Build Azure managed images and Azure Compute Gallery images with Packer. Use when creating custom images for Azure VMs.
Azure Image Builder is a HashiCorp Packer skill for building Azure managed images and Azure Compute Gallery images using Packer's azure-arm builder. It solves the problem of producing consistent, pre-provisioned custom VM images for Azure, giving copy-ready HCL templates and the surrounding build workflow.
The skill provides a complete basic managed-image template (required plugin block, sensitive client_id/client_secret variables, subscription and tenant variables, source image publisher/offer/SKU, VM size, location, tags, and a shell provisioner running apt updates) plus a Compute Gallery destination example with replication regions and storage-account type. It documents two authentication approaches using official Azure tooling: creating a service principal with az ad sp create-for-rbac and exporting ARM_CLIENT_ID/ARM_CLIENT_SECRET/ARM_SUBSCRIPTION_ID/ARM_TENANT_ID environment variables, or using managed identity via use_azure_cli_auth. Standard build commands (packer init, packer validate, packer build) and a common-issues section (authentication failures, immutable Compute Gallery versions, provisioning timeouts) round it out, along with links to the upstream Azure ARM builder and Compute Gallery documentation, and a note that builds incur cost and take 15-45 minutes.
It targets DevOps and platform engineers building golden images for Azure VMs with Packer. Credentials are handled through standard, documented practices (sensitive Packer variables and environment variables sourced from an Azure service principal or CLI auth) with no exfiltration; the shell provisioning shown is limited to routine package updates.
Azure managed images and Azure Compute Gallery (shared image gallery) images using Packer's azure-arm builder, with ready-to-adapt HCL templates for both.
Either a service principal created with az ad sp create-for-rbac, with credentials passed via ARM_CLIENT_ID/ARM_CLIENT_SECRET/ARM_SUBSCRIPTION_ID/ARM_TENANT_ID environment variables and sensitive Packer variables, or managed identity via use_azure_cli_auth.
Packer with the Azure plugin (~> 2.0), the Azure CLI for creating the service principal, an Azure subscription with Contributor rights on the target resource group, and awareness that builds incur cost and take roughly 15-45 minutes.
Authentication failures (verify credentials and Contributor role), Compute Gallery version conflicts (versions are immutable, so use unique date/build numbers), and provisioning timeouts (check network connectivity and NSG rules).
Set the ARM authentication environment variables, then run packer init to install plugins, packer validate to check the template, and packer build to produce the image.
Quick Setup:
.claude/skills/Repository
hashicorp/agent-skills