push-to-registry

作成者: hashicorp

PackerビルドのメタデータをHCP Packerレジストリにプッシュし、イメージのライフサイクル追跡とガバナンスを実現します。ビルドアーティファクトを最小限のオーバーヘッドでHCP Packerに登録し、メタデータのみ(実際のイメージは含まない)を保存して、ビルド時間に1分未満の追加で済みます。バケットレベルのラベル(ビルドごとに更新)と、バージョン管理およびコンプライアンス追跡のための不変のビルドレベルラベル(git SHA、タイムスタンプ)をサポートします。hcp_packer_artifactデータソースを介してTerraformと統合し、イメージをクエリしてデプロイします。

npx skills add https://github.com/hashicorp/agent-skills --skill push-to-registry

Push to HCP Packer Registry

Configure Packer templates to push build metadata to HCP Packer registry.

Reference: HCP Packer Registry

Note: HCP Packer is free for basic use. Builds push metadata only (not actual images), adding minimal overhead (<1 minute).

Basic Registry Configuration

packer {
  required_version = ">= 1.7.7"
}

variable "image_name" {
  type    = string
  default = "web-server"
}

locals {
  timestamp = regex_replace(timestamp(), "[- TZ:]", "")
}

source "amazon-ebs" "ubuntu" {
  region        = "us-west-2"
  instance_type = "t3.micro"

  source_ami_filter {
    filters = {
      name = "ubuntu/images/*ubuntu-jammy-22.04-amd64-server-*"
    }
    most_recent = true
    owners      = ["099720109477"]
  }

  ssh_username = "ubuntu"
  ami_name     = "${var.image_name}-${local.timestamp}"
}

build {
  sources = ["source.amazon-ebs.ubuntu"]

  hcp_packer_registry {
    bucket_name = var.image_name
    description = "Ubuntu 22.04 base image for web servers"

    bucket_labels = {
      "os"   = "ubuntu"
      "team" = "platform"
    }

    build_labels = {
      "build-time" = local.timestamp
    }
  }

  provisioner "shell" {
    inline = [
      "sudo apt-get update",
      "sudo apt-get upgrade -y",
    ]
  }
}

Authentication

Set environment variables before building:

export HCP_CLIENT_ID="your-service-principal-client-id"
export HCP_CLIENT_SECRET="your-service-principal-secret"
export HCP_ORGANIZATION_ID="your-org-id"
export HCP_PROJECT_ID="your-project-id"

packer build .

Create HCP Service Principal

  1. Navigate to HCP → Access Control (IAM)
  2. Create Service Principal
  3. Grant "Contributor" role on project
  4. Generate client secret
  5. Save client ID and secret

Registry Configuration Options

bucket_name (required)

The image identifier. Must stay consistent across builds!

bucket_name = "web-server"  # Keep this constant

bucket_labels (optional)

Metadata at bucket level. Updates with each build.

bucket_labels = {
  "os"        = "ubuntu"
  "team"      = "platform"
  "component" = "web"
}

build_labels (optional)

Metadata for each iteration. Immutable after build completes.

build_labels = {
  "build-time" = local.timestamp
  "git-commit" = var.git_commit
}

CI/CD Integration

GitHub Actions

name: Build and Push to HCP Packer

on:
  push:
    branches: [main]

env:
  HCP_CLIENT_ID: ${{ secrets.HCP_CLIENT_ID }}
  HCP_CLIENT_SECRET: ${{ secrets.HCP_CLIENT_SECRET }}
  HCP_ORGANIZATION_ID: ${{ secrets.HCP_ORGANIZATION_ID }}
  HCP_PROJECT_ID: ${{ secrets.HCP_PROJECT_ID }}

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: hashicorp/setup-packer@main

      - name: Build and push
        run: |
          packer init .
          packer build \
            -var "git_commit=${{ github.sha }}" \
            .

