Build Windows images with Packer using WinRM communicator and PowerShell provisioners. Use when creating Windows AMIs, Azure images, or VMware templates.
Detected risks:
This skill provides platform-agnostic patterns for building Windows machine images with HashiCorp Packer using the WinRM communicator and PowerShell provisioners. It solves the recurring friction of Windows image builds, which differ substantially from Linux builds: Windows requires WinRM (not SSH) for Packer communication, needs firewall and service configuration before provisioning can start, and incurs long build times (typically 45-120 minutes) driven mostly by Windows Updates. The skill packages known-good HCL and PowerShell configurations so teams can build reliably.
It includes example source blocks for AWS (amazon-ebs) and Azure (azure-arm), a WinRM setup script delivered via user data, and PowerShell provisioner examples for installing software (Chocolatey, Chrome, 7-Zip, IIS via Install-WindowsFeature), applying Windows Updates through the PSWindowsUpdate module with windows-restart handling, and cleaning up temp files and the Windows Update cache before imaging. It also documents common issues (WinRM timeouts, execution policy, long build times) and links to official HashiCorp Packer documentation for Windows builders, the WinRM communicator, and the PowerShell provisioner.
It targets DevOps and platform engineers building Windows AMIs, Azure managed images, or VMware templates. Note that some example configurations use build-time conveniences that weaken transport security (unencrypted WinRM, basic auth, skipping certificate verification) and bootstrap tooling by downloading and executing an install script from the internet. These are common ephemeral-build-VM practices, but reviewers should treat the WinRM settings and remote-install step as intentional choices to harden or pin for sensitive environments.
Building Windows images with Packer using the WinRM communicator and PowerShell provisioners, with worked examples for AWS AMIs, Azure managed images, and applicable to VMware templates.
The sample setup enables unencrypted WinRM, basic authentication, and skips certificate verification (winrm_insecure) to get ephemeral build VMs communicating quickly. For sensitive builds you should prefer TLS with verified certificates and avoid unencrypted/basic auth.
Typically 45-120 minutes per build, largely because of Windows Updates. Failed builds may leave cloud resources running, so the skill stresses verifying cleanup.
Via PowerShell provisioners, including bootstrapping Chocolatey by downloading and running its install script, then installing packages like Chrome and 7-Zip, and enabling Windows features such as IIS.
Yes. It installs the PSWindowsUpdate module to apply all updates with auto-reboot, and pairs it with a windows-restart provisioner and generous timeouts to survive the reboot cycles.
Quick Setup:
.claude/skills/Repository
hashicorp/agent-skills