Windows Builder

作者 hashicorpf706481af9b8無授權條款890 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 天前更新

Build Windows images with Packer using WinRM communicator and PowerShell provisioners. Use when creating Windows AMIs, Azure images, or VMware templates.

僅含說明DevOps & Cloud
AI 產生的概覽

提供使用 WinRM 通訊器與 PowerShell 佈建器建置 Windows 映像的 Packer 模式。

功能
此技能說明使用 Packer 建置 Windows 機器映像的通用模式,涵蓋 AWS 與 Azure 來源的 WinRM 通訊器設定、用於安裝軟體與 Windows 更新的 PowerShell 佈建器,以及清理步驟。它也列出常見問題,例如 WinRM 逾時、PowerShell 執行原則與建置時間過長。此技能僅含指示,產出的是設定指引而非檔案。
適用情境
需要在以 Packer 建立 Windows AMI、Azure 受控映像或 VMware 範本時使用。也適合用來排解 WinRM 連線、PowerShell 佈建或 Windows 建置耗時過長的問題。
執行需求
需要 Packer 以及 AWS 或 Azure 等目標平台;Azure 範例引用了 client_id、client_secret、subscription_id 與 tenant_id 變數。需要網路存取以取得基礎映像與套件來源。此技能未隨附指令碼;WinRM 設定指令碼僅以內嵌範例呈現。

Windows Builder

Platform-agnostic patterns for building Windows images with Packer.

Reference: WinRM Communicator

Note: Windows builds incur significant costs and time. Expect 45-120 minutes per build due to Windows Updates. Failed builds may leave resources running - always verify cleanup.

WinRM Communicator Setup

Windows requires WinRM for Packer communication.

AWS Example

hcl
source "amazon-ebs" "windows" {  region        = "us-west-2"  instance_type = "t3.medium"
  source_ami_filter {    filters = {      name = "Windows_Server-2022-English-Full-Base-*"    }    most_recent = true    owners      = ["amazon"]  }
  ami_name = "windows-server-2022-${local.timestamp}"
  communicator   = "winrm"  winrm_username = "Administrator"  winrm_use_ssl  = true  winrm_insecure = true  winrm_timeout  = "15m"
  user_data_file = "scripts/setup-winrm.ps1"}

WinRM Setup Script (scripts/setup-winrm.ps1)

powershell
<powershell># Configure WinRMwinrm quickconfig -qwinrm set winrm/config '@{MaxTimeoutms="1800000"}'winrm set winrm/config/service '@{AllowUnencrypted="true"}'winrm set winrm/config/service/auth '@{Basic="true"}'
# Configure firewallnetsh advfirewall firewall add rule name="WinRM 5985" protocol=TCP dir=in localport=5985 action=allownetsh advfirewall firewall add rule name="WinRM 5986" protocol=TCP dir=in localport=5986 action=allow
# Restart WinRMnet stop winrmnet start winrm</powershell>

Azure Example

hcl
source "azure-arm" "windows" {  client_id       = var.client_id  client_secret   = var.client_secret  subscription_id = var.subscription_id  tenant_id       = var.tenant_id
  managed_image_resource_group_name = "images-rg"  managed_image_name                = "windows-${local.timestamp}"
  os_type         = "Windows"  image_publisher = "MicrosoftWindowsServer"  image_offer     = "WindowsServer"  image_sku       = "2022-datacenter-g2"
  location = "East US"  vm_size  = "Standard_D2s_v3"
  # Azure auto-configures WinRM  communicator   = "winrm"  winrm_use_ssl  = true  winrm_insecure = true  winrm_timeout  = "15m"  winrm_username = "packer"}

PowerShell Provisioners

Install Software

hcl
build {  sources = ["source.amazon-ebs.windows"]
  # Install Chocolatey  provisioner "powershell" {    inline = [      "Set-ExecutionPolicy Bypass -Scope Process -Force",      "iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))"    ]  }
  # Install applications  provisioner "powershell" {    inline = [      "choco install -y googlechrome",      "choco install -y 7zip",    ]  }
  # Install IIS  provisioner "powershell" {    inline = [      "Install-WindowsFeature -Name Web-Server -IncludeManagementTools"    ]  }}

Windows Updates

hcl
provisioner "powershell" {  inline = [    "Install-PackageProvider -Name NuGet -Force",    "Install-Module -Name PSWindowsUpdate -Force",    "Import-Module PSWindowsUpdate",    "Get-WindowsUpdate -Install -AcceptAll -AutoReboot",  ]  timeout = "2h"}
# Wait for rebootsprovisioner "windows-restart" {  restart_timeout = "30m"}

Cleanup

hcl
provisioner "powershell" {  inline = [    "# Clear temp files",    "Remove-Item -Path 'C:\\Windows\\Temp\\*' -Recurse -Force -ErrorAction SilentlyContinue",    "# Clear Windows Update cache",    "Stop-Service -Name wuauserv -Force",    "Remove-Item -Path 'C:\\Windows\\SoftwareDistribution\\*' -Recurse -Force -ErrorAction SilentlyContinue",    "Start-Service -Name wuauserv",  ]}

Common Issues

WinRM Timeout

  • Increase winrm_timeout to 15m or more
  • Verify security group allows ports 5985/5986
  • Check user data script completed successfully

PowerShell Execution Policy

hcl
provisioner "powershell" {  inline = [    "Set-ExecutionPolicy Bypass -Scope Process -Force",    "# Your commands here",  ]}

Long Build Times

  • Windows Updates can take 1-2 hours
  • Use pre-patched base images when available
  • Set provisioner timeout = "2h"

References

來源與署名

來源:hashicorp/agent-skills位於plugins/packer/skills/windows-builder提交f706481

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架