You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Packer构建无SSH运行的AMI?适用于不可变基础设施

Can Packer Build AMIs Without SSH for Immutable Infrastructure?

Absolutely! This is a standard practice for hardening immutable infrastructure, and Packer has all the tools you need to pull it off. The key thing to remember is that Packer needs SSH during the build process to provision your images, but you can fully strip out SSH (and other remote access) in the final steps before creating the AMI.

Step 1: Build Your Golden Base Image First

Your golden base image will still need SSH enabled—this is how Packer connects to the instance to install dependencies, configure the OS, and set up any baseline tools you need. Treat this as your "build-time only" access; once the base image is ready, you'll use it to create your locked-down final image.

Step 2: Build the Locked-Down Final Image

When building your final image from the golden base, add a provisioner step that runs last to completely remove SSH and related components. Here's how to do it for common Linux distributions:

Example Packer Configuration Snippet

source "amazon-ebs" "final_no_ssh" {
  ami_name      = "production-no-ssh-{{timestamp}}"
  instance_type = "t2.micro"
  source_ami    = "ami-1234567890abcdef0" # Replace with your golden AMI ID
  ssh_username  = "ubuntu" # Or your base image's SSH user
}

build {
  sources = ["source.amazon-ebs.final_no_ssh"]

  # Add your other provisioners first (install apps, configs, etc.)
  # ...

  # Final provisioner: Remove SSH entirely
  provisioner "shell" {
    inline = [
      # Uninstall SSH server (Debian/Ubuntu example)
      "sudo apt remove --purge -y openssh-server",
      # For RHEL/CentOS, use: sudo dnf remove -y openssh-server
      
      # Delete SSH configs and user keys
      "sudo rm -rf /etc/ssh/ /root/.ssh/ /home/*/.ssh/",
      
      # Clean up leftover packages and cache
      "sudo apt autoremove -y",
      "sudo apt clean",
      
      # Ensure SSH service is disabled (just in case any remnants remain)
      "sudo systemctl disable --now sshd || true"
    ]
  }
}

Critical Notes to Avoid Issues

  • Run SSH removal last: Make sure this cleanup step is your final provisioner. If you remove SSH earlier, Packer will lose connection to the instance and the build will fail.
  • Remove other remote access tools: If your AMI uses other remote access methods (like EC2 Instance Connect on AWS), be sure to uninstall those too (e.g., sudo apt remove --purge -y ec2-instance-connect for Ubuntu).
  • Test your AMI: After building, launch an instance from the final AMI and verify you can't connect via SSH or any other remote method. This ensures your hardening worked as expected.
  • Adjust for your OS: The commands above are for Debian/Ubuntu—swap in dnf/yum commands for RHEL/CentOS, and adjust package names if you're using a different distro.

Why This Works

Packer only needs SSH to communicate with the temporary build instance during provisioning. Once all your configuration steps are done and you've stripped out SSH, Packer will still complete the AMI creation process normally—since it doesn't need SSH anymore after provisioning finishes.

内容的提问来源于stack exchange,提问作者jetole

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:21:48