aws-ami-builder
Build Amazon Machine Images (AMIs) with Packer using the amazon-ebs builder. Use when creating custom AMIs for EC2 instances.
Security Assessment
Detected risks:
About aws-ami-builder
AWS AMI Builder covers building custom Amazon Machine Images with HashiCorp Packer using the amazon-ebs builder. It applies when creating AMIs for EC2 instances, and notes up front that builds incur AWS costs (EC2 instances, EBS storage, data transfer) and typically take 10 to 30 minutes depending on provisioning complexity.
The skill provides a working HCL template that pins the github.com/hashicorp/amazon plugin, declares a region variable, builds a timestamp local for unique naming, and defines an amazon-ebs source with a source_ami_filter, ssh_username, ami_name, and tags, plus a build block with a shell provisioner. It includes ready-made source AMI filters for Ubuntu 22.04 LTS (owner Canonical, 099720109477) and Amazon Linux 2023 (owner amazon), and shows how to copy an image to additional regions with ami_regions.
Authentication follows Packer's standard AWS credential resolution order: environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), the ~/.aws/credentials file, or an IAM instance profile when running on EC2. The documented build workflow is packer init to install plugins, packer validate to check the template, and packer build to produce the AMI, with -var for overriding variables such as region. A troubleshooting section addresses the most common failures: SSH timeouts (ensure the security group allows port 22 and the subnet has internet access), non-unique AMI names (use the timestamp in the name), and volumes that are too small (set launch_block_device_mappings.volume_size relative to the source AMI). Links to the Amazon EBS builder and AWS AMI documentation are provided for deeper reference.
FAQ
What tool and builder does this skill use?
HashiCorp Packer with the amazon-ebs builder, driven by an HCL template that pins the github.com/hashicorp/amazon plugin.
How does Packer authenticate to AWS?
Through standard AWS credential resolution: environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), the ~/.aws/credentials file, or an IAM instance profile when running on EC2.
Can I build an AMI in more than one region?
Yes. Add the ami_regions attribute to the amazon-ebs source to copy the built image to additional regions such as us-east-1 or eu-west-1.
What are the core build commands?
packer init to install plugins, packer validate to check the template, and packer build to build the AMI, with -var to override variables like region.
How do I fix a build that fails with an SSH timeout?
Ensure the security group allows SSH on port 22 and that the subnet has internet access.
Install aws-ami-builder
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
hashicorp/agent-skills