Querying in Terraform

data "hcp_packer_artifact" "ubuntu" {
  bucket_name  = "web-server"
  channel_name = "production"
  platform     = "aws"
  region       = "us-west-2"
}

resource "aws_instance" "web" {
  ami           = data.hcp_packer_artifact.ubuntu.external_identifier
  instance_type = "t3.micro"

  tags = {
    PackerBucket = data.hcp_packer_artifact.ubuntu.bucket_name
  }
}

Common Issues

Authentication Failed

  • Verify HCP_CLIENT_ID and HCP_CLIENT_SECRET
  • Ensure service principal has Contributor role
  • Check organization and project IDs

Bucket Name Mismatch

  • Keep bucket_name consistent across builds
  • Don't include timestamps in bucket_name
  • Creates new bucket if name changes

Build Fails

  • Packer fails immediately if can't push metadata
  • Prevents drift between artifacts and registry
  • Check network connectivity to HCP API

Best Practices

  • Consistent bucket names - Never change for same image type
  • Meaningful labels - Use for versions, teams, compliance
  • CI/CD automation - Automate builds and registry pushes
  • Immutable build labels - Put changing data (git SHA, date) in build_labels

References

hashicorpのその他のスキル

provider-actions
hashicorp
Plugin Frameworkを使用してTerraform Providerのアクションを実装します。ライフサイクルイベント(前/後…)で実行される命令的操作を開発する際に使用します。
official
new-terraform-provider
hashicorp
新しいTerraformプロバイダーをPlugin Frameworkでスキャフォールディングする際に使用します:ワークスペースレイアウト、goモジュールのセットアップ、プロバイダーサーバーのmain.go、およびprovider.go…
official
terraform-test
hashicorp
Terraformテストの作成と実行に関する包括的なガイド。テストファイル(.tftest.hcl)の作成、runブロックを使ったテストシナリオの記述、検証の際に使用します…
official
terraform-test
hashicorp
Terraformテストの作成と実行に関する包括的なガイド。アサーション、モック、モジュール検証を含む。.tftest.hcl構文を使用してテストファイルを作成し、planまたはapplyモードで実行されるrunブロックを記述。逐次実行と並列実行をサポートし、オプションで状態の分離も可能。リソース属性、出力、データソースに対する条件をアサートし、expect_failuresを使用して無効な入力が適切に拒否されることを検証。モックプロバイダー(Terraform 1.7.0以降)はインフラストラクチャの動作をシミュレート...
official
provider-actions
hashicorp
プラグインフレームワークを使用して、リソースライフサイクルイベントで命令型のTerraformプロバイダーアクションを実装します。作成前/後および更新前/後のライフサイクルトリガーをサポートします(Terraform 1.14.0では破棄イベントは利用不可)。適切なスキーマ定義、正しいフレームワークタイプ、コレクション用のElementType、および入力検証用のバリデータが必要です。長時間実行操作のための進捗報告、タイムアウト管理、包括的なエラーハンドリングを含みます。ポーリングおよび...を実装します。
official
aws-ami-builder
hashicorp
Packerのamazon-ebsビルダーを使用してカスタムAmazonマシンイメージを構築します。ソースAMIからHCLテンプレートを使用してAMI作成を自動化し、プロビジョナー(シェルスクリプト、ファイルアップロード、構成管理)によるカスタマイズをサポートします。ami_regionsによるマルチリージョンAMI配布と、名前、所有者、仮想化タイプによる柔軟なソースAMIフィルタリングをサポートします。環境変数、AWS認証情報ファイル、またはIAMインスタンスプロファイルを介して認証し、テンプレートの検証およびビルドコマンドを含みます...
official
new-terraform-provider
hashicorp
Plugin Frameworkを使用して新しいTerraformプロバイダーをスキャフォールディングします。標準の「terraform-provider-」命名規則に従った新しいGoモジュールワークスペースを生成し、必要な依存関係を初期化します。カスタマイズ用のTODOマーカー付きで、HashiCorpのPlugin Frameworkパターンに従ったテンプレートmain.goファイルを提供します。ビルドおよびテストコマンドを実行してプロバイダーがコンパイルされ、初期チェックを通過することを確認することでセットアップを検証します。新しいワークスペースを作成する前に意図を確認することでワークスペース管理を処理します...
official
azure-verified-modules
hashicorp
AVM準拠を目指すAzure Terraformモジュールの認定要件とベストプラクティス。プロバイダーのバージョン制約(azurerm >= 4.0, < 5.0; azapi >= 2.0, < 3.0)を適用し、gitベースのモジュール参照を禁止して、固定されたTerraformレジストリソースを推奨。すべての識別子にスネークケース(小文字)を必須とし、正確な変数型、アンチコリューション層パターンによる個別の出力属性、アルファベット順のローカル変数を要求。新しいリソース追加には機能トグル変数を必要とする...
official