IAM)
  2. Create Service Principal
  3. Grant "Contributor" role on project
  4. Generate client secret
  5. Save client ID and secret

Registry Configuration Options

bucket_name (required)

The image identifier. Must stay consistent across builds!

hcl
bucket_name = "web-server"  # Keep this constant

bucket_labels (optional)

Metadata at bucket level. Updates with each build.

hcl
bucket_labels = {  "os"        = "ubuntu"  "team"      = "platform"  "component" = "web"}

build_labels (optional)

Metadata for each iteration. Immutable after build completes.

hcl
build_labels = {  "build-time" = local.timestamp  "git-commit" = var.git_commit}

CI/CD Integration

GitHub Actions

yaml
name: Build and Push to HCP Packer
on:  push:    branches: [main]
env:  HCP_CLIENT_ID: ${{ secrets.HCP_CLIENT_ID }}  HCP_CLIENT_SECRET: ${{ secrets.HCP_CLIENT_SECRET }}  HCP_ORGANIZATION_ID: ${{ secrets.HCP_ORGANIZATION_ID }}  HCP_PROJECT_ID: ${{ secrets.HCP_PROJECT_ID }}
jobs:  build:    runs-on: ubuntu-latest    steps:      - uses: actions/checkout@v4      - uses: hashicorp/setup-packer@main
      - name: Build and push        run: |          packer init .          packer build \            -var "git_commit=${{ github.sha }}" \            .

Querying in Terraform

hcl
data "hcp_packer_artifact" "ubuntu" {  bucket_name  = "web-server"  channel_name = "production"  platform     = "aws"  region       = "us-west-2"}
resource "aws_instance" "web" {  ami           = data.hcp_packer_artifact.ubuntu.external_identifier  instance_type = "t3.micro"
  tags = {    PackerBucket = data.hcp_packer_artifact.ubuntu.bucket_name  }}

Common Issues

Authentication Failed

  • Verify HCP_CLIENT_ID and HCP_CLIENT_SECRET
  • Ensure service principal has Contributor role
  • Check organization and project IDs

Bucket Name Mismatch

  • Keep bucket_name consistent across builds
  • Don't include timestamps in bucket_name
  • Creates new bucket if name changes

Build Fails

  • Packer fails immediately if can't push metadata
  • Prevents drift between artifacts and registry
  • Check network connectivity to HCP API

Best Practices

  • Consistent bucket names - Never change for same image type
  • Meaningful labels - Use for versions, teams, compliance
  • CI/CD automation - Automate builds and registry pushes
  • Immutable build labels - Put changing data (git SHA, date) in build_labels

References

來源與署名

來源:hashicorp/agent-skills位於plugins/packer/skills/push-to-registry提交f706481

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架