Skip to content

Instantly share code, notes, and snippets.

Created November 25, 2019 16:12
Show Gist options
  • Save chrisoldwood/aeec1e6876dadcc407109896d8d8aac7 to your computer and use it in GitHub Desktop.
Save chrisoldwood/aeec1e6876dadcc407109896d8d8aac7 to your computer and use it in GitHub Desktop.
Example Packer configuration files for creating a Windows 10 VM on QEMU/KVM/libvirt.
<?xml version="1.0" encoding="utf-8"?>
<unattend xmlns="urn:schemas-microsoft-com:unattend">
<settings pass="windowsPE">
<component name="Microsoft-Windows-International-Core-WinPE" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="" xmlns:xsi="">
<component name="Microsoft-Windows-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="" xmlns:xsi="">
<Disk wcm:action="add">
<CreatePartition wcm:action="add">
<ModifyPartition wcm:action="add">
<Label>Windows 10</Label>
<FullName>Packer Admin</FullName>
<component name="Microsoft-Windows-PnpCustomizationsWinPE" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="" xmlns:xsi="">
<PathAndCredentials wcm:action="add" wcm:keyValue="1">
<PathAndCredentials wcm:action="add" wcm:keyValue="3">
<settings pass="oobeSystem">
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="" xmlns:xsi="">
<LocalAccount wcm:action="add">
<DisplayName>Packer Admin</DisplayName>
<SynchronousCommand wcm:action="add">
<CommandLine>cmd.exe /c powershell -Command "Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Force"</CommandLine>
<Description>Set Execution Policy 64 Bit</Description>
<SynchronousCommand wcm:action="add">
<CommandLine>cmd.exe /c powershell -File a:\fixnetwork.ps1</CommandLine>
<Description>Fix public network</Description>
<SynchronousCommand wcm:action="add">
<CommandLine>cmd.exe /c powershell -File "a:\ConfigureRemotingForAnsible.ps1"</CommandLine>
<Description>Enable WinRM</Description>
<SynchronousCommand wcm:action="add">
<CommandLine>cmd.exe /c reg add "HKLM\System\CurrentControlSet\Control\Network\NewNetworkWindowOff"</CommandLine>
<Description>Network prompt</Description>
<settings pass="specialize">
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="" xmlns:xsi="">
"vm_name": "windows-10",
"type": "qemu",
"accelerator": "kvm",
"cpus": 1,
"memory": 4096,
"disk_size": 15360,
"iso_url": "Win10_1909_English_x64.iso",
"iso_checksum": "86c16116ebacf9b29e4766dd479b5a79",
"iso_checksum_type": "md5",
"output_directory": "qemu-drives",
[ "-drive", "file=qemu-drives/{{ .Name }},if=virtio,cache=writeback,discard=ignore,format=qcow2,index=1" ],
[ "-drive", "file=./virtio-win.iso,media=cdrom,index=3" ]
"communicator": "winrm",
"winrm_username": "packer",
"winrm_password": "packer",
"winrm_use_ssl": "true",
"winrm_insecure": "true",
"winrm_timeout" : "1h",
"shutdown_command": "shutdown /s /t 30 /f",
"shutdown_timeout": "15m"
Copy link

chrisoldwood commented Nov 15, 2022

Note: all the changes listed in these subsequent comments were the work of, not me, so please thank him 🙂 .

The following changes were made to the above config files when switching to booting via UEFI:


If you're building on Ubuntu you'll need the firmware package:

$ sudo apt install -y ovmf 


For the packer config we need to explicitly state what bios we're using (this assumes an Ubuntu based host) and also during boot time when no OS is initially installed we need to "press the enter key":

            "machine_type": "q35",

                [ "-bios", "/usr/share/OVMF/OVMF_CODE.fd" ],

            "boot_wait": "5s",
            "boot_command": [ "<enter>" ],

Note; the timing on how to long to wait before sending the keypress is quite sensitive, you can't be too quick or too slow. Also the machine_type may be unrelated, we were using libvirt to launch our VMs and this brought the defaults between packer and libvirt in-line.


The biggest change when switching to UEFI is the layout of the disk. Without it we have a single partition but with it we have many little partitions before the main one where we install the OS:

        <Disk wcm:action="add">
            <!-- System partition (ESP) -->
            <CreatePartition wcm:action="add">
            <!-- Microsoft reserved partition (MSR) -->
            <CreatePartition wcm:action="add">
            <!-- Windows partition -->
            <CreatePartition wcm:action="add">
            <!-- System partition (ESP) -->
            <ModifyPartition wcm:action="add">
            <!-- Windows partition -->
            <ModifyPartition wcm:action="add">
              <Label>Windows 10</Label>

Copy link

One other change which came in later was a simplification of the qemuargs -drive entries. In the early days if you added a -drive entry for the CDROM drive where the virtio drivers were located you also had to manually add any other -drive entries, such as for the main HDD. In later versions you can use -cdrom instead and let packer control the entry for the HDD:

                [ "-cdrom", "./virtio-win.iso" ]

Copy link

To enable remote access via SSH (as well as, or instead of PowerShell remoting) you can add the following to autounattend.xml:


        <SynchronousCommand wcm:action="add">
          <CommandLine>powershell -c "Add-WindowsCapability -Online -Name OpenSSH.Server~~~~"</CommandLine>
          <Description>Install OpenSSH server</Description>
        <SynchronousCommand wcm:action="add">
          <CommandLine>powershell -c "Set-Service -Name sshd -StartupType Automatic"</CommandLine>
          <Description>Set OpenSSH service to autostart</Description>
        <SynchronousCommand wcm:action="add">
          <CommandLine>powershell -c "Start-Service sshd"</CommandLine>
          <Description>Start OpenSSH server</Description>


Copy link

To enable a shared clipboard between host and guest when using the console, e.g. via virt-manager you need to install the SPICE agent:

            "type": "powershell",
                "$ErrorActionPreference = 'stop'",
                "# Install SPICE agent for shared clipboard",
                "(New-Object System.Net.WebClient).DownloadFile('', 'spice-vdagent.msi')",
                "Start-Process -FilePath msiexec -ArgumentList '/i spice-vdagent.msi /qn /norestart' -NoNewWindow -Wait",
                "Remove-Item spice-vdagent.msi"

Copy link

If you prefer to use the Git for Windows Bash implementation for the Windows-side shell for SSH you can enable it like so:

            "type": "powershell",
                "$ErrorActionPreference = 'stop'",
                "# Install Chocolatey package manager",
                "Invoke-Expression ((New-Object System.Net.WebClient).DownloadString(''))",
                "# Install git",
                "choco install git -y"
                "# Set bash as OpenSSH shell (as last step, in order not to interfere with powershell provisioners above)",
                "Set-ItemProperty -Path HKLM:\\SOFTWARE\\OpenSSH -Name DefaultShell -Value 'C:\\Program Files\\Git\\bin\\bash.exe' -Force"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment